Understand HIPAA requirements
Document handling of all PHI
Identify all areas where PHI is stored
Review and restrict PHI access permissions
Implement necessary technological protections
Approval: Security Officer for technological protections
Train employees on HIPAA compliance
Create an incident response plan
Assign a HIPAA compliance officer
Conduct a risk assessment
Implement a secure method for disposing of PHI
Approval: Compliance Officer for disposal method
Develop and implement a sanctions policy for non-compliance
Implement necessary physical safeguards to secure PHI
Create and enforce a policy for mobile devices access to PHI
Develop a Business Associate Agreement (BAA) process
Approval: Legal Counsel for BAA process
Develop physical security measures
Conduct regular HIPAA compliance audits
Create a contingency plan in case of a breach