Start Free Assessment

HIPAA New Year Compliance Checklist (2025-2026)

Start 2026 with a strong HIPAA compliance foundation by completing key January tasks and planning for the year ahead.

This checklist covers planning, budgeting, initial risk assessment, and January compliance activities to set your organization up for compliance success.

Pre-Year Planning (December/January)

Leadership & Planning

Schedule compliance planning meeting with leadership
Set compliance goals for the year
Review prior year audit findings
Prioritize remediation activities
Assign compliance ownership

Budget & Resources

Allocate budget for compliance activities
Plan training program costs
Budget for security tools/software
Plan audit/assessment costs
Schedule staff time for compliance work

Calendar & Scheduling

Create annual compliance calendar
Schedule quarterly review meetings
Block time for risk assessment
Schedule annual audit/assessment
Plan training dates

January Compliance Checklist

Risk Management

Schedule comprehensive risk assessment
Review and update risk register
Assess any new systems or changes
Document mitigation strategies

Access & User Management

Audit all user access to systems
Remove inactive user accounts
Review roles and permissions
Verify access controls working

Vendor & Business Associate

Update vendor and BAA list
Verify BAAs signed for all vendors
Schedule vendor security assessments
Request security certifications

Documentation & Records

Review compliance file organization
Archive prior year documentation
Start new year compliance tracking
Verify document retention procedures

Security Systems

Verify backups working properly
Check encryption on all systems
Verify firewall protection active
Test disaster recovery procedures

Policies & Training

Review and update all policies
Notify staff of any policy changes
Distribute updated policies
Schedule annual training program

Q1 Compliance Goals

Sample Q1 Goals

  • Complete Risk Assessment: Finish comprehensive annual risk assessment by February 28
  • Update Policies: Review and update all HIPAA policies by January 31
  • Audit Access: Complete user access audit and address any violations by February 15
  • BAA Review: Audit all Business Associate Agreements by March 31
  • Vendor Assessment: Begin annual vendor security assessments
  • Documentation: Organize and file all compliance documentation

Prepare Your 2026 Compliance Plan

Get templates, checklists, and planning tools for a successful compliance year.

Get Annual Planning Tools