Step-by-Step HIPAA Compliance Checklist for PrEP Clinic Owners

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

Step-by-Step HIPAA Compliance Checklist for PrEP Clinic Owners

Kevin Henry

HIPAA

October 06, 2026

7 minutes read
Share this article
Step-by-Step HIPAA Compliance Checklist for PrEP Clinic Owners

This step-by-step HIPAA compliance checklist helps PrEP clinic owners build a practical, defensible program that protects Protected Health Information (PHI) while supporting fast, stigma‑free care. You will align your operations with the Privacy Rule, Security Rule, and Breach Notification Rule through clear tasks you can track and verify.

HIPAA Compliance Basics

1) Establish governance

  • Appoint a Privacy Officer and a Security Officer; define decision rights and escalation paths.
  • Adopt a written HIPAA program that covers Privacy, Security, and Breach Notification policies.

2) Map PHI across your clinic

3) Complete a Risk Assessment

  • Conduct a Security Rule risk analysis covering confidentiality, integrity, and availability of ePHI.
  • Rank risks, assign owners, and implement mitigation plans with due dates.

4) Implement HIPAA safeguards

Patient Privacy Requirements

Minimum necessary and permissible uses

Patient rights and communications

  • Provide a Notice of Privacy Practices (NPP) and honor requests for access within 30 days (one 30‑day extension if needed).
  • Support confidential communications (e.g., alternate address, email, or phone) and restrictions when feasible.
  • Verify identity before releasing PHI; log denials, amendments, and accountings of disclosures.

Authorizations and special situations

  • Obtain written authorization for marketing, most research disclosures, or non‑routine releases.
  • Use de‑identification or a limited data set with a Data Use Agreement for quality improvement and reporting when full PHI is unnecessary.

Confidentiality of HIV Data

  • Limit disclosure of HIV status, test orders/results, and sexual history to staff with a need to know; label records to prevent incidental exposure.
  • Plan around potential exposure via explanations of benefits (EOBs) by discussing risks and offering confidential communication options.
  • Design neutral appointment reminders and portal notifications that avoid revealing HIV‑related services.

Security Measures Implementation

Administrative Safeguards

  • Risk Assessment and risk management plan reviewed at least annually or after major changes.
  • Workforce security: background checks where appropriate, onboarding/offboarding checklists, sanctions policy.
  • Contingency planning: data backups, disaster recovery, and emergency operations testing.
  • Vendor management: BAAs, security questionnaires, and right‑to‑audit clauses for vendors handling ePHI.

Technical Safeguards

  • Access Controls: unique user IDs, role‑based access, least privilege, multi‑factor authentication, and automatic logoff.
  • Audit controls: enable EHR and system logs; review access reports and anomaly alerts on a defined cadence.
  • Integrity and transmission security: encryption at rest and in transit (e.g., TLS), anti‑malware, email security, and data loss prevention.
  • Device and app security: mobile device management, remote wipe, patching, and blocked USB mass storage.

Physical safeguards

  • Secure workstations and networking gear; restrict server/IT closet access; visitor sign‑in and escort.
  • Media controls: track, encrypt, and sanitize or destroy devices before reuse or disposal.

Operational checklist for ePHI

  • Harden EHR settings; restrict printing/exports; standardize secure patient messaging.
  • Configure telehealth platforms for privacy (waiting rooms, passcodes, recording disabled by default).
  • Validate lab and pharmacy portals; confirm least‑privilege accounts and time‑bound access.

Staff Training and Awareness

Training program

  • Provide HIPAA training at hire, when roles change, and at least annually; include privacy, security, and incident reporting.
  • Use PrEP‑specific case studies (e.g., discreet reminders, handling HIV results) and document comprehension with sign‑offs.
  • Run phishing simulations and tabletop exercises for breach response and downtime procedures.

Role clarity and accountability

  • Define who can see HIV‑related data; use job descriptions to anchor least‑privilege access.
  • Apply and record sanctions for violations consistently.

Documentation Practices

What to document

  • Policies/procedures, Risk Assessment reports, mitigation plans, and periodic evaluations.
  • Training logs, access reviews, incident/breach logs, and patient rights request logs.
  • BAAs, vendor due‑diligence artifacts, contingency plan tests, and change‑management records.

How to manage records

  • Use version control, effective dates, and approval signatures; keep documents retrievable within minutes during audits.
  • Adopt retention schedules that meet HIPAA and applicable state requirements; secure archives and track destruction.

Breach Notification Procedures

Immediate response

  • Contain the incident (isolate systems, revoke access, remote‑wipe devices) and escalate to your Security Officer promptly.
  • Preserve evidence: logs, emails, messages, and system snapshots.

Risk assessment and determination

  • Analyze the nature and extent of PHI, the unauthorized recipient, whether PHI was actually viewed/acquired, and mitigation actions.
  • If low probability of compromise is not demonstrated, treat the event as a breach under the Breach Notification Rule.

Notifications and timelines

  • Notify affected individuals without unreasonable delay and no later than 60 days after discovery; include what happened, types of PHI, steps they should take, your mitigation, and contact info.
  • Notify HHS; if 500 or more residents of a state/territory are affected, also notify prominent media and post on your website if contact info is insufficient.
  • For incidents under 500 individuals, log and submit to HHS annually; document all decisions and timelines.

Business Associate involvement

  • Require BAs to notify you of incidents promptly per the BAA; coordinate content and timing of notices.
  • Perform post‑incident remediation and update safeguards and training.

PrEP Clinic-Specific Considerations

Discreet communications and scheduling

  • Offer confidential communications at intake; use neutral language in calls, texts, emails, and calendar invites.
  • Verify safe contact methods before sending lab reminders or refill prompts.

Labs and results handling

  • Segment access to HIV/STI results; delay or route sensitive results through clinicians for context where appropriate.
  • Coordinate with labs on secure result delivery and test naming conventions that protect the Confidentiality of HIV Data.

Pharmacy and refills

  • Confirm e‑prescribing workflows avoid unnecessary disclosures; prefer discreet packaging for mail delivery.
  • Limit refill reminder content to the minimum necessary; authenticate identity before discussing medications.

TelePrEP and remote care

  • Verify patient identity and confirm they are in a private setting before sensitive discussions.
  • Disable platform recordings by default; store only necessary screenshots or files with proper encryption and access reviews.

Minors, dependents, and insurance

  • Explain EOB risks; offer confidential communications and payment alternatives when feasible.
  • Follow state privacy laws that may provide stronger protections for HIV or sexual health services.

Data for quality and outreach

  • Use de‑identified or limited data sets for dashboards and outreach planning; execute Data Use Agreements as needed.
  • Avoid including HIV status in event sign‑up forms unless essential; secure all contact lists as PHI if they can identify care.

Conclusion

By executing this HIPAA compliance checklist—solid governance, clear privacy practices, strong security controls, trained staff, provable documentation, and crisp breach response—you safeguard PHI, respect the Confidentiality of HIV Data, and keep PrEP access fast, safe, and stigma‑free.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

FAQs

What are the key HIPAA requirements for PrEP clinics?

Focus on a documented Risk Assessment, Administrative Safeguards (policies, training, contingency plans), Technical Safeguards (Access Controls, audit logging, encryption), Physical safeguards, and clear Privacy Rule procedures for minimum necessary, patient rights, and BAAs—plus a tested Breach Notification Rule process.

Restrict access to staff with a need to know, label sensitive results, use discreet communications, honor requests for confidential communications, avoid revealing services in reminders or billing details, and follow state laws that may impose stricter rules on the Confidentiality of HIV Data.

What steps are involved in a HIPAA breach notification?

Contain the incident, investigate, perform a breach risk assessment, determine if low probability of compromise exists, then notify affected individuals without unreasonable delay and within 60 days, notify HHS (and media for large breaches), document actions, and remediate controls.

When is staff training required for HIPAA compliance?

Provide HIPAA training at hire, when job duties or systems change, and at least annually. Include privacy, security, incident reporting, and PrEP‑specific scenarios, and record attendance and comprehension.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles