◆ traztech
HIPAA Audit Prep Checklist
For digital health and medtech selling into US hospitals, payers, and providers. Covers the Security Rule safeguards buyers and auditors look for.
HIPAA readiness is not the same as full HITRUST certification. Most digital health startups need defensible HIPAA safeguards plus SOC 2, run together so evidence is built once.
Administrative safeguards
- Security risk analysis completed and documented
- Named HIPAA security and privacy officers
- Workforce security training with records
- Business Associate Agreements (BAAs) in place with every vendor touching PHI
Technical safeguards
- Access controls and unique user IDs for anyone touching PHI
- Audit logging on PHI systems, reviewed regularly
- Encryption of PHI at rest and in transit
- Automatic logoff and session controls
Physical safeguards
- Device and media controls (encryption, wipe, inventory)
- Workstation security policy
- Facility access controls where applicable
Breach & incident
- Breach notification procedure meeting the 60-day rule
- Incident response plan covering unauthorized PHI access
- Documented sanctions policy for violations
Run it with SOC 2
- Map HIPAA safeguards to SOC 2 controls to avoid double work
- One evidence repository serving both
- Consider PIPEDA/PHIPA overlap if you have Canadian operations