IT Compliance ⏱ 12 min read 📅 September 2026 Carl Williams, NzingaNet Inc.

HIPAA violations can result in costly penalties, but the bigger risk for healthcare organizations is often the security gap that leads to the violation in the first place. Recent HIPAA enforcement actions have highlighted failures involving risk analysis, access controls, and protection of electronic protected health information (ePHI).

These issues often occur when organizations focus on having HIPAA documentation in place but do not regularly verify that their technology controls are working as intended. Employee training, written policies, and vendor agreements are important, but medical practices must also ensure users have appropriate access, backups can be restored, systems are monitored, and patient data is protected across every platform where it is stored or shared.

This HIPAA IT compliance checklist guide covers the key technical safeguards healthcare providers should review to identify security gaps, strengthen their cybersecurity posture, and support ongoing HIPAA compliance.

What Is HIPAA IT Compliance?

HIPAA IT compliance is the application of administrative, physical, and technical safeguards to protect electronic protected health information, commonly called ePHI.

ePHI includes individually identifiable health information that is created, received, maintained, or transmitted electronically. It may exist in an electronic health record, patient portal, email, backup, billing system, imaging platform, mobile device, cloud application services, telehealth system, or vendor environment.

The HIPAA Security Rule requires regulated entities to protect the:

  • Confidentiality of ePHI by preventing unauthorized access or disclosure
  • Integrity of ePHI by protecting it from improper alteration or destruction
  • Availability of ePHI by ensuring authorized users can access it when needed

The rule applies to covered entities and business associates. Its safeguards are designed to remain flexible enough for organizations of different sizes, structures, risks, and technical environments. Compliance therefore does not mean installing one prescribed security product. It requires a documented, risk-based program that is appropriate for the organization.

Infographic listing five common errors that risk HIPAA compliance, including unencrypted PHI storage and sharing data without a BAA.

What Changed for Healthcare Organizations in 2026?

Healthcare organizations need to separate current HIPAA obligations from proposed regulatory changes. While the healthcare industry continues to see increased focus on cybersecurity, not every announced update has become a mandatory requirement.

Overview diagram of current HIPAA Security Rule requirements, privacy notice updates, and proposed changes.

The Current HIPAA Security Rule Still Applies

The existing HIPAA Security Rule remains in effect. Although the U.S. Department of Health and Human Services (HHS) proposed significant updates in late 2024, those changes have not replaced the current rule.

Healthcare organizations must continue following the existing framework, including conducting risk analyses, implementing appropriate safeguards, controlling access to electronic protected health information (ePHI), and maintaining reasonable security measures based on their environment.

Privacy Notice Requirements Were Updated

Beginning February 16, 2026, certain HIPAA-covered entities, including applicable healthcare providers and health plans, must update their Notices of Privacy Practices to include required information related to substance use disorder records. These updates are separate from the proposed Security Rule changes and represent specific privacy obligations that covered organizations must address.

Proposed Security Rule Changes Require Preparation

The proposed HIPAA Security Rule updates would make cybersecurity requirements more specific and prescriptive. However, these changes should be viewed as preparation targets rather than current compliance requirements until HHS issues a final rule and establishes an effective compliance date.

Potential updates include:

  • Mandatory multifactor authentication with limited exceptions
  • Broader encryption requirements
  • Annual compliance reviews
  • Vulnerability scanning at least every six months
  • Annual penetration testing
  • Network segmentation requirements
  • More detailed contingency planning requirements

Healthcare organizations can use these proposed changes as a roadmap for improving security maturity, but they should not describe proposed requirements as current HIPAA obligations.

Security Area Current HIPAA Security Rule Proposed Security Rule Changes
Risk Analysis Organizations must conduct an accurate and thorough risk analysis based on their specific environment and security risks. More detailed written risk analyses performed at least annually are proposed.
Multifactor Authentication (MFA) Required based on an organization's risk assessment and applicable security safeguards. Broad MFA requirements with limited exceptions are proposed.
Encryption Considered an addressable safeguard that organizations implement based on their risk analysis. Encryption would become required with limited exceptions.
Vulnerability Scanning Frequency is determined based on organizational risk and security needs. Vulnerability scanning at least every six months is proposed.
Penetration Testing No universal testing frequency is currently required under HIPAA. Annual penetration testing is proposed.
Compliance Audits HIPAA does not currently require a universal annual compliance audit. Annual compliance audits are proposed.

For healthcare organizations, the practical takeaway is simple: continue meeting current HIPAA obligations while preparing for a more security-focused regulatory environment. Strong access controls, MFA, encryption, vulnerability management, and tested recovery processes are valuable investments regardless of when future requirements become final.

HIPAA IT Compliance Checklist for 2026

Process diagram detailing ten essential steps to strengthen HIPAA IT compliance in 2026.

1. Define Security Ownership and Responsibilities

HIPAA compliance requires more than having security policies on paper. Healthcare organizations need clear ownership over the decisions, processes, and safeguards that protect electronic protected health information (ePHI).

Start by identifying who is responsible for managing the organization's security program. This may be an internal IT leader, compliance officer, security team, or an external technology partner. Regardless of who performs the work, the organization should know who is accountable for making decisions and verifying that security controls are working.

Security responsibilities should cover areas such as:

  • Performing and updating risk analyses
  • Approving user access
  • Reviewing security alerts
  • Managing vendors with access to ePHI
  • Coordinating incident response
  • Overseeing backups and recovery processes
  • Maintaining HIPAA documentation

Many healthcare organizations rely on MSPs (Managed Service Providers), cloud providers, EHR vendors, or security consultants. These partners can help manage security tasks, but they do not remove the organization's responsibility to oversee its compliance program.

Review:

  • Who owns HIPAA security decisions?
  • Who approves access to patient information?
  • Who reviews security risks and remediation efforts?
  • Are responsibilities documented and reviewed regularly?

2. Map Every Location and Flow of ePHI

Before an organization can secure patient information, it must understand where that information exists and how it moves through the environment.

Many healthcare organizations focus only on their EHR system and overlook other locations where ePHI may be stored or transmitted. Patient information can exist in email accounts, cloud storage, billing platforms, telehealth applications, imaging systems, mobile devices, backups, and vendor platforms.

Create an inventory that identifies:

  • Systems that store ePHI
  • Applications that process patient information
  • Users and vendors with access
  • Data exchanged between systems
  • Locations where backups are stored

A data flow review helps uncover security gaps, such as patient records stored in unauthorized applications, outdated user access, or vendors with unnecessary permissions.

Review:

  • Where does ePHI enter the organization?
  • Which systems store or process it?
  • Who can access it?
  • Which vendors handle or transmit it?

HHS states that the risk analysis must consider all ePHI the organization creates, receives, maintains, or transmits, including ePHI handled through external vendors and consultants.

3. Identify and Prioritize Security Risks

A risk analysis is not simply a vulnerability scan or a completed questionnaire. It should evaluate threats that could affect the confidentiality, integrity, and availability of ePHI, including cyberattacks, unauthorized access, system failures, employee human error, cybersecurity mistakes, vendor risks, and operational disruptions.

The results should be turned into a risk management plan. Organizations should prioritize findings based on business impact and track remediation until issues are resolved or formally accepted.

Examples of risk remediation may include:

  • Enabling MFA for critical accounts
  • Removing unnecessary user permissions
  • Replacing unsupported systems
  • Improving backup protection
  • Updating vendor agreements
  • Strengthening monitoring capabilities

Review:

  • When was the last risk analysis completed?
  • Are identified risks assigned owners?
  • Are security improvements tracked over time?
  • Are major technology changes triggering new reviews?

4. Control Who Can Access Patient Information

Access controls determine who can view, modify, or manage ePHI. Poor access management can expose patient data even when other security tools are in place.

Healthcare organizations should ensure employees receive access based on their job responsibilities. A physician, receptionist, billing employee, IT administrator, and contractor should not automatically have the same level of access.

Review:

  • Employee accounts
  • Administrator privileges
  • EHR permissions
  • Remote access
  • Vendor accounts
  • Shared credentials
  • Inactive users
  • Former employee access

Strong authentication should also be part of the access strategy. MFA should be prioritized for high-risk areas such as administrator accounts, email platforms, remote access systems, and applications containing sensitive patient information. Account recovery processes should also be secured. Attackers may attempt to bypass MFA by convincing support teams to reset authentication methods without proper verification.

Review:

  • Does every user have an individual account?
  • Are permissions reviewed regularly?
  • Are privileged accounts protected with stronger controls?
  • Are terminated users removed quickly?

5. Secure the Technology Environment Supporting ePHI

Healthcare organizations depend on a wide range of technology to deliver care and operate efficiently. Every endpoint, application, and connection point can introduce risk if it is not properly maintained.

A secure healthcare environment should include:

  • Supported operating systems
  • Regular security updates
  • Endpoint protection
  • Email security controls
  • Firewalls
  • Secure wireless networks
  • Vulnerability management
  • Secure device configurations
  • Network segmentation where appropriate

Organizations should also consider how cloud applications and connected medical devices are secured. New technology should be reviewed before deployment to understand how it handles patient information and integrates with existing systems.

Security controls should not remain static. As organizations add new applications, locations, devices, and users, their security approach must evolve.

Review:

  • Are all devices documented and managed?
  • Are unsupported systems still in use?
  • Are security tools deployed consistently?
  • Are new applications reviewed before use?

6. Protect Patient Data and Prepare for Recovery

Protecting ePHI requires more than preventing unauthorized access. Healthcare organizations must also ensure patient information remains available during disruptions.

Encryption helps protect sensitive information stored on devices, servers, databases, and cloud platforms. Organizations should evaluate where encryption is needed based on their risk analysis and document their decisions.

Backup and recovery processes are equally important. A backup strategy should answer:

  • What data is backed up?
  • How often are backups performed?
  • Where are backups stored?
  • Who can access backup systems?
  • How quickly can systems be restored?

Regular recovery testing is essential. A backup that completes successfully but cannot restore critical systems during an outage provides limited protection.

Review:

  • Are backups protected from unauthorized access?
  • Are restoration tests performed?
  • Can critical systems be recovered during downtime?
  • Are backup accounts secured?

The Security Rule requires technical policies and procedures that restrict ePHI access to authorized persons. The Privacy Rule's minimum-necessary standard also requires organizations to develop appropriate policies for their operations, subject to defined exceptions.

7. Monitor Systems to Detect Suspicious Activity

Security controls are only effective when organizations can identify problems quickly. IT security audit logs and monitoring help healthcare organizations understand what is happening across systems containing ePHI.

Organizations should collect and review activity from:

  • EHR systems
  • Cloud platforms
  • Administrator accounts
  • Remote access tools
  • File storage systems
  • Security platforms
  • Email systems

Monitoring should help identify unusual behavior, such as:

  • Access from unexpected locations
  • Excessive failed login attempts
  • Unauthorized privilege changes
  • Unusual patient record access
  • Suspicious data movement

Logging alone is not enough. Organizations need defined processes for reviewing alerts, investigating activity, and documenting outcomes.

Review:

  • Which systems generate security logs?
  • Who reviews suspicious activity?
  • How are alerts investigated?
  • Are findings documented?

8. Prepare Before a Security Incident Happens

Systems containing ePHI should generate logs that help organizations identify unusual activity. Review logging for:

  • EHR access
  • Administrator changes
  • Cloud sign-ins
  • File access
  • Failed login attempts
  • Remote connections

Collecting logs is only useful if someone reviews them and responds to suspicious activity.

9. Review Third-Party Access and Vendor Responsibilities

Healthcare organizations often depend on vendors that access or manage systems containing PHI. These relationships create additional compliance responsibilities. Maintain an updated vendor inventory that identifies:

  • Which vendors access PHI
  • What systems they access
  • Why access is required
  • What security responsibilities they have
  • Whether a Business Associate Agreement (BAA) is required

A signed BAA is important, but it does not replace vendor oversight. Organizations should understand how vendors protect information, report incidents, manage access, and handle data when the relationship ends.

Review:

  • Are all PHI-handling vendors identified?
  • Are BAAs current?
  • Is vendor access reviewed regularly?
  • Are vendor security responsibilities documented?

OCR's January 2026 cybersecurity guidance emphasizes enabling, configuring, and maintaining available security measures, including anti-malware, endpoint detection and response, and security information and event management tools where appropriate.

10. Maintain Documentation and Keep the Program Current

HIPAA compliance requires ongoing documentation that reflects actual security practices, not just written policies. Organizations should maintain records showing that security activities are performed, reviewed, and improved over time.

Important documentation includes:

  • Risk assessments
  • Security policies
  • Access reviews
  • Training records
  • Incident reports
  • Vendor agreements
  • Backup testing results
  • Security reviews
  • Remediation activities

Documentation helps demonstrate that the organization understands its risks and takes reasonable steps to address them.

HIPAA generally requires documentation to be retained for six years, but organizations should also ensure documents remain accurate as technology and business operations change.

Review:

  • Are policies updated when systems change?
  • Are employees trained regularly?
  • Are security decisions documented?
  • Can the organization demonstrate compliance activities?

What Documentation Should Be Ready for a HIPAA Compliance Audit?

Being audit ready requires more than having HIPAA policies stored in a folder. Auditors and regulators typically look for evidence that security practices are actually implemented, reviewed, and improved over time.

A healthcare organization should be able to demonstrate how it identifies risks, protects ePHI, manages access, monitors systems, responds to incidents, and oversees third-party vendors. Documentation should show not only what controls exist, but also who is responsible for them, when they were reviewed, and how effectiveness is verified.

An audit-ready documentation package should typically include:

Documentation Area Examples of Evidence
Risk Management Security risk analysis, risk register, remediation plans, corrective action records, accepted risk documentation
ePHI Inventory and Data Flow Asset inventory, applications containing ePHI, data flow diagrams, system ownership records
Access Management User access reviews, privileged account reports, onboarding and termination records, MFA coverage reports
Security Controls Patch reports, vulnerability assessments, endpoint protection reports, firewall reviews, security configuration records
Monitoring and Detection Audit log reviews, security alerts, investigation records, monitoring procedures
Backup and Recovery Backup reports, restoration test results, disaster recovery procedures, contingency testing records
Incident Response Incident response plan, security incident records, breach assessments, post-incident improvement actions
Vendor Management Business Associate Agreements, vendor inventory, security questionnaires, third-party risk reviews
Workforce Security Security awareness training records, policy acknowledgments, role-based training documentation
Governance and Policies Current policies, approval records, review schedules, version history, exception documentation

The goal is to create a clear connection between identified risks, implemented safeguards, ongoing reviews, and documented improvements. For example, if a risk assessment identifies excessive administrator access, an audit-ready organization should be able to show who reviewed the access, what changes were made, when they were completed, and how the organization verified the issue was resolved.

OCR's recent audit initiative focuses on selected Security Rule provisions relevant to hacking and ransomware. OCR also continued ransomware and risk-analysis enforcement through 2026, including four settlements announced in April affecting more than 427,000 people.

The strongest evidence connects each identified risk with an owner, safeguard, verification activity, and completed corrective action.

Checklist outlining ten practical steps healthcare organizations must take to prepare for a HIPAA audit.

Build a 90-Day HIPAA IT Improvement Plan

Improving HIPAA security does not happen by changing every control at once. A practical approach is to first understand where risks exist, then strengthen the most important safeguards, and finally verify that those improvements are working.

A 90-day improvement plan helps healthcare organizations move from identifying gaps to implementing measurable security improvements.

Days 1–30: Identify Risks and Establish Visibility

The first month should focus on understanding the current environment and identifying the areas that require attention. Key activities include:

  • Confirm security ownership and define responsibilities for compliance decisions.
  • Update the inventory of systems, devices, vendors, and locations where ePHI is stored or accessed.
  • Review Business Associate Agreements and identify vendors with access to patient information.
  • Complete or update the HIPAA security risk analysis.
  • Review user accounts, inactive accounts, shared accounts, and unnecessary access permissions.
  • Identify critical gaps involving backups, endpoint security, remote access, and authentication controls.

Goal: Build an accurate understanding of the organization's security posture and prioritize the risks that require immediate action.

Days 31–60: Strengthen Controls and Reduce Exposure

Once risks are identified, the next phase focuses on improving security controls and documenting the changes being made. Key activities include:

  • Remove unnecessary access and correct excessive permissions.
  • Strengthen administrator accounts and remote-access protections.
  • Review MFA coverage, encryption settings, patch management, and endpoint security controls.
  • Improve audit logging and monitoring processes for systems containing ePHI.
  • Update incident response, downtime, and contingency procedures.
  • Assign owners, deadlines, and tracking methods for remaining remediation efforts.

Goal: Reduce security gaps by implementing practical safeguards and creating accountability for ongoing improvements.

Days 61–90: Test, Validate, and Demonstrate Progress

The final phase focuses on proving that controls work as expected and preparing evidence that demonstrates ongoing compliance efforts. Key activities include:

  • Test restoration of critical systems and verify backup reliability.
  • Conduct an incident-response exercise to evaluate communication and recovery procedures.
  • Complete user access reviews and confirm appropriate permissions.
  • Review vendor security documentation and third-party responsibilities.
  • Close high-priority remediation items or formally document remaining risks.
  • Prepare a management report summarizing completed improvements, outstanding risks, responsible owners, and upcoming review dates.

Goal: Confirm that security improvements are effective and create a repeatable process for maintaining HIPAA IT compliance.

A 90-day improvement plan should be tailored to the organization's size, technology environment, clinical operations, and risk profile. It does not replace the need for a comprehensive HIPAA risk analysis, but it provides a structured path for turning identified gaps into measurable security improvements.

How to Evaluate a HIPAA IT Provider

Choosing a HIPAA-focused IT provider requires more than confirming that they support healthcare organizations. The right provider should help strengthen security controls, manage technology risks, and support compliance efforts while being clear that no vendor can guarantee HIPAA compliance on behalf of the organization.

Six-step flow chart outlining how to conduct a comprehensive HIPAA risk assessment for ePHI.

Before signing an agreement, evaluate how the provider approaches security, accountability, and ongoing support. Ask the provider:

  • Will you sign a Business Associate Agreement (BAA)? Confirm whether the provider will accept the responsibilities required when handling or accessing ePHI.
  • How will you identify and manage risks in our environment? A strong provider should explain how it reviews systems, applications, access points, vendors, and security gaps rather than simply installing tools.
  • What services are included and what responsibilities remain with us? Understand whether the agreement covers monitoring, patching, backups, endpoint protection, security reviews, incident support, and documentation.
  • How do you protect privileged access? Ask how administrator accounts are secured, whether MFA is required, how access is reviewed, and whether technician activity is logged.
  • How are security events identified and handled? The provider should explain who monitors alerts, how incidents are escalated, and how communication works during a security event.
  • How do you verify backup reliability? A provider should explain backup frequency, protection methods, retention, and how restoration tests are performed.
  • What reports and documentation will we receive? Ask whether the provider provides security reports, vulnerability findings, access reviews, backup reports, compliance documentation, and remediation tracking.
  • What is your incident notification process? Understand how quickly the provider reports suspected security incidents, what information is provided, and how responsibilities are divided during an investigation.
  • Which subcontractors or vendors can access our ePHI? Confirm whether third parties are involved and how their access and security responsibilities are managed.
  • How are our credentials, documentation, and data handled if we leave? A professional provider should have a clear offboarding process for returning documentation, removing access, and transferring operational information.

A reliable HIPAA IT provider should make shared responsibilities clear from the beginning. The healthcare organization, EHR vendor, cloud provider, security provider, and other technology partners may each control different parts of the environment. Without clearly defined ownership, important security tasks can be overlooked.

The goal is not simply to find a provider that offers HIPAA-related services. It is to choose a partner that can explain what it manages, what evidence it provides, and how it helps the organization continuously reduce risk.

Build a Stronger HIPAA IT Security Program With NzingaNet

NzingaNet helps healthcare organizations strengthen their IT security foundation through services such as HIPAA-focused assessments, security planning, managed IT support, access management, cloud services, backup and recovery, monitoring, reporting, and technical support. The goal is to help practices identify gaps, improve operational controls, and maintain better visibility into the systems that support patient information.

While technology providers can support implementation and ongoing management, HIPAA responsibility remains with the healthcare organization. We work alongside internal teams and leadership to help align technical safeguards, documentation, and processes with the organization's compliance requirements.

Schedule a HIPAA IT assessment to review your current security controls, identify improvement opportunities, and build a clearer path toward stronger ePHI protection.

Need Help Strengthening Your HIPAA IT Compliance?

NzingaNet helps healthcare organizations strengthen their IT security foundation through HIPAA-focused assessments, security planning, managed IT support, access management, cloud services, backup and recovery, monitoring, and reporting.

Schedule a Free Consultation →

COMMON QUESTIONS

Frequently Asked Questions

Is the proposed HIPAA Security Rule in effect in 2026?

No. HHS has proposed substantial updates, but the current Security Rule remains in effect while rulemaking continues. Healthcare organizations should comply with the current rule and may use the proposal to prepare for stronger future expectations without describing proposed controls as existing legal requirements.

How often must a HIPAA risk analysis be completed?

The current rule requires an accurate and thorough risk analysis but does not set one universal annual schedule for every organization. The process should remain ongoing and be updated when environmental, operational, or technical changes could affect the security of ePHI.

Are addressable safeguards optional?

No. The organization must assess each addressable specification, implement it when reasonable and appropriate, use an appropriate alternative where justified, or document why neither measure is reasonable and appropriate. The decision must be based on the organization's circumstances and risk analysis.

Is encryption required under HIPAA?

Encryption is addressable under the current Security Rule. Organizations must evaluate whether it is reasonable and appropriate and document their decision. The proposed Security Rule would make encryption more broadly mandatory with limited exceptions, but that proposal is not yet final.

Is multifactor authentication required under HIPAA?

The existing rule does not contain a universal MFA mandate for every user and system. Organizations must implement appropriate access control and authentication safeguards based on risk. The proposed Security Rule would introduce a broader MFA requirement with limited exceptions.

Does Microsoft 365 make a medical practice HIPAA compliant?

No technology platform automatically makes an organization compliant. Compliance depends on the service arrangement, BAA, configuration, access controls, risk analysis, policies, monitoring, workforce practices, and actual use of the platform. HHS does not endorse or certify specific cloud technologies.

Which vendors need a Business Associate Agreement?

A vendor generally needs a BAA when it creates, receives, maintains, or transmits PHI on behalf of a covered entity or another business associate. The relationship and services determine the requirement. A cloud provider may be a business associate even when it stores only encrypted ePHI and cannot view the information.

How long should HIPAA IT documentation be retained?

Security Rule documentation must generally be retained for six years from the date it was created or the date it was last in effect, whichever is later. Other laws, contracts, or record-retention duties may require certain information to be retained longer.

Ready to Strengthen Your HIPAA IT Compliance?

NzingaNet helps healthcare organizations strengthen their IT security foundation through HIPAA-focused assessments, security planning, managed IT support, access management, cloud services, backup and recovery, monitoring, and reporting.