HIPAA Compliance Checklist for Healthcare Organizations

Keep your HIPAA compliance program airtight and in shape with this checklist covering PHI, risk analysis, safeguards, vendors, training, and breach response.

Anwesha Kiran

Updated: 

October 1, 2026

People trust healthcare organizations with some of their most sensitive information. For hospital and healthcare foundations, too, this information is extremely valuable since it could bring a patient to a diagnosis, treatment, provider, or healthcare experience. As it moves across teams, systems, and individuals, protecting this information becomes a crucial, shared responsibility for all involved organizations.

This makes HIPAA compliance indispensable for fundraising and advancement teams, particularly when patient information touches donor records, grateful patient programs, communications, or third-party technology. A good HIPAA compliance program covers much more than keeping information behind a secure login. In fact, the most important part is for organizations to understand what information they handle, who can access it, how it moves between systems, and what happens if something goes wrong.

This HIPAA compliance checklist covers the main areas healthcare organizations should review, like identifying protected health information (PHI),managing vendors, and documenting compliance efforts.

What Is HIPAA and Who Needs to Comply?

The Health Insurance Portability and Accountability Act of 1996, or HIPAA, established federal requirements around the privacy and security of certain health information.

The HIPAA Rules include requirements covering the privacy and security of protected health information, along with requirements for responding to breaches and protecting individuals' rights.

For organizations handling health information, these parts of HIPAA are particularly relevant:

  • Privacy Rule: Establishes standards for how protected health information (PHI) can be used and disclosed and gives individuals certain rights over their information.
  • Security Rule: Establishes safeguards for electronic protected health information (ePHI), including administrative, physical, and technical safeguards.
  • Breach Notification Rule: Establishes requirements for notifying individuals, HHS, and, in some cases, the media after a breach of unsecured PHI.

Who needs to comply with HIPAA?

HIPAA applies to covered entities and business associates.

Covered entities include healthcare providers, health plans, and healthcare clearinghouses that meet HIPAA's definitions. A business associate is generally an organization or individual that performs certain functions or services for a covered entity that involve creating, receiving, maintaining, or transmitting PHI.

If an organization does not meet the definition of a covered entity or business associate, HIPAA may not apply to it.

Does HIPAA Apply to Healthcare Foundations?

Being affiliated with a hospital does not automatically make a foundation a covered entity under HIPAA. What’s relevant is looking at what information the foundation handles and what role it plays in relation to the covered entity.

For example, a foundation may work with information connected to grateful patient programs or receive information from a hospital that contains PHI. In those situations, the foundation and hospital need to understand their respective responsibilities and how this information should be handled.

The same principle applies when a foundation brings in an outside technology provider. If the provider functions as a business associate, HIPAA requires an appropriate written arrangement covering how PHI will be handled and safeguarded. It’s not a standard answer across the board for every organization and differs each time in relation to the data, partnerships, vendors and other factors involved. So it becomes important to have an understanding of what will make your organization compliant even under changing circumstances.

The HIPAA Compliance Checklist

HIPAA compliance addresses everything, including the data you collect, the systems your team uses and even the vendors you work with.

The following checklist will help you review the major areas of your compliance program. Before we get into it in detail, here’s the checklist at a glance:

1. Know What Data You're Responsible For

This is the most  fundamental step to get right before you can approach protecting the data: you need to know where it is and how your organization uses it. The best way to look for it would be to break this down into granular steps.

Ideally, this should include:

  • Identifying the PHI and ePHI your organization handles
  • Documenting where PHI is stored
  • Identifying how PHI enters and leaves your organization
  • Mapping the systems and workflows that use or transmit PHI
  • Identifying employees, teams, and vendors that can access it
  • Reviewing whether each person or system actually needs that access

For a healthcare foundation, this could mean looking closely at how information moves between the hospital, advancement team, CRM, fundraising platform, communication tools, and other systems.

2. Know Who Has Access and Why

Once you’re certain where the PHI is stored, and how it enters and leaves your systems, look at who can access it and deliberate on the access. Of course, trust plays a huge part in this process, and you probably trust your team to be responsible with handling this data.

However, access should be tied to a person's responsibilities. Someone working on donor communications may not need the same access as a member of a grateful patient team, for example. Consider access from this perspective.

Review whether your organization:

  • Uses role-based access controls
  • Requires appropriate authentication
  • Removes access when employees change roles or leave
  • Reviews permissions periodically
  • Maintains records of system activity and access
  • Limits access to the information needed for a person's role

Regular access reviews can also help catch permissions that made sense when they were created but no longer make sense today.

3. Let Your Policies Match How People Work

A HIPAA policy sitting in an internal folder or understood by only a few employees will only be so effective. Employees need to understand what the policies mean for the work they do every day.

Your organization should establish policies and procedures covering areas such as:

  • How PHI can be used and disclosed
  • The minimum necessary use of PHI
  • Privacy and security incident reporting
  • Employee responsibilities for protecting PHI
  • Appropriate use of devices and systems
  • Workforce training and security awareness
  • Procedures for updating policies as technology and workflows change

Training should also reflect people's responsibilities. A fundraising officer, IT administrator, and volunteer who encounter health information in different ways may need different guidance. Consider conducting specific workshops and training to address these role-based differences.

4. Secure the Systems and Places Where PHI Lives

The HIPAA Security Rule organizes safeguards into three categories: administrative, physical, and technical.

Here's what to review in each area.

Administrative safeguards

Administrative safeguards focus on the policies, processes, and people responsible for protecting ePHI.

You must include:

  • Conducting a security risk analysis
  • Establishing security policies and procedures
  • Assigning responsibility for security
  • Training your workforce
  • Establishing security incident procedures
  • Creating contingency and disaster recovery plans
  • Conducting periodic evaluations

HHS credits risk analysis as a foundational step in identifying and implementing appropriate safeguards. It also notes that organizations should take their own environment and circumstances into account rather than relying on a single compliance blueprint.

Physical safeguards

Physical safeguards protect the facilities, workstations, and devices where ePHI can be accessed.

Review whether your organization:

  • Controls physical access to relevant facilities
  • Has appropriate workstation security policies
  • Protects devices that can access ePHI
  • Controls the movement and disposal of electronic media
  • Has procedures for handling devices that contain ePHI

Technical safeguards

Technical safeguards focus on the technology used to protect ePHI.

Depending on your environment and setup, this means:

  • User identification and authentication
  • Access controls
  • Audit controls
  • Data integrity protections
  • Encryption
  • Secure transmission
  • Automatic logoff and session controls

The exact safeguards an organization needs will depend on its systems, risks, and environment. This is one reason the risk analysis should come before deciding which controls to implement.

5. Put Your Vendors Under the Same Microscope

Your organization can have strong internal controls and still introduce risk through a third-party vendor.

To minimize this risk, identify every vendor that creates, receives, maintains, or transmits PHI on your behalf. Then determine what information each vendor handles and what protections are in place.

Check that you:

  • Identify vendors that handle PHI
  • Determine whether a Business Associate Agreement (BAA) is required
  • Review vendor security and privacy practices
  • Understand how subcontractors handle PHI
  • Establish procedures for reporting security incidents
  • Review vendor relationships periodically

A BAA establishes permitted uses and disclosures of PHI and requires the business associate to implement appropriate safeguards. HHS also requires business associates to address certain obligations with their subcontractors.

This detail is particularly relevant when evaluating fundraising and engagement technology. A CRM, event platform, communication tool, or other system may interact with information that falls within your organization's HIPAA obligations, so its data practices should be part of your vendor review.

6. Be Ready If Something Goes Wrong

A compliance program is not complete without a plan for incidents. Your organization should have a clear process for identifying, reporting, investigating, and responding to potential breaches.

Make sure you can:

  • Define what constitutes a potential breach
  • Give employees a clear way to report incidents
  • Identify who investigates and responds to incidents
  • Establish an escalation process
  • Document the incident and investigation
  • Determine if notification is required
  • Track corrective actions after an incident

Under the HIPAA Breach Notification Rule, covered entities and business associates have notification obligations following a breach of unsecured PHI.

Having these procedures in place before an incident occurs gives your team a defined process to follow if the need arises.

7. Prove That Your Program Works

A part of HIPAA compliance also means having evidence on hand of the work your organization has done.

Document the following:

  • Risk assessments and analyses
  • Policies and procedures
  • Employee training records
  • Business Associate Agreements
  • Vendor reviews
  • Incident reports
  • Corrective actions
  • Periodic evaluations and security reviews

It’s best to set up a regular cadence for reviewing these materials. Any new development, such as a new vendor, system, fundraising workflow, or a change in how information is shared introduces new risks that were not part of the previous assessment. Regular cadences will help make compliance part of your organization's rhythm and ensure you stay on top of these changes.

How Almabase Helps Healthcare Foundations Support HIPAA-Compliant Fundraising

Healthcare fundraising teams work with a wide range of information across donor engagement, events, giving, communications, and grateful patient programs. The technology used for these processes needs to support the organization's privacy and security requirements.

Almabase is designed to help healthcare foundations manage these fundraising workflows with security and HIPAA considerations built into the platform.

Keep sensitive information protected

Almabase provides controls designed to help healthcare organizations manage access to sensitive information, including permissions and audit trails. The platform also supports a Business Associate Agreement for organizations that require one.

Bring fundraising workflows together

Healthcare foundations can use Almabase to manage donor engagement, giving, events, communications, and other advancement workflows in one connected environment.

Keep your fundraising data connected

Almabase integrates with Raiser’s Edge NXT and other CRMs to help reduce manual data movement between platforms and keep donor and engagement information synchronized. Reducing unnecessary movement of information makes day-to-day data management easier to control.

Wrapping Up

HIPAA compliance is an ongoing process. As your organization adds new technology, works with new vendors, or changes how teams handle information, your compliance measures must adapt to remain airtight.

This means keeping an eye on how patient and donor information moves through fundraising workflows and making sure the right people, systems, and safeguards are in place.

Use this checklist as a starting point for reviewing your current practices, identifying gaps, and deciding where your team may need to take a closer look. Regular risk assessments, policy reviews, employee training, and vendor reviews can help keep your HIPAA program aligned with the way your organization actually works.

Looking for a fundraising platform built with healthcare organizations in mind? 
See how Almabase supports healthcare fundraising →

FAQs About HIPAA Compliance

1. Which entities need to comply with HIPAA?

HIPAA applies to covered entities and business associates. Covered entities include qualifying healthcare providers, health plans, and healthcare clearinghouses. Business associates provide certain services to covered entities that involve PHI.

2. What is protected health information (PHI)?

PHI is individually identifiable health information that is created, received, maintained, or transmitted by a covered entity or business associate and is subject to HIPAA's protections.

3. What is the HIPAA Privacy Rule?

The Privacy Rule establishes standards for how covered entities may use and disclose PHI and gives individuals certain rights regarding their health information.

4. What is the HIPAA Security Rule?

The Security Rule establishes requirements for protecting electronic protected health information through administrative, physical, and technical safeguards.

5. What is the HIPAA Breach Notification Rule?

The Breach Notification Rule establishes requirements for notifying affected individuals, HHS, and, in certain cases the media following a breach of unsecured PHI.

6. What is the HIPAA Enforcement Rule?

The Enforcement Rule establishes procedures for investigations, hearings, penalties, and enforcement of the HIPAA Rules.

7. What is the Omnibus Rule?

The 2013 Omnibus Rule implemented changes to the HIPAA Privacy, Security, Enforcement, and Breach Notification Rules under the HITECH Act and strengthened requirements for business associates and their subcontractors.

8. Are all HIPAA rules necessary to stay compliant?

The HIPAA requirements that apply to an organization depend on its role and circumstances. Organizations should first determine whether they are a covered entity or business associate and then identify the specific requirements that apply to their activities.

Table of Contents

Subscribe

See how modern advancement teams bring alumni engagement and fundraising together.

Plan faster. Execute better

Explore free templates designed for alumni and fundraising teams.

Anwesha Kiran

Anwesha is an educator and pedagogy enthusiast, passionate about the transformative impact of education, kindness, and creativity on individuals and communities.

As an artist, she brings a unique perspective to her work and is committed to inspiring growth, empathy, and understanding

Get a closer look at how modern advancement teams use Almabase to engage, raise, and retain

Book a demo