What a HIPAA program actually needs
The whole program in one place: the twelve things a real HIPAA compliance program contains, what the rule says about each, what it takes to run it by hand in a clinic with thirty staff and no compliance officer, and how to tell whether yours is real.
Last verified: 2026-07-12
Everything else on this site explains one piece of the law. This page is the whole thing, assembled, from the perspective of somebody who has to actually run it on a Tuesday.
Here is the claim it rests on. A compliance program is not a set of documents. It is a set of habits that produce documents, and the documents are only worth what the habits behind them are worth. Which is why a clinic can own a beautiful binder and have no program, and why an investigator or a buyer can tell the difference in about ten minutes.
There are twelve parts. Each one has a rule behind it, an artifact it produces, and a way of quietly dying.
“A compliance program is not a set of documents. It is a set of habits that produce documents, and the documents are only worth what the habits behind them are worth”
1. The risk analysis
The rule: required (45 CFR 164.308(a)(1)(ii)(A)). An accurate and thorough assessment of the risks to all of your ePHI.
What it produces: an inventory of every system, device, app, and vendor that touches PHI; the threats against each; what safeguards you already have; and a rating of what is likely and what would hurt.
Why it is first: everything downstream is calibrated by it. The rule’s flexibility (45 CFR 164.306(b)) lets you choose measures appropriate to your size, your systems, your budget, and your risks, and you cannot invoke that flexibility about risks you never identified.
How it dies: it gets done once, filed, and never revisited, until it describes a clinic that no longer exists. Full treatment here.
2. The risk management plan
The rule: required (45 CFR 164.308(a)(1)(ii)(B)). Implement security measures sufficient to reduce the identified risks to a reasonable and appropriate level.
What it produces: a list of findings, each with an owner, a date, and evidence of what was done.
How it dies: the analysis identifies a gap and nothing happens. This is the exact failure OCR has said its enforcement is moving toward: not “did you look,” but “what did you do about what you found.”
3. The named officers
The rule: required. A security official (45 CFR 164.308(a)(2)) and a privacy official (45 CFR 164.530(a)).
What it produces: a name, in writing, on a document, with the authority to actually do something.
How it dies: “everyone is responsible,” which means nobody is. Or the officer left in 2023 and nobody noticed.
4. The policies
The rule: required (45 CFR 164.316(a); 45 CFR 164.530(i)). Reasonable and appropriate policies and procedures to comply with the rules.
What it produces: a policy set that describes what your clinic actually does.
How it dies: it gets purchased. A generic policy set describes a generic clinic, and documentation that does not match reality is worse than none, because it proves you knew the requirement and represented compliance you did not have.
5. The training
The rule: two requirements, not one. Privacy training on your policies, at hire and after material changes (45 CFR 164.530(b)), and a security awareness and training program for everyone including management (45 CFR 164.308(a)(5)).
What it produces: a record. Who, when, on what.
How it dies: it runs annually in a clinic that hires monthly, so the RBT who started in February is in homes for ten months untrained while the clinic feels compliant. The two requirements, explained.
6. Access, granted and revoked
The rule: workforce security and information access management (45 CFR 164.308(a)(3) and (a)(4)), enforced technically by access control and unique user identification (45 CFR 164.312(a)).
What it produces: a current picture of who can see what, and a termination process that runs the day employment ends.
How it dies: turnover outruns the access review. The RBT who left in March still has a login in September, and nobody can say who opened which chart, because four people share an account.
7. The vendor register and the BAAs
The rule: you may disclose PHI to a business associate only under a signed agreement (45 CFR 164.502(e), 164.308(b)), with the required contents (45 CFR 164.504(e)).
What it produces: a list of every vendor touching PHI, with an executed BAA against each.
How it dies: a clinician adopts a tool. The AI notetaker, the scheduling app, the cloud folder. The list was accurate the day it was written. The walkthrough.
8. The incident and breach process
The rule: security incident procedures are required (45 CFR 164.308(a)(6)); the breach machinery runs on discovery and the 60-day clock (45 CFR 164.404), and the burden of proof is yours (45 CFR 164.414).
What it produces: a log. Every incident, what it was, what you decided, and why, including the ones that turned out to be nothing.
How it dies: nothing gets logged because nothing seemed reportable. An empty incident log does not read as a clean clinic. It reads as a clinic that never looked. What to do on the day.
9. The technical safeguards, actually switched on
The rule: 45 CFR 164.312. Unique logins and emergency access are required; automatic logoff, encryption, integrity checks, and transmission encryption are addressable, which means assessed and decided.
What it produces: encrypted devices, individual logins, audit logs that someone reads, and a written record of every addressable decision.
How it dies: encryption is available on every device in the clinic and switched on for none of them, because it was nobody’s job.
10. The physical controls
The rule: 45 CFR 164.310. Facility access, workstation use and security, and device and media controls, with disposal and media re-use both required.
What it produces: a device register, a wipe-on-reassignment habit, and rules for the rooms you do not own.
How it dies: the tablet is reassigned without a wipe; the old laptop is donated with the drive intact.
11. The individual rights machinery
The rule: access within 30 days (45 CFR 164.524), amendment (164.526), accounting (164.528), restrictions and confidential communications (164.522), and a current Notice of Privacy Practices (164.520).
What it produces: a process for the day a parent asks, and evidence you met the clock.
How it dies: a records request arrives and nobody knows who owns it. Right of access is OCR’s longest-running enforcement initiative, and in ABA it is compounded by the psychotherapy-notes myth, which causes clinics to withhold records they are legally required to produce.
12. The review that keeps all of it true
The rule: evaluation is a standard (45 CFR 164.308(a)(8)), security measures must be reviewed and modified as needed (45 CFR 164.306(e)), and documentation must be reviewed and updated (45 CFR 164.316(b)(2)(iii)).
What it produces: a dated annual review, plus a trigger-based one whenever the clinic materially changes: a new location, a new platform, a telehealth program, an AI tool.
How it dies: silently. It is the most forgotten standard in the rule, and it is the one that makes every other item on this list stay true.
The six-year rule underneath all of it
Every artifact above is subject to the same retention requirement: written or electronic, kept six years from creation or from when it was last in effect, available to the people who need it, and reviewed and updated (45 CFR 164.316(b); 45 CFR 164.530(j)).
Six years is also, in practice, the window a buyer’s counsel looks back over. The auditor’s file and the buyer’s file are the same file.
What it takes to actually run this
Be honest about the shape of the work, because the twelve items are not equally hard.
Four of them are artifacts you produce and maintain: the risk analysis, the risk management plan, the policies, and the officer designations. These take real effort once and moderate effort to keep current.
Eight of them are living processes, and this is where clinics fail. Training happens at hiring speed. Access changes at turnover speed. Vendors change when a clinician downloads something. Incidents happen when they happen. Devices move. Records requests arrive. The reviews recur. None of these can be done in a burst in December and none of them stay true on their own.
That is the honest answer to why HIPAA feels impossible in a small clinic: not because the rules are exotic, but because eight of the twelve parts are processes that decay continuously, in an operation where nobody’s job title contains the word compliance.
The test
Forget the binder. For each of the twelve, ask two questions: what do we actually do, and when did we last do it?
If you can answer both for all twelve, you have a program, and the documents to prove it will already exist, because the documents are what the habits produce. If you can only answer for four of them, you have four parts of a program and eight liabilities, and you now know exactly which eight.
And if the honest answer is amber on several, that is not a failure. A program showing two amber items and a dated remediation plan is more credible, and more valuable, than an implausibly perfect binder, both to an investigator and to a buyer. Red that is true and being worked is a functioning program. Green that is false is the only real disaster.
The short version
- A real program has twelve parts, and each one produces evidence as a by-product of being run.
- The order matters: the risk analysis comes first, because everything else is calibrated by what it finds.
- Almost every requirement is a living process, not an artifact: access changes, training happens, incidents get logged, reviews recur.
- The honest test is not whether you have the documents. It is whether you could show, for each one, what you actually do and when you last did it.
- A program that shows two amber items and a dated remediation plan is more credible, and more valuable, than an implausibly perfect binder.
This article is educational information about the HIPAA regulations, not legal advice. It describes what the rules say; it does not tell you what to do about your specific situation, and reading it does not create an attorney-client or consultant-client relationship. Regulations change, and enforcement positions change with them. For advice on your clinic, talk to a qualified professional.
Sources
- Security standards: General rules45 CFR 164.306https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.306
- Administrative safeguards45 CFR 164.308https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.308
- Physical safeguards45 CFR 164.310https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.310
- Technical safeguards45 CFR 164.312https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.312
- Policies and procedures and documentation requirements45 CFR 164.316https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-C/section-164.316
- Administrative requirements of the Privacy Rule45 CFR 164.530https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.530
- Breach notification to individuals45 CFR 164.404https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-D/section-164.404
- Business associate contracts45 CFR 164.502(e) and 164.504(e)https://www.ecfr.gov/current/title-45/subtitle-A/subchapter-C/part-164/subpart-E/section-164.504
Twelve parts, one honest picture.
WiseUpHIPAA runs the twelve from your clinic's real operational data and computes where each one actually stands, including the parts that are red. Not a binder. A program that shows its own state.