A practical HIPAA compliance checklist
By Sam Rivera, Founder, SentinelPanda · June 19, 2026 · 1 min read · HIPAA
HIPAA looks sprawling until you list it out. For a tech business associate it comes down to a risk analysis, the safeguards, BAAs, and a breach process — done and documented.
Foundation: scope and risk analysis
Begin by mapping where PHI lives and minimising it, then run a genuine security risk analysis of those systems — the keystone requirement and the first thing a regulator asks for. Everything downstream references it, so do it properly rather than as a formality.
The safeguards
- Administrative: risk management, workforce training, access management, sanction policy, incident procedures, contingency plan.
- Technical: unique logins and RBAC, audit logging, encryption in transit and at rest, MFA, integrity controls.
- Physical: device management and secure disposal; inherit data-centre controls from your cloud provider's BAA.
Contracts and breach process
Execute BAAs with your healthcare customers and with every subcontractor that touches PHI. Stand up a breach/incident process that can assess whether PHI was compromised and meet the notification timelines (including notifying the covered entity). These are the HIPAA-specific pieces on top of your general security program.
Document and maintain
HIPAA is not a one-time project — keep the risk analysis, policies, training records, BAAs, and safeguard evidence current and reviewed. Most of this overlaps with SOC 2 and ISO 27001, so run it as one program. SentinelPanda maps the HIPAA safeguards to your controls and keeps the evidence audit-ready.