HIPAA IT Readiness Checklist Know where you stand.

Work through the technical safeguard requirements under HIPAA. See your compliance score by category and export a summary for your records. Takes about 10 minutes. No signup needed.

๐Ÿฅ Medical Offices ๐Ÿฆท Dental Practices Free ยท No Signup Runs in Your Browser Print / Export Ready
0 of 36 items answered 0%
๐Ÿ” Access Controls 0 / 7
Every user has a unique login โ€” no shared accounts
Shared logins make audit trails useless and violate the unique user ID standard.
Required
Multi-factor authentication (MFA) is enabled for all staff
Covers email, EHR/EMR login, remote access, and any cloud system with ePHI.
Required
Role-based access โ€” staff only see data their role requires
A front-desk coordinator doesn't need access to clinical notes. Limit by role in your EHR settings.
Required
Terminated employees are offboarded same day (accounts disabled, access revoked)
Includes email, EHR, remote access, and any shared tools.
Required
Workstations auto-lock after 5โ€“10 minutes of inactivity
Prevents unauthorized access when a staff member steps away from a patient-facing workstation.
Addressable
Emergency access procedure is documented
A defined process to access ePHI when the primary system is unavailable (e.g., system outage during patient care).
Required
Password policy enforces minimum length and complexity
At minimum: 12+ characters, no reuse of last 5 passwords. Enforced via policy, not just guidelines.
Addressable
๐Ÿ“‹ Audit Controls & Logging 0 / 5
EHR/EMR login and access events are logged automatically
Most EHR systems have built-in audit logs โ€” confirm they are enabled and retained for at least 6 years.
Required
Audit logs are reviewed periodically (at least quarterly)
Logs are useless if no one reviews them. Schedule a quarterly review and document that it happened.
Required
Failed login attempts trigger an alert or are logged
Multiple failed logins can indicate a brute-force attempt or a former employee trying to regain access.
Addressable
Audit log retention meets the 6-year HIPAA minimum
Logs cannot be deleted or overwritten within the retention period. Confirm with your EHR vendor.
Required
System activity is monitored for unusual access patterns
E.g., a staff member downloading a large number of patient records, or accessing records outside their department.
Addressable
๐Ÿ”’ Encryption & Transmission Security 0 / 6
All devices storing ePHI use full-disk encryption
Covers laptops, workstations, mobile devices, and any external drives. BitLocker (Windows) or FileVault (Mac) at minimum.
Addressable
Patient data is never sent via unencrypted email
Standard email is not HIPAA-compliant for ePHI. Use a HIPAA-compliant messaging platform or encrypted email service.
Required
Remote access to office systems uses a VPN or encrypted connection
Staff working from home accessing the EHR must use a VPN. RDP exposed to the internet without VPN is a HIPAA violation waiting to happen.
Required
Patient-facing portals use HTTPS / TLS
Any web portal where patients can view records, book appointments, or message staff must be served over HTTPS.
Required
USB drives and removable media with ePHI are encrypted
If staff use USB drives for any reason that touches patient data, those drives must be encrypted.
Addressable
Office Wi-Fi is segmented โ€” patient/guest network is separate from clinical systems
A single flat network means a guest on your Wi-Fi has potential access to the same segment as your EHR server.
Addressable
๐Ÿ’พ Backup & Data Integrity 0 / 6
Patient data is backed up daily (automated)
Manual backups are not reliable. Daily automated backups are the minimum for any practice with active patient records.
Required
Backups are stored off-site or in a separate cloud location
A backup stored on the same server it's backing up isn't a backup โ€” it's a copy. Off-site or cloud backup is required for disaster recovery.
Required
Backups are tested with an actual restore at least quarterly
A backup job that shows green doesn't mean the data is actually recoverable. Test a real restore periodically and document it.
Required
Backup data is encrypted at rest and in transit
Unencrypted backups of ePHI are a HIPAA violation even if the primary system is encrypted.
Addressable
A disaster recovery plan exists and is documented
Covers what happens if the server fails, ransomware hits, or the office is inaccessible. Must include RTO (how fast you recover) and RPO (how much data you can afford to lose).
Required
EHR/practice management vendor has a signed BAA on file
A Business Associate Agreement is legally required for any vendor that accesses, stores, or processes ePHI on your behalf.
Required
๐Ÿ’ป Device & Endpoint Security 0 / 6
All workstations run current, supported OS versions
Windows 10 support ends October 2025. Any machine still on Windows 10 or older after that date is a compliance risk.
Required
Endpoint protection (antivirus/EDR) is installed and current on all devices
Windows Defender alone is insufficient for a medical practice. A managed EDR solution provides better detection and centralized alerting.
Required
OS and software patches are applied within 30 days of release
Unpatched systems are the #1 ransomware entry point in healthcare. Automate patching where possible.
Addressable
Mobile devices used for work are enrolled in MDM or have remote wipe enabled
A staff member's personal phone accessing patient emails or the EHR app is a covered device under HIPAA.
Addressable
Devices are inventoried โ€” a record exists of all hardware that accesses ePHI
You can't protect what you don't know exists. A simple spreadsheet works; a managed endpoint tool is better.
Required
Decommissioned devices are wiped before disposal or donation
A factory reset is not sufficient. Use NIST 800-88-compliant wiping or physical destruction for drives that held ePHI.
Required
๐Ÿ“š Training & Policies 0 / 6
All staff complete annual HIPAA security awareness training
Required for every employee who handles ePHI. Training completion must be documented.
Required
A Security Officer (or designated responsible person) is named
HIPAA requires a designated Security Officer. In a small practice this is often the owner or office manager โ€” it just needs to be documented.
Required
A written Security Risk Assessment (SRA) has been completed in the last 12 months
The SRA is the cornerstone of HIPAA compliance. Without it, no other control is sufficient. HHS provides a free SRA tool.
Required
A breach notification policy exists and staff know how to report a potential breach
Staff need to know what counts as a breach and who to tell. A phishing click that exposed patient data is a reportable breach.
Required
Phishing simulation or awareness testing is done at least annually
Email is the #1 attack vector in healthcare. Simulated phishing tests measure real risk, not just training completion.
Addressable
BAAs are in place with all business associates (IT provider, billing, cloud storage, etc.)
Every vendor that touches ePHI needs a signed BAA โ€” including your IT provider, your cloud backup vendor, and your billing company.
Required

Your HIPAA IT Readiness Summary

Items checked 0
Items marked N/A 0
Items outstanding 36
Overall score 0%
Readiness level Not started

Gaps found? We can help.

LineSight Digital provides HIPAA-aware IT support for medical and dental practices across the Bay Area. We'll review your results and tell you exactly what to fix first.

  • Free IT assessment โ€” no obligation
  • On-site visits in San Jose & surrounding cities
  • BAA available for all managed IT clients
  • 1-business-day response
Get Free IT Assessment See HIPAA IT Compliance Services โ†’
Common Questions

HIPAA IT Questions Answered

What are HIPAA technical safeguards? +

HIPAA technical safeguards are the technology controls required to protect electronic protected health information (ePHI). They cover access controls, audit controls, integrity controls, and transmission security โ€” including user authentication, encryption, audit logs, and secure data transfer.

Do dental offices need to be HIPAA compliant? +

Yes. Dental offices are covered entities under HIPAA because they transmit protected health information electronically for billing and referrals. Full HIPAA compliance applies โ€” including technical safeguards for every system that stores or touches patient records.

What happens if a practice fails a HIPAA audit? +

Fines range from $100 to $50,000 per violation depending on negligence level, up to $1.9 million per violation category per year. Beyond fines, breaches require mandatory patient notification and can result in corrective action plans monitored by the HHS Office for Civil Rights.

Is this checklist a substitute for a formal Security Risk Assessment? +

No. This checklist covers the technical safeguard layer and is a useful starting point, but a formal Security Risk Assessment (SRA) is a separate, broader requirement under HIPAA. The HHS provides a free SRA Tool at healthit.gov. LineSight Digital can help you complete a full SRA as part of an IT assessment engagement.

Need Help Closing These Gaps?

LineSight Digital works with medical and dental offices across the Bay Area to implement HIPAA technical safeguards, verified backups, and endpoint security. Get a free assessment โ€” no obligation.

Get Free IT Assessment HIPAA IT Compliance Services