HIPAA Policy Review Schedule
Interactive compliance calendar with annual, quarterly, and monthly tasks. Track policy reviews, training, audits, and compliance activities throughout the year.
Quick Answer: Ongoing Compliance Requirements
HIPAA requires periodic risk analysis and evaluation but does not set a specific review frequency. OCR guidance describes risk analysis as an ongoing process rather than a one-time event, and many organizations choose annual comprehensive reviews, quarterly compliance checks, and monthly monitoring of access logs and security incidents. Use this calendar to maintain consistent compliance activities.
Annual Compliance Tasks
Year-End Review & Planning
| Task | Owner | Due Date | Status |
|---|---|---|---|
|
Comprehensive Risk Assessment
|
Security Officer | Q1 (Jan-Mar) | Annual |
|
Review & Update HIPAA Policies
|
Privacy Officer | Q1 (Jan-Mar) | Annual |
|
Annual HIPAA Training for All Staff
|
Compliance Manager | Q1 or Q2 | Annual |
|
Audit All Business Associate Agreements
|
Privacy Officer | Q1 (Jan-Mar) | Annual |
|
Review Breach Notification Procedures
|
Privacy & Security Officer | Q1 (Jan-Mar) | Annual |
|
Internal Compliance Audit
|
Compliance Officer | Q3-Q4 (Sep-Dec) | Annual |
|
Plan Next Year Compliance Budget
|
CFO & Privacy Officer | Q4 (Oct-Dec) | Annual |
Quarterly Compliance Tasks
Every Quarter - 4 Times Per Year
| Task | Description | Frequency | Status |
|---|---|---|---|
|
Review Audit Logs (3-month sample)
|
Review access patterns, identify anomalies, verify logging completeness | Quarterly | Q1, Q2, Q3, Q4 |
|
Vulnerability Assessment
|
Scan systems for new vulnerabilities. Document findings and prioritize remediation | Quarterly | Q1, Q2, Q3, Q4 |
|
Compliance Committee Meeting
|
Review compliance status, address findings, plan upcoming activities | Quarterly | Q1, Q2, Q3, Q4 |
|
User Access Review
|
Audit user accounts, verify appropriate access levels, identify and remove unnecessary access | Quarterly | Q1, Q2, Q3, Q4 |
|
Data Integrity Check
|
Verify backup integrity, test disaster recovery procedures, document results | Quarterly | Q1, Q2, Q3, Q4 |
|
Review New Vendors/BAAs
|
Evaluate any new business associates, execute BAAs, update inventory | Quarterly | Q1, Q2, Q3, Q4 |
Monthly Compliance Tasks
January
- Risk assessment planning meeting
- Review previous year incident reports
- Update compliance roadmap
- Begin annual audit log review
February
- Conduct risk assessment
- Review and update policies
- Complete vendor risk assessment
- Audit sample of access logs
March
- Finalize risk assessment report
- Complete policy updates
- Plan annual training program
- Review Q1 compliance metrics
April
- Plan Q2 training sessions
- Begin mandatory annual training
- Monitor incident trends
- Vulnerability scan scheduled
May
- Continue staff training rollout
- Review Q2 audit logs
- Assess training completion rates
- Schedule Q2 compliance meeting
June
- Finalize Q2 training completion
- Q2 compliance committee meeting
- Mid-year compliance review
- Plan H2 priorities
July
- Plan Q3 audit preparation
- Summer vulnerability scan
- Review incident response plan
- Prepare mock audit schedule
August
- Conduct user access review
- Remove unnecessary access
- Q3 audit log review
- Backup integrity testing
September
- Schedule internal audit
- Audit preparation begins
- Q3 compliance meeting
- Document preparation
October
- Conduct internal audit
- Document audit findings
- Plan corrective actions
- Begin Q4 training plans
November
- Implement audit corrections
- Final Q4 audit log review
- Plan next year's budget
- Year-end risk assessment prep
December
- Year-end compliance review
- Finalize corrective actions
- Document annual accomplishments
- Plan next year initiatives
Monthly Monitoring Tasks (All Months)
Ongoing Monthly Requirements
| Task | Frequency | Responsibility | Status |
|---|---|---|---|
|
Monitor Audit Logs for Suspicious Activity
|
Monthly | IT Security | Ongoing |
|
Review System Security Alerts
|
Monthly | IT Security | Ongoing |
|
Review Incident Reports & Breaches
|
Monthly | Privacy Officer | Ongoing |
|
Update BAA Inventory
|
Monthly | Procurement & Privacy | Ongoing |
|
Verify Backup Completion
|
Monthly | IT Operations | Ongoing |
|
Review New Hire Onboarding Compliance
|
Monthly | HR & Compliance | Ongoing |
Documentation Tips
- Keep detailed records of all compliance activities for OCR audit readiness
- Document meeting minutes from compliance committee meetings quarterly
- Maintain evidence of training completion (attendance records, test scores)
- Keep copies of vulnerability assessments and remediation plans
- Store audit logs for minimum of 6 years (preferably longer)
- Document all policy updates with dates and versions