September 10, 2026
HIPAA violations can result in costly penalties, but the bigger risk for healthcare organizations is often the security gap that leads to the violation in the first place. Recent HIPAA enforcement actions have highlighted failures involving risk analysis, access controls, and protection of electronic protected health information (ePHI).
These issues often occur when organizations focus on having HIPAA documentation in place but do not regularly verify that their technology controls are working as intended. Employee training, written policies, and vendor agreements are important, but medical practices must also ensure users have appropriate access, backups can be restored, systems are monitored, and patient data is protected across every platform where it is stored or shared.
This HIPAA IT compliance checklist guide covers the key technical safeguards healthcare providers should review to identify security gaps, strengthen their cybersecurity posture, and support ongoing HIPAA compliance.
- What Is HIPAA IT Compliance?
- What Changed for Healthcare Organizations in 2026?
- HIPAA IT Compliance Checklist for 2026
- What Documentation Should Be Ready for a HIPAA Compliance Audit?
- Build a 90-Day HIPAA IT Improvement Plan
- How to Evaluate a HIPAA IT Provider
- Build a Stronger HIPAA IT Security Program With NzingaNet
- Frequently Asked Questions
What Is HIPAA IT Compliance?
HIPAA IT compliance is the application of administrative, physical, and technical safeguards to protect electronic protected health information, commonly called ePHI.
ePHI includes individually identifiable health information that is created, received, maintained, or transmitted electronically. It may exist in an electronic health record, patient portal, email, backup, billing system, imaging platform, mobile device, cloud application services, telehealth system, or vendor environment.
The HIPAA Security Rule requires regulated entities to protect the:
- Confidentiality of ePHI by preventing unauthorized access or disclosure
- Integrity of ePHI by protecting it from improper alteration or destruction
- Availability of ePHI by ensuring authorized users can access it when needed
The rule applies to covered entities and business associates. Its safeguards are designed to remain flexible enough for organizations of different sizes, structures, risks, and technical environments. Compliance therefore does not mean installing one prescribed security product. It requires a documented, risk-based program that is appropriate for the organization.
What Changed for Healthcare Organizations in 2026?
Healthcare organizations need to separate current HIPAA obligations from proposed regulatory changes. While the healthcare industry continues to see increased focus on cybersecurity, not every announced update has become a mandatory requirement.
The Current HIPAA Security Rule Still Applies
The existing HIPAA Security Rule remains in effect. Although the U.S. Department of Health and Human Services (HHS) proposed significant updates in late 2024, those changes have not replaced the current rule.
Healthcare organizations must continue following the existing framework, including conducting risk analyses, implementing appropriate safeguards, controlling access to electronic protected health information (ePHI), and maintaining reasonable security measures based on their environment.
Privacy Notice Requirements Were Updated
Beginning February 16, 2026, certain HIPAA-covered entities, including applicable healthcare providers and health plans, must update their Notices of Privacy Practices to include required information related to substance use disorder records. These updates are separate from the proposed Security Rule changes and represent specific privacy obligations that covered organizations must address.
Proposed Security Rule Changes Require Preparation
The proposed HIPAA Security Rule updates would make cybersecurity requirements more specific and prescriptive. However, these changes should be viewed as preparation targets rather than current compliance requirements until HHS issues a final rule and establishes an effective compliance date.
Potential updates include:
- Mandatory multifactor authentication with limited exceptions
- Broader encryption requirements
- Annual compliance reviews
- Vulnerability scanning at least every six months
- Annual penetration testing
- Network segmentation requirements
- More detailed contingency planning requirements
Healthcare organizations can use these proposed changes as a roadmap for improving security maturity, but they should not describe proposed requirements as current HIPAA obligations.
| Security Area | Current HIPAA Security Rule | Proposed Security Rule Changes |
|---|---|---|
| Risk Analysis | Organizations must conduct an accurate and thorough risk analysis based on their specific environment and security risks. | More detailed written risk analyses performed at least annually are proposed. |
| Multifactor Authentication (MFA) | Required based on an organization's risk assessment and applicable security safeguards. | Broad MFA requirements with limited exceptions are proposed. |
| Encryption | Considered an addressable safeguard that organizations implement based on their risk analysis. | Encryption would become required with limited exceptions. |
| Vulnerability Scanning | Frequency is determined based on organizational risk and security needs. | Vulnerability scanning at least every six months is proposed. |
| Penetration Testing | No universal testing frequency is currently required under HIPAA. | Annual penetration testing is proposed. |
| Compliance Audits | HIPAA does not currently require a universal annual compliance audit. | Annual compliance audits are proposed. |
For healthcare organizations, the practical takeaway is simple: continue meeting current HIPAA obligations while preparing for a more security-focused regulatory environment. Strong access controls, MFA, encryption, vulnerability management, and tested recovery processes are valuable investments regardless of when future requirements become final.
HIPAA IT Compliance Checklist for 2026
1. Define Security Ownership and Responsibilities
HIPAA compliance requires more than having security policies on paper. Healthcare organizations need clear ownership over the decisions, processes, and safeguards that protect electronic protected health information (ePHI).
Start by identifying who is responsible for managing the organization's security program. This may be an internal IT leader, compliance officer, security team, or an external technology partner. Regardless of who performs the work, the organization should know who is accountable for making decisions and verifying that security controls are working.
Security responsibilities should cover areas such as:
- Performing and updating risk analyses
- Approving user access
- Reviewing security alerts
- Managing vendors with access to ePHI
- Coordinating incident response
- Overseeing backups and recovery processes
- Maintaining HIPAA documentation
Many healthcare organizations rely on MSPs (Managed Service Providers), cloud providers, EHR vendors, or security consultants. These partners can help manage security tasks, but they do not remove the organization's responsibility to oversee its compliance program.
Review:
- Who owns HIPAA security decisions?
- Who approves access to patient information?
- Who reviews security risks and remediation efforts?
- Are responsibilities documented and reviewed regularly?
2. Map Every Location and Flow of ePHI
Before an organization can secure patient information, it must understand where that information exists and how it moves through the environment.
Many healthcare organizations focus only on their EHR system and overlook other locations where ePHI may be stored or transmitted. Patient information can exist in email accounts, cloud storage, billing platforms, telehealth applications, imaging systems, mobile devices, backups, and vendor platforms.
Create an inventory that identifies:
- Systems that store ePHI
- Applications that process patient information
- Users and vendors with access
- Data exchanged between systems
- Locations where backups are stored
A data flow review helps uncover security gaps, such as patient records stored in unauthorized applications, outdated user access, or vendors with unnecessary permissions.
Review:
- Where does ePHI enter the organization?
- Which systems store or process it?
- Who can access it?
- Which vendors handle or transmit it?
HHS states that the risk analysis must consider all ePHI the organization creates, receives, maintains, or transmits, including ePHI handled through external vendors and consultants.
3. Identify and Prioritize Security Risks
A risk analysis is not simply a vulnerability scan or a completed questionnaire. It should evaluate threats that could affect the confidentiality, integrity, and availability of ePHI, including cyberattacks, unauthorized access, system failures, employee human error, cybersecurity mistakes, vendor risks, and operational disruptions.
The results should be turned into a risk management plan. Organizations should prioritize findings based on business impact and track remediation until issues are resolved or formally accepted.
Examples of risk remediation may include:
- Enabling MFA for critical accounts
- Removing unnecessary user permissions
- Replacing unsupported systems
- Improving backup protection
- Updating vendor agreements
- Strengthening monitoring capabilities
Review:
- When was the last risk analysis completed?
- Are identified risks assigned owners?
- Are security improvements tracked over time?
- Are major technology changes triggering new reviews?
4. Control Who Can Access Patient Information
Access controls determine who can view, modify, or manage ePHI. Poor access management can expose patient data even when other security tools are in place.
Healthcare organizations should ensure employees receive access based on their job responsibilities. A physician, receptionist, billing employee, IT administrator, and contractor should not automatically have the same level of access.
Review:
- Employee accounts
- Administrator privileges
- EHR permissions
- Remote access
- Vendor accounts
- Shared credentials
- Inactive users
- Former employee access
Strong authentication should also be part of the access strategy. MFA should be prioritized for high-risk areas such as administrator accounts, email platforms, remote access systems, and applications containing sensitive patient information. Account recovery processes should also be secured. Attackers may attempt to bypass MFA by convincing support teams to reset authentication methods without proper verification.
Review:
- Does every user have an individual account?
- Are permissions reviewed regularly?
- Are privileged accounts protected with stronger controls?
- Are terminated users removed quickly?
5. Secure the Technology Environment Supporting ePHI
Healthcare organizations depend on a wide range of technology to deliver care and operate efficiently. Every endpoint, application, and connection point can introduce risk if it is not properly maintained.
A secure healthcare environment should include:
- Supported operating systems
- Regular security updates
- Endpoint protection
- Email security controls
- Firewalls
- Secure wireless networks
- Vulnerability management
- Secure device configurations
- Network segmentation where appropriate
Organizations should also consider how cloud applications and connected medical devices are secured. New technology should be reviewed before deployment to understand how it handles patient information and integrates with existing systems.
Security controls should not remain static. As organizations add new applications, locations, devices, and users, their security approach must evolve.
Review:
- Are all devices documented and managed?
- Are unsupported systems still in use?
- Are security tools deployed consistently?
- Are new applications reviewed before use?
6. Protect Patient Data and Prepare for Recovery
Protecting ePHI requires more than preventing unauthorized access. Healthcare organizations must also ensure patient information remains available during disruptions.
Encryption helps protect sensitive information stored on devices, servers, databases, and cloud platforms. Organizations should evaluate where encryption is needed based on their risk analysis and document their decisions.
Backup and recovery processes are equally important. A backup strategy should answer:
- What data is backed up?
- How often are backups performed?
- Where are backups stored?
- Who can access backup systems?
- How quickly can systems be restored?
Regular recovery testing is essential. A backup that completes successfully but cannot restore critical systems during an outage provides limited protection.
Review:
- Are backups protected from unauthorized access?
- Are restoration tests performed?
- Can critical systems be recovered during downtime?
- Are backup accounts secured?
The Security Rule requires technical policies and procedures that restrict ePHI access to authorized persons. The Privacy Rule's minimum-necessary standard also requires organizations to develop appropriate policies for their operations, subject to defined exceptions.
7. Monitor Systems to Detect Suspicious Activity
Security controls are only effective when organizations can identify problems quickly. IT security audit logs and monitoring help healthcare organizations understand what is happening across systems containing ePHI.
Organizations should collect and review activity from:
- EHR systems
- Cloud platforms
- Administrator accounts
- Remote access tools
- File storage systems
- Security platforms
- Email systems
Monitoring should help identify unusual behavior, such as:
- Access from unexpected locations
- Excessive failed login attempts
- Unauthorized privilege changes
- Unusual patient record access
- Suspicious data movement
Logging alone is not enough. Organizations need defined processes for reviewing alerts, investigating activity, and documenting outcomes.
Review:
- Which systems generate security logs?
- Who reviews suspicious activity?
- How are alerts investigated?
- Are findings documented?
8. Prepare Before a Security Incident Happens
Systems containing ePHI should generate logs that help organizations identify unusual activity. Review logging for:
- EHR access
- Administrator changes
- Cloud sign-ins
- File access
- Failed login attempts
- Remote connections
Collecting logs is only useful if someone reviews them and responds to suspicious activity.
9. Review Third-Party Access and Vendor Responsibilities
Healthcare organizations often depend on vendors that access or manage systems containing PHI. These relationships create additional compliance responsibilities. Maintain an updated vendor inventory that identifies:
- Which vendors access PHI
- What systems they access
- Why access is required
- What security responsibilities they have
- Whether a Business Associate Agreement (BAA) is required
A signed BAA is important, but it does not replace vendor oversight. Organizations should understand how vendors protect information, report incidents, manage access, and handle data when the relationship ends.
Review:
- Are all PHI-handling vendors identified?
- Are BAAs current?
- Is vendor access reviewed regularly?
- Are vendor security responsibilities documented?
OCR's January 2026 cybersecurity guidance emphasizes enabling, configuring, and maintaining available security measures, including anti-malware, endpoint detection and response, and security information and event management tools where appropriate.
10. Maintain Documentation and Keep the Program Current
HIPAA compliance requires ongoing documentation that reflects actual security practices, not just written policies. Organizations should maintain records showing that security activities are performed, reviewed, and improved over time.
Important documentation includes:
- Risk assessments
- Security policies
- Access reviews
- Training records
- Incident reports
- Vendor agreements
- Backup testing results
- Security reviews
- Remediation activities
Documentation helps demonstrate that the organization understands its risks and takes reasonable steps to address them.
HIPAA generally requires documentation to be retained for six years, but organizations should also ensure documents remain accurate as technology and business operations change.
Review:
- Are policies updated when systems change?
- Are employees trained regularly?
- Are security decisions documented?
- Can the organization demonstrate compliance activities?
What Documentation Should Be Ready for a HIPAA Compliance Audit?
Being audit ready requires more than having HIPAA policies stored in a folder. Auditors and regulators typically look for evidence that security practices are actually implemented, reviewed, and improved over time.
A healthcare organization should be able to demonstrate how it identifies risks, protects ePHI, manages access, monitors systems, responds to incidents, and oversees third-party vendors. Documentation should show not only what controls exist, but also who is responsible for them, when they were reviewed, and how effectiveness is verified.
An audit-ready documentation package should typically include:
| Documentation Area | Examples of Evidence |
|---|---|
| Risk Management | Security risk analysis, risk register, remediation plans, corrective action records, accepted risk documentation |
| ePHI Inventory and Data Flow | Asset inventory, applications containing ePHI, data flow diagrams, system ownership records |
| Access Management | User access reviews, privileged account reports, onboarding and termination records, MFA coverage reports |
| Security Controls | Patch reports, vulnerability assessments, endpoint protection reports, firewall reviews, security configuration records |
| Monitoring and Detection | Audit log reviews, security alerts, investigation records, monitoring procedures |
| Backup and Recovery | Backup reports, restoration test results, disaster recovery procedures, contingency testing records |
| Incident Response | Incident response plan, security incident records, breach assessments, post-incident improvement actions |
| Vendor Management | Business Associate Agreements, vendor inventory, security questionnaires, third-party risk reviews |
| Workforce Security | Security awareness training records, policy acknowledgments, role-based training documentation |
| Governance and Policies | Current policies, approval records, review schedules, version history, exception documentation |
The goal is to create a clear connection between identified risks, implemented safeguards, ongoing reviews, and documented improvements. For example, if a risk assessment identifies excessive administrator access, an audit-ready organization should be able to show who reviewed the access, what changes were made, when they were completed, and how the organization verified the issue was resolved.
OCR's recent audit initiative focuses on selected Security Rule provisions relevant to hacking and ransomware. OCR also continued ransomware and risk-analysis enforcement through 2026, including four settlements announced in April affecting more than 427,000 people.
The strongest evidence connects each identified risk with an owner, safeguard, verification activity, and completed corrective action.

Build a 90-Day HIPAA IT Improvement Plan
Improving HIPAA security does not happen by changing every control at once. A practical approach is to first understand where risks exist, then strengthen the most important safeguards, and finally verify that those improvements are working.
A 90-day improvement plan helps healthcare organizations move from identifying gaps to implementing measurable security improvements.
Days 1–30: Identify Risks and Establish Visibility
The first month should focus on understanding the current environment and identifying the areas that require attention. Key activities include:
- Confirm security ownership and define responsibilities for compliance decisions.
- Update the inventory of systems, devices, vendors, and locations where ePHI is stored or accessed.
- Review Business Associate Agreements and identify vendors with access to patient information.
- Complete or update the HIPAA security risk analysis.
- Review user accounts, inactive accounts, shared accounts, and unnecessary access permissions.
- Identify critical gaps involving backups, endpoint security, remote access, and authentication controls.
Goal: Build an accurate understanding of the organization's security posture and prioritize the risks that require immediate action.
Days 31–60: Strengthen Controls and Reduce Exposure
Once risks are identified, the next phase focuses on improving security controls and documenting the changes being made. Key activities include:
- Remove unnecessary access and correct excessive permissions.
- Strengthen administrator accounts and remote-access protections.
- Review MFA coverage, encryption settings, patch management, and endpoint security controls.
- Improve audit logging and monitoring processes for systems containing ePHI.
- Update incident response, downtime, and contingency procedures.
- Assign owners, deadlines, and tracking methods for remaining remediation efforts.
Goal: Reduce security gaps by implementing practical safeguards and creating accountability for ongoing improvements.
Days 61–90: Test, Validate, and Demonstrate Progress
The final phase focuses on proving that controls work as expected and preparing evidence that demonstrates ongoing compliance efforts. Key activities include:
- Test restoration of critical systems and verify backup reliability.
- Conduct an incident-response exercise to evaluate communication and recovery procedures.
- Complete user access reviews and confirm appropriate permissions.
- Review vendor security documentation and third-party responsibilities.
- Close high-priority remediation items or formally document remaining risks.
- Prepare a management report summarizing completed improvements, outstanding risks, responsible owners, and upcoming review dates.
Goal: Confirm that security improvements are effective and create a repeatable process for maintaining HIPAA IT compliance.
A 90-day improvement plan should be tailored to the organization's size, technology environment, clinical operations, and risk profile. It does not replace the need for a comprehensive HIPAA risk analysis, but it provides a structured path for turning identified gaps into measurable security improvements.
How to Evaluate a HIPAA IT Provider
Choosing a HIPAA-focused IT provider requires more than confirming that they support healthcare organizations. The right provider should help strengthen security controls, manage technology risks, and support compliance efforts while being clear that no vendor can guarantee HIPAA compliance on behalf of the organization.

Before signing an agreement, evaluate how the provider approaches security, accountability, and ongoing support. Ask the provider:
- Will you sign a Business Associate Agreement (BAA)? Confirm whether the provider will accept the responsibilities required when handling or accessing ePHI.
- How will you identify and manage risks in our environment? A strong provider should explain how it reviews systems, applications, access points, vendors, and security gaps rather than simply installing tools.
- What services are included and what responsibilities remain with us? Understand whether the agreement covers monitoring, patching, backups, endpoint protection, security reviews, incident support, and documentation.
- How do you protect privileged access? Ask how administrator accounts are secured, whether MFA is required, how access is reviewed, and whether technician activity is logged.
- How are security events identified and handled? The provider should explain who monitors alerts, how incidents are escalated, and how communication works during a security event.
- How do you verify backup reliability? A provider should explain backup frequency, protection methods, retention, and how restoration tests are performed.
- What reports and documentation will we receive? Ask whether the provider provides security reports, vulnerability findings, access reviews, backup reports, compliance documentation, and remediation tracking.
- What is your incident notification process? Understand how quickly the provider reports suspected security incidents, what information is provided, and how responsibilities are divided during an investigation.
- Which subcontractors or vendors can access our ePHI? Confirm whether third parties are involved and how their access and security responsibilities are managed.
- How are our credentials, documentation, and data handled if we leave? A professional provider should have a clear offboarding process for returning documentation, removing access, and transferring operational information.
A reliable HIPAA IT provider should make shared responsibilities clear from the beginning. The healthcare organization, EHR vendor, cloud provider, security provider, and other technology partners may each control different parts of the environment. Without clearly defined ownership, important security tasks can be overlooked.
The goal is not simply to find a provider that offers HIPAA-related services. It is to choose a partner that can explain what it manages, what evidence it provides, and how it helps the organization continuously reduce risk.
Build a Stronger HIPAA IT Security Program With NzingaNet
NzingaNet helps healthcare organizations strengthen their IT security foundation through services such as HIPAA-focused assessments, security planning, managed IT support, access management, cloud services, backup and recovery, monitoring, reporting, and technical support. The goal is to help practices identify gaps, improve operational controls, and maintain better visibility into the systems that support patient information.
While technology providers can support implementation and ongoing management, HIPAA responsibility remains with the healthcare organization. We work alongside internal teams and leadership to help align technical safeguards, documentation, and processes with the organization's compliance requirements.
Schedule a HIPAA IT assessment to review your current security controls, identify improvement opportunities, and build a clearer path toward stronger ePHI protection.
Need Help Strengthening Your HIPAA IT Compliance?
NzingaNet helps healthcare organizations strengthen their IT security foundation through HIPAA-focused assessments, security planning, managed IT support, access management, cloud services, backup and recovery, monitoring, and reporting.
COMMON QUESTIONS
Frequently Asked Questions
PENNSYLVANIA & BEYOND
Ready to Strengthen Your HIPAA IT Compliance?
NzingaNet helps healthcare organizations strengthen their IT security foundation through HIPAA-focused assessments, security planning, managed IT support, access management, cloud services, backup and recovery, monitoring, and reporting.



![HIPAA IT Compliance Checklist for Medical Practices & Healthcare Providers [2026]](https://www.nzinganet.net/files/2026/09/healthcare-professionals-reviewing-patient-data-300x180.jpg)

