Skip to main content
v2026.11,610 entries · CC-BY 4.0

The HIPAA Compliance Checklist for Research and Clinical Teams (What Actually Gets Audited)

A genuine, checklist-style walkthrough of what HIPAA’s Security and Privacy Rules actually require for research and clinical teams — administrative, physical, and technical safeguards, the breach-notification timeline, and the recurring failure points OCR audits flag most.

Ask about The HIPAA Compliance Checklist for Research and Clinical Teams (What Actually Gets Audited)

Answers are drawn from this guide and the rest of the CASRAI corpus, with a link to every source.

Answers are AI-generated from CASRAI’s own published pages and can be wrong, so check the linked sources before relying on one; your question is logged without personal data — never sold, never used to train a third-party model — to show us what CASRAI is missing, so please do not type personal or confidential details. How we use this

Written and maintained by CASRAI Editorial Board

Last updated

Most “HIPAA checklists” circulating online are marketing copy dressed up as a compliance tool — a dozen bullet points, no citation, and a form to fill in for a “free HIPAA audit.” This one is built the other way around: it walks through what 45 CFR Parts 160 and 164 actually require, organized the way HHS’s Office for Civil Rights (OCR) itself organizes an investigation, and it names the specific failure points OCR keeps citing in real enforcement actions. LAC Health’s standards glossary also carries a HIPAA primer aimed at procurement and supply-chain readers. If you never scroll past the safeguards section, this page has still done its job.

What “HIPAA Compliant” Actually Means

HIPAA doesn’t certify organizations or products as “compliant” the way a building gets a fire-code inspection sticker. There is no HHS seal of approval, and no vendor is “HIPAA compliant” on its own — compliance is a property of how protected health information (PHI) is actually handled inside a specific workflow. Two roles matter:

  • Covered entity — a health plan, health care clearinghouse, or health care provider that transmits health information electronically in connection with a standard transaction (45 CFR 160.103). Most academic medical centers, hospital-affiliated research units, and clinics running human-subjects research fall squarely into this category.
  • Business associate — any person or entity (not part of the covered entity’s own workforce) that creates, receives, maintains, or transmits PHI on the covered entity’s behalf, including subcontractors one layer removed. A cloud EDC vendor, a transcription service, a fax provider, and a statistical consultant working with identifiable data can all be business associates.

Every safeguard below exists to protect “protected health information” — individually identifiable health information, held or transmitted by a covered entity or business associate, that relates to a person’s past, present, or future physical or mental health, health care, or payment for health care (45 CFR 160.103). If your data has been properly de-identified under the Safe Harbor or Expert Determination method (45 CFR 164.514(a)-(b)), it’s no longer PHI and HIPAA’s requirements no longer attach to it — which is itself one of the most under-used compliance options on a research team’s checklist.

Administrative Safeguards: What Auditors Check First

The Security Rule (45 CFR 164.308) puts the administrative category first for a reason — OCR’s own post-audit reporting has repeatedly found that most investigated organizations are weakest here, not on the technology. A complete administrative safeguards checklist includes:

  • A documented risk analysis — an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI across every system that touches it, not a one-time exercise from years ago. This is currently OCR’s single most cited enforcement gap (more below).
  • Risk management — actual remediation measures that follow from the risk analysis, at a level that reduces risk to a reasonable and appropriate level, not just the analysis document sitting in a drawer.
  • A sanction policy — documented, applied consequences for workforce members who violate PHI policies, consistently enforced (a policy that exists but has never been invoked in the face of a known violation reads as unenforced to an auditor).
  • Information system activity review — regular review of audit logs, access reports, and security incident tracking, not just the capability to produce logs on request.
  • An assigned security official — one named individual responsible for developing and implementing security policies (see the compliance-officer question below).
  • Workforce security and information access management — role-based access so staff can reach only the PHI their role requires, with documented procedures for granting, changing, and — critically — terminating access.
  • Security awareness and training — periodic training for all workforce members with PHI access, including password management and awareness of phishing/social-engineering, not a single onboarding-day slide deck.
  • Security incident procedures — a written process for identifying, responding to, and documenting suspected or known security incidents.
  • A contingency plan — data backup, disaster recovery, and emergency-mode operation plans, tested rather than theoretical.
  • Business associate agreements (BAAs) — a written contract with every vendor that creates, receives, maintains, or transmits PHI on the covered entity’s behalf (45 CFR 164.502(e), 164.308(b)), executed before PHI ever flows to that vendor, not after.

See CASRAI’s dedicated business associate agreement guide for what a compliant BAA actually needs to contain in a research context.

Physical Safeguards

The physical category (45 CFR 164.310) covers the tangible environment PHI lives in — easy to overlook in a research unit that thinks of itself as “all digital,” but still a real audit line item:

  • Facility access controls — limiting physical access to the facilities and systems where PHI is housed to authorized personnel, with a documented process for validating that access.
  • Workstation use and workstation security policies — rules governing how workstations that can access PHI are used and physically secured (screen positioning in shared spaces, auto-lock timers, no shared logins on a lab computer that touches identifiable data).
  • Device and media controls — documented procedures for the receipt, removal, and final disposal of hardware and electronic media containing PHI, including a certified wipe or destruction step before a device is surplused or a drive is repurposed.

Technical Safeguards

The technical category (45 CFR 164.312) is where “addressable” versus “required” actually matters — an addressable specification isn’t optional, it means the organization must implement it, an equivalent alternative, or document why neither is reasonable and appropriate for its environment:

  • Access control — unique user identification for every person accessing ePHI (required, no shared logins), an emergency access procedure, and automatic logoff and encryption/decryption of ePHI at rest (addressable).
  • Audit controls — hardware, software, or procedural mechanisms that record and examine activity in systems containing ePHI.
  • Integrity controls — mechanisms to confirm ePHI hasn’t been improperly altered or destroyed.
  • Person or entity authentication — verifying that whoever is attempting to access ePHI is actually who they claim to be.
  • Transmission security — integrity controls and encryption (addressable) to guard against unauthorized access to ePHI while it’s in transit over an electronic network — the specification that governs email, upload, fax-over-IP, and every other channel PHI moves through.

What Counts as a HIPAA Administrative Safeguard vs. a Technical Safeguard?

The dividing line is whether the control is a policy/process/people question or a system/technology question. A risk analysis, a sanction policy, workforce training, and a BAA are administrative — they govern how the organization manages people and decisions. Encryption, audit logging, automatic logoff, and unique user IDs are technical — they’re implemented in the systems themselves. Physical safeguards sit in between: they’re about the physical environment (locked server rooms, workstation placement) rather than either policy or software. A single real-world control often has all three flavors at once — a compliant EDC platform, for instance, needs an administrative BAA in place, physical hosting-facility controls, and technical audit trails and encryption, all three, before it satisfies the Security Rule end to end.

Do We Need a Designated HIPAA Compliance Officer?

Yes, in two distinct roles that HIPAA requires by name — a covered entity must formally designate both, and a smaller research unit can have the same person hold both titles if that’s a genuine fit for its size:

  • Security official (45 CFR 164.308(a)(2)) — responsible for developing and implementing the Security Rule policies and procedures covering ePHI.
  • Privacy official (45 CFR 164.530(a)(1)) — responsible for developing and implementing the Privacy Rule policies and procedures generally.

For an academic medical center this is usually a dedicated compliance office; for a smaller research unit operating under a larger covered entity’s HIPAA program, it’s often an existing research administrator or IT security lead formally designated into the role — the requirement is a named, accountable person, not necessarily a new hire.

What Is the HIPAA Breach Notification Timeline?

The Breach Notification Rule (45 CFR Part 164, Subpart D) sets three separate clocks, all keyed to the date the breach was discovered, not the date it happened:

  • Individuals (45 CFR 164.404) — notified without unreasonable delay and no later than 60 calendar days after discovery.
  • Media (45 CFR 164.406) — required only when a breach affects more than 500 residents of a single state or jurisdiction, on the same 60-day clock.
  • HHS Secretary (45 CFR 164.408) — for breaches affecting 500 or more individuals, notice to HHS is contemporaneous with individual notice; for breaches under 500, the covered entity logs them and submits the log to HHS within 60 days after the end of the calendar year in which they were discovered.

A written breach-notification procedure that assigns who determines “discovery,” who runs the risk assessment on whether an impermissible disclosure actually rises to a reportable breach, and who owns each of the three notification clocks above is itself an administrative-safeguard requirement — and, per the section below, its absence is one of the things auditors flag most.

What Do HIPAA Auditors Actually Flag Most Often in Research Units?

OCR’s own audit and enforcement history points to a short, repeatable list — and a research unit’s version of it tends to cluster around a handful of specific, avoidable gaps:

  • No risk analysis, or a stale one. This is OCR’s current enforcement priority, expanded to also cover risk management follow-through — a risk analysis that predates a new system, a new vendor, or a new research protocol doesn’t cover that system, vendor, or protocol.
  • Missing or incomplete business associate agreements. A vendor is in place and PHI is already flowing before anyone confirms a signed BAA exists — one of the single most common findings across OCR settlements, and one of the easiest to fix before it’s ever an issue.
  • Access that was never reviewed or revoked. A departed research coordinator, a graduated student, or a rotated-off resident whose system access was never terminated shows up repeatedly in enforcement narratives — and it undermines every other control, since an auditor can’t verify who actually touched a record if access was never properly scoped in the first place.
  • No documented breach-notification procedure, or one that’s never been tested against a hypothetical incident — see the timeline above.
  • PHI still moving over an unencrypted or unmanaged channel. Personal email, a consumer file-sharing link, a shared office fax machine with no audit trail, or a workstation with no automatic logoff in a shared lab space are the concrete, everyday version of a transmission-security or access-control gap — the exact addressable specifications in the technical-safeguards section above.

Does Secure Online Fax Count as a Compliant PHI Transmission Method?

Fax is still a real part of the workflow in a lot of research and clinical settings — signed consent forms, referral paperwork, records requests, IRB correspondence with an outside site. The Security Rule doesn’t ban fax as a channel; it requires that whatever channel PHI moves through satisfy transmission security (45 CFR 164.312(e)) and that any vendor in that chain be under a signed BAA (45 CFR 164.502(e), 164.308(b)). A shared office fax machine sitting in an open hallway, printing an unattended physical page anyone can pick up, with no log of who sent or received what, fails on both the physical-safeguards and audit-controls fronts even though “fax” itself isn’t the problem.

Editorial disclosure: Some links on this page are CASRAI referral links. If you sign up through one, CASRAI may earn a commission at no extra cost to you — this helps fund our nonprofit mission. We only recommend tools our editorial team has independently researched, and we say plainly where a tool is not the right fit. Read our full disclosure policy →

Tip: try code CASRAI at checkout for 15% off, if the offer is currently active for this program — codes vary by vendor and aren’t guaranteed.

A secure online fax service closes the gaps a physical shared machine can’t: it puts PHI transmission behind a per-user login rather than an unattended tray, keeps a send/receive audit trail (satisfying the audit-controls specification above), encrypts in transit, and — the part teams most often skip checking — signs a BAA as a business associate before your first fax goes out. Fax.Plus is one option built around exactly that model: per-user accounts instead of a shared line, an audit trail per transmission, and a signed BAA available on request. It’s one line item on this checklist, not the whole page — if your team’s actual gap is the risk analysis or the access-review process above, fixing the fax line first won’t move the needle on those.

See Fax.Plus’s HIPAA-compliant plans →

For a deeper, vendor-by-vendor look at this specific line item, CASRAI’s existing HIPAA-compliant fax service comparison and Is Fax.Plus HIPAA Compliant? pages cover the buying decision in full — this page’s job is the checklist, not the vendor shortlist.

A Quick Self-Audit Worksheet

Before an actual OCR audit is the wrong time to find these gaps. A fast, honest pass through the list below catches most of what shows up in real enforcement actions:

  • Do we have a risk analysis dated within the last 12 months that covers every current system, vendor, and protocol touching PHI?
  • Is there a signed BAA on file for every vendor that creates, receives, maintains, or transmits PHI on our behalf — including ones added informally, like a consultant’s personal cloud-storage account?
  • Can we produce, right now, a list of everyone with active access to a PHI-containing system, and confirm every departed staff member’s access was revoked on their last day, not sometime after?
  • Do we have a named security official and privacy official, and would either of them recognize their role if asked?
  • Is there a written breach-notification procedure that names who determines discovery and who owns the 60-day clock?
  • Does every channel PHI moves through — email, upload, fax, courier — have an audit trail and a BAA behind it, or is at least one of them running on an untracked, unmanaged default?

A “no” or “not sure” on any of these is worth fixing before an audit forces the question — not because the fine is likely, but because each gap above is the concrete, documented version of a control HIPAA already requires you to have.

For related definitional grounding, see CASRAI’s dictionary entries on HIPAA and the HIPAA Privacy Rule, the 18 HIPAA identifiers and de-identification guide for the Safe Harbor method referenced above, and CASRAI’s broader HIPAA compliance software and compliance management software guides if your gap is tracking/documentation infrastructure rather than any single line item above.

Check Fax.Plus’s HIPAA plans →

Follow CASRAI

Research-administration guidance, standards updates and independent tool reviews.

Referenced across the research world

University of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logoUniversity of Cambridge logoColumbia University logoCrossref logoUniversity of Edinburgh logoHarvard University logoUniversity of Oxford logoPrinceton University logoStanford School of Medicine logoUniversity College London logoORCID logo
  • University of Cambridge logo
  • Columbia University logo
  • Crossref logo
  • University of Edinburgh logo
  • Harvard University logo
  • University of Oxford logo
  • Princeton University logo
  • Stanford School of Medicine logo
  • University College London logo
  • ORCID logo

View CASRAI adoption →

Regulatory Radar

Stop finding out after the fact

$29/month, cancel anytime. Daily digest updates from our analysis, a dashboard holding the same items, and a cited assistant for everything they raise.

  • Federal Register, Federal Register+, Grants.gov, Regulations.gov, NSF News, UKRI, plus CASRAI’s own published content.
  • 44,322 indexed passages, and every answer cites the ones it drew on.