Start by checking which HIPAA rules apply to your organization, then identify risks, assign responsibility and put the required safeguards into practice. These five steps help organize that work; completing a checklist alone does not establish compliance.
We’ll walk through each action, point out common traps, and show where Advatek can take the heavy lifting off your plate.
Handling health information alone does not make an organization a HIPAA covered entity. HHS identifies covered entities as health plans, health care clearinghouses and health care providers that transmit health information electronically in connection with HIPAA-standard transactions. Business associates are a separate category with their own applicable duties.
A billing company or IT provider may be a business associate when its work for a covered entity involves protected health information. Check the actual service and data relationship. A nursing home or home-health agency should assess its provider activities and covered transactions rather than relying on its business name.
A small practice can be covered, but merely emailing a lab result is not the test for covered-entity status. Document your activities and get qualified advice if the classification is unclear.
Document whether you are a covered entity, a business associate, both in different relationships, or outside HIPAA’s scope. Record the basis for that decision and the duties that apply. Other privacy laws and contractual obligations may still apply when HIPAA does not.
The regulation says every workforce member must be trained on policies that let them handle PHI safely.
For a regulated organization, workforce responsibilities depend on role and access. Business associates must address their own applicable obligations, including their workforce and subcontractors; a vendor is not automatically part of the customer’s workforce.
A risk analysis is the foundation of any compliance program. You need to identify threats to confidentiality, integrity, and availability of ePHI, then weigh how likely each threat is and what impact it could have.
Start by inventorying every system that stores or transmits PHI, EHRs, email servers, backup tapes, cloud apps. Map who accesses each system and why.
Next, look for known vulnerabilities: outdated software, weak passwords, unencrypted laptops. Use a scoring matrix to rank each risk as low, medium, or high.Document your findings in a written report. The report must show you’ve considered all three safeguards (administrative, physical, technical) and that you’ve taken steps to address high‑risk items.
The Department of Health and Human Services requires this analysis under 45 CFR § 164.308(a)(1)(ii). HIPAA risk assessment guidance provides a step‑by‑step checklist you can adapt. For additional professional support, HIPAA audit and risk assessment services can help your team identify gaps and prioritize practical fixes.
Set a review schedule that fits your risks, and reassess when systems, threats or operations change. HHS says the current Security Rule does not prescribe one fixed risk-analysis frequency. An annual review can be an internal policy, but it is not a universal legal interval.
Our team at Advatek runs automated scans and then layers expert review, so you get a risk report that’s both thorough and easy to act on.
After the assessment, you’ll know exactly where to focus your remediation budget.
For a quick reference, see How to Pass a HIPAA Security Audit: Step‑by‑Step Guide for audit‑ready documentation tips.
With risks identified, you can draft the policies that the HIPAA Security Rule expects. These fall into three categories: administrative, physical, and technical safeguards.
Administrative safeguards include a written security plan, workforce training, and a designated security officer. Physical safeguards cover facility access controls, device disposal, and workstation security. Technical safeguards involve encryption, access controls, audit logs, and transmission security.
| Safeguard Type | Key Controls |
|---|---|
| Administrative | Security policy, risk management, workforce training |
| Physical | Facility access, device & media controls, workstation security |
| Technical | Encryption, access controls, audit logs, integrity checks |
Each control should be written in plain language. For example, an access‑control policy might read: “All users must use multi‑factor authentication to access any system that contains ePHI.” Keep policies short enough that staff can read them without a legal dictionary.
Use encryption and MFA as part of a documented security plan. Under the current rule, encryption is an addressable implementation specification: assess whether it is reasonable and appropriate, implement it when it is, and document the required reasoning and any appropriate equivalent alternative when it is not. “Addressable” does not mean it can simply be ignored. MFA reduces password-related risk; it cannot prevent every intrusion.
Advatek offers 24/7 monitoring and AI security services. Agree which systems are monitored, how alerts reach your team and who responds. Detection tools can support incident response, but they cannot guarantee that every breach will be prevented.
When you finish drafting, get senior leadership to sign off. Their endorsement shows a culture of compliance.
Here’s a quick video that walks through the three safeguard categories:
After the video, review the draft with your security officer and make any needed tweaks.
For additional background, review this HIPAA overview.
Finally, store the policies in a secure, version‑controlled repository so you always know which edition is in effect.
When the policies are locked down, you’ll have a living document that grows with your organization.
Identify which vendors are business associates under the HHS definition. A BAA is generally needed for covered services involving PHI, including relevant subcontractors. Exceptions exist: a provider receiving information to treat a patient is not a business associate solely because of that disclosure.
Put the required BAA in place before a business associate handles PHI. Review permitted uses, safeguards, incident reporting and subcontractor duties. Security requirements in the service contract should match the work and risks. A signature alone does not show that the service is properly configured or operated.
Beyond the BAA, assess the vendor’s security posture. Do they run regular penetration tests? Do they have an incident‑response team? Advatek can run an independent security assessment on any vendor you plan to use.
When you onboard a new system, configure it to meet the technical safeguards you defined earlier: enable encryption at rest, enforce MFA, and set up logging that feeds into our 24/7 monitoring platform.
Review BAAs when services, responsibilities or legal requirements change. An annual contract review may be useful, but do not confuse your internal review schedule with a universal HIPAA deadline.
For a checklist of must‑have BAA clauses, see IT Support Service for Healthcare Service in Florida, USA.
Keep a master list of all vendors, their BAA status, and the date of the last review. This list is a key artifact during an HHS audit.
If you learn of a material breach or pattern of violations by a business associate, take reasonable steps to cure it or end the violation. If those steps fail, termination is required when feasible. Follow the applicable rule and obtain advice when termination is not feasible; adding an addendum alone does not cure an ongoing violation.
Advatek’s managed services include vendor risk management, so you never have to chase down a missing BAA on your own.
For more on securing cloud environments, see Managed IT Services and Security in South Florida.
Training is the human side of HIPAA. Every workforce member must know the policies that apply to their role, and they must receive refresher training when procedures change.
Start with a baseline module that covers the privacy rule, the security rule, and the consequences of a breach. Then branch into role‑specific tracks, clinical staff get a module on patient‑record handling, while IT staff focus on technical safeguards. A qualified provider can also help select and manage HIPAA security training for medical staff that fits each role and remains aligned with your policies.

After training, test knowledge with short quizzes. Set a clear passing threshold appropriate for your organization. Track results in a compliance dashboard.
Testing doesn’t stop at quizzes. Conduct regular simulated phishing attacks and audit log reviews to see if staff follow the policies in real time.
Monitoring needs a defined response process. Ask your IT provider which access events it can detect, what its reports contain and how quickly an authorized person investigates an alert. Test that process rather than treating the presence of AI as proof of compliance.
When you spot a gap, run a quick remediation sprint: update the policy, retrain the affected staff, and document the fix.
Schedule periodic compliance evaluations and additional reviews when your security environment changes. An annual audit can be a useful internal check. The HIPAA security audit guide can help organize the evidence, but passing a private audit does not guarantee compliance.
Keeping training fresh and controls tested turns compliance from a paperwork exercise into an everyday habit.

Advatek offers compliance and cybersecurity education. Confirm the delivery format, any LMS integration and how completion is documented before choosing a training program.
By now you should have a solid framework: you know if HIPAA applies, you’ve measured risk, you’ve written policies, you’ve locked down vendors, and you’re training people every year.
If your organization is subject to HIPAA, the Privacy Rule protects PHI in paper form as well as electronic form. The Security Rule specifically covers electronic PHI. Paper-only handling does not by itself answer whether the organization is a covered entity or business associate.
Make risk analysis ongoing and update it when circumstances warrant. HHS risk-analysis guidance says the current rule does not set one required frequency for every organization. Choose and document a review schedule that reflects your environment, and reassess material changes or incidents promptly.
A cloud provider’s role depends on what it does with PHI, not whether it calls itself a generic service. Before using a service to store or process ePHI on your behalf, confirm the applicable business-associate relationship, obtain the required BAA and assess the service’s safeguards and configuration.
Penalties depend on factors such as the level of negligence.
Ask Advatek to confirm the BAA, permitted data handling and safeguards for your specific service. A monitoring tool or marketing description cannot by itself establish HIPAA compliance. The organization and relevant business associates each remain responsible for their applicable obligations.
Ready to get started? Choose Advatek as your compliance partner, then follow the five steps above. Contact us today to schedule a free risk‑assessment kickoff.
Want to learn more about opening your own franchise? Fill out this form to get started: