HIPAA IT checklist for medical and dental practices
The short answer. HIPAA's Security Rule asks a practice for three things from its IT: technical safeguards on every system that touches patient information, a signed Business Associate Agreement with every vendor that touches it too, and a written record that proves both. This checklist covers what a practice of 5 to 50 people needs, what "documented" means, and what an auditor or a breach investigation actually asks for.
First, the two documents
- Risk analysis. HIPAA requires a documented risk analysis, updated when the practice changes. It is the document investigators ask for first, and the one most practices do not have.
- Business Associate Agreements (BAAs). Every vendor that stores, transmits or can see protected health information: your IT provider, EHR, email platform, backup vendor, billing service, cloud storage, phone system with voicemail transcription. No BAA, no vendor. We sign ours at the first engagement.
Technical safeguards, practice-sized
- Access control. Every person has their own login; nobody shares. Access to patient data matches the role. Departed staff are disabled the same day.
- Multi-factor authentication. On email, the EHR, remote access and administrator accounts.
- Encryption. Laptops and desktops encrypted (BitLocker or FileVault); phones that receive practice email encrypted and wipeable; email that carries patient information sent through encrypted channels.
- Audit logs. Systems must log who accessed what. Microsoft 365 audit logging on, EHR audit reports reviewed, and the review noted.
- Endpoint security. Managed detection and response on every computer, watched after hours, because a breach on a Friday evening is still a breach.
- Patching. Operating systems and applications updated on a schedule, with a report.
- Backup and recovery. Encrypted backups, off site or immutable, restore tested and dated. Ransomware is the most common HIPAA breach in small practices.
- Network segmentation. Patient Wi-Fi separate from the practice network; imaging and lab devices separate from workstations where possible.
- Secure disposal. Old computers and drives wiped or destroyed with a certificate.
- Physical safeguards. Screens not visible from the waiting room, server or network closet locked, workstations locked when unattended.
Administrative safeguards you can do in a month
A named security officer (a role, not a hire), staff training with a record, a sanctions policy, an incident response procedure with the breach notification deadlines (60 days to individuals; HHS annually or within 60 days for 500 or more people), and contingency planning that your hurricane checklist already covers.
What "documented" means
A policy that says what you do, evidence that you do it (reports, logs, screenshots with dates), and a review date. An auditor reads the policy, then asks for the evidence. Most findings are "policy exists, evidence does not".
Common findings in South Florida practices
Shared logins at the front desk; personal phones with practice email and no management; a "backup" that is a USB drive in a drawer; patient Wi-Fi on the same network as the server; a BAA missing for the email provider; no risk analysis on file.
How we work with practices
We sign the BAA first. Then a technical review against this checklist, red-amber-green. Then we close the gaps, most of which are configuration in Microsoft 365 and on the devices, and we hand you the evidence folder: policies, reports, the device inventory and the restore test. IT Shield covers endpoint security from $10 per device; a managed plan adds the maintenance, and Standard and Premium plans add 24/7 response to emergencies. Either way the documentation is yours.
Questions
Do you sign a Business Associate Agreement?
Yes. We sign a HIPAA Business Associate Agreement with every medical and dental practice at the first engagement, before we touch any system that holds protected health information.
Is Microsoft 365 HIPAA compliant?
Microsoft signs a BAA and the platform supports the safeguards, but compliance comes from configuration: multi-factor authentication, audit logging, encryption and device management have to be turned on and documented. We do that.
How much does HIPAA-ready IT cost for a small practice?
Many practices run on IT Shield ($10 per device per month, three-device minimum) plus On-Demand support at $119 an hour. Practices with ten or more seats usually choose a managed plan from $120 per seat.
Do we need a HIPAA certification?
There is no official HIPAA certification. What exists is the documented risk analysis, the safeguards, the BAAs and the evidence. Vendors selling "HIPAA certified" are selling a badge, not compliance.
- How much does managed IT cost in Miami in 2026?
- Cyber insurance IT checklist: what insurers ask for and how to prove it
- Hurricane IT checklist for South Florida businesses
- How to choose an IT company in Miami: twelve questions that separate the good ones
- On-Demand or managed IT: which one fits your business?