Does HIPAA Require Employee Background Checks?

Does HIPAA require organizations to conduct background checks on employees that have access to protected health information? What Regulated Entities Must Know

Executive Summary:

Technically, no. The Health Insurance Portability and Accountability Act (HIPAA) text does not explicitly mandate criminal background checks for employees. However, HIPAA does require strict data access controls, and the Department of Health and Human Services (HHS) penalizes organizations that hire individuals excluded from federal healthcare programs. Consequently, background and exclusion checks are considered an industry best practice for regulatory compliance.

HIPAA Rules vs. Background Checks: Decoding CFR ยง 164.308

While you wonโ€™t find the phrase “background check” written into the Code of Federal Regulations (CFR) for HIPAA, compliance is heavily implied under the HIPAA Security Rule.

Specifically, 45 CFR ยง 164.308 (Administrative Safeguards) outlines Information Access Management. This standard requires covered entities and business associates to implement strict policies and procedures for authorizing access to electronic protected health information (ePHI).

How “Authorized Access” Impacts Hiring

  • Role-Based Access: Access to PHI must be appropriate for the workforce member’s specific role.
  • The Trustworthiness Standard: To defend your authorization process during an OCR audit, your organization must prove it verified that the workforce member is trustworthy enough to handle sensitive data.
  • The Industry Best Practice: Conducting criminal background checks during the pre-employment phase is the most defensible way to demonstrate due diligence in vetting workforce trustworthiness.

The OIG Exclusion List: A Mandatory Compliance Check

While criminal background checks are a strong recommendation, checking the HHS Office of Inspector General (OIG) database is practically mandatory if you want to avoid massive civil fines.

Organizations must screen all prospective hires against the List of Excluded Individuals/Entities (LEIE). If your organization employs an individual or entity on the LEIE to provide items or services funded by a federal healthcare program, you face severe Civil Monetary Penalties (CMP).

Real-World Compliance Warning: In a recent enforcement case, Windham Eye Care Practice and its owners were forced to pay a $192,000 civil penalty solely for employing an “excluded” individual. Failing to run an OIG exclusion check can result in direct, devastating financial consequences.

Frequently Asked Questions (FAQ)

Is a criminal background check required by HIPAA?

No, criminal background checks are not explicitly required by HIPAA regulations. However, they are highly recommended under HIPAA Administrative Safeguards to verify employee trustworthiness before granting access to protected health information (PHI).

What background checks are recommended for healthcare employees?

At a minimum, healthcare employers should conduct a criminal background check and a mandatory screening against the HHS OIG List of Excluded Individuals/Entities (LEIE).

What happens if a healthcare company hires an excluded individual?

Hiring an individual on the OIG exclusion list can result in massive civil monetary penalties, exclusion from federal funding (like Medicare and Medicaid), and an immediate investigation by the Office for Civil Rights (OCR) or OIG.

Ready to Eliminate Your HIPAA Risks?

Small, overlooked gaps in your hiring or information access workflows can trigger devastating federal audits.

At Colington Consulting, we specialize in making HIPAA compliance painless and efficient. We can help your organization develop robust onboarding policies, structure your information access management, and ensure you are defensibly positioned for an OCR investigation.

Schedule Your Free 30-Minute HIPAA Risk Review Now to identify your compliance gaps before they become costly violations.

  • Updated on June 9, 2026 and Reviewed By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert
  • Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.