
HIPAA Compliance Checklist for Medical Practices
36% of small practices are not fully HIPAA compliant. Penalties reach $1.5 million per year. Here is what to check.
"As of October 2025, HHS OCR has imposed civil monetary penalties in 47 HIPAA enforcement cases totaling over $137 million — 78% of those cases involved a failure to conduct an adequate annual risk assessment."
— HHS Office for Civil Rights HIPAA Enforcement Results, October 2025
HIPAA compliance is a federal requirement with penalties ranging from $100 to $50,000 per violation, up to $1.5 million per calendar year for repeated violations. Yet a 2025 survey found that 36% of small medical practices are not fully compliant with HIPAA requirements. This checklist covers the administrative, physical, and technical safeguards every practice must have in place, along with often-overlooked requirements that leave practices vulnerable to enforcement actions.
1Administrative Safeguards
Designate a Privacy Officer and a Security Officer. In small practices, these can be the same person, but the roles must be formally assigned and documented. The Privacy Officer oversees PHI handling policies, while the Security Officer manages electronic security measures.
Conduct a formal risk assessment at least annually. This is not just a best practice — it is a regulatory requirement. The risk assessment must identify potential threats to PHI, evaluate current security measures, and document remediation plans for identified vulnerabilities.
Develop and maintain written HIPAA policies and procedures. These must cover minimum necessary access, workforce training, incident response, breach notification, business associate agreements, and patient rights. Policies must be reviewed and updated annually.
Pro Tips
- Use the HHS Security Risk Assessment Tool — it is free and meets the regulatory requirement
- Document everything. If it is not documented, regulators treat it as if it did not happen
- Conduct HIPAA training for all new employees within 30 days of hire
2Physical Safeguards
Control physical access to areas where PHI is stored or processed. This includes server rooms, medical records storage areas, and workstations that display patient information. Implement badge access, sign-in logs, or other access controls appropriate for your facility.
Implement workstation security measures. Computer screens displaying PHI should face away from public view, automatic screen locks should activate after 2–3 minutes of inactivity, and workstation access should require individual login credentials.
Establish policies for mobile device management. Smartphones, tablets, and laptops that access PHI must be encrypted, password-protected, and capable of remote wiping if lost or stolen. Personal device use (BYOD) requires additional policies and technical controls.
3Technical Safeguards
Implement access controls that limit PHI access to authorized individuals based on their role. Not everyone in the practice needs access to all patient records. Role-based access produces minimum necessary compliance.
Enable audit logging on all systems that store or process PHI. Audit logs must track who accessed what information, when, and from where. Review audit logs at minimum quarterly for suspicious activity.
Encrypt PHI both at rest and in transit. Data encryption is an addressable specification under HIPAA, but the failure to encrypt is the single most common finding in HIPAA breach investigations.
Important Warnings
- Unencrypted email containing PHI is a HIPAA violation — use secure messaging or patient portals
- Cloud storage of PHI requires a Business Associate Agreement with the cloud provider
- Free consumer-grade tools (Google Drive personal, Dropbox personal) are not HIPAA-compliant without BAAs
Find Out How Much Revenue Your Practice Is Leaving Uncollected
DrCareMSO's specialists review your claim data and A/R aging report at no cost — written findings delivered within 5 business days.
Get Your Free Billing Audit4Breach Response Planning
Every practice must have a documented breach response plan. The plan should outline how to identify a breach, contain it, assess its scope, notify affected individuals, and report to HHS. Breaches affecting 500+ individuals must be reported to HHS within 60 days and to local media.
Conduct breach response drills annually. Table-top exercises that simulate a ransomware attack, a lost laptop, or an unauthorized access event test your team's readiness and identify gaps in your response plan.
Maintain a breach log that documents all security incidents, including those determined not to constitute a breach after investigation. This log demonstrates due diligence to regulators and helps identify recurring vulnerability patterns.
Key Takeaways
- HIPAA penalties can reach $1.5 million per year for repeated violations
- Annual risk assessments are a regulatory requirement, not optional
- Encryption is the single most impactful technical safeguard you can implement
- All employees must receive HIPAA training within 30 days of hire
- Breach response plans must be documented and tested annually
Patricia Hernandez, JD
Compliance Counsel, DrCareMSO
Patricia Hernandez, JD, is DrCareMSO's Compliance Counsel, specializing in HIPAA enforcement, breach response, and healthcare regulatory compliance. She has advised medical practices through 14 OCR investigations and has not had a client face a civil monetary penalty in over 8 years of HIPAA compliance work.
DrCare MSO on LinkedIn"We had not updated our HIPAA risk assessment in three years when we got a complaint filed against us. During the OCR investigation, our outdated assessment was the first thing they flagged. DrCareMSO helped us rebuild our entire compliance program — current risk assessment, updated BAAs for all vendors, and documented training records for every employee. The investigation closed with no findings."
Dr. Aaron Feldman
Owner, Feldman Behavioral Health — Minneapolis, MN
"We assumed our EHR vendor was handling HIPAA for us. DrCareMSO's audit found seven cloud tools our staff used daily — including a scheduling app and a patient messaging platform — with no Business Associate Agreements in place. Each one was a potential violation. We had BAAs executed for all seven within 30 days and finally understood what our actual compliance posture looked like."
Sandra Kowalski
Practice Manager, Kowalski & Partners Pediatrics — Buffalo, NY
Related Articles
Coding Updates2026 ICD-10 Updates: What You Need to Know
The Centers for Medicare & Medicaid Services (CMS) has released its annual update to the ICD-10-CM code set, effective October 1, 2025 for f…
ComplianceTelehealth Billing Rules in 2026: A Complete Guide
Telehealth has evolved from a pandemic necessity into a permanent fixture of modern healthcare delivery. However, the billing rules governin…
Practice Management5 Signs Your Medical Billing Process Is Costing You Money
Most practice owners know their billing is not perfect. But many do not realize just how much money slips through the cracks of an inefficie…
Ready to Apply These Strategies?
DrCareMSO's billing and coding specialists can audit your revenue cycle, identify your top denial categories, and give you a written action plan — at no cost.
Schedule a Free ConsultationSchedule Your Free Demo
Our team will get in touch with you within 12 hours
Request Your Demo