Skip to content
All posts

HIPAA IT Compliance Checklist for Small Healthcare Practices

If your practice creates, stores, or transmits protected health information (PHI), HIPAA's Security Rule applies to you — regardless of size. For small practices without a dedicated IT team, staying compliant can feel overwhelming. This checklist breaks the technical side into clear, manageable pieces.

This is a general overview, not legal or compliance advice — work with a qualified professional to confirm your obligations.

The IT compliance checklist

Access controls

  • ☐ Unique logins for every user (no shared accounts)
  • ☐ Role-based access — staff can reach only the PHI they need
  • ☐ Multi-factor authentication on systems containing PHI
  • ☐ Automatic logoff on unattended devices

Encryption

  • ☐ PHI encrypted at rest (on servers, computers, and mobile devices)
  • ☐ PHI encrypted in transit (email, file transfers, remote access)

Audit and monitoring

  • ☐ Activity logs that record who accessed PHI and when
  • ☐ Ongoing monitoring to detect suspicious activity

Backup and recovery

  • ☐ Regular, tested backups of PHI
  • ☐ A documented disaster recovery plan

Device and network security

  • ☐ Managed, up-to-date endpoint protection on all devices
  • ☐ Secured wireless network, separate from guest access
  • ☐ A properly configured firewall
  • ☐ A plan for lost or stolen devices (remote wipe)

People and paperwork

  • ☐ Security awareness training for all staff
  • ☐ A Security Risk Assessment (required, and often overlooked)
  • ☐ Business Associate Agreements with vendors who touch PHI — including your IT provider
  • ☐ Written policies and an incident response plan

The two most-missed items

In practice, small practices most often stumble on two things: the Security Risk Assessment (a formal, documented requirement — not just "we think we're fine") and staff training (since phishing is the leading cause of healthcare breaches). Don't let these slide.

Make compliance manageable

You became a healthcare provider to care for patients, not to manage IT security. An IT partner experienced with HIPAA can implement these safeguards, sign a Business Associate Agreement, and keep your systems monitored and documented. See our healthcare IT case study for a real example, and contact us for a confidential assessment.