HIPAA Compliance Checklist for Medical Practices: 15 Questions Every Practice Should Answer

Healthcare organizations handle some of the most sensitive data in the world—protected health information (PHI). While electronic health records (EHRs), cloud-based software, and connected medical devices have improved patient care, they've also increased cybersecurity risks and the complexity of maintaining HIPAA compliance.

So, how do you know if your medical practice is HIPAA compliant?

The truth is, there is no official HIPAA certification. Compliance isn't a one-time event or a certificate you hang on the wall. It's an ongoing process of identifying risks, implementing safeguards, training employees, and continuously improving your security posture.

This checklist is designed to help physicians, office managers, and practice administrators evaluate whether their organization has the technical safeguards and processes expected under the HIPAA Security Rule. While it isn't a replacement for a formal Security Risk Assessment, it provides a practical starting point for identifying common gaps before they become costly problems.

Why HIPAA Compliance Is an Ongoing Process

One of the biggest misconceptions in healthcare is that a practice can become permanently "HIPAA compliant."

In reality, HIPAA compliance is a continuous process.

Every time you:

  • Hire a new employee
  • Add a new computer
  • Deploy new software
  • Implement a new EHR feature
  • Enable remote work
  • Open another location

...your security environment changes.

Cybercriminals also evolve their tactics constantly. A practice that was well protected two years ago may now have significant vulnerabilities if its technology hasn't kept pace.

That's why the HIPAA Security Rule emphasizes ongoing risk analysis and continuous improvement rather than a one-time checklist.

The 15-Point HIPAA Compliance Checklist

Use the following checklist to evaluate your practice's current technology environment.

1. Have You Completed a Security Risk Assessment Within the Last 12 Months?

A Security Risk Assessment is the foundation of HIPAA compliance.

It identifies vulnerabilities that could affect the confidentiality, integrity, or availability of electronic Protected Health Information (ePHI).

Ask yourself:

  • Have we completed a formal assessment within the past year?
  • Have we documented our findings?
  • Have we addressed identified risks?

If the answer is "no," this should be your highest priority.

2. Is Multi-Factor Authentication Enabled?

Passwords alone no longer provide adequate protection.

Multi-Factor Authentication (MFA) should protect:

  • Microsoft 365
  • Email
  • VPN access
  • Remote Desktop
  • Administrative accounts
  • Cloud applications
  • Password managers

MFA is one of the most effective ways to prevent unauthorized access.

3. Are All Devices Encrypted?

Healthcare professionals frequently use laptops and mobile devices inside and outside the office.

Every portable device containing patient information should use full-disk encryption.

Examples include:

  • Laptops
  • Tablets
  • Company smartphones
  • Surface devices

Encryption protects patient data if a device is lost or stolen.

4. Are Security Updates Installed Promptly?

Outdated software is one of the leading causes of successful cyberattacks.

Your IT provider should routinely install updates for:

  • Windows
  • macOS
  • Servers
  • Microsoft Office
  • Browsers
  • Medical software
  • Firewalls

Delayed patching leaves your practice exposed to known vulnerabilities.

5. Are Your Backups Tested?

Creating backups isn't enough.

You should also know:

  • Can they be restored?
  • How long does recovery take?
  • Who verifies successful backups?
  • Have recovery procedures been tested?

Backups that haven't been tested shouldn't be considered reliable.

6. Do You Use Endpoint Detection & Response (EDR)?

Traditional antivirus software detects known threats.

Endpoint Detection & Response (EDR) actively monitors devices for suspicious behavior and helps stop ransomware before it spreads.

If your IT provider still relies solely on antivirus software, your practice may be underprotected.

7. Is Your Email Protected Against Phishing?

Email remains the #1 attack vector for healthcare organizations.

Your cybersecurity strategy should include:

  • Spam filtering
  • Malware detection
  • Safe attachment scanning
  • URL protection
  • Impersonation detection
  • User awareness training

Even one successful phishing attack can lead to significant operational disruption.

8. Do Employees Receive Regular Security Awareness Training?

Technology alone cannot stop cybercrime.

Employees should receive ongoing training on:

  • Phishing emails
  • Social engineering
  • Password security
  • Safe internet browsing
  • Handling patient information
  • Reporting suspicious activity

Security awareness should be reinforced throughout the year—not just during onboarding.

9. Are User Permissions Reviewed Regularly?

Every employee should have access only to the systems and data necessary for their role.

Review permissions when:

  • Employees are hired
  • Job responsibilities change
  • Employees leave the practice

Removing unnecessary access reduces the risk of accidental or unauthorized disclosure.

10. Do You Maintain a Complete Inventory of Technology Assets?

You can't secure technology you don't know exists.

Maintain an inventory of:

  • Desktop computers
  • Laptops
  • Servers
  • Tablets
  • Firewalls
  • Network switches
  • Wireless access points
  • Medical devices
  • Company-owned mobile devices

A complete inventory simplifies security management and future planning.

11. Do You Have a Written Incident Response Plan?

No organization plans to experience a cybersecurity incident—but every practice should be prepared.

An incident response plan should answer questions such as:

  • Who is contacted first?
  • How are infected devices isolated?
  • How is patient care maintained?
  • Who communicates with vendors?
  • When should legal counsel or insurance providers be involved?

A documented plan helps reduce confusion during a stressful event.

12. Is Remote Access Secure?

Many healthcare employees work remotely or access systems after hours.

Secure remote access should include:

  • Multi-Factor Authentication
  • VPN or secure remote access tools
  • Company-managed devices
  • Device encryption
  • Endpoint protection

Remote convenience should never compromise patient security.

13. Have You Signed Business Associate Agreements?

If a vendor has access to Protected Health Information (PHI), you should determine whether a Business Associate Agreement (BAA) is required.

This commonly includes:

  • Managed IT providers
  • Cloud storage providers
  • Backup vendors
  • EHR vendors
  • Billing companies

A qualified healthcare IT provider should understand when a BAA is appropriate and be prepared to execute one when required.

14. Is Your Wireless Network Properly Secured?

Your wireless network should never expose patient information unnecessarily.

Best practices include:

  • Separate guest Wi-Fi
  • WPA3 (or current recommended encryption)
  • Strong administrative passwords
  • Network segmentation
  • Regular firmware updates

A secure wireless environment helps reduce unnecessary risk.

15. Do You Meet With Your IT Provider Quarterly?

Technology shouldn't only be discussed when something breaks.

Quarterly technology reviews allow your practice to:

  • Review cybersecurity risks
  • Plan equipment replacements
  • Discuss compliance initiatives
  • Evaluate backup reports
  • Review security incidents
  • Budget for future improvements

Strategic planning is one of the biggest differences between a reactive IT vendor and a proactive healthcare technology partner.

Common HIPAA Compliance Gaps We See in Medical Practices

After supporting healthcare organizations throughout Central Texas, we've found that many practices share similar technology challenges.

Some of the most common include:

  • Shared user accounts
  • Weak password policies
  • Missing Multi-Factor Authentication
  • Unencrypted laptops
  • Outdated Windows systems
  • Backups that haven't been tested
  • No formal Security Risk Assessment
  • Limited employee cybersecurity training
  • Missing documentation
  • Reactive IT support instead of proactive management

The good news is that these issues are often straightforward to address with the right technology strategy and experienced IT partner.

What Your IT Provider Should Be Responsible For

Your managed IT provider should help implement and maintain the technical safeguards that support HIPAA compliance.

This typically includes:

  • Endpoint security
  • Device encryption
  • Microsoft 365 security
  • Firewall management
  • Patch management
  • Backup monitoring
  • Disaster recovery planning
  • Security monitoring
  • Access control management
  • Technical documentation
  • Cybersecurity guidance
  • Technology planning

While your practice remains responsible for HIPAA compliance overall, your IT provider should play a critical role in maintaining a secure technology environment.

Real Client Success Story

Trusted Healthcare IT Partner for Over 10 Years

Healthcare organizations need more than someone to fix computers—they need a trusted technology partner who understands the unique demands of patient care, security, and compliance.

For more than a decade, Torch Networks has supported Relda J. Setliff, M.D., P.A., helping the practice maintain secure, reliable technology so the team can focus on delivering exceptional patient care.

"For over 10 years, Torch Networks has been a trusted technology partner for our medical practice. In healthcare, reliable and secure IT support is essential, and their team understands the unique technology, security, and compliance needs of healthcare providers. They are knowledgeable, responsive, and consistently provide dependable service that allows us to focus on what matters most…our patients. Their proactive approach and commitment to keeping our systems secure have earned our trust year after year. I highly recommend Torch Networks to any healthcare organization looking for an IT partner they can truly rely on."

— Dr. Relda Setliff
Relda J. Setliff, M.D., P.A.

Long-term partnerships like this reflect the value of proactive IT management, responsive support, and a deep understanding of healthcare technology requirements.

Frequently Asked Questions

Is there an official HIPAA certification?

No. HIPAA does not provide an official certification. Organizations demonstrate compliance by implementing and maintaining appropriate administrative, physical, and technical safeguards.

How often should a Security Risk Assessment be performed?

Most healthcare organizations should conduct a Security Risk Assessment at least annually and whenever significant technology or operational changes occur.

Does Microsoft 365 make my practice HIPAA compliant?

No. Microsoft 365 offers powerful security capabilities, but those features must be properly configured and managed as part of a broader compliance strategy.

Can small medical practices be targeted by cybercriminals?

Absolutely. Small and midsize healthcare organizations are frequently targeted because attackers often view them as having fewer cybersecurity resources than larger health systems.

Should my IT provider understand HIPAA?

Yes. If your IT provider supports healthcare organizations, they should understand the HIPAA Security Rule, healthcare cybersecurity best practices, and the technical safeguards needed to protect ePHI.

How Does Your Practice Score?

If you answered "No" to several items on this checklist, it doesn't necessarily mean your practice is non-compliant—but it does indicate opportunities to strengthen your security posture.

Technology risks don't improve with time. Addressing gaps proactively is almost always less expensive and less disruptive than responding to a cybersecurity incident or compliance investigation.

At Torch Networks, we specialize in helping healthcare organizations throughout Austin and Central Texas build secure, resilient technology environments. Our team understands the unique security, compliance, and operational challenges medical practices face, and we work alongside your staff to reduce risk while supporting exceptional patient care.

Whether you need a second opinion on your current IT environment, assistance preparing for a Security Risk Assessment, or a long-term technology partner, we're here to help.

Schedule a Healthcare IT Assessment

If you'd like to better understand your current technology risks, cybersecurity posture, and opportunities for improvement, contact Torch Networks to schedule a Healthcare IT Assessment. We'll help you identify potential gaps, prioritize recommendations, and build a technology roadmap that supports your practice today and into the future.