A HIPAA Compliance Checklist for Long-Term Care Facilities
HIPAA does not care that your facility has sixty beds instead of six hundred. The Security Rule, the Privacy Rule, and the Breach Notification Rule apply the same way to a rural skilled nursing building with no IT department as they do to a national chain with a compliance office. The gap is not the regulation — it is the machinery. Larger operators have people whose whole job is HIPAA. Smaller and rural long-term care facilities have a DON wearing four hats and an administrator wearing five. This checklist is built for them: the concrete, recurring HIPAA tasks every LTC facility has to own, organized so a building without a dedicated compliance officer can still stay survey-ready.
Start with the three rules that actually get cited
HIPAA is large, but for a long-term care facility it comes down to three enforceable pieces. The Security Rule governs electronic protected health information (ePHI) — access, encryption, audit logs, device control. The Privacy Rule governs how any PHI is used and disclosed — notices, minimum-necessary practices, and disclosure logging. The Breach Notification Rule governs what you do when something goes wrong. Nearly every citation and settlement traces back to a missing artifact under one of these three: an unfinished risk analysis, a stale access review, an untrained new hire, a disclosure nobody logged. The checklist below is grouped the same way surveyors think.
Security Rule checklist
- Annual (or on-change) risk analysis. A documented assessment of where ePHI lives and what threatens it. This is the single most-cited administrative safeguard — and the one small facilities most often skip.
- Role-based access control. Each staff member should see only the PHI their role requires. A dietary aide does not need chart access; a floor nurse does not need billing. Document who has access to what, and why.
- Access reviews on a schedule. Terminations and role changes leave orphaned accounts. Review active users on a recurring cadence and pull access the day someone leaves.
- Device and media controls. Track the phones, tablets, and workstations that touch ePHI. Enforce screen locks, encryption, and a clear process for wiping a lost or retired device.
- Audit logging. Systems that hold PHI should record who accessed what and when — and someone should actually review those logs periodically, not just collect them.
- Business Associate Agreements (BAAs). Every vendor that touches your PHI — including your software providers — needs a signed BAA on file. Keep the list current.
Privacy Rule checklist
- Notice of Privacy Practices. Current, posted, and provided to residents — with acknowledgment on file.
- Minimum-necessary reviews. Periodically confirm that routine disclosures and internal access are limited to what the task requires.
- Disclosure logging. Track disclosures that fall outside treatment, payment, and operations so you can produce an accounting on request.
- Resident rights handling. A defined path for access, amendment, and restriction requests — with deadlines that don't quietly lapse.
Breach Notification checklist
- A written incident-response process every supervisor knows how to trigger — not a plan that lives in a binder nobody opens.
- Breach risk assessment to determine whether an incident is reportable, documented either way.
- Notification timelines — affected individuals without unreasonable delay and no later than 60 days; HHS and, for larger breaches, the media within the required windows.
- A running incident log so patterns surface before they become a pattern a surveyor finds first.
Workforce training — the safeguard hiding in plain sight
The most common real-world HIPAA failure in long-term care is not a firewall gap. It is a new CNA who started three weeks ago and never got HIPAA training, or an annual refresher that slipped because the person who used to run it left. Training is an administrative safeguard, and it is one of the easiest to document — if you make it a recurring, assigned task instead of an annual scramble. Every new hire trained before day one on the floor; every existing employee refreshed on a set cadence; every completion time-stamped and stored where you can pull it in seconds. That log is often the first thing a surveyor asks for.
The pattern behind every item: recurring, assigned, evidenced
Read back through the checklist and the same structure repeats. Each item is a recurring task, it belongs to a specific role, and it produces a piece of evidence. That is exactly why HIPAA compliance falls apart in buildings without a compliance officer: the tasks are real but they live in someone's memory, and memory doesn't produce a time-stamped record when a surveyor walks in. The fix is not a bigger binder. It is turning each checklist item into a small task that lands on the right person's phone, on the right day, with a spot to attach proof.
That is the model we built My Tasks around. It ships with pre-seeded, federally-aligned compliance libraries — including HIPAA Security and HIPAA Privacy — already mapped to department groups, so the security officer gets the access reviews and log audits, and the administrator gets the roll-up. Staff check a task off, attach a photo or PDF as evidence, and it rolls into a dashboard that exports to PDF or Excel for the survey binder. The alerts module is HIPAA-conscious in the same way — targeted, role-based communication with read receipts, so the whole operation runs on role-appropriate access rather than an all-staff free-for-all.
Use the checklist, then make it run itself
Print this list, walk your building against it, and you will find the gaps in an afternoon — the stale access list, the untrained hire, the vendor without a BAA, the risk analysis nobody finished last year. Closing them once is the easy part. Keeping them closed, week after week, through staff turnover and survey cycles, is the real work. A rural facility does not need an enterprise compliance department to do it. It needs the same three things every item on this checklist demands: make each task recurring, assign it to a role, and capture the evidence automatically. Do that, and HIPAA stops being the thing you cram for before a survey and becomes the quiet weekly rhythm of a building that is simply ready. See how the MyLTC Apps suite ties compliance, alerts, and daily operations together on the phone your staff already carry.