← EasyWayIT.com
EasyWayIT — Tampa Bay

HIPAA IT Compliance Checklist
for Small Healthcare Practices

The 10 technical safeguards OCR checks first — and how to document each one for practices under 50 staff.

Applies to: Medical practices, therapy clinics, dental offices, specialty practices Updated: 2026 Regulation: HIPAA Security Rule (45 CFR §164.312)
This checklist covers the technical safeguards that OCR (Office for Civil Rights) investigators prioritize in small practice audits. Administrative safeguards (policies, training records, BAAs) matter too, but technical gaps — unencrypted devices, missing audit logs, shared logins — are the most commonly cited deficiencies and the easiest for an examiner to document. Work through this list before your next risk assessment. Each item includes what to look for and how to document it.
1
Unique User Identification
  • Every staff member has their own login — no shared accounts Shared accounts (e.g., "front desk" login used by 3 people) make audit trails meaningless and violate the Unique User ID standard. Frequently cited
  • Generic or default accounts removed from all systems Default admin accounts on routers, EHR systems, and practice management software must be renamed or disabled.
  • Documentation: user account list with role and access level maintained Keep a current list of who has access to what — reviewed when staff join, change roles, or leave.
2
Automatic Logoff
  • All workstations lock automatically after ≤15 minutes of inactivity Exam room and front desk computers are highest risk — a patient or visitor should never find an unlocked session unattended. Frequently cited
  • EHR and practice management software also time out independently Windows screensaver lock is not enough — application-level session timeouts should be configured separately in the EHR settings.
  • Documentation: Group Policy or MDM settings showing timeout configuration A screenshot of the policy setting with the date applied is sufficient for an examiner.
3
Encryption — Data at Rest
  • BitLocker (Windows) or FileVault (Mac) enabled on all laptops and desktops A lost or stolen unencrypted laptop is a reportable breach. Encryption makes it an addressable non-event. This is the single most common gap in small practices. Most common gap
  • Any portable storage (USB drives, external hard drives) containing PHI is encrypted If PHI is never stored on portable media, document that policy instead.
  • Documentation: encryption status report from endpoint management tool, or manual audit log Run a BitLocker status report and save it. Repeat quarterly.
4
Encryption — Data in Transit
  • All PHI transmitted over the internet uses TLS encryption (HTTPS, encrypted email) Patient portals, referral communications, and lab results sent via email must use encrypted transport. Standard Gmail or Outlook without encryption add-ons is not sufficient for PHI.
  • Wi-Fi network uses WPA3 or WPA2-Enterprise — not WPA2-Personal with a shared password A shared Wi-Fi password known by patients, vendors, and staff creates unnecessary exposure.
  • Patient-facing guest Wi-Fi is on a separate network from clinical systems A guest network that shares the same segment as EHR workstations is a common configuration gap.
5
Audit Controls
  • EHR system has audit logging enabled — who accessed what record and when Most modern EHRs have this built in but it must be actively turned on and the logs retained. Check your EHR vendor settings. Frequently cited
  • Logs are retained for a minimum of 6 years HIPAA requires retention of documentation for 6 years from creation or last effective date.
  • Logs are reviewed periodically for unusual access patterns Quarterly review is sufficient for most small practices. Document who reviewed and when.
6
Multi-Factor Authentication
  • MFA enabled on all email accounts (Microsoft 365, Google Workspace) Email is the most common entry point for credential-based breaches. MFA on email alone prevents the majority of account takeover attacks. Most common gap
  • MFA enabled on EHR and practice management portals Most EHR vendors now support or require MFA — check the admin settings if you haven't configured it yet.
  • MFA enabled on any cloud storage used for PHI (OneDrive, SharePoint, Dropbox) Cloud storage containing patient documents must be protected — PHI in a personal Dropbox without MFA is a reportable exposure.
7
Business Associate Agreements (BAA)
  • Signed BAA on file for every vendor that touches PHI Includes: IT support, EHR vendor, cloud storage provider, billing service, transcription service, and any other vendor with access to patient data. Frequently cited
  • BAA list reviewed annually — departing vendors removed, new vendors added A BAA with a vendor you no longer use is not a compliance gap, but a missing BAA with a current vendor is.
  • BAAs stored in a retrievable location — not just in email inboxes Keep signed BAAs in a designated compliance folder accessible to the Privacy Officer.
8
Backup & Disaster Recovery
  • Automated daily backup of all systems containing PHI Backup must run automatically — "we can do a manual backup when needed" does not satisfy the contingency plan standard.
  • Backups are tested and verified — not just assumed to be running Test a restore quarterly. Document the test date and result. A backup that has never been tested is not a backup. Most common gap
  • At least one backup copy stored off-site or in the cloud An on-site-only backup is destroyed in the same fire or flood as your primary systems. The 3-2-1 rule: 3 copies, 2 media types, 1 off-site.
9
Risk Analysis Documentation
  • A formal written risk analysis has been completed and is on file This is the #1 cited HIPAA deficiency across all practice sizes. The risk analysis must identify where PHI exists, what threats and vulnerabilities apply, and what controls are in place. #1 cited deficiency
  • Risk analysis is reviewed and updated at least annually When new systems are added, staff changes, or after any security incident — update the risk analysis.
  • Risk management plan documents how identified risks are being addressed The analysis alone is not enough — you need a plan showing what you're doing about the risks you found.
10
Incident Response Plan
  • Written incident response plan exists and is accessible to staff The plan must cover: how to identify a breach, who to notify internally, and when to involve OCR. It does not need to be complex — a one-page procedure is sufficient for most small practices.
  • Breach notification timeline understood — 60 days from discovery to OCR notification Breaches affecting 500+ individuals in a state require notification to media and OCR within 60 days. Smaller breaches are logged and reported annually.
  • Staff know who to contact if they suspect a breach or see suspicious activity Every staff member should know: do not ignore it, do not try to fix it yourself, contact [name/role] immediately.
Important note on "addressable" vs. "required" safeguards: HIPAA uses two designations. "Required" items must be implemented as written. "Addressable" items must either be implemented OR you must document why an equivalent alternative was chosen. "Addressable" does not mean optional. Items 2, 4, and 5 above are addressable — all others are required. If you choose not to implement an addressable safeguard, document your reasoning in writing.
Self-Assessment Score
Checked items
__ / 30
OCR Priority items
__ / 12
Date completed
___________
Review annually or after any system change