Action Plan

HIPAA Action Plan: Eight Priorities to Verify

After the five-step orientation, use these eight implementation priorities to define the environment, analyze risk, improve safeguards, prepare evidence, test response, and keep the work current.

Eight connected HIPAA action checkpoints surrounding a documented compliance file
Core roadmap

Eight actions that work together

The five simple steps explain how to move through this ecosystem. These eight priorities organize the implementation work once gaps are known. A policy binder alone is not enough; the organization should be able to show how responsibilities, safeguards, evidence, testing, and corrective action operate.

1

Confirm scope and applicability

Determine regulated status and map PHI/ePHI, systems, workflows, devices, cloud services, locations, and vendors.

2

Conduct a risk analysis

Assess threats and vulnerabilities affecting the confidentiality, integrity, and availability of every ePHI location.

3

Manage and reduce risk

Prioritize findings, assign owners and deadlines, record decisions, and retain proof that corrective actions were completed.

4

Establish governance

Designate Privacy and Security Officials, approve procedures, manage complaints and sanctions, and retain required documentation.

5

Apply privacy controls

Address minimum necessary use, permitted disclosures, authorizations, Notices of Privacy Practices, and patient rights.

6

Implement security safeguards

Use administrative, physical, and technical controls for access, authentication, logs, integrity, transmission, facilities, and devices.

7

Train people and manage vendors

Use role-based access, workforce training, termination procedures, BAAs, due diligence, and documented vendor oversight.

8

Prepare, respond, and recover

Maintain incident response, breach assessment, notification, backups, disaster recovery, emergency operations, and periodic evaluation.

Implementation references: HHS Security Rule Summary, HHS Risk Analysis Guidance, and NIST SP 800-66 Rev. 2.

Evidence of compliance

Be ready to show that controls operate

Current records should connect policy, responsibility, technical operation, review, correction, and management decisions.

Governance and risk
  • PHI/ePHI scope, system inventory, and data-flow records
  • Current risk analysis and risk-management register
  • Approved policies, procedures, revisions, and decisions
  • Workforce training, acknowledgments, and access changes
  • Vendor inventory, due diligence, and executed BAAs
Operating proof
  • Access approvals, reviews, audit logs, and terminations
  • Configuration, patching, vulnerability, and safeguard evidence
  • Backup results, restore tests, and recovery exercises
  • Incident assessments, notifications, and lessons learned
  • Periodic evaluations and remediation tracking
Review rhythm

Keep the program current

HIPAA does not set one universal risk-analysis frequency. Review cadence should respond to the organization’s environment, changes, and risk.

Continuous or monthly

Security alerts, vulnerabilities, patch status, backup results, access events, and corrective actions.

Quarterly

Access reviews, vendor follow-up, remediation status, selected control tests, and evidence completeness.

Annually and after change

Update risk analysis as appropriate, review procedures and training, test contingency plans, and perform periodic evaluation.

Some substance-use-disorder records need an added review

If the organization handles records subject to 42 CFR Part 2, review the Part 2 final rule, consent and redisclosure workflows, breach duties, and Notice of Privacy Practices changes. HHS states that compliance with the 2024 final rule was required by February 16, 2026.

Review current HHS Part 2 guidance.

Small medical practices can continue with the HIPAA requirements for medical practices; dental teams can use the HIPAA compliance guide for dental offices.

Turn the action plan into verified work

OC Security Audit can assess safeguards, review risk and evidence, and perform technical validation such as a network vulnerability assessment or cybersecurity risk assessment where appropriate. A scan is one technical input; it does not independently establish HIPAA compliance. IT Perfection can support healthcare IT implementation and ongoing operations when findings require technical follow-through. Do not include PHI in an initial inquiry.