Skip to main content
Continuous HIPAA Compliance: Your 90-Day CycleRegulatory Framework
5 min readFor Compliance Officers

Continuous HIPAA Compliance: Your 90-Day Cycle

Your annual Risk Assessment is complete. Staff training is done. You've checked the boxes, updated your policies, and filed everything away. You're compliant, right?

Not according to the Office for Civil Rights (OCR). If you're treating HIPAA as a yearly event, you're not just behind schedule, you're violating the Security Rule's monitoring requirements.

This checklist guides you through shifting from annual compliance to a continuous 90-day cycle that keeps you audit-ready and reduces breach risk. It's built around three core areas: dynamic risk management, regular access audits, and policy evolution.

What This Checklist Covers

You'll establish a quarterly compliance rhythm that satisfies 45 CFR § 164.308's requirement for "regular review of records and system activity." This isn't about doing more work; it's about distributing compliance tasks across the year so that changes to your IT environment, workforce, or vendor relationships don't leave you exposed.

Each item includes the regulatory basis, what completion looks like, and common failure points.

Prerequisites

Before you start this 90-day cycle, verify you have:

  • A baseline Risk Assessment completed within the last 12 months. This should include a documented threat and vulnerability analysis for every system that creates, receives, maintains, or transmits Electronic Protected Health Information (ePHI), with risk ratings and mitigation plans.

  • Designated Privacy Official and Security Officer roles assigned. Ensure written appointment letters, clear authority to implement and enforce policies, and regular executive reporting.

  • An inventory of all systems, applications, and Business Associates that touch Protected Health Information (PHI). Maintain a living spreadsheet or database with system owners, data flows, and last-review dates.

90-Day Compliance Cycle Checklist

Month 1: Risk Management Review

1. Trigger a Risk Assessment update for any environmental or operational change since your last review.

Regulatory basis: 45 CFR § 164.308(a)(1)(ii)(A) requires periodic Risk Assessments and updates when changes occur.

Review new hires with ePHI access, departures, new vendors, cloud migrations, software updates, workflow changes, new devices, or facility moves. Document each change and assess whether it introduces new vulnerabilities or requires additional safeguards.

Ensure a change log with risk impact ratings and mitigation actions for each item. If you migrated to a new Electronic Health Record system in March, assess it immediately, not in January.

2. Test one critical technical safeguard.

Pick one Required or Addressable Specification from 45 CFR § 164.312 and verify it's working. Rotate through encryption (at rest and in transit), access controls, audit controls, integrity controls, and transmission security across your quarterly cycles.

Document test results with date, tester name, system tested, and pass/fail outcome. If you test encryption, verify that ePHI on laptops and backup drives is actually encrypted, not just policy-compliant on paper.

3. Review and update your breach response plan.

Consider scenarios your current plan doesn't address: ransomware, insider theft, lost unencrypted devices, cloud misconfigurations, vendor breaches.

Conduct a tabletop exercise summary showing who would do what in the first 60 minutes of a breach discovery, with gaps documented and assigned for remediation.

Month 2: Access Audits and Monitoring

4. Pull and review access logs for one high-risk system.

Regulatory basis: 45 CFR § 164.308(a)(1)(ii)(D) and § 164.312(b) require regular review of system activity.

Choose your most sensitive system each quarter: billing, EHR, patient portal, claims processing. Look for access outside business hours, bulk record pulls, terminated employees still in the system, or generic shared accounts.

Create a summary report flagging anomalies, with follow-up actions for each. If you find a former employee's credentials still active three months post-termination, you've identified a gap in your offboarding process.

5. Audit workforce access permissions against current job roles.

Compare who has access to what against their actual job functions. Remove access that's no longer needed (the "permission creep" problem).

Develop a matrix showing role, systems accessed, and justification. If your front-desk staff have administrative access to your EHR, that's a finding.

6. Verify Business Associate Agreements (BAAs) are current and complete.

Pull your vendor list. Confirm you have signed BAAs for every Business Associate. Check that agreements include breach notification terms, subcontractor flow-down, and termination/data-return clauses.

Maintain a spreadsheet with vendor name, service description, BAA signature date, and next review date. Missing or outdated BAAs are one of OCR's most common audit findings.

Month 3: Policy Evolution and Training

7. Update one policy or procedure to reflect current operations.

Don't let policies gather dust. Pick one area where your documented process doesn't match what your team actually does, or where new technology has changed your workflow.

Revise the policy with version number, effective date, and summary of changes. If you've moved to cloud-based telehealth but your remote-access policy still references on-premise VPN, update it.

8. Deliver targeted training on one high-risk area.

Annual training satisfies the baseline requirement, but quarterly micro-training on specific risks (phishing, device security, social engineering, proper disposal) keeps awareness high.

Document training attendance records, quiz scores if applicable, and topics covered. Consider a 15-minute session on recognizing phishing emails rather than waiting for next year's two-hour compliance marathon.

9. Document this quarter's compliance activities.

Compile your change log, test results, audit findings, policy updates, and training records into a quarterly compliance report.

Create a summary document your Privacy Official or Security Officer can present to leadership, showing what you reviewed, what you found, and what you fixed. This becomes your audit trail if OCR comes calling.

Common Mistakes

Treating the Risk Assessment as a January ritual. If you onboard a new cloud vendor in June, assess it in June. Waiting for your annual cycle means you're operating with unvetted risk for months.

Logging access but never reviewing logs. Audit controls are Required Specifications under § 164.312(b), but they're useless if no one looks at them. Set calendar reminders to pull and review logs quarterly.

Updating policies without updating practice. Your team needs to know about policy changes. A revised procedure that lives only in your compliance binder doesn't protect anyone.

Skipping the documentation. If you can't prove you did it, you didn't do it, at least not in OCR's eyes. Document every review, test, and update with dates and responsible parties.

Next Steps

Start your first 90-day cycle next month. Assign each checklist item to a specific person with a specific deadline. Add quarterly compliance reviews to your leadership calendar so they become routine, not crisis-driven.

If you discover gaps during your first cycle, that's the point. You're catching problems before they become breaches. Treat each finding as a win, document your remediation, and move to the next quarter.

Compliance isn't an annual event. It's a continuous pulse.

You Might Also Like