← All posts
$title · Readiness Drill

What to Gather Before a HIPAA Readiness Drill Starts

2026-07-11 · HIPAA readiness

A practical pre drill checklist for healthcare teams that want a private HIPAA readiness stress test to measure real evidence readiness instead of scrambling after the clock begins.

A readiness drill works best when it feels realistic. The point is not to create a perfect binder the night before. The point is to learn whether your team can find the right evidence, explain who owns it, and spot gaps before a regulator, payer, enterprise customer, or security incident forces the issue.

For a small clinic, billing service, telehealth practice, healthcare SaaS vendor, or business associate, the hardest part is often not knowing where to begin. Policies may live in one folder, risk notes in another, training records in email, vendor agreements in DocuSign, and security settings inside tools that only one person knows how to access. A timed HIPAA readiness drill gives that scattered reality a useful shape.

Before the clock starts, gather the materials below. You do not need to rewrite them. You do not need to make them pretty. In fact, a private drill is more valuable when it measures the current operating state honestly.

1. Your current HIPAA policies and procedures

Start with the obvious documents: privacy policy, security policy, breach response procedure, sanctions policy, access control procedure, workstation or device rules, password/MFA expectations, and any documentation about how staff should handle protected health information.

If the policies are old, still gather them. If they were copied from a template, gather them anyway. The drill can show whether they match your actual workflow. A generic policy that nobody follows is not useless, but it is a signal: either the policy needs to be updated, or the workflow needs to be tightened so the organization can defend what it says it does.

2. Security risk analysis and risk management notes

HIPAA readiness depends heavily on whether you have looked for risks and tracked how you handled them. Pull the most recent security risk analysis, risk register, remediation plan, gap list, or spreadsheet of security tasks.

If there is no formal risk analysis, gather whatever exists: notes from an IT review, findings from a consultant, screenshots from a security tool, board or owner notes, or a list of known weak spots. The drill should identify whether the organization has an evidence trail for risk decisions, not just whether someone remembers discussing them.

3. Training evidence

Training evidence is usually simple but surprisingly easy to lose. Gather completion reports, sign in sheets, LMS exports, onboarding checklists, employee attestations, or email confirmations showing that workforce members were trained on privacy and security expectations.

The useful question is not only “did people take training?” It is also “can we prove who took it, when they took it, and what topic was covered?” If the answer requires searching five inboxes, the drill will expose that operational weakness before it matters.

4. Business associate and vendor documentation

Make a list of vendors that touch systems, records, communications, payments, analytics, scheduling, hosting, backup, email, support, or other workflows connected to health information. Then gather business associate agreements, vendor security questionnaires, contracts, renewal emails, or notes explaining why a vendor is not treated as a business associate.

This does not need to be legal perfection for a private drill. It needs to be findable evidence. If a vendor is important but no agreement can be located, that is a clean remediation item.

5. Access control evidence

Access control is one of the best places to test whether written policy matches reality. Gather user lists from EHR, billing, cloud storage, email, password manager, help desk, remote access, practice management, and admin systems. If possible, include role names, admin accounts, inactive users, MFA settings, and recent access review notes.

A drill should help answer practical questions: Who has admin rights? Are former staff removed? Are shared accounts still used? Can the owner show that access is reviewed periodically? Screenshots and exports are fine as long as they are current and understandable.

6. Incident response and breach response material

Gather incident response plans, breach notification procedures, contact trees, cyber insurance instructions, past incident notes, tabletop exercise notes, and any “what to do if something happens” checklist. If the organization has never had a tabletop exercise, that is not a reason to avoid the drill. It is a reason to measure how ready the team is right now.

The strongest incident evidence usually shows ownership: who decides severity, who contacts legal or compliance help, who handles patients or clients, who preserves logs, and who communicates with vendors.

7. Backup, disaster recovery, and continuity proof

Pull backup settings, restore test notes, screenshots from backup tools, cloud retention settings, recovery procedures, and continuity plans. Do not stop at “we have backups.” The drill should make the team prove that backups are monitored, restorable, and connected to actual recovery steps.

If nobody has tested a restore recently, say so in the evidence. The goal is to create a useful gap report, not to pretend the control is stronger than it is.

8. Asset and system inventory

A simple system list can save hours. Include laptops, servers, cloud platforms, EHR or practice software, billing tools, phone/SMS tools, email, file storage, analytics, forms, and integrations. Add owners if known.

This inventory does not need to be enterprise grade. Even a clear spreadsheet is helpful. A drill can then connect evidence to actual systems instead of scoring policies in the abstract.

9. Recent proof beats perfect formatting

For a private readiness stress test, recent evidence is usually better than polished evidence. A current screenshot, export, signed checklist, or dated note often says more than a beautiful policy last touched three years ago. Keep filenames plain: `mfa settings july 2026.pdf`, `training export q2 2026.csv`, `vendor baa list.xlsx`, or `backup restore test notes.docx`.

That naming discipline helps the team under pressure. It also helps identify which artifacts should become permanent compliance evidence after the drill.

How to use the drill result

After the drill, sort findings into three groups: missing evidence, weak evidence, and workflow gaps. Missing evidence means the team may be doing the right thing but cannot prove it. Weak evidence means the proof exists but is outdated, unclear, or incomplete. Workflow gaps mean the actual process needs repair.

That distinction matters. A missing training export is a different problem from untrained staff. An outdated vendor list is a different problem from having no vendor review process. The best remediation plans are specific enough to assign, price, and finish.

Readiness Drill is designed for that kind of practical measurement: timed, private, evidence focused, and honest about what is not being stored. Gather what you already have, run the drill, and use the gap report to decide what deserves attention first.