HIPAA Risk Assessment Checklist: A Two Part Framework

A real HIPAA risk assessment checklist has to cover two entirely different kinds of work, what your policies say and what your systems actually do, because those two things frequently do not match. Most checklists circulating online only cover the first half, a list of administrative questions mapped loosely to the HIPAA Security Rule. This one includes both, since that is the actual methodology we run in our own HIPAA risk assessments, a structured interview mapped against NIST 800-66, paired with technical verification of the real cloud environment. We have also written about the reasoning behind this approach for Cybersecurity Insiders, this piece is the working checklist version of that same methodology.

Why a Checklist Needs Two Parts, Not One

A HIPAA security risk assessment checklist that only asks interview questions can tell you whether a policy exists on paper. It cannot tell you whether multi factor authentication is actually enforced, whether a storage bucket is quietly public, or whether the backup your contingency plan describes actually runs and actually restores. Those are two different failure modes, and catching only one of them is how a HealthTech startup ends up with a clean looking policy binder and a real, exploitable gap sitting in production.

The full checklist below, along with a downloadable version you can run against your own environment, covers both halves.

HIPAA risk assessment checklist covering administrative, physical, and technical safeguards alongside technical verification steps

Part One: Structured Interview

This half is mapped directly to NIST Special Publication 800-66, which is the federal government’s own guidance for applying the HIPAA Security Rule. A NIST 800-66 checklist like this one covers three categories of safeguards.

Administrative safeguards cover the policy and process layer, a documented risk analysis, a named security official, workforce training, incident response procedures, a tested contingency plan, and business associate agreements with every vendor that touches PHI.

Physical safeguards cover facility access, workstation use and security, and device or media disposal procedures that ensure PHI cannot be recovered once equipment is retired.

Technical safeguards cover unique user identification, automatic logoff, audit controls, integrity verification, and transmission security for PHI in transit.

Part Two: Technical Verification

This is the half most HIPAA compliance checklists for startups skip entirely, and it is usually where the real gaps live. We run this using Prowler against the actual cloud environment, but the checks themselves apply regardless of which tool performs them.

Identity and access management gets checked directly, is multi factor authentication actually enforced, are there stale credentials sitting on privileged accounts, does access follow least privilege in practice rather than in policy. Encryption gets verified the same way, is PHI actually encrypted at rest and in transit, not just described as encrypted in a data flow diagram. Logging, monitoring, and network configuration get checked for the failure mode that shows up constantly in real environments, a storage bucket or database containing PHI that is quietly exposed to the public internet despite every policy document saying otherwise.

Want the full checklist as a working document you can run against your own environment? Download the HIPAA risk assessment checklist PDF and use it directly, no email required.

Scoring the Gaps You Find

A checklist only tells you what to look for, not what matters most once you find something. Score every gap on two axes, likelihood and impact, each from 1 to 5, and multiply the two for a rough priority order. Anything scoring 4 or 5 on either axis on its own deserves attention before your next audit cycle or enterprise deal review, regardless of what the combined score works out to. This is the same scoring approach referenced in the HHS Security Risk Assessment Tool guidance, which frames risk analysis as an ongoing process rather than a one time exercise.

What This Costs to Do Properly

Running both halves of this checklist thoroughly, especially the technical verification piece, takes real time and cloud access, which is part of why HIPAA risk assessment cost varies as much as it does between vendors. A HIPAA compliance checklist for startups also needs to account for how this work fits alongside a broader HIPAA compliant penetration test, since the two are often scoped together. A checklist that only covers Part One is faster and cheaper to deliver, and it is also the version most likely to miss a gap that matters. If you are comparing quotes, ask directly whether technical verification is included, or whether you are only paying for an interview.

Packet33 is a penetration testing and compliance advisory firm serving SaaS and HealthTech startups in the US, Canada, and UK. This checklist reflects the same two part methodology we use in every HIPAA risk assessment we run.

If you want this checklist run against your actual environment instead of filled out from memory, book a scoping call and we will walk through what a full assessment would surface.