What HIPAA Documentation Should a Hospital Keep for Auditors? A Complete Checklist
When auditors arrive, they expect complete, well-organized HIPAA documentation that proves how you safeguard electronic protected health information (ePHI). Use this checklist to confirm that every required record is available, current, and mapped to the Security, Privacy, and Breach Notification Rules.
Your files should show that you assess risks, apply controls, monitor access, respond to incidents, and manage vendors—all aligned to ePHI confidentiality, integrity, and availability.
Risk Analysis and Management
Maintain a formal, enterprise-wide risk analysis that covers every location, workflow, device, application, and data flow that stores, processes, or transmits ePHI. Auditors will look for a repeatable method, clear scoring, and a documented risk management plan that drives remediation.
- Most recent enterprise risk analysis with scope, methodology, likelihood/impact scoring, and results.
- Risk register listing assets, threats, vulnerabilities, risk ratings, owners, target dates, and status.
- Risk management plan mapping each risk to selected controls and planned timelines.
- Evidence of remediation: tickets, screenshots/config baselines, change logs, and acceptance memos.
- Vulnerability scans and penetration test summaries with tracked fixes.
- Asset inventory of ePHI repositories and critical systems, plus current data flow diagrams.
- Executive review and approval sign-offs, including review cadence and triggers for updates (e.g., new EHR modules, cloud migrations, telehealth expansions).
Update the analysis after material changes and keep version history showing authors, approvers, effective dates, and what changed.
Written Policies and Procedures
Auditors expect written, implemented policies and procedures that match how you operate. Keep current, approved copies that staff can access and that you can demonstrate are followed in practice.
- Administrative, physical, and technical safeguard policies aligned to the HIPAA Security Rule.
- Access management: authorization, authentication, role-based access, provisioning/termination, and privileged access controls.
- Minimum necessary use/disclosure, workforce clearance, and sanctions policy.
- Device and media controls: inventory, reuse, disposal; workstation security; BYOD and remote access standards.
- Encryption and transmission security standards for data at rest and in transit, including email and texting with PHI.
- Change/configuration management procedures and secure development practices where applicable.
- Privacy practices, including uses/disclosures and accounting of disclosures procedures.
- HIPAA breach notification policy with decision-making workflow and documentation expectations.
- Policy distribution records and workforce attestations acknowledging receipt and understanding.
- Version control showing author, approver, effective date, and full revision history.
Workforce Training Records
Training proves your workforce knows how to protect ePHI and follow policy. Auditors test both completion and effectiveness, so document who was trained, on what, when, and how you handled gaps.
- Annual training plan and role-based curricula (privacy, security awareness, phishing, incident reporting, and job-specific modules).
- New-hire onboarding records with completion dates and orientation content.
- Proof of completion: LMS transcripts, sign-in sheets, and e-signature acknowledgments of policies.
- Knowledge checks or exam results with remediation for non-completion or low scores.
- Rosters showing attendee names, roles, dates, topics covered, and instructor or platform.
- Targeted communications for urgent updates (e.g., new EHR features, policy changes, phishing alerts) with distribution evidence.
Retain training documentation long enough to demonstrate sustained compliance and trend improvement over time.
Security Incident Reports
Keep a centralized register and a complete case file for each event. Security incident documentation should show rapid detection, effective response, transparent decisions, and corrective actions that stick.
- Initial report with date/time of discovery, systems and users affected, and a clear description.
- Triage, containment, eradication, and recovery steps with timestamps and responsible owners.
- For suspected exposure of unsecured PHI, a documented risk assessment and HIPAA breach notification actions (individual notices without unreasonable delay and no later than 60 days, plus HHS/media when required).
- Decision memo explaining whether the event met breach criteria and the rationale.
- Copies of notifications to individuals, HHS, media, and business associates, with dates and content.
- Collected evidence: logs, alerts, emails, screenshots, forensic notes, and chain-of-custody records.
- Root-cause analysis, corrective/preventive actions, verification of effectiveness, and ticket references.
- Lessons learned, policy/process updates, and leadership sign-off.
Track near-misses and attempted compromises as well; they demonstrate monitoring effectiveness and help auditors assess maturity.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.
Audit Logs and Reviews
Auditors expect procedures to regularly review records of information system activity. Show that you collect the right logs, analyze them, resolve anomalies, and keep evidence of the reviews themselves.
- EHR and application access logs capturing view, edit, export, and deletion events for ePHI.
- Authentication/authorization logs: successful/failed logins, MFA results, and privilege changes.
- Administrative activity logs for configuration changes, user provisioning, and security settings.
- Network, firewall, VPN, endpoint, database, and API logs correlated in a SIEM where feasible.
- Defined review cadence (e.g., near real-time alerts and daily checks for privileged events; weekly reviews for high-risk systems; monthly trend reports; quarterly access recertifications).
- Evidence of review: reports, case notes, tickets, and management sign-offs, including escalation outcomes.
- Time synchronization, log integrity/tamper-evidence, restricted access to log repositories, and backup of logs.
- An audit log retention standard aligned to policy—often six years to match broader HIPAA documentation timelines—plus any state or payer requirements.
If you adjust frequency or scope after an incident, document the rationale and the measurable results.
Contingency Planning Documentation
Contingency planning proves you can restore access to ePHI during disruptions. Auditors look for plans, roles, and repeatable contingency plan testing that validates your recovery objectives.
- Data backup plan covering scope, frequency, retention, encryption, and offsite/immutable storage.
- Disaster recovery plan detailing RTO/RPO targets, restoration runbooks, alternative sites, and vendor dependencies.
- Emergency mode operation plan describing how you maintain critical ePHI access during outages.
- Testing evidence: backup restore tests, failover/failback exercises, and tabletop drills with after-action reports and tracked remediation.
- Application and information criticality analysis that prioritizes recovery sequencing.
- Emergency access procedures, downtime forms/workflows, and communication trees with current contacts.
- Plan maintenance log with review dates, approvals, revisions, and training/awareness activities.
Business Associate Agreements
Every vendor that creates, receives, maintains, or transmits PHI must be governed by a written BAA. Auditors test both the contract language and your operational oversight for business associate agreement compliance.
- Executed BAAs for all applicable vendors, including cloud service providers and hosted EHR modules.
- Contract terms covering permitted uses/disclosures, required safeguards, breach reporting timeframes, and subcontractor flow-down requirements.
- Vendor due diligence files (security questionnaires, certifications, independent assessments) and documented risk tiering.
- Inventory mapping each vendor to systems, data types, and integrations, with designated business owners.
- Ongoing oversight: periodic reassessments, incident notices, corrective actions, and performance tracking.
- Termination steps, data return/destruction attestations, and documented change-control for amendments.
Keep these records current and centralized. Doing so lets you answer auditor questions quickly, demonstrate control over ePHI, and show continuous improvement across risk management, monitoring, incident response, and vendor oversight.
FAQs.
What is the required retention period for HIPAA documentation?
HIPAA requires you to retain required policies, procedures, and related documentation for six years from the date of creation or the date last in effect, whichever is later. Many hospitals align audit log retention, risk analyses, training records, and BAAs to this six-year standard, while honoring any longer state, payer, or litigation-hold requirements.
How should hospitals document workforce training for HIPAA compliance?
Record who was trained, on what content, when, and how you verified understanding. Keep curricula, slides or modules, LMS transcripts or sign-in sheets, policy acknowledgments, quiz results, and remediation plans for missed or failed training. Maintain rosters and completion metrics, and retain the full training record set for at least six years.
What types of security incidents must be reported and documented?
Document any attempted or successful unauthorized access, use, disclosure, modification, or destruction of information or interference with system operations. Examples include lost or stolen devices, misdirected emails/faxes, malware or ransomware, privilege misuse, EHR snooping, suspicious PHI exports, and outages affecting availability. If unsecured PHI may be compromised, perform a breach risk assessment and take HIPAA breach notification steps as required.
How often should audit logs be reviewed to ensure compliance?
HIPAA requires regular review but does not prescribe a fixed frequency. Use a risk-based cadence: near real-time alerting and daily checks for privileged or high-risk events, weekly reviews for critical ePHI systems, monthly trend reporting, and quarterly access recertifications. Always keep evidence of each review and the actions taken on exceptions.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.