LLC Register
  • Start your business

    • Start an LLC
    • Form a Business
    • File an S-Corp Election
    • Hire a Registered Agent

    Filings & compliance

    • Articles of Organization
    • Certificate of Formation
    • Operating Agreement
    • EIN & Tax ID Number
    • Foreign Qualification
    • Change Registered Agent
    • Annual Report
    • Stay Compliant

    Not sure where to start?

    Pick your state to see LLC filing fees.

    CaliforniaFiling fee $70

    Form your LLC in California →
    Help me decide →
  • Resources
  • About Us
Start my LLC
  • Start your business
    • Start an LLC
    • Form a Business
    • File an S-Corp Election
    • Hire a Registered Agent
    Filings & compliance
    • Articles of Organization
    • Certificate of Formation
    • Operating Agreement
    • EIN & Tax ID Number
    • Foreign Qualification
    • Change Registered Agent
    • Annual Report
    • Stay Compliant

    Not sure where to start?

    Pick your state to see LLC filing fees.

    CaliforniaFiling fee $70

    Form your LLC in California →
  • Resources
  • About Us
Start my LLC
LLC Register
  1. Home
  2. ›
  3. Resources
  4. ›
  5. Business Compliance

Healthcare Business Compliance Checklist

A healthcare business compliance checklist starts with HIPAA, which requires covered entities and their business associates to follow the Privacy Rule, Security Rule and Breach Notification Rule, with civil penalties the Department of Health and Human Services can assess from roughly $145 to over $2.19 million per violation depending on culpability. Beyond HIPAA, most healthcare businesses also need state professional licensing, OSHA's bloodborne pathogens protections for staff, and, for prescribers, DEA registration.

By LLC Register · Last reviewed October 1, 2026

Read Comprehensive Guide
LLC Register

Key Takeaways

  • HIPAA applies to covered entities and their business associates

    A covered entity, such as a provider, health plan or clearinghouse, and any business associate that handles protected health information on its behalf both have direct HIPAA compliance obligations, per the Department of Health and Human Services.

  • HIPAA penalties scale with culpability

    HHS's Office for Civil Rights can assess civil penalties across four tiers, from several hundred dollars per violation for unknowing violations up to more than $2 million per violation for uncorrected willful neglect.

  • Bloodborne pathogen protections are an OSHA requirement, not a HIPAA one

    Any employer whose staff can reasonably expect contact with blood or other infectious materials must follow OSHA's Bloodborne Pathogens Standard, including an exposure control plan and offering hepatitis B vaccination.

  • Prescribing controlled substances requires separate DEA registration

    A practitioner who prescribes, administers or dispenses a controlled substance needs its own DEA registration, separate from state medical licensing.

Start Your LLC
In this article
  • Comprehensive Guide
  • Practical Considerations

Comprehensive Guide

HIPAA Is the Starting Point

The Health Insurance Portability and Accountability Act applies to "covered entities," which include healthcare providers who transmit health information electronically in connection with certain transactions, health plans, and healthcare clearinghouses, according to the Department of Health and Human Services. It also directly applies to "business associates," outside companies or individuals that create, receive, maintain or transmit protected health information on a covered entity's behalf, such as a billing service, an IT vendor, or a cloud storage provider. Both the covered entity and its business associates need a HIPAA-compliant contract, called a business associate agreement, spelling out how the associate will protect that information.

The Three Rules That Make Up HIPAA Compliance

HIPAA compliance in practice means following three linked rules:

  • The Privacy Rule governs who can access, use and disclose a patient's protected health information and gives patients rights to see and request corrections to their own records.
  • The Security Rule requires administrative, physical and technical safeguards specifically for electronic protected health information, covering things like access controls, encryption and workforce training.
  • The Breach Notification Rule requires notifying affected individuals, HHS, and in some cases the media, after a breach of unsecured protected health information, within specific timeframes that scale with the size of the breach.

What a Violation Can Cost

HHS's Office for Civil Rights enforces HIPAA through a tiered civil penalty structure, with amounts adjusted annually for inflation. The tiers run from violations where the entity didn't know and reasonably couldn't have known of the violation, at the low end, up to violations involving willful neglect that go uncorrected, at the high end, where the per-violation penalty can exceed $2 million, according to HHS. Criminal penalties, prosecuted by the Department of Justice, can also apply to the most serious violations, such as knowingly obtaining or disclosing protected health information for personal gain.

OSHA's Bloodborne Pathogens Standard

Separately from HIPAA, any healthcare employer whose staff can reasonably anticipate contact with blood or other potentially infectious materials, which covers most clinical settings, has to follow OSHA's Bloodborne Pathogens Standard. This requires a written exposure control plan, use of safer medical devices where feasible, personal protective equipment, offering hepatitis B vaccination to exposed employees, and a specific response protocol after an exposure incident.

State Professional Licensing and Facility Requirements

Every state licenses healthcare practitioners through its own medical, nursing, dental or allied-health board, and many also separately license healthcare facilities, such as clinics or surgical centers, through a state health department. These licenses have their own renewal cycles, continuing education requirements, and scope-of-practice rules that are entirely separate from HIPAA or OSHA and have to be tracked with the specific licensing board, not the business formation agency.

Federal Registrations Tied to What You Do

A practitioner who prescribes, administers or dispenses a controlled substance needs a Drug Enforcement Administration registration, renewed periodically and specific to the practitioner and practice location. Most healthcare providers that bill Medicare or Medicaid, or that are identified in healthcare transactions, also need a National Provider Identifier from the Centers for Medicare & Medicaid Services, and a laboratory performing even simple tests on human specimens generally needs certification under the Clinical Laboratory Improvement Amendments.

Building the Checklist Into Daily Operations

Because these requirements come from different federal agencies and your state licensing board, no single filing or renewal covers all of them. A practical approach is tracking HIPAA risk assessments and training, OSHA exposure control plan reviews, state license renewals, and any federal registration renewals, like DEA and CLIA, on one compliance calendar rather than relying on each agency's own reminder system.

Practical Considerations

A Risk Assessment Is the Foundation of HIPAA Compliance

HHS expects covered entities and business associates to conduct a periodic risk assessment identifying where protected health information lives and what could compromise it; most enforcement actions cite a missing or outdated risk assessment as a contributing factor, not just the underlying breach itself.

Business Associate Agreements Are Easy to Overlook

A vendor that touches patient data without a signed business associate agreement in place is a common gap, especially with newer software or billing vendors brought on quickly. Review your vendor list specifically for this.

State Law Can Be Stricter Than HIPAA

Some states impose additional privacy or breach-notification requirements on healthcare information beyond HIPAA's floor. Check your specific state's health privacy law in addition to HIPAA, rather than assuming federal compliance covers everything.

This Is Not Legal or Compliance Advice

Healthcare compliance is a specialized area where the applicable rules depend heavily on your specific license type, services and state. Talk to a healthcare attorney or compliance consultant to build a program suited to your practice, particularly before a HIPAA risk assessment, a licensing application, or responding to a breach.

Related Resources

  • Data Privacy Compliance for Small Businesses

    Learn data privacy compliance basics for small businesses, including FTC security expectations, breach notification laws, and state privacy law triggers.

  • Online Business License Requirements

    Learn online business license requirements, including local licenses based on where you work, sales tax permits, and the FTC's 30-day shipping rule.

  • Real Estate Business Compliance Checklist

    Learn the real estate business compliance checklist, covering state licensing, trust account rules, Fair Housing Act duties, and RESPA disclosures.

Sources

The official sources used for this article.

HHS: Covered entities and business associates

hhs.gov/hipaa/for-professionals/covered-entities/index.html

HHS Office for Civil Rights: HIPAA enforcement

hhs.gov/hipaa/for-professionals/compliance-enforcement/index.html

OSHA: Bloodborne pathogens and needlestick prevention

osha.gov/bloodborne-pathogens

DEA Diversion Control Division: Registration

deadiversion.usdoj.gov/drugreg/index.html

CMS: National Provider Identifier Standard

cms.gov/regulations-and-guidance/administrative-simplification/nationalprovidentstand

Created by: LLC RegisterLast reviewed October 1, 2026

Updated: October 1, 2026

Frequently Asked Questions

Who counts as a HIPAA covered entity?

A covered entity is generally a healthcare provider that transmits health information electronically in connection with certain transactions, a health plan, or a healthcare clearinghouse, per the Department of Health and Human Services. Business associates, such as billing services or IT vendors that handle protected health information, have their own direct HIPAA obligations too.

How much can a HIPAA violation cost a healthcare business?

HHS's Office for Civil Rights enforces a tiered civil penalty structure, with amounts adjusted annually for inflation that can range from several hundred dollars per violation for unknowing violations up to more than $2 million per violation for uncorrected willful neglect.

Does a small medical practice need an OSHA exposure control plan?

Yes, if staff can reasonably anticipate contact with blood or other potentially infectious materials, which covers most clinical settings. OSHA's Bloodborne Pathogens Standard requires a written exposure control plan regardless of how many employees the practice has.

Do I need a separate DEA registration to prescribe controlled substances?

Yes. A practitioner who prescribes, administers or dispenses a controlled substance needs its own DEA registration, specific to that practitioner and practice location, separate from state medical licensing.

Form your business with LLC Register

$99 a year for a registered agent, with LLC formation in year one and annual report filing included. State fees are passed through at cost.

Start Your LLC
LLC Register

Any questions?

We're available Monday through Friday from 9am - 6pm CST

Start your business

Start an LLCForm a BusinessFile an S-Corp ElectionHire a Registered Agent

Filings & compliance

Articles of OrganizationCertificate of FormationOperating AgreementEIN & Tax ID NumberForeign QualificationChange Registered AgentAnnual ReportStay Compliant

Company

ResourcesContact UsPrivacy PolicyTerms of Service360 Legal

LLC Register helps entrepreneurs form and maintain their LLC with fast, guided filings and ongoing compliance support. This site provides general information and is not a substitute for legal or tax advice.

LLC Register is not a law firm and does not provide legal advice. Communications with LLC Register are not protected by attorney-client privilege.

Powered by 360Legal