Healthcare Business Compliance Checklist
A healthcare business compliance checklist starts with HIPAA, which requires covered entities and their business associates to follow the Privacy Rule, Security Rule and Breach Notification Rule, with civil penalties the Department of Health and Human Services can assess from roughly $145 to over $2.19 million per violation depending on culpability. Beyond HIPAA, most healthcare businesses also need state professional licensing, OSHA's bloodborne pathogens protections for staff, and, for prescribers, DEA registration.
By LLC Register · Last reviewed October 1, 2026
Comprehensive Guide
HIPAA Is the Starting Point
The Health Insurance Portability and Accountability Act applies to "covered entities," which include healthcare providers who transmit health information electronically in connection with certain transactions, health plans, and healthcare clearinghouses, according to the Department of Health and Human Services. It also directly applies to "business associates," outside companies or individuals that create, receive, maintain or transmit protected health information on a covered entity's behalf, such as a billing service, an IT vendor, or a cloud storage provider. Both the covered entity and its business associates need a HIPAA-compliant contract, called a business associate agreement, spelling out how the associate will protect that information.
The Three Rules That Make Up HIPAA Compliance
HIPAA compliance in practice means following three linked rules:
- The Privacy Rule governs who can access, use and disclose a patient's protected health information and gives patients rights to see and request corrections to their own records.
- The Security Rule requires administrative, physical and technical safeguards specifically for electronic protected health information, covering things like access controls, encryption and workforce training.
- The Breach Notification Rule requires notifying affected individuals, HHS, and in some cases the media, after a breach of unsecured protected health information, within specific timeframes that scale with the size of the breach.
What a Violation Can Cost
HHS's Office for Civil Rights enforces HIPAA through a tiered civil penalty structure, with amounts adjusted annually for inflation. The tiers run from violations where the entity didn't know and reasonably couldn't have known of the violation, at the low end, up to violations involving willful neglect that go uncorrected, at the high end, where the per-violation penalty can exceed $2 million, according to HHS. Criminal penalties, prosecuted by the Department of Justice, can also apply to the most serious violations, such as knowingly obtaining or disclosing protected health information for personal gain.
OSHA's Bloodborne Pathogens Standard
Separately from HIPAA, any healthcare employer whose staff can reasonably anticipate contact with blood or other potentially infectious materials, which covers most clinical settings, has to follow OSHA's Bloodborne Pathogens Standard. This requires a written exposure control plan, use of safer medical devices where feasible, personal protective equipment, offering hepatitis B vaccination to exposed employees, and a specific response protocol after an exposure incident.
State Professional Licensing and Facility Requirements
Every state licenses healthcare practitioners through its own medical, nursing, dental or allied-health board, and many also separately license healthcare facilities, such as clinics or surgical centers, through a state health department. These licenses have their own renewal cycles, continuing education requirements, and scope-of-practice rules that are entirely separate from HIPAA or OSHA and have to be tracked with the specific licensing board, not the business formation agency.
Federal Registrations Tied to What You Do
A practitioner who prescribes, administers or dispenses a controlled substance needs a Drug Enforcement Administration registration, renewed periodically and specific to the practitioner and practice location. Most healthcare providers that bill Medicare or Medicaid, or that are identified in healthcare transactions, also need a National Provider Identifier from the Centers for Medicare & Medicaid Services, and a laboratory performing even simple tests on human specimens generally needs certification under the Clinical Laboratory Improvement Amendments.
Building the Checklist Into Daily Operations
Because these requirements come from different federal agencies and your state licensing board, no single filing or renewal covers all of them. A practical approach is tracking HIPAA risk assessments and training, OSHA exposure control plan reviews, state license renewals, and any federal registration renewals, like DEA and CLIA, on one compliance calendar rather than relying on each agency's own reminder system.
Practical Considerations
A Risk Assessment Is the Foundation of HIPAA Compliance
HHS expects covered entities and business associates to conduct a periodic risk assessment identifying where protected health information lives and what could compromise it; most enforcement actions cite a missing or outdated risk assessment as a contributing factor, not just the underlying breach itself.
Business Associate Agreements Are Easy to Overlook
A vendor that touches patient data without a signed business associate agreement in place is a common gap, especially with newer software or billing vendors brought on quickly. Review your vendor list specifically for this.
State Law Can Be Stricter Than HIPAA
Some states impose additional privacy or breach-notification requirements on healthcare information beyond HIPAA's floor. Check your specific state's health privacy law in addition to HIPAA, rather than assuming federal compliance covers everything.
This Is Not Legal or Compliance Advice
Healthcare compliance is a specialized area where the applicable rules depend heavily on your specific license type, services and state. Talk to a healthcare attorney or compliance consultant to build a program suited to your practice, particularly before a HIPAA risk assessment, a licensing application, or responding to a breach.
Sources
The official sources used for this article.
HHS: Covered entities and business associates | hhs.gov/hipaa/for-professionals/covered-entities/index.html |
|---|---|
HHS Office for Civil Rights: HIPAA enforcement | hhs.gov/hipaa/for-professionals/compliance-enforcement/index.html |
OSHA: Bloodborne pathogens and needlestick prevention | osha.gov/bloodborne-pathogens |
DEA Diversion Control Division: Registration | deadiversion.usdoj.gov/drugreg/index.html |
CMS: National Provider Identifier Standard | cms.gov/regulations-and-guidance/administrative-simplification/nationalprovidentstand |
Created by: LLC RegisterLast reviewed October 1, 2026
Updated: October 1, 2026
Frequently Asked Questions
Who counts as a HIPAA covered entity?
A covered entity is generally a healthcare provider that transmits health information electronically in connection with certain transactions, a health plan, or a healthcare clearinghouse, per the Department of Health and Human Services. Business associates, such as billing services or IT vendors that handle protected health information, have their own direct HIPAA obligations too.
How much can a HIPAA violation cost a healthcare business?
HHS's Office for Civil Rights enforces a tiered civil penalty structure, with amounts adjusted annually for inflation that can range from several hundred dollars per violation for unknowing violations up to more than $2 million per violation for uncorrected willful neglect.
Does a small medical practice need an OSHA exposure control plan?
Yes, if staff can reasonably anticipate contact with blood or other potentially infectious materials, which covers most clinical settings. OSHA's Bloodborne Pathogens Standard requires a written exposure control plan regardless of how many employees the practice has.
Do I need a separate DEA registration to prescribe controlled substances?
Yes. A practitioner who prescribes, administers or dispenses a controlled substance needs its own DEA registration, specific to that practitioner and practice location, separate from state medical licensing.
Form your business with LLC Register
$99 a year for a registered agent, with LLC formation in year one and annual report filing included. State fees are passed through at cost.
