Keep your HIPAA compliance program airtight and in shape with this checklist covering PHI, risk analysis, safeguards, vendors, training, and breach response.
Updated:
October 1, 2026
.jpg)
People trust healthcare organizations with some of their most sensitive information. For hospital and healthcare foundations, too, this information is extremely valuable since it could bring a patient to a diagnosis, treatment, provider, or healthcare experience. As it moves across teams, systems, and individuals, protecting this information becomes a crucial, shared responsibility for all involved organizations.
This makes HIPAA compliance indispensable for fundraising and advancement teams, particularly when patient information touches donor records, grateful patient programs, communications, or third-party technology. A good HIPAA compliance program covers much more than keeping information behind a secure login. In fact, the most important part is for organizations to understand what information they handle, who can access it, how it moves between systems, and what happens if something goes wrong.
This HIPAA compliance checklist covers the main areas healthcare organizations should review, like identifying protected health information (PHI),managing vendors, and documenting compliance efforts.
The Health Insurance Portability and Accountability Act of 1996, or HIPAA, established federal requirements around the privacy and security of certain health information.
The HIPAA Rules include requirements covering the privacy and security of protected health information, along with requirements for responding to breaches and protecting individuals' rights.
For organizations handling health information, these parts of HIPAA are particularly relevant:
HIPAA applies to covered entities and business associates.
Covered entities include healthcare providers, health plans, and healthcare clearinghouses that meet HIPAA's definitions. A business associate is generally an organization or individual that performs certain functions or services for a covered entity that involve creating, receiving, maintaining, or transmitting PHI.
If an organization does not meet the definition of a covered entity or business associate, HIPAA may not apply to it.
Being affiliated with a hospital does not automatically make a foundation a covered entity under HIPAA. What’s relevant is looking at what information the foundation handles and what role it plays in relation to the covered entity.
For example, a foundation may work with information connected to grateful patient programs or receive information from a hospital that contains PHI. In those situations, the foundation and hospital need to understand their respective responsibilities and how this information should be handled.
The same principle applies when a foundation brings in an outside technology provider. If the provider functions as a business associate, HIPAA requires an appropriate written arrangement covering how PHI will be handled and safeguarded. It’s not a standard answer across the board for every organization and differs each time in relation to the data, partnerships, vendors and other factors involved. So it becomes important to have an understanding of what will make your organization compliant even under changing circumstances.
HIPAA compliance addresses everything, including the data you collect, the systems your team uses and even the vendors you work with.
The following checklist will help you review the major areas of your compliance program. Before we get into it in detail, here’s the checklist at a glance:

This is the most fundamental step to get right before you can approach protecting the data: you need to know where it is and how your organization uses it. The best way to look for it would be to break this down into granular steps.
Ideally, this should include:
For a healthcare foundation, this could mean looking closely at how information moves between the hospital, advancement team, CRM, fundraising platform, communication tools, and other systems.
Once you’re certain where the PHI is stored, and how it enters and leaves your systems, look at who can access it and deliberate on the access. Of course, trust plays a huge part in this process, and you probably trust your team to be responsible with handling this data.
However, access should be tied to a person's responsibilities. Someone working on donor communications may not need the same access as a member of a grateful patient team, for example. Consider access from this perspective.
Review whether your organization:
Regular access reviews can also help catch permissions that made sense when they were created but no longer make sense today.
A HIPAA policy sitting in an internal folder or understood by only a few employees will only be so effective. Employees need to understand what the policies mean for the work they do every day.
Your organization should establish policies and procedures covering areas such as:
Training should also reflect people's responsibilities. A fundraising officer, IT administrator, and volunteer who encounter health information in different ways may need different guidance. Consider conducting specific workshops and training to address these role-based differences.
The HIPAA Security Rule organizes safeguards into three categories: administrative, physical, and technical.
Here's what to review in each area.
Administrative safeguards focus on the policies, processes, and people responsible for protecting ePHI.
You must include:
HHS credits risk analysis as a foundational step in identifying and implementing appropriate safeguards. It also notes that organizations should take their own environment and circumstances into account rather than relying on a single compliance blueprint.
Physical safeguards protect the facilities, workstations, and devices where ePHI can be accessed.
Review whether your organization:
Technical safeguards focus on the technology used to protect ePHI.
Depending on your environment and setup, this means:
The exact safeguards an organization needs will depend on its systems, risks, and environment. This is one reason the risk analysis should come before deciding which controls to implement.
Your organization can have strong internal controls and still introduce risk through a third-party vendor.
To minimize this risk, identify every vendor that creates, receives, maintains, or transmits PHI on your behalf. Then determine what information each vendor handles and what protections are in place.
Check that you:
A BAA establishes permitted uses and disclosures of PHI and requires the business associate to implement appropriate safeguards. HHS also requires business associates to address certain obligations with their subcontractors.
This detail is particularly relevant when evaluating fundraising and engagement technology. A CRM, event platform, communication tool, or other system may interact with information that falls within your organization's HIPAA obligations, so its data practices should be part of your vendor review.
A compliance program is not complete without a plan for incidents. Your organization should have a clear process for identifying, reporting, investigating, and responding to potential breaches.
Make sure you can:
Under the HIPAA Breach Notification Rule, covered entities and business associates have notification obligations following a breach of unsecured PHI.
Having these procedures in place before an incident occurs gives your team a defined process to follow if the need arises.
A part of HIPAA compliance also means having evidence on hand of the work your organization has done.
Document the following:
It’s best to set up a regular cadence for reviewing these materials. Any new development, such as a new vendor, system, fundraising workflow, or a change in how information is shared introduces new risks that were not part of the previous assessment. Regular cadences will help make compliance part of your organization's rhythm and ensure you stay on top of these changes.
Healthcare fundraising teams work with a wide range of information across donor engagement, events, giving, communications, and grateful patient programs. The technology used for these processes needs to support the organization's privacy and security requirements.
Almabase is designed to help healthcare foundations manage these fundraising workflows with security and HIPAA considerations built into the platform.
Almabase provides controls designed to help healthcare organizations manage access to sensitive information, including permissions and audit trails. The platform also supports a Business Associate Agreement for organizations that require one.
Healthcare foundations can use Almabase to manage donor engagement, giving, events, communications, and other advancement workflows in one connected environment.
Almabase integrates with Raiser’s Edge NXT and other CRMs to help reduce manual data movement between platforms and keep donor and engagement information synchronized. Reducing unnecessary movement of information makes day-to-day data management easier to control.
HIPAA compliance is an ongoing process. As your organization adds new technology, works with new vendors, or changes how teams handle information, your compliance measures must adapt to remain airtight.
This means keeping an eye on how patient and donor information moves through fundraising workflows and making sure the right people, systems, and safeguards are in place.
Use this checklist as a starting point for reviewing your current practices, identifying gaps, and deciding where your team may need to take a closer look. Regular risk assessments, policy reviews, employee training, and vendor reviews can help keep your HIPAA program aligned with the way your organization actually works.
Looking for a fundraising platform built with healthcare organizations in mind?
See how Almabase supports healthcare fundraising →
HIPAA applies to covered entities and business associates. Covered entities include qualifying healthcare providers, health plans, and healthcare clearinghouses. Business associates provide certain services to covered entities that involve PHI.
PHI is individually identifiable health information that is created, received, maintained, or transmitted by a covered entity or business associate and is subject to HIPAA's protections.
The Privacy Rule establishes standards for how covered entities may use and disclose PHI and gives individuals certain rights regarding their health information.
The Security Rule establishes requirements for protecting electronic protected health information through administrative, physical, and technical safeguards.
The Breach Notification Rule establishes requirements for notifying affected individuals, HHS, and, in certain cases the media following a breach of unsecured PHI.
The Enforcement Rule establishes procedures for investigations, hearings, penalties, and enforcement of the HIPAA Rules.
The 2013 Omnibus Rule implemented changes to the HIPAA Privacy, Security, Enforcement, and Breach Notification Rules under the HITECH Act and strengthened requirements for business associates and their subcontractors.
The HIPAA requirements that apply to an organization depend on its role and circumstances. Organizations should first determine whether they are a covered entity or business associate and then identify the specific requirements that apply to their activities.
Subscribe
See how modern advancement teams bring alumni engagement and fundraising together.
Plan faster. Execute better
Explore free templates designed for alumni and fundraising teams.