Why a Defined Compliance Process Matters
OCR does not just check whether you have individual safeguards in place. They evaluate whether your organization follows a systematic, documented approach to protecting patient information. The Security Rule under 45 CFR 164.306(a) requires covered entities and business associates to ensure the confidentiality, integrity, and availability of all ePHI they create, receive, maintain, or transmit.
A defined process turns compliance from a guessing game into an operational system. Each step builds on the previous one. Skipping steps or addressing them out of order creates gaps that OCR specifically looks for during investigations.
If you are starting from scratch or unsure where your practice stands, our HIPAA starting point guide covers the first priorities. For a phased checklist approach, see the HIPAA starter checklist.
Eight Steps to HIPAA Compliance
Discovery & Scope Assessment
Identify the boundaries of your compliance program: which locations, systems, and workforce members handle PHI. Document your current state against the requirements of 45 CFR 164.306(a). This determines what the remaining seven steps need to cover.
Key deliverables: PHI inventory, system inventory, workforce roster, scope document.
HIPAA gap analysis servicesSecurity Risk Assessment
Conduct a thorough SRA as required by 45 CFR 164.308(a)(1)(ii)(A). Identify every system, device, and workflow that stores, transmits, or accesses ePHI. Document threats and vulnerabilities, rate risk levels, and create a prioritized remediation plan. This is the most commonly cited deficiency in OCR enforcement actions. See how the gap analysis and remediation plan are built from the SRA.
Key deliverables: Completed SRA report, risk register, remediation plan with timelines.
Security Risk Assessment requirements and processPolicy & Procedure Development
Develop written policies and procedures that comply with the Security Rule as required by 45 CFR 164.316(a). Policies must reflect how your practice actually operates, not how a generic template assumes you operate. At minimum, cover privacy, security management, access control, training, device controls, incident response, BAA management, facility access, contingency planning, and sanctions.
Key deliverables: Customized policy manual, procedure documents, adoption records.
HIPAA policy templates for small practicesWorkforce Training
Train every workforce member who handles PHI before they access patient information, as required by 45 CFR 164.308(a)(5)(i). Training must cover the Privacy Rule, Security Rule, breach reporting, phishing awareness, and your practice-specific policies. Document completion with signed attestations and schedule annual refresher training.
Key deliverables: Training curriculum, completion records, signed attestations, refresher schedule.
HIPAA training requirements and program detailsBAA Management
Identify every vendor and subcontractor that creates, receives, maintains, or transmits PHI on your behalf. Execute Business Associate Agreements as required by 45 CFR 164.502(e) and 164.308(b)(1). Maintain a current BAA inventory and review vendor compliance annually.
Key deliverables: Vendor inventory, executed BAAs, annual review schedule.
BAA management and vendor complianceIncident Response & Breach Preparedness
Establish an incident response plan covering breach identification, containment, risk assessment, notification timelines, and documentation. Meet the notification requirements of 45 CFR 164.404(b), 164.406, and 164.408. Conduct tabletop exercises so your team knows what to do before a breach occurs.
Key deliverables: Incident response plan, notification procedures, tabletop exercise records.
Incident response and breach managementEvidence Packaging & Documentation
Organize and retain all compliance documentation for at least six years as required by 45 CFR 164.530(j). This includes your completed SRA, written policies, training records, BAA inventory, incident reports, and remediation evidence. If OCR investigates, this documentation is your evidence of a systematic compliance effort.
Key deliverables: Organized compliance binder, document retention schedule, evidence index.
Documentation requirements and starting pointAnnual Review & Sustainment
Review and update your entire compliance program at least annually, as required by 45 CFR 164.530(a)(1) and 164.308(a)(2). Reassess risks when systems or workflows change, update policies accordingly, retrain staff, verify BAA currency, and test your incident response plan. Compliance is not a one-time project.
Key deliverables: Annual review report, updated SRA, policy revision log, training refresher records.
Vendor management and annual review servicesHow Long Does This Take?
For a small practice with 1 to 25 staff members, the initial compliance process typically takes 60 to 90 days when working with a consultant. Here is a realistic breakdown:
Steps 1 & 2
Discovery, scoping, and Security Risk Assessment
Steps 3 & 4
Policy development and workforce training
Steps 5 & 6
BAA management and incident response planning
Step 7
Evidence packaging and documentation organization
Step 8
Annual review and continuous sustainment
Timelines vary based on practice size, complexity, and existing documentation. Larger organizations or those with multiple locations may need additional time.
Two Ways to Work Through This
Self-Guided
Portal access with templates, training modules, and guided workflows. You work through each step at your own pace with built-in checklists and documentation tools.
View Plan DetailsFull-Scope Consulting
A Certified HIPAA Professional walks you through every step. Includes your SRA, custom policies, staff training, BAA review, and ongoing support.
View Plan DetailsHIPAA Compliance Process FAQ
HIPAA compliance generally follows eight steps: (1) Discovery and scope assessment under 45 CFR 164.306(a), (2) Security Risk Assessment under 45 CFR 164.308(a)(1)(ii)(A), (3) Policy and procedure development under 45 CFR 164.316(a), (4) Workforce training under 45 CFR 164.308(a)(5)(i), (5) BAA management under 45 CFR 164.502(e) and 164.308(b)(1), (6) Incident response and breach preparedness under 45 CFR 164.404(b), 164.406, and 164.408, (7) Evidence packaging and documentation under 45 CFR 164.530(j), and (8) Annual review and sustainment under 45 CFR 164.530(a)(1) and 164.308(a)(2). Each step builds on the previous one. Organizations should consult legal counsel for guidance specific to their situation.
For a small practice with 1 to 25 staff members, the initial compliance process typically takes 60 to 90 days when working with a consultant. Discovery and the Security Risk Assessment under 45 CFR 164.308(a)(1)(ii)(A) generally take the first three weeks. Policy development under 45 CFR 164.316(a) and training under 45 CFR 164.308(a)(5)(i) fill weeks three through six. BAA management and incident response planning typically complete by day 60, with documentation packaging finishing by day 75. Annual sustainment under 45 CFR 164.530(a)(1) is then ongoing. Timelines vary based on practice size, complexity, and existing documentation.
The first step is a discovery and scope assessment: identifying which locations, systems, workforce members, and vendors handle protected health information in your organization. This is grounded in the general requirements of 45 CFR 164.306(a), which require covered entities to ensure the confidentiality, integrity, and availability of all ePHI they create, receive, maintain, or transmit. Without understanding the boundaries of your compliance program, subsequent steps like the Security Risk Assessment under 45 CFR 164.308(a)(1)(ii)(A) cannot be scoped accurately.
A small practice can work through the compliance process independently using self-guided tools and templates. The regulatory requirements under 45 CFR Parts 160 and 164 apply regardless of whether a consultant is involved. Self-guided approaches work best for practices that have someone on staff with time to manage the process and familiarity with the Security Rule under 45 CFR 164.308 and the Privacy Rule under 45 CFR 164.530. Practices with limited internal resources or no prior compliance documentation may benefit from professional guidance to avoid common gaps in their Security Risk Assessment and policy development.
Learn More About HIPAA Compliance
Ready to Start Your Compliance Journey?
One Guy Consulting works directly with small practices to build HIPAA compliance programs from scratch. A Certified HIPAA Professional walks you through every step.
Book Your Free 30 Minute HIPAA Compliance Review