Blog

A Realistic 90-Day HIPAA Compliance Plan for Startups and New Compliance Officers

A practical, week-by-week HIPAA compliance plan for your first 90 days. What to do, what to skip, and what actually matters to regulators.

Administrative safeguards Physical safeguards Technical safeguards Privacy rule Breach notification

You just inherited HIPAA. Maybe you’re the founder of a health tech startup whose first enterprise prospect sent over a 200-question security questionnaire. Maybe you’re an ops lead who got “compliance” added to your title last Tuesday. Either way, you searched for a HIPAA compliance plan and found a wall of legal jargon and vendors promising a “certification” that doesn’t exist.

This is the plan we wish someone had handed us. It’s built for people with real jobs, limited budgets, and 90 days to get from “we should probably do something about HIPAA” to a program you can defend to a regulator, an auditor, or a customer’s security team.

One honest note before we start: 90 days gets you to a credible baseline, not a finish line. HIPAA compliance is a program, not a project. But the difference between “we have nothing” and “we have a documented risk analysis, signed BAAs, core policies, and trained staff” is enormous — both legally and commercially.

First, confirm HIPAA actually applies to you

HIPAA applies to two groups: covered entities (providers, health plans, and healthcare clearinghouses) and business associates (companies that create, receive, maintain, or transmit protected health information on behalf of a covered entity).

If you’re a startup, you’re most likely a business associate. That matters because business associates are directly liable under the HIPAA Security Rule (45 CFR §164.302–318) and parts of the Privacy Rule. “We’re just the software vendor” stopped being a defense in 2013 when the Omnibus Rule took effect.

A few edge cases worth checking:

  • Wellness apps that never touch a covered entity’s data may fall outside HIPAA entirely — but the FTC Health Breach Notification Rule may still apply.
  • Employers holding employee health info in their HR role are generally not covered entities for that data, though their group health plan is.
  • Subcontractors of business associates are themselves business associates. Being two steps removed from a hospital doesn’t exempt you.

If you’re genuinely unsure, resolve this in week one. Everything else in this plan assumes HIPAA applies.

Days 1–15: Map your PHI before you touch anything else

The single most common mistake new compliance officers make is starting with policies. Policies written before you understand your data flows are fiction, and regulators can tell.

Spend your first two weeks building a PHI data map:

  • Systems: Which databases, SaaS tools, file shares, email accounts, and devices hold PHI? Include the unglamorous ones — the shared Google Drive folder, the support ticketing tool, the Slack channel where someone once pasted a patient record.
  • People: Which roles actually need PHI access to do their jobs? You’ll use this for access reviews later.
  • Vendors: Every third party that touches PHI. Cloud hosting, analytics, email, transcription, backups, that offshore QA team.
  • Flows: How PHI enters, moves through, and leaves your environment. A simple diagram is fine. A whiteboard photo is better than nothing.

Interview people instead of just reading architecture docs. The gap between how systems are supposed to work and how staff actually use them is where breaches live.

Deliverable by day 15: a written PHI inventory and data flow map. Keep it in version control or a document with a revision history — provenance matters when you’re later asked “when did you know about this system?”

Days 15–30: Run your security risk analysis

The HIPAA Security Rule requires an “accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability” of ePHI — that’s 45 CFR §164.308(a)(1)(ii)(A). In enforcement actions, a missing or superficial risk analysis is the finding that shows up over and over. If you do only one thing from this entire plan, do this.

A defensible risk analysis at this stage doesn’t require consultants or a 200-page report. It requires:

  1. Scope: All ePHI, everywhere — not just your production database.
  2. Threat identification: For each asset, what could realistically go wrong? Ransomware, credential theft, lost laptops, misconfigured cloud storage, insider snooping, vendor breaches.
  3. Current controls: What’s already in place — encryption, MFA, backups, access controls?
  4. Likelihood and impact ratings: A simple high/medium/low scale is acceptable if you apply it consistently.
  5. A risk register: A ranked list of risks with owners and target dates.

We’ve written a full walkthrough in our step-by-step risk analysis guide, and our free HIPAA readiness assessment will surface your biggest gaps in about ten minutes if you want a fast starting point.

Deliverable by day 30: a documented risk analysis and a prioritized risk register. Dated. Signed off by leadership.

Days 30–45: Close the dangerous gaps first

Your risk register will be longer than your budget. That’s normal. Triage by fixing the things that cause breaches and enforcement pain first:

  • Turn on MFA everywhere PHI is accessible. Credential compromise is the leading initial vector in healthcare breaches, and MFA is cheap.
  • Encrypt data at rest and in transit. Encryption is technically “addressable” under the Security Rule, but “addressable” means you must implement it or document why an alternative is reasonable — not that it’s optional. Practically: encrypt everything, especially laptops.
  • Kill shared accounts and stale access. Unique user IDs are a required specification (§164.312(a)(2)(i)). Offboarded employees with live credentials are an audit finding waiting to happen.
  • Verify backups actually restore. Ransomware resilience is a Security Rule concern (data backup and disaster recovery under §164.308(a)(7)).
  • Lock down cloud storage. Publicly readable buckets holding PHI remain one of the most preventable breach patterns in existence.

Resist the urge to buy a big security platform this month. Configuration discipline on tools you already have closes more risk per dollar than new software.

Days 45–60: Get your Business Associate Agreements signed

Pull out the vendor list from your data map. Every vendor that creates, receives, maintains, or transmits PHI on your behalf needs a signed Business Associate Agreement (BAA) before PHI flows — that’s a Privacy Rule requirement, and disclosing PHI to a vendor without one is itself a violation.

Work through it methodically:

  • Major cloud providers (AWS, Google Cloud, Azure, most major SaaS with healthcare offerings) have standard BAAs, sometimes self-service. Sign them and configure only the covered services.
  • Vendors that won’t sign a BAA cannot receive PHI. Full stop. Either de-identify the data, replace the vendor, or re-architect so they never see PHI.
  • If you’re a business associate yourself, your subcontractors need BAAs from you. Flow-down is your obligation, not your customer’s.

Track every BAA in one place: vendor, signature date, and what data they handle. Deals stall when a prospect asks for your BAA list and you spend three weeks reconstructing it. Our HIPAA templates include a BAA and a vendor tracking sheet if you’re starting from zero.

Days 60–75: Write the policies you’ll actually follow

Now — with a data map, a risk analysis, and remediation underway — you can write policies that describe reality. The Security Rule requires documented policies and procedures (§164.316), and the core set includes:

  • Security management and risk analysis process
  • Access control and workforce access authorization
  • Sanction policy for workforce violations
  • Security incident response and reporting
  • Breach notification procedures (including the 60-day individual notification clock)
  • Contingency planning: backup, disaster recovery, emergency mode
  • Device, media, and disposal controls
  • Workstation and mobile device use

Two rules of thumb. First, shorter policies that match your actual practice beat 80-page templates nobody has read. Second, never adopt a policy you can’t currently follow — a policy you violate daily is evidence against you, not for you. Our HIPAA checklist maps each required policy to its regulatory citation so you can confirm coverage.

Also designate, in writing, your Security Officer and Privacy Officer. They can be the same person at a small company. It might be you.

Days 75–90: Train your workforce and document it

HIPAA requires security awareness training for all workforce members (§164.308(a)(5)), and training is your cheapest breach prevention. Cover:

  • What PHI is and where it lives in your systems
  • Phishing and credential hygiene
  • What to do when something goes wrong — and that reporting fast is rewarded, never punished
  • Your sanction policy, stated plainly

Keep attendance records with dates and content covered. “We trained everyone” without documentation is, from a regulator’s perspective, indistinguishable from not training anyone.

Close out the 90 days with a leadership review: present the risk register, what’s been fixed, what’s deferred and why, and the budget you need for the next two quarters. Getting leadership sign-off on residual risk isn’t just political cover — it’s exactly the kind of governance evidence that separates a program from a binder.

What a 90-day plan deliberately leaves out

Honesty matters here. In 90 days you will not have:

  • A mature audit-logging and log-review practice
  • Penetration testing or formal vulnerability management
  • SOC 2 or HITRUST, if customers are asking for those
  • A tested incident response tabletop exercise
  • Full remediation of your risk register

That’s fine. Regulators and sophisticated customers distinguish between “immature program with a clear plan” and “no program.” Your 90-day artifacts — data map, risk analysis, risk register, BAAs, policies, training records — are what put you in the first category.

A word about “HIPAA certification”

Sooner or later a vendor will offer to make you “HIPAA certified” for a fee. Be skeptical: HHS does not run, endorse, or recognize any HIPAA certification program. There is no certificate that transfers liability or guarantees compliance, and presenting one to a customer’s security team can actively damage your credibility.

What does exist, and what sophisticated buyers respect, is a documented risk analysis plus an independent assessment — a third party reviewing your program against the actual regulatory requirements and producing a readiness report. If that’s the evidence you need for a deal, our HIPAA gap assessment is built for exactly that, and pricing is public so you’re not guessing.

Your 90 days at a glance

  • Days 1–15: Confirm applicability. Build your PHI inventory and data flow map.
  • Days 15–30: Complete and document your security risk analysis; build the risk register.
  • Days 30–45: Fix the dangerous gaps — MFA, encryption, access cleanup, backups, cloud configuration.
  • Days 45–60: Sign BAAs with every PHI-touching vendor; build your BAA tracker.
  • Days 60–75: Write right-sized policies; designate Security and Privacy Officers.
  • Days 75–90: Train the workforce, document it, and brief leadership on residual risk.

Then keep going: review the risk analysis at least annually and after major changes, retrain on a cycle, and re-verify access quarterly.

If you want to know where you stand before day one, take the free HIPAA readiness assessment — it takes about ten minutes and gives you a scored gap list you can drop straight into this plan. And if you’d rather talk it through with a human, book a 20-minute call. No pitch theater, just a working session on your actual situation.

Questions

Can you become HIPAA compliant in 90 days?

You can build a defensible compliance program in 90 days: a documented risk analysis, core policies, signed BAAs, and workforce training. HIPAA compliance is ongoing, so 90 days gets you to a credible baseline, not a finish line.

What is the first thing a new HIPAA compliance officer should do?

Map where PHI lives. Before writing policies or buying tools, inventory every system, vendor, and workflow that creates, receives, stores, or transmits PHI. Every other compliance decision depends on that map.

Is there an official HIPAA certification we can get?

No. HHS does not endorse or recognize any HIPAA certification program. Anyone selling a 'HIPAA certification' is selling their own label. What you can do is complete a documented risk analysis and get an independent assessment or readiness report.

See your compliance program in one place

A 20-minute walkthrough with a practitioner. No slides, no pressure.

Book a demo