HIPAA Compliance Checklist for Merging Medical Practices

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

HIPAA Compliance Checklist for Merging Medical Practices

Kevin Henry

HIPAA

April 21, 2026

7 minutes read
Share this article
HIPAA Compliance Checklist for Merging Medical Practices

Merging organizations must safeguard Protected Health Information across every system, workflow, and location. This HIPAA Compliance Checklist for Merging Medical Practices gives you a clear, actionable path to keep care uninterrupted while preventing gaps that could lead to breaches or penalties.

Use it to coordinate IT, compliance, operations, and vendor teams so you maintain Privacy Rule Compliance and a defensible audit trail from pre-merger planning through post-merger stabilization.

Verifying Patient Data Security

Start by mapping where Protected Health Information lives and moves. Build a unified data inventory that names each system, data type, storage location, owner, permitted uses and disclosures, retention period, encryption state, and data flows between entities.

Confirm that security controls are consistent across both environments before any data exchange. Validate encryption in transit and at rest, role-based access, multi-factor authentication, audit logging, data loss prevention, and secure backup/restore processes.

  • Compile a single PHI data inventory and system-of-record with owners and lawful purposes.
  • Verify TLS for all transmissions and strong encryption for storage, including portable media and backups.
  • Harden identity and access management: unique user IDs, least privilege, and prompt deprovisioning.
  • Enable audit logs on all systems handling PHI; retain and review them routinely.
  • Create a secure migration plan with integrity checks, rollback steps, and after-action validation.
  • Scan legacy data for malware and sensitive data patterns before import; quarantine where needed.
  • Define recovery time and recovery point objectives and test restores from backups.
  • Deactivate and sanitize decommissioned systems; document destruction of media.

Ensuring Staff HIPAA Training

Unify training so every workforce member—employees, contractors, volunteers, and temps—understands the combined entity’s policies and daily practices. Cover Privacy Rule basics, minimum necessary use, secure messaging, disposal of PHI, and incident reporting.

Deliver role-based modules for clinicians, billers, front desk, research, and IT. Track completion, assessments, and attestations, and retain records for at least the HIPAA-required period.

  • Provide new-hire and merger-specific orientation before cutover to shared systems.
  • Assign annual refreshers and ad hoc training when policies or systems change.
  • Run phishing simulations and privacy rounding to reinforce real-world behaviors.
  • Train on EHR workflows, break-the-glass procedures, and secure telehealth practices.
  • Require signed confidentiality and sanction acknowledgments.
  • Maintain rosters, curricula, dates, scores, and attestations as auditable evidence.

Updating Business Associate Agreements

Identify every vendor that creates, receives, maintains, or transmits PHI and confirm a current Business Associate Agreement is in place. Validate the combined entity’s legal name, contact details, and whether assignment or novation is required due to the merger.

Each BAA should specify permitted uses/disclosures, required safeguards, breach reporting timelines, subcontractor flow-down, termination, and PHI return or destruction. Add practical terms such as encryption requirements, audit rights, incident cooperation, and evidence of security testing.

  • Build a complete vendor list and categorize by PHI access and criticality.
  • Close BAA gaps before data sharing; ensure no vendor operates on legacy terms that weaken protections.
  • Set breach notice windows and escalation paths; require subcontractor compliance.
  • Capture security artifacts (e.g., summaries of assessments) during due diligence.
  • Store fully executed BAAs and version history in a central, access-controlled repository.

Implementing Physical and Technical Safeguards

Align facilities and systems to a common baseline so protections are consistent regardless of where staff or devices are located. Address both Physical Safeguards and Technical Safeguards to prevent unauthorized access and ensure availability and integrity of PHI.

  • Physical Safeguards: control facility access with badges and visitor logs; secure server rooms; lock workstations; use privacy screens; protect and track mobile devices; manage device and media movement; shred or sanitize media before disposal.
  • Technical Safeguards: enforce MFA, role-based access, automatic logoff, and session timeouts; encrypt databases and endpoints; maintain centralized logging and security monitoring; segment networks and require VPN for remote access; patch systems promptly; deploy endpoint protection and email security; implement DLP and secure configuration baselines.

Document exceptions with compensating controls and remediation timelines, and review them during leadership risk meetings.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Reviewing Policies and Procedures

Eliminate conflicting rules by harmonizing policies across the new organization. Focus on Privacy Rule Compliance, minimum necessary standards, authorization and consent management, right of access, accounting of disclosures, sanctions, incident response, and breach notification.

Use version control and formal approvals. Communicate updates, require attestations, and keep retired versions and effective dates for audit readiness.

  • Notice of Privacy Practices, patient rights, and uses/disclosures of PHI.
  • Access management, device and media control, and remote work standards.
  • Change management, vendor management, and data retention/destruction.
  • Security incident response, disaster recovery, and business continuity.
  • Workforce training, monitoring, and sanctions procedures.

Securing Electronic Health Records

Standardize Electronic Health Record Security before consolidating charts or granting cross-entity access. Align templates, roles, and break-the-glass workflows, and verify patient identity proofing and portal processes to prevent account mix-ups.

Clean data going in, monitor activity continuously, and ensure downtime procedures support safe care if the EHR is unavailable.

  • Master Patient Index reconciliation and duplicate resolution with defined match thresholds.
  • Role-based access aligned to clinical need; restrict sensitive modules and research data.
  • Break-the-glass alerts with justification capture and post-access review.
  • Comprehensive audit trails with regular analytics on anomalous behavior.
  • Secure e-prescribing workflows with appropriate identity verification.
  • Patient portal account merges with MFA and validated contact details.
  • Backups, immutable copies, and tested recovery for databases and interfaces.
  • API access governance for third-party apps, including consent and scope management.

Conducting Comprehensive Risk Assessments

Perform and document a formal Risk Analysis tied to the merger. Evaluate threats, vulnerabilities, likelihood, and impact across people, processes, technology, facilities, and vendors, then prioritize remediation with owners and deadlines.

Refresh the assessment at key milestones: pre-integration, cutover, and post-integration, and update your risk register as controls mature or environments change.

  • Define scope, assets, data flows, and trust boundaries for both organizations.
  • Identify gaps in Technical Safeguards and Physical Safeguards and rate residual risk.
  • Create a remediation plan with budgets, timelines, and accountable leaders.
  • Track progress, evidence, and validation tests; escalate overdue items.
  • Retain the analysis, decisions, and evidence as defensible documentation.

By following this HIPAA Compliance Checklist for Merging Medical Practices, you reduce breach risk, maintain operational continuity, and create a consistent compliance posture across the combined entity.

FAQs.

How do you maintain HIPAA compliance during a medical practice merger?

Start with a single PHI inventory and data flow map, then align policies, access controls, and training to one standard. Update every Business Associate Agreement before sharing data, implement consistent Physical and Technical Safeguards, and complete a documented Risk Analysis. Assign owners, deadlines, and evidence requirements to each task, and track progress in a central register.

What are the key risk factors in merging practices under HIPAA?

The biggest risks are unknown PHI repositories, inconsistent user access, legacy systems lacking patches or encryption, and incomplete audit logging. Rushed data migrations, poor patient matching, weak vendor oversight, and inadequate workforce training also increase the chance of impermissible disclosures and downtime. A structured risk assessment and staged cutover help contain these risks.

How should business associate agreements be handled in mergers?

Inventory all vendors touching PHI and confirm each has a current Business Associate Agreement with the new legal entity. Verify permitted uses, required safeguards, breach notification timelines, subcontractor flow-down, termination, and PHI return or destruction. Update contact details and assignment or novation language as needed, add practical security clauses (e.g., encryption and audit rights), and store executed BAAs with version history for audit readiness.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles