Skip to content
Back to Blog
ComplianceOctober 6, 20264 min readMy MSP TechMy MSP Tech Editorial Team

HIPAA IT Compliance for Small Practices: A Plain-English Checklist

What does HIPAA actually require from your practice's IT?

HIPAA's Security Rule requires you to protect electronic protected health information (PHI) with three kinds of safeguards: administrative (policies, risk analysis, workforce training), physical (device and facility controls), and technical (access controls, audit logging, and encryption). It also requires a signed Business Associate Agreement with every vendor that touches PHI. There is no certificate that makes you "HIPAA certified" — compliance is an ongoing program, not a one-time checkbox.

Why is a small practice a bigger target than it feels like?

Attackers know that a two-provider dental office or a solo therapy practice usually has the same valuable patient data as a hospital but a fraction of the defenses. Medical records sell for more than credit cards on the dark web because they can't be canceled. The HHS Office for Civil Rights (OCR) enforces HIPAA regardless of practice size, and the cost of a single reportable breach — forensics, patient notification, OCR response, and lost trust — dwarfs the cost of doing IT right up front. For most small practices, one incident costs far more than years of proper managed IT services.

The plain-English HIPAA IT checklist

Here's what your systems and your IT partner should have in place. If you can't confidently check every box, that's your work list.

  • Signed Business Associate Agreements. Every vendor that stores, processes, or can access PHI — your EHR host, cloud backup, email provider, even your IT company — must sign a BAA. Vendors like Epic and athenahealth provide one; so should your MSP. No BAA, no PHI.
  • Access controls with unique logins. Every user gets their own account — no shared "frontdesk" password. Apply least-privilege so a scheduler can't pull full clinical records, and turn on multi-factor authentication everywhere it's offered.
  • Audit logging. Your EHR and network should record who accessed which record and when, and someone should actually review those logs. Audit logging is how you prove — to OCR or to yourself — that PHI wasn't improperly touched.
  • Encryption at rest and in transit. Laptops and phones with full-disk encryption, TLS on email and portals, encrypted backups. Encrypted-and-lost is not a reportable breach under the HIPAA safe harbor; unencrypted-and-lost is.
  • A documented Security Risk Analysis. This is the single most-cited HIPAA failure. You must periodically assess where PHI lives and what threatens it — and write it down.
  • Backup and disaster recovery. Tested, encrypted, offsite backups so a ransomware hit doesn't erase your patient records. See our backup and disaster recovery overview.
  • Workforce training and offboarding. Staff trained on phishing and PHI handling, and access removed the day someone leaves.
  • A breach response plan. Written steps and a 60-day notification clock you already understand before anything goes wrong.

How does your EHR fit in — Epic, athenahealth, and the rest?

Your EHR vendor secures their platform and signs a BAA, but the responsibility is shared. Epic or athenahealth protects the data on their side; you're still on the hook for the devices, network, logins, and staff behavior that connect to it. A misconfigured Wi-Fi network or a workstation without a screen lock can leak PHI no matter how secure the EHR itself is. This is exactly where compliance-focused IT services earn their keep — hardening everything around the EHR and keeping the evidence that proves it.

Should a small practice handle this in-house or hire it out?

A HIPAA program touches risk analysis, network security, access controls, audit logging, encryption, and documentation — a lot for a front-desk lead or a part-time tech to own alongside their real job. Most small practices get further, faster by partnering with a provider that already does healthcare compliance daily. If you're weighing options, our guide on HIPAA-compliant IT services and our healthcare IT overview break down what to look for, and how to choose a managed IT provider walks through vetting one.

FAQ

Is my practice "HIPAA certified" once I finish this checklist?

No — there's no official HIPAA certification. Compliance is an ongoing program of safeguards, documentation, and periodic risk analysis. A vendor claiming to make you "certified" is overselling; what you want is a partner who keeps you continuously compliant and can produce the evidence.

Does my EHR vendor's security cover me?

Only partly. Epic, athenahealth, and similar platforms secure their side and sign a BAA, but HIPAA responsibility is shared. Your devices, network, logins, backups, and staff practices are yours to secure.

What's the most common HIPAA IT mistake OCR finds?

A missing or outdated Security Risk Analysis. It's the foundation the rest of your safeguards are built on, and it's the item OCR cites most often after a breach.

Ready to close the gaps? Compare vetted providers — free.

HIPAAhealthcare ITcompliancePHImanaged IT