Free resource
HIPAA Security Rule Checklist
Every Administrative, Physical and Technical safeguard — Required and Addressable — plus breach notification. Work through it below, or download the CSV with status and evidence columns.
Administrative Safeguards (§164.308)
- Security management process — risk analysis, risk management, sanction policy, activity review (R)
- Assigned security responsibility — named Security Official (R)
- Workforce security & information access management (A)
- Security awareness and training (A)
- Security incident procedures — response and reporting (R)
- Contingency plan — backup, disaster recovery, emergency mode (R)
- Periodic evaluation (R)
- Business Associate Agreements in place (R)
Physical Safeguards (§164.310)
- Facility access controls (A)
- Workstation use policy (R)
- Workstation security (R)
- Device and media controls — disposal and re-use (R); accountability & backup (A)
Technical Safeguards (§164.312)
- Access control — unique user ID & emergency access (R); auto logoff & encryption (A)
- Audit controls — record and examine system activity (R)
- Integrity — authenticate ePHI (A)
- Person or entity authentication (R)
- Transmission security — integrity & encryption (A)
Breach Notification & Privacy
- Breach risk assessment & notification (individuals / HHS / media) (R)
- Notice of Privacy Practices and minimum-necessary policy (R)
(R) = Required, (A) = Addressable. Summarised from the HIPAA Security Rule (45 CFR Part 164, Subpart C) — see hhs.gov for the authoritative text. Not legal advice.
HIPAA Security Rule FAQ
- What is the HIPAA Security Rule?
- The HIPAA Security Rule (45 CFR Part 164, Subpart C) sets the standards for protecting electronic protected health information (ePHI). It is organised into three categories of safeguards — Administrative, Physical and Technical — each with standards and implementation specifications. This checklist lists every one, marked Required (R) or Addressable (A).
- What is the difference between Required and Addressable?
- Required specifications must be implemented as written. Addressable specifications are not optional — you must assess whether the specification is reasonable and appropriate for your environment, and either implement it, implement an equivalent alternative, or document why it is not reasonable and appropriate. "Addressable" is not "ignore".
- Is a HIPAA risk analysis mandatory?
- Yes. The risk analysis under the Security Management Process is a Required implementation specification and is the foundation of the whole Security Rule — it is also one of the most commonly cited gaps in OCR enforcement. You must conduct an accurate and thorough assessment of the risks to ePHI and then manage those risks. CATAAM helps by continuously proving the technical safeguards that a risk analysis depends on.
- Can CATAAM help with HIPAA?
- CATAAM automates and continuously verifies the technical and many administrative safeguards — access control, unique IDs, audit logging, encryption, transmission security, backups and vendor (business associate) management — and maps them to the Security Rule, so your checklist fills itself in with timestamped evidence instead of screenshots.
Prove your safeguards, don't screenshot them
CATAAM collects and maps the HIPAA technical safeguards automatically — access, audit logs, encryption, backups and business-associate coverage — continuous and timestamped.