HIPAA OCR enforcement hit Anthem with a $16M fine and Premera $6.85M — almost always for the same root causes: no enterprise-wide risk analysis, missing BAAs, or insufficient access controls. This checklist walks the Privacy Rule, Security Rule (administrative, physical, technical), and Breach Notification in the order an OCR auditor will ask for them.
Drop your existing HIPAA policy or upload a draft — ComplianceIQ runs the same checklist against your document and returns a 0–100 score, gap-by-gap with exact fixes and remediation copy.