A HIPAA compliance checklist for small practices should follow the three safeguard categories in the Security Rule: administrative (risk analysis, policies, training, vendor agreements), physical (facility, workstation and device controls) and technical (access control, audit logs, encryption, transmission security). Most small medical and dental offices on the Treasure Coast already do parts of this well; the gaps are almost always a missing written risk analysis, unsigned business associate agreements, and unencrypted or unmanaged devices.
This checklist is what we use when onboarding a practice for compliance support. It is not legal advice, and it does not replace a formal risk analysis, but it will show you where you stand before an auditor or a breach does.
What are the administrative safeguards?
These are the policies and people parts, and they are what auditors ask for first.
- Security risk analysis. A written, dated assessment of where electronic protected health information (ePHI) lives, what threatens it and how likely and severe each threat is. Required, and the most commonly missing item. Update it annually and after major changes.
- Risk management plan. What you are doing about the findings, with owners and dates.
- Designated security officer. A named person, even in a five-person office.
- Written policies and procedures. Acceptable use, password and MFA, mobile devices, remote access, incident response, sanctions for violations, and data backup and disaster recovery.
- Workforce training. At hire and at least annually, with records. Phishing simulations count as evidence of ongoing awareness.
- Business associate agreements (BAAs). Signed with every vendor that touches ePHI: your IT provider, EHR and practice management vendors, cloud backup, email provider, billing service, shredding company, answering service and any AI tool staff use on patient data.
- Access management. A documented process for granting, changing and removing access when staff join, change roles or leave. Terminated employees with live logins are a recurring audit finding.
- Contingency plan. Backup, disaster recovery and emergency mode operation. In Florida that means a tested plan for hurricane season, not a paragraph.
- Incident response and breach notification procedure. Who to call, how to assess, and the notification timelines.
What are the physical safeguards?
- Facility access. Server or network closet locked, keys or codes tracked, visitor sign-in where appropriate.
- Workstation placement and use. Screens in reception and operatories positioned or filtered so patients cannot read them; automatic screen lock after a short idle period.
- Device and media controls. Inventory of every laptop, tablet, phone, USB drive and imaging workstation that touches ePHI; a documented wipe-and-dispose process for old hardware, including copiers with hard drives.
- Portable devices. Encrypted, password-protected, and remotely wipeable. A lost unencrypted laptop is a reportable breach; a lost encrypted one usually is not.
What are the technical safeguards?
- Unique user IDs. No shared front-desk logins. Every action must trace to a person.
- Multi-factor authentication on email, remote access, the EHR where supported, and administrative accounts.
- Role-based access. Billing sees billing; hygienists see charts; nobody sees everything by default.
- Automatic logoff on workstations and applications.
- Audit logs. Enabled on the EHR, servers and Microsoft 365, retained, and reviewed on a schedule you can document.
- Encryption at rest on servers, workstations, laptops and backups, and in transit for email containing ePHI (secure email or portal), remote access and any data sent to vendors.
- Endpoint protection and patching. Managed EDR on every device, operating systems and applications patched on a schedule, and no end-of-life systems on the network. Older imaging and lab equipment that must run outdated software should be isolated on its own network segment.
- Email security. Filtering, anti-phishing and a policy for when patient information may be emailed.
- Backup and recovery. Encrypted, offsite, tested restores, with retention that meets Florida medical record requirements.
What does a HIPAA audit actually ask for?
Whether it is an OCR investigation after a complaint, a cyber-insurance underwriter or a due-diligence review before a practice sale, the requests are consistent:
- Your most recent risk analysis and the risk management plan that followed it
- Written policies, with evidence they are followed (training logs, access reviews, audit log reviews)
- The BAA file
- An inventory of systems and devices holding ePHI
- Proof of encryption on portable devices and backups
- Your incident log, even if it says no incidents
- Evidence of a tested contingency plan
Practices that can produce these in a day are in good shape. Practices that need three weeks to assemble them usually have real gaps behind the paperwork.
What are the most common HIPAA gaps in small practices?
- No written risk analysis, or one from years ago that predates the cloud, telehealth and remote work
- BAAs missing for the IT provider, the email platform or a billing service
- Shared logins at the front desk
- Unencrypted laptops and tablets, especially provider-owned devices
- Backups that have never been test-restored
- Former staff still able to log in to email or the patient portal
- Staff using consumer AI tools or personal email with patient details
- Old imaging or lab PCs on unsupported Windows versions sitting on the main network
Every one of these is fixable, and most are inexpensive. The pattern we see in Vero Beach and Port St. Lucie practices is that the technical controls are half-done and the documentation is missing entirely; closing both takes a few focused weeks with the right partner. Our cybersecurity team handles the controls, and our compliance work produces the evidence file.
If you would like an honest picture of where your practice stands, MainSail Data offers a free HIPAA readiness review for medical and dental offices across the Treasure Coast. Call (772) 794-1194 or request a consultation and we will walk through this checklist with you.

