← Assad Nadeem Qureshi
Healthcare checklistPrintable · PHI-safe

HIPAA Software Readiness Checklist

A practical review for healthcare founders and product teams before building, buying, or scaling software that may touch protected health information.

How to use it

Start before architecture hardens

This checklist is for early technical discovery, product due diligence, and pre-build review. It helps a team find the software decisions that will affect PHI handling, vendor scope, cloud architecture, AI, analytics, monitoring, delivery, and operational evidence.

Important: this is not legal advice, a compliance certificate, or a replacement for a formal HIPAA risk analysis. HHS describes HIPAA security as administrative, physical, and technical safeguards for electronic PHI, and business associate relationships also need written assurances when PHI is handled on behalf of a covered entity.

Source basis: HHS guidance on the HIPAA Security Rule, its Security Rule summary, and covered entities and business associates.

Download PDF Review a project
Checklist

Readiness review

1. Covered workflow

Identify whether the product supports care, payment, operations, clinical documentation, patient communication, insurance, provider workflows, or another healthcare function.

2. PHI data map

List where PHI is created, received, maintained, transmitted, transformed, exported, deleted, logged, backed up, or viewed by support users.

3. Vendor and BAA scope

Review cloud, email, SMS, AI, analytics, monitoring, storage, search, support, video, and data-processing vendors for BAA availability and covered features.

4. Identity and roles

Define patient, clinician, staff, admin, support, service-account, and emergency-access roles with least-privilege permissions and reviewable access history.

5. Tenant and account boundaries

Decide how organizations, clinics, practices, departments, patients, and internal users are separated across application data, storage, queues, caches, and jobs.

6. Environments

Separate development, staging, and production. Prefer synthetic data outside production, and govern any production-derived subset with access limits and expiry.

7. Encryption and secrets

Check transport security, encryption at rest, key ownership, secret storage, rotation, workload identity, break-glass access, and recovery paths.

8. Audit evidence

Capture meaningful access, administrative, deployment, data-change, vendor, and support events without placing unnecessary PHI into logs.

9. Analytics and monitoring

Design allowlisted event names and technical identifiers. Review URLs, breadcrumbs, stack traces, replay tools, exports, alerts, and integrations for PHI leakage.

10. AI and automation

Map prompts, files, transcripts, embeddings, logs, model retention, subprocessors, human review, failure modes, and whether the AI service is covered by the right agreement.

11. Backup and recovery

Set recovery objectives, protect backup access, test restore paths, document retention, and verify deletion expectations across derived and backup copies.

12. Delivery readiness

Review CI/CD permissions, protected releases, artifact provenance, dependency scanning, database migrations, rollback plans, and emergency deployment ownership.

Decision notes

What to document before building

  1. What data is in scope? Write down the specific PHI categories, files, identifiers, events, and derived data the product may handle.
  2. Who is responsible? Assign product, engineering, security, privacy, legal, support, and vendor-review owners before launch pressure arrives.
  3. Which vendors can receive what? Record approved services, covered features, retention settings, subprocessors, and data that must never be sent.
  4. What evidence proves the controls? Define the audit trails, access reviews, restore tests, incident runbooks, release records, and deletion checks you expect to see later.
  5. What remains unresolved? Keep a risk register for legal review, architecture decisions, vendor gaps, manual workflows, and post-launch controls.
Useful companion guides

Go deeper

HIPAA-compliant app development

How I think about the engineering side of HIPAA-aware healthcare software delivery.

Production data in staging

How to avoid casual PHI movement into development and QA workflows.

Configure Sentry without PHI

Practical controls for error monitoring, traces, replays, alerts, and integrations.

Vendor checklist

Questions to ask analytics and monitoring vendors before healthcare data can reach them.

Want a technical review?

Send the workflow, current stack, vendors, integrations, and the biggest risk you already see. I can help turn this checklist into a practical architecture and delivery plan.

Start a project inquiry

Please do not send PHI, patient records, credentials, keys, screenshots containing patient data, or incident evidence by email.