HIPAA for Small Practices: The IT Compliance Checklist That Won't Overwhelm You

Sep 23, 2026

0 Comments

HIPAA for Small Practices: The IT Compliance Checklist That Won't Overwhelm You

HIPAA compliance does not require a large compliance department or an unlimited technology budget.

It does require a clear understanding of where electronic protected health information (ePHI) lives, who can access it, how it is protected, and what happens when something goes wrong.

For a small medical practice, the goal is not to buy every security tool available. The goal is to implement reasonable safeguards, document your decisions, and keep improving as your systems and risks change.

This checklist focuses on the IT areas that create the most practical value:

  • Access controls
  • Encryption
  • Audit logs
  • Business Associate Agreements
  • Risk analysis and documentation
  • Backups and incident response

We will also explain where cybersecurity consulting, managed IT services for small business, and IT consulting services can help without creating unnecessary complexity.

> Important: This article is an IT-focused guide, not legal advice. HIPAA obligations can vary based on your practice, services, state laws, contracts, and business relationships. Involve qualified legal or compliance professionals when you need a formal determination.

START WITH A DOCUMENTED RISK ANALYSIS

The first step is not purchasing software. It is understanding your environment.

The HIPAA Security Rule requires covered entities to conduct an accurate and thorough assessment of the risks and vulnerabilities affecting ePHI. Small practices are not exempt. However, your safeguards can be scaled to your size, complexity, capabilities, and risks.

Your risk analysis should answer:

  • Where is ePHI created, received, stored, changed, or transmitted?
  • Which employees, contractors, and vendors can access it?
  • What devices connect to your systems?
  • What would happen if your EHR became unavailable?
  • What safeguards already exist?
  • Which risks require immediate action?

Include your:

  • Electronic health record and practice management systems
  • Billing and claims platforms
  • Email and secure messaging tools
  • Telehealth applications
  • Cloud storage
  • Workstations, laptops, and mobile devices
  • Backup systems
  • Printers, scanners, and removable media
  • IT providers and other vendors

Your risk analysis should produce more than a report. It should produce a prioritized remediation plan.

For example:

  • Critical: Former employees still have active accounts
  • High: Laptops containing ePHI are not encrypted
  • Medium: EHR audit logs are enabled but never reviewed
  • Low: Security policies are outdated or difficult for staff to find

A practical assessment can often be completed in one to two weeks, depending on the number of systems, locations, and vendors involved. The important part is keeping the analysis current. Review it at least annually and after major changes such as a new EHR, office move, cloud migration, acquisition, or security incident.

Learn more about how Five 9 approaches risk-based protection through our security services.

1. CONTROL WHO CAN ACCESS PATIENT INFORMATION

Access control means more than giving employees usernames and passwords. It means ensuring that each person can access only the information and systems required for their role.

Start with these controls:

  • Assign a unique user ID to every workforce member.
  • Prohibit shared accounts wherever possible.
  • Use role-based access permissions.
  • Review administrative privileges regularly.
  • Require multi-factor authentication for remote, privileged, and high-risk access.
  • Disable accounts promptly when someone leaves the practice.
  • Update permissions when an employee changes roles.
  • Use automatic screen locks and session timeouts.
  • Establish emergency access procedures.

A front-desk employee may need scheduling and demographic information. A billing employee may need claims data. A clinician may need access to clinical records. Those roles do not automatically require the same permissions.

This is the principle of least privilege: give people the access they need to do their jobs, and no more.

HIPAA access controls showing role-based permissions and multi-factor authentication

MAKE ONBOARDING AND OFFBOARDING REPEATABLE

Small practices often rely on informal processes. A manager sends an email when a new employee starts. Someone remembers to disable an account after a departure. That approach creates avoidable risk.

Create a short access checklist for every employee:

  • Account created with the correct role
  • MFA enrolled
  • Device issued and secured
  • Required applications assigned
  • Security training completed
  • Access reviewed by a supervisor

Repeat the process in reverse during offboarding. Disable accounts, revoke remote access, recover devices, rotate shared credentials where necessary, and document completion.

2. ENCRYPT EPHI IN TRANSIT AND AT REST

Encryption makes data unreadable without the appropriate key. It is one of the most effective ways to reduce exposure if a device is lost, a connection is intercepted, or a storage system is accessed improperly.

HIPAA treats encryption as an addressable implementation specification. That does not mean you can simply ignore it. You must evaluate whether encryption is reasonable and appropriate for your environment. If you decide not to use it, document why and implement an equivalent safeguard.

For most modern practices, encryption should be the standard.

ENCRYPTION CHECKLIST

Use encryption for:

  • Laptops and workstations that store ePHI
  • Smartphones and tablets used for practice business
  • Servers and cloud storage
  • Backup repositories
  • Removable media
  • Remote connections
  • Patient portals and web applications
  • Email or messaging that transmits ePHI

Use secure, modern connections such as TLS for data moving between systems. Do not send patient information through ordinary personal email or consumer messaging platforms unless the service is configured for HIPAA-appropriate use and covered by a Business Associate Agreement when required.

Also confirm that lost or stolen devices can be remotely locked or wiped. Mobile device management can enforce encryption, screen-lock policies, application restrictions, and remote-wipe capabilities without requiring staff to manage every setting manually.

3. TURN ON AUDIT LOGS AND REVIEW THEM

Audit controls record activity in systems that contain or use ePHI. They help you answer basic but important questions:

  • Who accessed a patient record?
  • When did they access it?
  • What did they view or change?
  • Was information exported or downloaded?
  • Did an administrator change permissions?
  • Was there unusual activity outside normal business hours?

Enable audit logging in your:

  • EHR
  • Practice management system
  • Patient portal
  • E-prescribing platform
  • Secure messaging tools
  • Cloud applications
  • VPN
  • Firewalls and other network devices

Logs are only useful if someone reviews them. Create a schedule that fits your practice. Critical EHR and administrative activity may warrant more frequent review. Broader system reviews can occur monthly or according to your documented risk plan.

Watch for:

  • Repeated failed login attempts
  • Logins from unfamiliar locations
  • Large data exports
  • Access to records outside a user’s normal role
  • Unusual after-hours activity
  • Sudden changes to permissions
  • Disabled security tools

Protect logs from unauthorized alteration and retain compliance documentation according to HIPAA, contractual, and applicable state requirements. Many HIPAA-related records are retained for six years, but your legal and compliance advisors should confirm the requirements that apply to your practice.

Encrypted healthcare data vault with protected cloud storage and audit activity timeline

4. REVIEW EVERY BUSINESS ASSOCIATE AGREEMENT

A Business Associate Agreement, or BAA, is required when a vendor creates, receives, maintains, or transmits PHI on behalf of your practice.

This can include:

  • EHR providers
  • Medical billing companies
  • Cloud hosting providers
  • Backup vendors
  • Email and secure messaging providers
  • Telehealth platforms
  • IT service providers
  • Document destruction companies
  • Claims clearinghouses
  • Practice management consultants

Do not assume that a vendor is compliant simply because its website says “HIPAA-ready.” Review the agreement and confirm that it addresses permitted uses, safeguards, breach reporting, subcontractors, and the responsibilities of both parties.

Maintain a vendor inventory with:

  • Vendor name and service
  • Type of PHI involved
  • Systems or locations accessed
  • BAA status
  • Contract owner
  • Renewal date
  • Security documentation reviewed
  • Date of most recent vendor review

A vendor that refuses to sign an appropriate BAA should not receive PHI unless qualified counsel confirms that no BAA is required.

Secure vendor relationship represented by a healthcare office, cloud provider, and signed compliance agreement

5. TEST BACKUPS AND PREPARE FOR INCIDENTS

HIPAA compliance includes availability. Your practice must be able to protect and restore ePHI when systems fail, ransomware strikes, or a facility becomes unavailable.

Your backup and recovery plan should define:

  • Which systems and data are backed up
  • How often backups run
  • Where backups are stored
  • How backups are encrypted
  • Who can access them
  • How long they are retained
  • How quickly systems must be restored
  • Who makes recovery decisions

A backup that has never been restored is an assumption, not a recovery plan. Test restores regularly and document the results.

You also need a written incident response process. Staff should know how to report:

  • Suspected phishing
  • Lost or stolen devices
  • Incorrectly sent emails
  • Unauthorized access
  • Malware or ransomware
  • Unusual EHR activity
  • Accidental disclosures

Your process should cover containment, investigation, documentation, vendor coordination, and breach notification decisions. You may also need to coordinate with legal counsel, cyber insurance providers, law enforcement, and HHS depending on the incident.

6. TRAIN STAFF AND KEEP EVIDENCE

Technology cannot compensate for unclear expectations.

Train employees when they join the practice and at least annually thereafter. Training should cover:

  • Passwords and MFA
  • Phishing and social engineering
  • Secure handling of printed records
  • Email and messaging rules
  • Incident reporting
  • Mobile device security
  • Clean-desk and screen-lock requirements
  • Appropriate access to patient information

Keep evidence of training completion. Also document policy reviews, risk analysis updates, access reviews, log reviews, backup tests, incident investigations, and vendor assessments.

HIPAA compliance is not only about having a policy. It is about showing that the policy exists, employees understand it, and the practice follows it.

WHEN TO BRING IN IT EXPERTS

You do not need to manage every technical detail alone.

A cybersecurity consulting engagement can help identify vulnerabilities, prioritize remediation, and validate whether controls work as intended. Managed IT services for small business can provide ongoing monitoring, patching, access management, backup oversight, and support. IT consulting services can help you make decisions about EHR integrations, cloud systems, network design, and vendor responsibilities.

Look for a partner that:

  • Explains risks in plain English
  • Provides clear scopes and deliverables
  • Supports your existing team
  • Documents the work
  • Helps with implementation, not just reports
  • Offers flexible project or recurring support options
  • Is transparent about what it can and cannot handle

Five 9’s consulting services are designed around solving specific technical problems while transferring knowledge to your internal team. Our security services can support assessments, compliance frameworks, vulnerability management, incident response planning, and ongoing protection.

YOUR SMALL-PRACTICE HIPAA IT CHECKLIST

You are moving in the right direction if you can answer “yes” to these questions:

  1. Have we documented where ePHI exists and how it moves?
  2. Do all users have unique accounts and appropriate permissions?
  3. Is MFA enabled for remote and privileged access?
  4. Are laptops, mobile devices, servers, and backups encrypted?
  5. Are audit logs enabled and reviewed?
  6. Do we have a current BAA with every applicable vendor?
  7. Are backups tested and recoverable?
  8. Do employees know how to report a suspected incident?
  9. Are HIPAA policies and training records current?
  10. Do we have a prioritized plan for unresolved risks?

You do not need to solve every gap in one week. Start with the highest-impact risks. Assign owners. Set deadlines. Document progress.

If you want an honest assessment of where your practice stands, contact Five 9 for a no-pressure conversation. We can help you understand the gaps, explain your options, and determine whether our support is a good fit.

Five 9 Assistant

Automated · not a live person
HIPAA for Small Practices: The IT Compliance Checklist That Won't Overwhelm You | Five 9 Blog