OCR has driven most 2025–2026 enforcement actions against small practices through its Risk Analysis Initiative. Small practices with documentation gaps have paid five-figure settlements plus two years of federal oversight after a single breach.
This free 14-page checklist tells you — in under 30 minutes — exactly where you stand.
Each section maps to a specific set of HIPAA requirements under 45 CFR § 164. You'll answer Yes / Partial / No / Unknown — and every gap turns into a specific, fixable action item with references to the relevant regulations.
Risk analysis, risk management plan, workforce training, sanctions policies, termination procedures.
Workstation security, paper PHI storage, device inventory, encryption, visitor logs, secure destruction.
Unique logins, MFA, audit logs, encryption at rest and in transit, backups, patching, phishing training.
BAA inventory, signed agreements, security posture review, termination procedures.
Notice of Privacy Practices (Feb 2026 Part 2 update), Right of Access, amendment and restriction procedures.
Written plan, four-factor test, patient/HHS/media templates, tabletop exercise, cyber liability coverage.
Every page is built for a working medical office — fillable on screen, printable for a clipboard, scoreable in minutes. Navy and gold accents hold up on a laser printer. Three sample pages below.
Core documentation and controls are in place. Review annually.
Any single gap could become a finding. Focus on Admin, Technical, Breach Response.
Small practices here have paid five-figure settlements. Closable in 30–60 days.
A breach would likely result in findings and a corrective action plan.
The checklist shows you where the gaps are. The Complete HIPAA Compliance System gives you the documentation to close each one — attorney-drafted, practice-ready, no retainer required.
The full documentation pack — risk analysis template, risk management plan, Privacy & Security policies, Breach Response Kit, BAA templates, training materials, patient request logs, and the updated 2026 NPP.
The documents provided by Lifeline Compliance are attorney-developed templates for general informational and practice use only. They do not constitute legal advice and do not create an attorney-client relationship. Practices should consult qualified legal counsel for jurisdiction-specific compliance guidance, complex regulatory matters, or active government proceedings.
Copyright 2026 Highland Summit Consulting. All rights reserved.