HIPAA Compliance Checklist for Medical Practices

A checklist of administrative, physical and technical safeguards, plus how to prepare for a breach.

Topic
Compliance
Published
Reading time
3 min
From
DrCareMSO
Brass combination padlock on a laptop keyboard beside a bank card

Key takeaways

  • HIPAA penalties can reach $1.5 million per year for repeated violations
  • Annual risk assessments are a regulatory requirement, not optional
  • Encryption is the single most impactful technical safeguard you can implement
  • All employees must receive HIPAA training within 30 days of hire
  • Breach response plans must be documented and tested annually

HIPAA compliance is a federal requirement with penalties ranging from $100 to $50,000 per violation, up to $1.5 million per calendar year for repeated violations. Yet a 2025 survey found that 36% of small medical practices are not fully compliant with HIPAA requirements. This checklist covers the administrative, physical, and technical safeguards every practice must have in place, along with often-overlooked requirements that leave practices vulnerable to enforcement actions.

Administrative Safeguards

Designate a Privacy Officer and a Security Officer. In small practices, these can be the same person, but the roles must be formally assigned and documented. The Privacy Officer oversees PHI handling policies, while the Security Officer manages electronic security measures.

Conduct a formal risk assessment at least annually. This is not just a best practice — it is a regulatory requirement. The risk assessment must identify potential threats to PHI, evaluate current security measures, and document remediation plans for identified vulnerabilities.

Develop and maintain written HIPAA policies and procedures. These must cover minimum necessary access, workforce training, incident response, breach notification, business associate agreements, and patient rights. Policies must be reviewed and updated annually.

Practical tips

  • Use the HHS Security Risk Assessment Tool — it is free and meets the regulatory requirement
  • Document everything. If it is not documented, regulators treat it as if it did not happen
  • Conduct HIPAA training for all new employees within 30 days of hire

Physical Safeguards

Control physical access to areas where PHI is stored or processed. This includes server rooms, medical records storage areas, and workstations that display patient information. Implement badge access, sign-in logs, or other access controls appropriate for your facility.

Implement workstation security measures. Computer screens displaying PHI should face away from public view, automatic screen locks should activate after 2–3 minutes of inactivity, and workstation access should require individual login credentials.

Establish policies for mobile device management. Smartphones, tablets, and laptops that access PHI must be encrypted, password-protected, and capable of remote wiping if lost or stolen. Personal device use (BYOD) requires additional policies and technical controls.

Technical Safeguards

Implement access controls that limit PHI access to authorized individuals based on their role. Not everyone in the practice needs access to all patient records. Role-based access produces minimum necessary compliance.

Enable audit logging on all systems that store or process PHI. Audit logs must track who accessed what information, when, and from where. Review audit logs at minimum quarterly for suspicious activity.

Encrypt PHI both at rest and in transit. Data encryption is an addressable specification under HIPAA, but the failure to encrypt is the single most common finding in HIPAA breach investigations.

Watch out for

  • Unencrypted email containing PHI is a HIPAA violation — use secure messaging or patient portals
  • Cloud storage of PHI requires a Business Associate Agreement with the cloud provider
  • Free consumer-grade tools (Google Drive personal, Dropbox personal) are not HIPAA-compliant without BAAs

Breach Response Planning

Every practice must have a documented breach response plan. The plan should outline how to identify a breach, contain it, assess its scope, notify affected individuals, and report to HHS. Breaches affecting 500+ individuals must be reported to HHS within 60 days and to local media.

Conduct breach response drills annually. Table-top exercises that simulate a ransomware attack, a lost laptop, or an unauthorized access event test your team's readiness and identify gaps in your response plan.

Maintain a breach log that documents all security incidents, including those determined not to constitute a breach after investigation. This log demonstrates due diligence to regulators and helps identify recurring vulnerability patterns.

About this article

Published by the DrCareMSO team. It is general information for practice owners and billing staff, not legal, coding or compliance advice. Coding rules and payer policies change, so check current CMS, AMA and payer guidance before you act.

Keep reading

All articles
Free Consultation

Schedule Your Free Demo

Our team will get in touch with you within 12 hours

Request Your Demo
Call NowFree Consult

Dr. Care AI

Your Medical Billing Assistant

Welcome! 👋

Please share your details to get started.