HIPAA New Year Compliance Checklist (2025-2026)
Start 2026 with a strong HIPAA compliance foundation by completing key January tasks and planning for the year ahead.
This checklist covers planning, budgeting, initial risk assessment, and January compliance activities to set your organization up for compliance success.
Pre-Year Planning (December/January)
Leadership & Planning
Schedule compliance planning meeting with leadership
Set compliance goals for the year
Review prior year audit findings
Prioritize remediation activities
Assign compliance ownership
Budget & Resources
Allocate budget for compliance activities
Plan training program costs
Budget for security tools/software
Plan audit/assessment costs
Schedule staff time for compliance work
Calendar & Scheduling
Create annual compliance calendar
Schedule quarterly review meetings
Block time for risk assessment
Schedule annual audit/assessment
Plan training dates
January Compliance Checklist
Risk Management
Schedule comprehensive risk assessment
Review and update risk register
Assess any new systems or changes
Document mitigation strategies
Access & User Management
Audit all user access to systems
Remove inactive user accounts
Review roles and permissions
Verify access controls working
Vendor & Business Associate
Update vendor and BAA list
Verify BAAs signed for all vendors
Schedule vendor security assessments
Request security certifications
Documentation & Records
Review compliance file organization
Archive prior year documentation
Start new year compliance tracking
Verify document retention procedures
Security Systems
Verify backups working properly
Check encryption on all systems
Verify firewall protection active
Test disaster recovery procedures
Policies & Training
Review and update all policies
Notify staff of any policy changes
Distribute updated policies
Schedule annual training program
Q1 Compliance Goals
Sample Q1 Goals
- Complete Risk Assessment: Finish comprehensive annual risk assessment by February 28
- Update Policies: Review and update all HIPAA policies by January 31
- Audit Access: Complete user access audit and address any violations by February 15
- BAA Review: Audit all Business Associate Agreements by March 31
- Vendor Assessment: Begin annual vendor security assessments
- Documentation: Organize and file all compliance documentation
Prepare Your 2026 Compliance Plan
Get templates, checklists, and planning tools for a successful compliance year.
Get Annual Planning Tools