Skip to content
2026

Now taking on 4 new clients this year — white-glove onboarding, month to month.

Book a call
HomeBlogHealthcare IT

HIPAA IT Compliance Checklist for Small Medical and Dental Practices

HIPAA IT compliance checklist on a clipboard beside a stethoscope and laptop at a small medical practice front desk

A HIPAA IT compliance checklist gives a small medical or dental practice a concrete path through the HIPAA Security Rule: run a risk analysis, control access, turn on MFA, encrypt patient data, test backups, sign BAAs, train staff, plan for incidents, and keep audit logs. Work those nine controls and you cover the Rule's technical core.

The Security Rule is the part of HIPAA that requires administrative, physical, and technical safeguards for electronic protected health information (ePHI), and it applies to practices of every size. The stakes are not abstract: 276,775,457 healthcare records were breached in 2024 across 725 large reported incidents, per HIPAA Journal's 2024 Healthcare Data Breach Report, including roughly 190 million people affected by the Change Healthcare ransomware attack alone, the largest healthcare breach on record. Healthcare also remained the most expensive industry for breaches at $6.64 million per incident, per IBM's 2026 Cost of a Data Breach report.

What does the HIPAA Security Rule require right now?

Today's Rule requires a documented risk analysis, a designated security official, workforce training, access and audit controls, integrity and transmission security measures, contingency planning with data backup, incident response procedures, and written business associate agreements, per HHS's Security Rule summary.

Some specifications, including encryption, are labeled "addressable." HHS is blunt that addressable does not mean optional: a practice must implement the measure if it is reasonable and appropriate, and otherwise must document why not and adopt an equivalent alternative. For a small practice with modern hardware, it is very hard to argue that encryption is not reasonable and appropriate.

What belongs on a HIPAA IT compliance checklist?

  1. Security risk analysis, done and dated. The foundation of the Rule and the first thing investigators request. Assess where ePHI lives, what threatens it, and what you are doing about each risk; refresh it annually and after major changes like a new EHR. HHS's Office for Civil Rights launched a Risk Analysis Initiative in October 2024 specifically to enforce this requirement.
  2. Access controls with unique user IDs. Every staff member gets their own login, scoped to their role. Shared front-desk accounts destroy accountability, and departed employees should lose access the day they leave.
  3. Multifactor authentication (MFA). Enable it on email, the EHR, VPN, and anything reachable from the internet. The current Rule requires authentication procedures without naming MFA; the proposed update would require MFA explicitly, and insurers already expect it.
  4. Encryption at rest and in transit. Full-disk encryption on every laptop and workstation (BitLocker, FileVault), encrypted transmission for anything carrying ePHI, and no patient data over plain personal texting apps.
  5. Tested, separated backups. The Rule's contingency planning standard requires retrievable copies of ePHI. Keep at least one backup copy isolated from your network, and prove restores actually work before ransomware runs the test for you.
  6. Business associate agreements (BAAs). A signed BAA for every vendor touching ePHI: EHR, billing service, clearinghouse, email platform, cloud storage, and your IT provider. Keep an inventory so nothing is missed.
  7. Security awareness training. Required for the whole workforce, including physicians. Cover phishing, password handling, and PHI hygiene, and document who completed it and when.
  8. Incident response plan. Written procedures for who isolates systems, who gets called, and how breach notification duties get met, printed somewhere reachable when systems are down.
  9. Audit logs, kept and reviewed. The Rule's audit controls standard requires mechanisms that record activity in systems containing ePHI. Keep EHR and Microsoft 365 logging enabled and review it, since logs nobody reads only tell the story after the damage.

What would change under the proposed Security Rule update?

In December 2024, HHS proposed a sweeping overhaul of the Security Rule; the notice of proposed rulemaking (NPRM) was published in the Federal Register on January 6, 2025, and its comment period closed March 7, 2025. It remains a proposed rule, not law: as of August 2026 no final rule has been issued, and HHS's entry in the OMB regulatory agenda now anticipates final action in July 2027, a year later than previously planned, per HIPAA Journal's July 2026 reporting. The current Security Rule stays fully in effect in the meantime.

Control areaCurrent Security Rule (in force)Proposed update (not final)
Encryption of ePHIAddressable: implement if reasonable and appropriate, or document an equivalent alternativeRequired at rest and in transit, with limited exceptions
Multifactor authenticationNot named; authentication procedures requiredRequired, with limited exceptions
Asset inventory and network mapNot an explicit standardRequired, reviewed at least every 12 months and after changes
Backup and recoveryBackup and contingency procedures requiredWritten procedures to restore certain systems and data within 72 hours
Security testingPeriodic evaluation requiredPenetration testing at least annually; vulnerability scans every six months
Required vs. addressableDistinction existsDistinction removed; specifications required with limited exceptions

Details above are from HHS's NPRM fact sheet. The practical read for a small practice: everything in the proposal is already best practice, so building toward it now means the eventual final rule, whatever its exact shape, arrives as a formality rather than a scramble. An annual penetration test is a sensible head start, since the proposal would make one mandatory.

Where do small practices fall short on HIPAA IT compliance?

Overwhelmingly, on the first checkbox. When OCR audited covered entities in 2016-2017, only 14% were substantially fulfilling their risk analysis obligations, per OCR's published audit findings, and the Risk Analysis Initiative has produced a steady stream of settlements since its October 2024 launch. The pattern in those enforcement actions is consistent: a breach happens, OCR investigates, and the practice cannot produce a current, thorough risk analysis.

The fix is unglamorous: schedule the risk analysis, remediate what it finds, and keep the paper trail. Most small practices get there fastest with help, because nobody on staff owns security full time. The NetSys Group has supported medical and dental practices across the New York metro area since 1998, and its security assessments map directly to the risk analysis and safeguard documentation OCR asks for.

Frequently asked questions

Is encryption mandatory under HIPAA right now?

Under the current Security Rule, encryption is an addressable specification: you must implement it if reasonable and appropriate, or document why not and use an equivalent measure, per HHS. The 2025 proposed rule would make encryption of ePHI mandatory with limited exceptions, but as of August 2026 that proposal has not been finalized.

Does HIPAA require multifactor authentication today?

Not by name. The current Rule requires procedures to verify that people seeking access to ePHI are who they claim to be, and MFA is the accepted modern way to meet that bar. HHS's proposed Security Rule update would require MFA explicitly, with limited exceptions, with final action now projected for July 2027.

How often does a practice need a HIPAA risk analysis?

The Security Rule requires an accurate and thorough assessment and expects it to stay current, without naming a calendar interval. In practice, most practices run one annually and after significant changes such as a new EHR, a new location, or a merger. Documented remediation of what the analysis finds matters as much as the analysis itself.

Reading is free. So is knowing where you stand.

Turn insight into action.

Take a free cybersecurity or AI readiness assessment, or book a call with a NetSys engineer — no obligation, no runaround.