# Achieving HIPAA Compliance | Secureframe

> Learn what it takes to become HIPAA compliant, from required documentation and procedures to common costs.

canonical: https://secureframe.com/hub/hipaa/compliance

If you’re just getting started with HIPAA compliance, the process and scope of what needs to be done can be overwhelming.  

Completing a risk assessment, building your policy library, implementing safeguards, training staff  — it’s difficult to know where to start. 

We’ve created this section to share best practices for achieving and maintaining compliance and help you identify opportunities to save time and effort. 

Here’s everything you need to know about achieving HIPAA compliance.

## Intermediate: I’m preparing for HIPAA compliance

**So you’re in prep mode for HIPAA compliance. **

[Getting HIPAA compliant](https://secureframe.com/blog/gdpr-announcement) is important for avoiding violation penalties and, perhaps more importantly, gaining customer trust and protecting your organization from a breach. Knowing what to expect along the way can make it easier to manage the compliance process and set the right expectations with internal stakeholders.

![](https://images.prismic.io/secureframe-com/a0f363a4-6cd5-4ce6-b808-7e4e85a0f56e_hippa-compliance-checklist-hero.png?auto=compress,format)

## **How do I become HIPAA compliant?**

While HIPAA legislation requires organizations to be proactive about protecting PHI, it doesn’t specify the exact actions covered entities must take. 

This flexibility allows organizations to decide which safeguards are best suited to their unique needs. A regional hospital system will likely need to have different safeguards in place than a small family clinic, for example. 

That said, all organizations will need to follow some key steps to achieve HIPAA compliance.

### Conduct a risk assessment

Under the Security Rule, covered entities are required to complete a [HIPAA risk assessment](https://secureframe.com/blog/hipaa-risk-assessment). This risk analysis helps organizations understand their threat landscape, define their risk tolerance, and identify the probability and potential impact of each risk. 

During a risk assessment, organizations identify and rank potential threats to their security posture, including human error, technical failures, and natural disasters. Armed with this knowledge, covered entities can build more effective strategies for identifying vulnerabilities, mitigating risks, and improving data security standards.

Both covered entities and business associates are required to complete periodic risk assessments, typically on an annual basis. 

### Implement safeguards

HIPAA compliance requirements include three types of safeguards covered entities and business associates must put in place to protect PHI.

**Administrative safeguards**

Administrative safeguards ensure employees know how to properly access and store PHI. For example, completing security training, reviewing privacy policies, and ensuring staff know how to secure PHI in the event of an emergency.

**Physical safeguards**

Physical safeguards protect areas that allow physical access to PHI, such as file cabinets and workstations. These can include requiring ID badges to access PHI, locking file cabinets, and ensuring any screens displaying PHI aren’t publically visible.

**Technical safeguards**

Technical safeguards protect ePHI (PHI that’s stored electronically) from unauthorized access and alteration. Examples include using cybersecurity measures like antivirus software and data encryption.

### Designate a HIPAA compliance officer

A compliance officer is responsible for monitoring HIPAA compliance over time. Responsibilities include:

- Ensuring security and privacy policies are followed and enforced
- Managing privacy training for employees
- Completing periodic risk assessments
- Developing security and privacy processes
- Investigating any security incidents or suspected/confirmed data breaches
- Reporting breaches when required
- Creating a disaster recovery plan
- Ensuring the organization is has properly implemented the Security Rule’s administrative, physical, and technical safeguards

### Complete staff security and privacy awareness training

Proper[ HIPAA training](https://secureframe.com/training/hipaa) ensures that all employees handling PHI understand how to protect it and are familiar with HIPAA regulations and rules. 

HIPAA rules and regulations can be complex for newcomers, so ensuring all employees who interface with PHI receive proper training is an essential step for compliance. HIPAA training ensures your staff understands their role in upholding security standards and know exactly what steps they should take to keep PHI private and secure. 

### Collect Business Associate Agreements (BAAs)

Under HIPAA, covered entities may only work with business associates and service providers who also comply with HIPAA requirements for protecting PHI. Business Associate Agreements are written agreements that specify each party’s responsibilities surrounding PHI. 

According to the Department of Health and Human Services (HHS), a BAA must include: 

- A description of when PHI is either permitted or required to be used by the Business Associate
- Assurance that the Business Associate will not use or disclose PHI outside of what’s either permitted in the agreement or required by law
- A requirement that the Business Associate implement appropriate safeguards to protect PHI against unauthorized access or disclosure

You’ll need to collect these BAAs, review them on an annual basis, and update them to reflect any changes. 

### Establish a breach notification process

 A data breach isn’t always a guaranteed penalty — in some cases, a breach is either unintentional or outside your control to prevent. 

Failing to report a breach, on the other hand, is a definite violation of the Breach Notification Rule. This rule requires organizations to report a data breach to the Office for Civil Rights (OCR) and notify any individuals who may have been affected within 60 days. 

To be compliant, you’ll need to have a documented breach notification process that defines how your organization will follow this rule. This process should be reviewed and updated on an annual basis by your compliance officer. 

### Document evidence of compliance

In the event of a HIPAA audit or complaint investigation, the OCR will need to review your documentation to verify compliance (or noncompliance). Keep a record of your security and privacy policies, risk assessments, internal audit reports, remediation plans, employee training certificates, business associate agreements, and other documentation related to HIPAA.
