A HIPAA readiness checklist for a small practice
6 min read · last reviewed 2026-10-06
HIPAA is not a product you buy, and no IT provider can certify you as compliant. What technology can do is remove the common failure modes: shared logins, unencrypted devices, untested backups and no idea what happened after a breach. This is the technical checklist we walk through with practices, written for a practice manager rather than a lawyer.
Access: every person, their own account
Shared logins are the single most common finding in a small practice, and they defeat everything else — you cannot audit who did what, and offboarding becomes a password everyone already knows. The rule is one account per person, the least access the role needs, and a written list of who has access to what.
- Unique accounts, no shared or generic logins
- Multi-factor authentication on email, remote access and your EHR
- Administrator accounts used only for administration
- A documented process for when someone joins or leaves
Data at rest and in motion
Protected health information should be encrypted both while it is stored and while it travels. In practice that means full-disk encryption on every laptop and workstation, encryption on backups, and TLS for anything crossing a network — including the practice-management or imaging traffic between the back-room server and the front desk.
Email is a special case. Standard email is not a safe way to send PHI, so the practical setup is encrypted email or a secure portal, with a clear rule about which one your staff should use.
Backup, and the part everyone skips
A backup that has never been restored is a hope. What auditors and insurers both ask for is evidence: that copies are encrypted, that at least one copy is offsite (or in a different cloud from the source), and that someone has actually restored from it and checked the result.
Keep a short log — what was restored, when, by whom, and whether the data matched. That page answers more questions than any policy document.
Logging, and knowing what normal looks like
You cannot report a breach you did not notice. Turn on the logging your systems already offer, keep it long enough to investigate, and review alerts rather than collecting them. For most small practices this means authentication logs, email-security alerts and a way to see unusual remote logins.
Pair it with a one-page incident plan: who to call, in what order, what to unplug, and how clients will be told. The requirement to notify affected individuals exists whether or not you have a plan — the plan is what makes the difference between a bad week and a catastrophe.
The written side, in one paragraph
HIPAA expects documented policies: a security risk analysis you review periodically, policies for access and devices, and a business associate agreement with every vendor who can touch PHI — your IT provider, your cloud provider, your billing service. We keep the IT half of that evidence organised and produce it when you ask; the legal drafting belongs with your counsel, which is why this page is a checklist and not a warranty.
This is general guidance for practices in Utah — it is not legal, medical, compliance or tax advice, and it is not a substitute for advice on your own systems and obligations. Reviewed 2026-10-06; tell us if something in it has changed.
