Is Your Practice Audit-Ready? Find Out in 5 Minutes.

A 35-point HIPAA policy compliance checklist for small healthcare practices. Covers Privacy Rule, Security Rule, documentation requirements, and the common gaps auditors look for.

No spam. Unsubscribe anytime. We'll send you the checklist and a few follow-up tips — that's it.

What the checklist covers

  • 8 required Privacy Rule policies — Notice of Privacy Practices, patient access, breach notification, and more
  • 13 required Security Rule policies — Risk analysis, workforce security, access controls, encryption, and more
  • 7 documentation requirements — Retention periods, designated officers, training records
  • 7 common audit gaps — Social media policy, remote work, texting, portable devices
  • Scoring guide — Know where you stand before an auditor tells you

The most common audit finding isn't missing policies. It's staff who can't find them.

Most small practices have policies. They're in a binder, a shared drive, or an email from 2022.

The problem isn't documentation. It's accessibility.

This checklist helps you identify which policies you have, which you're missing, and whether your team can actually find them when it matters.

Found gaps? There's a faster way to fix them.

PolicyKeeper is an AI-powered compliance platform for small healthcare practices. Upload your HIPAA policies, and your staff can ask questions in plain English — "What's our breach notification procedure?" — and get instant answers with source citations.

No training. No searching through folders. Just answers.

Try PolicyKeeper Free

50 credits/month, no credit card required