HIPAA enforcement against small practices rarely starts with a hacker. It starts with a patient complaint about records access, a stolen laptop, or a ransomware incident, and then the first question from the Office for Civil Rights is whether you can produce an accurate and thorough security risk analysis. Most practices cannot. This checklist walks the administrative, physical, and technical safeguards in plain terms, then gives you a risk analysis worksheet, a vendor and BAA register, and a breach log you can actually maintain.
How to use this template
- Work through it with your IT vendor in the room. Half of the technical section requires someone who can see your network.
- The risk analysis worksheet is the core. Everything else supports it. Fill it in even if the entries are short.
- Date and sign every section. HIPAA documentation must generally be retained for six years from creation or last effective date, whichever is later.
- Mark items "N/A" with a reason rather than leaving them blank, so a reviewer can see you considered them.
- This is a starting framework, not legal advice, and it does not cover state privacy and breach laws, which often add requirements.
Practice information
| Field | Entry |
|---|---|
| Practice name | |
| Locations covered | |
| Number of workforce members | |
| Designated privacy official | |
| Designated security official | |
| IT vendor (BAA signed? Y/N) | |
| Practice management software and version | |
| Imaging software | |
| Date of this review | |
| Date of prior review |
Administrative safeguards
Policies, people, and process
- Privacy official and security official designated in writing
- Written privacy and security policies and procedures, dated and version controlled
- Current security risk analysis on file with a dated risk management plan
- Sanction policy for workforce members who violate policies, applied consistently
- Workforce training at hire and at least annually, with sign-in sheets retained
- Confidentiality acknowledgments signed by every workforce member, including temps and students
- Role-based access: each person's software permissions match their job
- Termination procedure that disables accounts, collects keys and devices, and is documented the same day
- Minimum necessary standard applied to internal access and outside disclosures
- Notice of Privacy Practices current, given to new patients, posted in the office and on the website
- Patient right of access process: responses generally within 30 days, one 30-day extension with written notice, reasonable cost-based fees
- Accounting of disclosures process in place
- Complaint process, with a log of complaints and how they were resolved
- Written contingency plan: data backup plan, disaster recovery plan, and emergency mode operation plan
- Periodic evaluation of the security program documented
- Incident response procedure written, with who to call at what hour
| Field | Entry |
|---|---|
| Date of last workforce training | |
| Number of workforce members trained | |
| Date policies last updated | |
| Open items from this section |
Physical safeguards
Facility and devices
- Server or network closet locked, with limited and documented key or code access
- Alarm system and after-hours access controls; access list reviewed when staff leave
- Workstation placement: monitors at the front desk and in operatories not visible to patients in waiting or hallway areas
- Privacy filters where a screen cannot be repositioned
- Automatic screen lock on every workstation after a short idle period
- Paper charts, day sheets, route slips, and sign-in sheets stored out of public view
- Cross-cut shredding or a shredding vendor with a signed BAA
- Device and media inventory: workstations, laptops, tablets, phones, servers, external drives, imaging devices
- Media reuse and disposal procedure: drives wiped or destroyed, with a certificate of destruction retained
- Backup media stored securely and encrypted
- Visitor and vendor access controlled in clinical and server areas
- Emergency access procedure so care can continue when systems are down
| Device or media type | Count | Encrypted? | Where stored | Owner |
|---|---|---|---|---|
| Servers | ||||
| Desktop workstations | ||||
| Laptops | ||||
| Tablets and phones with PHI access | ||||
| External and backup drives | ||||
| Imaging devices and sensors | ||||
| Other |
Technical safeguards
Access, integrity, and transmission
- Unique user ID for every person; no shared logins anywhere, including the front desk
- Strong password or passphrase policy enforced by the system, not by honor
- Multifactor authentication on email, remote access, and cloud applications
- Remote access secured (VPN or a vendor-managed secure tool), with accounts reviewed quarterly
- Automatic logoff configured on all workstations
- Audit logging enabled in practice software; logs reviewed on a defined schedule
- User access review at least annually and at every termination
- Operating systems and software supported and patched; no end-of-life systems touching PHI
- Endpoint protection installed and reporting centrally
- Firewall in place and configured; default credentials changed on every network device
- Guest Wi-Fi separated from the clinical network
- Encryption at rest on servers, laptops, and backups
- Encryption in transit: secure email or a patient portal for anything containing PHI
- Backups: at least one copy offline or otherwise isolated from the network
- Backup restore tested with an actual restore, with the date recorded
- Email filtering and phishing protection; staff trained on what to report
- Texting and communication platforms reviewed for PHI handling and a signed BAA
| Field | Entry |
|---|---|
| Last user access review (date) | |
| Last backup restore test (date, result) | |
| Number of accounts disabled in the last review | |
| Systems still unpatched or unsupported |
Vendor and business associate register
| Vendor | Service provided | Touches PHI? (Y/N) | BAA signed (date) | Where the signed copy is kept | Reviewed on |
|---|---|---|---|---|---|
Vendor categories to check
- Practice management and imaging software vendors
- IT support and managed service provider
- Cloud backup provider
- Patient communication: reminders, texting, online forms, review requests
- Outsourced billing, insurance verification, and collections
- Email and cloud storage used for PHI
- Answering service or outsourced call center
- Shredding and records storage
- Dental labs that receive patient identifiers
- Consultants, CPAs, or attorneys with access to patient-level data
- Teledentistry or virtual consult platforms
Security risk analysis worksheet
List where ePHI lives, the realistic threats to it, what you do about each, and what is still open.
| Where ePHI lives | Threat or vulnerability | Likelihood (L/M/H) | Impact (L/M/H) | Risk level | Control in place | Action needed | Owner | Due date |
|---|---|---|---|---|---|---|---|---|
Prompts for the "where it lives" column
- Practice management server or cloud tenant
- Imaging server and sensor workstations
- Email inboxes and sent items
- Backups, on site and off site
- Laptops and home computers used for remote access
- Staff phones with practice email or messaging
- Online forms, patient portal, and website submissions
- Texting and reminder platforms
- Scanned documents on shared drives
- Paper records, day sheets, and radiograph duplicates
Breach and incident log
| Date discovered | What happened | PHI involved | Individuals affected | Four-factor assessment done? (date) | Breach? (Y/N) | Individuals notified (date) | HHS reported (date) | Media notice needed? | Mitigation |
|---|---|---|---|---|---|---|---|---|---|
Breach response reminders
- An impermissible use or disclosure is presumed to be a breach unless a documented four-factor risk assessment shows a low probability of compromise
- The four factors: nature and extent of the PHI, who received or used it, whether it was actually acquired or viewed, and the extent to which risk has been mitigated
- Notify affected individuals without unreasonable delay and no later than 60 days after discovery
- Breaches affecting 500 or more individuals: notify HHS within 60 days of discovery, plus media notice for more than 500 residents of a state or jurisdiction
- Breaches affecting fewer than 500: log them and report to HHS within 60 days after the end of the calendar year
- Properly encrypted data under HHS guidance is not "unsecured" PHI
- Ransomware that encrypts patient data is presumed to be a breach unless you can demonstrate a low probability of compromise
- State breach laws may have shorter deadlines and different content requirements; call counsel immediately
Sign-off
| Field | Entry |
|---|---|
| Completed by | |
| Date completed | |
| Security official signature | |
| Owner signature | |
| Next scheduled review | |
| Open remediation items count |
How to run the review
Block three hours and do the whole thing in one sitting with your IT vendor and your office manager. Splitting it across weeks is how it never gets finished. Work top to bottom: administrative safeguards are mostly the office manager's domain, physical safeguards are a walk-through, and technical safeguards need someone who can log into the firewall and the server.
Do the walk-through literally. Stand where a patient stands at the front desk and see what is on the screen. Sit in the waiting room and see whether the sign-in sheet shows other patients' names. Open the server closet and see whether it is locked and whether it has become a storage room. These are the findings that matter, and no questionnaire surfaces them.
Then fill in the risk analysis worksheet last, because by that point you know where the problems are. A usable risk analysis for a small practice inventories where ePHI lives, names realistic threats (ransomware, phishing, a stolen laptop, a failed backup, a former employee with an active login), rates likelihood and impact, and records what you will do about each risk, by when, and who owns it. It does not need to be a hundred pages. It needs to be accurate, specific to your practice, and current.
How often, and who owns it
HHS does not set a fixed interval for updating the risk analysis, but it must be updated when things change, and many practices refresh it annually. Treat "things change" broadly: new practice management software, a new location, adding a cloud imaging service, a change of ownership, a security incident, or significant staff turnover all justify a refresh. Between annual reviews, the user access review and the backup restore test should happen on their own schedule.
The security official owns this. In a solo or small group practice that is usually the owner or the office manager, with the IT vendor doing the technical work under their direction. That designation has to be written down, and the person has to have enough authority to say no to a vendor who will not sign a BAA. The privacy official may be the same person; the roles are distinct but frequently combined in small offices.
HHS and its health IT office publish a free Security Risk Assessment Tool designed for small and medium providers, which walks through the standards question by question and produces a report. If you would rather not build your own document, use that tool and keep this checklist as the operational layer on top of it.
What good looks like
A good review produces three artifacts: a completed checklist with dates and signatures, a risk analysis worksheet with real entries and named owners, and a short list of remediation items with due dates. Six months later, someone can point at that list and say which items were closed.
Good also means the basics are genuinely in place rather than nominally in place. No shared logins. Multifactor authentication on email and remote access. Laptops and backup drives encrypted. At least one backup copy isolated from the network. A restore that has actually been tested. Those five items prevent most of what turns into a reportable breach in a dental office.
And good means the vendor register is complete, not selective. Every company that creates, receives, maintains, or transmits PHI on your behalf needs a signed BAA before you share anything. Review the register annually, and treat a vendor's refusal to sign as a decision about whether to use them.
Common mistakes
Confusing a checklist with a risk analysis. A completed questionnaire is not a risk analysis. The analysis has to identify your specific risks, rate them, and produce a management plan. OCR's enforcement announcements repeatedly cite the failure to conduct an accurate and thorough one, and OCR runs a dedicated initiative on exactly this point.
Leaving accounts active after someone leaves. The day someone's employment ends, their access ends: practice software, email, remote access, cloud backup portal, the building code. Put it in the termination checklist and document it.
Using consumer tools for PHI. Personal email accounts, ordinary text messaging, and consumer file-sharing services generally will not sign a BAA and are not built for this. If a tool will not sign, do not send patient information through it.
Trusting the backup log. A nightly "success" message is not proof of recoverability. Do a real restore, write the date on the checklist, and keep one copy offline. See ransomware in dental practices and dental office IT setup.
Ignoring the Privacy Rule half. Right of access complaints are a real enforcement path against dental practices specifically. Know your workflow for a records request, respond within the required window, and charge only reasonable, cost-based fees.
Handling a breach alone. Deadlines are short, state laws add requirements, and the four-factor assessment needs to be documented properly. Call counsel and your cyber carrier the day you discover something. Our walkthrough of the first 72 hours covers the sequence.
Related ChairsideSource resources
- Compliance: OSHA, HIPAA, infection control, and more
- HIPAA breach response: the first 72 hours
- Cybersecurity for dental practices: the realistic threat list
- Annual OSHA and compliance calendar
- Dental records retention: how long to keep what
This template is educational and is not legal advice. It summarizes federal HIPAA requirements as of September 2026 and does not cover state privacy or breach notification laws. Confirm your obligations with a healthcare attorney.
This guide is educational content and does not constitute legal, financial, tax, or clinical advice. Laws and regulations vary by state and change over time. Consult your own dental-specific attorney, CPA, and state dental board before acting.