HIPAA Compliance for Nonprofit Healthcare Organizations: Requirements, Checklist, and Best Practices

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

HIPAA Compliance for Nonprofit Healthcare Organizations: Requirements, Checklist, and Best Practices

Kevin Henry

HIPAA

May 27, 2026

10 minutes read
Share this article
HIPAA Compliance for Nonprofit Healthcare Organizations: Requirements, Checklist, and Best Practices

HIPAA Applicability to Nonprofits

HIPAA applies to your organization based on what you do with health data—not on whether you are a nonprofit. If you provide healthcare services, process claims, run a health plan, or handle Protected Health Information (PHI) for others, you may be a covered entity or a business associate and must comply with HIPAA’s Privacy, Security, and Breach Notification Rules.

Common nonprofit examples include free and charitable clinics, community health centers, student-run clinics, disaster-relief medical programs, and charities offering telehealth, care coordination, or billing support. Even if only one program handles PHI, you may designate a “hybrid entity” so HIPAA applies to specific covered components while keeping unrelated programs separate.

At‑a‑Glance Nonprofit HIPAA Compliance Checklist

  • Confirm whether you are a covered entity, a business associate, or a hybrid entity.
  • Map PHI: where it is created, received, maintained, or transmitted (including cloud tools and mobile devices).
  • Complete formal Risk Assessments and implement risk management plans.
  • Adopt Administrative Safeguards, Physical Safeguards, and Technical Safeguards appropriate to your risks.
  • Execute and manage Business Associate Agreements with all vendors handling PHI.
  • Train your workforce, including volunteers and students, and maintain training records.
  • Establish Breach Notification Procedures and test your incident response.
  • Document policies, decisions, and evidence of ongoing monitoring and audits.

Avoid common pitfalls: assuming nonprofit status exempts you, overlooking volunteer access to ePHI, using donor tools for outreach without a compliant pathway, or relying on cloud defaults without encryption and access controls.

Covered Entities and Business Associates

Covered entities include health plans, healthcare clearinghouses, and healthcare providers that conduct standard electronic transactions (such as electronic claims or eligibility checks). If you fall into one of these categories and handle PHI, HIPAA applies directly to you.

Business associates are persons or organizations—consultants, IT providers, EHR vendors, billing services, fundraising service providers, data analytics firms—that create, receive, maintain, or transmit PHI for a covered entity. Subcontractors of business associates that handle PHI are also business associates and must comply under flow‑down obligations.

Many nonprofits operate mixed programs. If only certain departments handle PHI (for example, the clinic, but not the food pantry), formally designate covered components and segregate PHI. When nonclinical programs need information, use de-identified data or a limited data set with a Data Use Agreement instead of broad PHI sharing.

Privacy Rule Requirements

The Privacy Rule governs how you may use and disclose PHI and the rights individuals have regarding their information. Permitted uses without authorization include treatment, payment, and healthcare operations. For other purposes, obtain a valid authorization or rely on a specific permission in the Rule. Apply the Minimum Necessary standard to limit PHI access and disclosures to what is reasonably needed.

You must provide a clear Notice of Privacy Practices, uphold individual rights (access, amendments, accounting of disclosures, restrictions, and confidential communications), and respond to access requests promptly. Maintain appropriate safeguards to prevent impermissible uses or disclosures and to mitigate any harmful effects when incidents occur.

Fundraising and Communications

Nonprofits may use limited PHI for fundraising, such as demographic information and dates or departments of service, subject to strict conditions. Fundraising communications must offer a simple, free opt‑out and cannot be conditioned on treatment or payment. Do not include diagnosis or detailed clinical information unless the individual has expressly authorized it.

De‑identification and Limited Data Sets

To share data without HIPAA restrictions, remove identifiers using the safe harbor method or obtain expert determination that the risk of re‑identification is very small. When you need some identifiers (for research, public health, or planning), use a limited data set accompanied by a Data Use Agreement to control permitted uses and disclosures.

Security Rule Requirements

The Security Rule focuses on electronic PHI (ePHI) and requires safeguards that are reasonable and appropriate to your size, complexity, and risks. Implementation specifications are “required” or “addressable,” but addressable does not mean optional—you must implement them if reasonable or document why an alternative achieves equivalent protection.

Administrative Safeguards

  • Perform Risk Assessments, assign a security official, and manage workforce security and sanctions.
  • Define Information Access Management and the Minimum Necessary standard in policy and practice.
  • Provide ongoing security awareness and training, including phishing and social engineering.
  • Establish Security Incident Procedures and a Contingency Plan with backups and disaster recovery.
  • Evaluate your program periodically and when technology or operations change.

Physical Safeguards

  • Control facility access, especially for shared or volunteer-operated spaces.
  • Secure workstations and portable devices; prevent viewing by unauthorized persons.
  • Implement device and media controls for receipt, removal, reuse, and disposal; sanitize or destroy media containing ePHI.
  • Maintain an equipment inventory and chain of custody for devices storing ePHI.

Technical Safeguards

  • Enforce unique user IDs, strong authentication (preferably multi-factor), and automatic logoff.
  • Enable audit controls and routinely review logs for unusual access or exfiltration.
  • Protect integrity of ePHI and implement Transmission Security (e.g., TLS for data in transit, vetted encryption for data at rest).
  • Segment networks, restrict admin privileges, and keep systems patched and securely configured.

Encryption is considered an addressable control but is effectively expected given the prevalence of mobile devices and cloud storage. Using vetted encryption also provides safe harbor for certain lost-device incidents when PHI is rendered unusable, unreadable, or indecipherable to unauthorized persons.

Breach Notification Rule

A breach is an impermissible use or disclosure of unsecured PHI that compromises its security or privacy. Certain exceptions apply (for example, unintentional access by an authorized workforce member acting in good faith). When an incident occurs, conduct a risk assessment considering the nature of the PHI, who used or received it, whether it was actually viewed or acquired, and the extent of mitigation.

If a breach is reportable, notify affected individuals without unreasonable delay and no later than 60 calendar days from discovery. For incidents affecting 500 or more residents of a state or jurisdiction, notify the Department of Health and Human Services and prominent media; for fewer than 500 individuals, log incidents and report them to HHS annually. Business associates must notify the covered entity, providing the information needed for timely notices.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Breach Notification Procedures

  • Activate your incident response team and contain the incident; preserve evidence.
  • Complete the four‑factor risk assessment and determine if notification is required.
  • Provide written notices that describe what happened, the types of PHI involved, protective steps individuals should take, corrective actions taken, and contact information.
  • Offer mitigation where appropriate (for example, credit monitoring after certain exposures).
  • Document timelines, decisions, and remediation to support regulatory inquiries and improve defenses.

Business Associate Agreements

Execute Business Associate Agreements (BAAs) with every vendor or partner that handles PHI for your nonprofit—including EHR and billing vendors, cloud and email providers configured for PHI, telehealth and texting platforms, fundraising service providers using limited PHI, and data analytics firms. Do not permit PHI sharing until a compliant BAA is fully executed.

Essential BAA Clauses

  • Permitted and required uses/disclosures of PHI, consistent with your Minimum Necessary policies.
  • Safeguard obligations that mirror HIPAA’s Security Rule and require prompt incident reporting.
  • Subcontractor flow‑down: ensure downstream vendors agree to equivalent protections.
  • Breach Notification Procedures with clear timing, content, and cooperation requirements.
  • Right to audit, assistance with individual rights requests, and return or destruction of PHI at termination if feasible.
  • Allocation of responsibilities for access, amendments, accounting of disclosures, and data retention.

Perform vendor due diligence before signing—review security practices, data location, encryption, access controls, and the vendor’s track record. Reassess high‑risk vendors regularly and keep your BAA inventory and renewal dates current.

Risk Analysis and Management

Risk Assessments are foundational to HIPAA compliance. Inventory assets that create, receive, maintain, or transmit ePHI; map data flows; identify threats and vulnerabilities; and estimate likelihood and impact. Prioritize risks and implement controls proportionate to your nonprofit’s resources and operational reality.

Translate findings into a living risk management plan with owners, timelines, and budget. Address quick wins (for example, enabling MFA or encrypting laptops) while planning longer-term projects (such as network segmentation or centralized logging). Reassess after significant changes—new systems, mergers, telehealth expansion—or at planned intervals.

Practical Tips for Small Nonprofits

  • Use structured templates to document scope, methodology, findings, and decisions; keep evidence attached.
  • Combine vulnerability scanning with qualitative interviews to capture real‑world workflows.
  • Leverage recognized security practices and community frameworks to guide prioritization.
  • Maintain a concise risk register that leadership reviews at least quarterly.

Staff Training and Awareness

Your workforce includes employees, volunteers, students, contractors, and board members with access to PHI. Provide role‑based training at hire, when roles change, and periodically thereafter. Cover privacy principles, secure handling of PHI, incident reporting, phishing awareness, remote work expectations, and sanctions for violations.

Keep training short, practical, and scenario‑based. Reinforce with periodic micro‑lessons and phishing simulations. Maintain attendance records, copies of materials, and policy acknowledgments—these demonstrate compliance and help you identify areas needing extra attention.

Core Training Topics

  • Privacy Rule basics, Minimum Necessary, and permitted uses/disclosures.
  • Security Rule responsibilities: passwords, MFA, device security, and data handling.
  • Breach recognition and immediate reporting steps.
  • Safe communications: texting, email, telehealth, and working in public spaces.
  • Fundraising boundaries for PHI and honoring opt‑outs.

Documentation and Record-Keeping

HIPAA expects thorough documentation and retention (typically six years from the date of creation or last effective date). If it isn’t documented, regulators will treat it as not done. Keep policies and procedures current, versioned, and accessible to your workforce.

What to Maintain

  • Risk Assessments, remediation plans, and evidence of implemented controls.
  • Policies, procedures, and sanction records; Security Incident and Breach logs.
  • Notices of Privacy Practices, authorizations, and records of individual rights requests and responses.
  • Business Associate Agreements and vendor due‑diligence artifacts.
  • Training materials, attendance logs, and acknowledgments.
  • Device inventories, access reviews, backup and recovery tests, and audit reports.

Align documentation with daily operations. For example, pair access provisioning checklists with HR onboarding, and attach termination checklists to offboarding. Treat documents as living tools, not binders on a shelf.

Regular Audits and Monitoring

Build a cadence of internal audits to verify that policies match practice. Review user access to EHRs and shared drives, sample disclosures for Minimum Necessary compliance, and spot‑check encryption, patching, and logging. Validate that Breach Notification Procedures work through tabletop exercises and after‑action reviews.

Monitor continuously where feasible: security alerts, anomalous downloads, failed logins, and data loss prevention events. Conduct vendor performance reviews against BAA commitments. Report metrics to leadership and your board to drive accountability and resource allocation.

Suggested Audit Activities

  • Quarterly access reviews for high‑risk systems and privileged accounts.
  • Monthly log reviews or automated alerts for unusual access and data movement.
  • Annual policy attestations and targeted walk‑throughs of frontline workflows.
  • Periodic penetration testing and vulnerability scanning proportionate to your risk.
  • Annual BAA inventory review and vendor reassessments.

FAQs

What are the HIPAA requirements for nonprofit healthcare organizations?

They mirror those for any healthcare entity: follow the Privacy Rule for permitted uses/disclosures and individual rights; implement Security Rule safeguards for ePHI; honor the Breach Notification Rule; execute and manage Business Associate Agreements; conduct Risk Assessments and risk management; train the workforce; and document policies, decisions, and ongoing monitoring.

How should nonprofits handle Business Associate Agreements?

Identify every vendor that creates, receives, maintains, or transmits PHI and sign a BAA before sharing PHI. Ensure the BAA defines permitted uses, safeguards, breach reporting, subcontractor flow‑down, audit rights, and PHI return or destruction. Perform and document vendor due diligence and revisit high‑risk vendors regularly.

What training is required for staff to maintain HIPAA compliance?

Provide role‑based privacy and security training at hire, when roles or systems change, and periodically thereafter. Cover Minimum Necessary, secure handling of PHI, phishing and social engineering, incident reporting, and expectations for remote or mobile work. Keep records of attendance, content, and acknowledgments.

How often should risk assessments be conducted?

Complete a comprehensive Risk Assessment initially and revisit it regularly—at least annually for many nonprofits—and whenever there are major changes, such as new systems, telehealth expansion, mergers, or significant incidents. Update your risk register and remediation plan as threats, technologies, and operations evolve.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles