Skip to content

A practical HIPAA compliance checklist

By Sam Rivera, Founder, SentinelPanda · June 19, 2026 · 1 min read · HIPAA

HIPAA looks sprawling until you list it out. For a tech business associate it comes down to a risk analysis, the safeguards, BAAs, and a breach process — done and documented.

Foundation: scope and risk analysis

Begin by mapping where PHI lives and minimising it, then run a genuine security risk analysis of those systems — the keystone requirement and the first thing a regulator asks for. Everything downstream references it, so do it properly rather than as a formality.

The safeguards

  • Administrative: risk management, workforce training, access management, sanction policy, incident procedures, contingency plan.
  • Technical: unique logins and RBAC, audit logging, encryption in transit and at rest, MFA, integrity controls.
  • Physical: device management and secure disposal; inherit data-centre controls from your cloud provider's BAA.

Contracts and breach process

Execute BAAs with your healthcare customers and with every subcontractor that touches PHI. Stand up a breach/incident process that can assess whether PHI was compromised and meet the notification timelines (including notifying the covered entity). These are the HIPAA-specific pieces on top of your general security program.

Document and maintain

HIPAA is not a one-time project — keep the risk analysis, policies, training records, BAAs, and safeguard evidence current and reviewed. Most of this overlaps with SOC 2 and ISO 27001, so run it as one program. SentinelPanda maps the HIPAA safeguards to your controls and keeps the evidence audit-ready.

HIPAA security risk analysis HIPAA for SaaS and tech companies HIPAA vs SOC 2: do you need both?

Run your compliance program in one workspace.