Compliance

HIPAA IT Compliance Checklist for Medical Practices

In brief

A HIPAA IT compliance checklist covers the Security Rule's three safeguard groups: administrative (risk analysis, policies, training, vendor agreements), physical (facility and device controls), and technical (access controls, audit logs, encryption, and multi-factor authentication). For a medical practice in 2026, a current risk analysis, encryption, and MFA on every system that touches patient data are the highest-priority items.

A HIPAA IT compliance checklist for a medical practice is the set of administrative, physical, and technical safeguards the HIPAA Security Rule requires to protect electronic protected health information, known as ePHI. In practice that means a documented security risk analysis, written policies and workforce training, controlled facilities and devices, and the technical controls that stop unauthorized access: unique logins, audit logging, automatic logoff, encryption at rest and in transit, and multi-factor authentication. This guide lists what belongs on that checklist in 2026, explains why each item matters, and flags the controls the proposed Security Rule update will soon make mandatory.

The stakes for a Texas practice climbed sharply. Healthcare is both the most breached and the most expensive industry to breach in the country, and the Office for Civil Rights, the HHS agency that enforces HIPAA, has signaled that "good enough" security no longer clears the bar. A practice that cannot produce a current risk analysis and show working technical controls is exposed on two fronts at once, to the attackers who prize medical records and to the regulators who penalize the practices that failed to protect them. The checklist below is built to close both gaps in order of priority.

The three parts of every HIPAA IT checklist

The HIPAA Security Rule sorts IT compliance into three safeguard groups, and a complete checklist covers all three. Administrative safeguards are the policies, risk analysis, and training that govern how your practice manages security day to day. Physical safeguards protect the buildings, servers, and devices that store ePHI. Technical safeguards are the software and configuration controls that guard the data itself. Leave out any one group and you leave a hole that an auditor and an attacker both find. Hacking is where that math turns real, because software controls are the layer criminals test first.

81.2% of large healthcare data breaches in 2024 were caused by hacking and other IT incidents, 589 of the 725 breaches reported to federal regulators, together exposing at least 259 million records. Technical safeguards are not paperwork. They are the controls that stop the most common cause of a breach. HIPAA Journal 2024 Healthcare Data Breach Report

Administrative safeguards checklist

Start with the administrative safeguards, because the risk analysis drives every other decision on this list. This group is the governance layer, and it is also the area the Office for Civil Rights cites most often when it penalizes a practice. Work through each item and keep the documentation, because in HIPAA a control you cannot evidence counts as a control you do not have.

  • Complete a security risk analysis that maps where ePHI lives, moves, and is stored, then rates the threats to each location. Update it at least annually and after any material change.
  • Run a risk management plan that fixes the gaps the analysis found, ranked by severity, with owners and dates.
  • Name a security official who is accountable for the program, even at a small practice.
  • Maintain written policies and procedures covering access, passwords, mobile devices, and sanctions for violations.
  • Train the workforce on security awareness, phishing, and correct handling of patient data, and record who completed it.
  • Sign a Business Associate Agreement with every vendor that touches ePHI, including your IT provider, cloud host, billing company, and email service.
  • Keep an incident response and breach notification plan so a suspected breach triggers a defined, timed process rather than a scramble.

Physical safeguards checklist

Physical safeguards protect the hardware and locations where ePHI sits, and they matter as much for a laptop left in a car as for a server room. A stolen or improperly wiped device is a reportable breach even when no network was hacked, so the checklist treats every device that has ever held patient data as a liability until it is secured or destroyed.

  • Control facility access with locks, visitor logs, and limits on who reaches servers and network gear.
  • Secure and position workstations so screens showing ePHI are not visible to patients or passersby, with automatic screen locks enabled.
  • Track devices and media in an inventory that lists every laptop, phone, drive, and server that can access ePHI.
  • Encrypt portable devices so a lost laptop or phone does not become a notifiable breach.
  • Dispose of hardware securely by wiping or destroying drives before any device leaves the practice, and record the disposal.

Technical safeguards checklist: the IT core

Technical safeguards are where most practices carry the greatest exposure, and they are the controls the proposed rule strengthens most. This is the software and configuration layer that decides whether a stolen password or an intercepted email turns into a breach. Build these controls first if your resources are limited, because they block the hacking and IT incidents that cause the overwhelming majority of healthcare breaches.

  • Access control with a unique user ID for every person, role-based permissions that grant the minimum access needed, automatic logoff after inactivity, and an emergency-access procedure.
  • Audit controls that log activity on any system holding ePHI, with someone actually reviewing the logs for unusual access.
  • Integrity controls that detect and prevent improper alteration or destruction of patient records.
  • Authentication that confirms a user is who they claim to be, using multi-factor authentication on email, remote access, and the electronic health record.
  • Transmission security that encrypts ePHI in transit, so patient data sent by email or across the internet cannot be read if intercepted.
  • Encryption at rest on servers, workstations, and backups, which also provides safe-harbor protection under the Breach Notification Rule.

Supporting these safeguards are the perimeter controls that most audits expect to see: a business-grade firewall, endpoint detection on every workstation, prompt patching of software and internet-facing systems, network segmentation that separates guest Wi-Fi and clinical devices, and tested, offline backups that let you recover from ransomware without paying. None of these is named line by line in the rule, yet each one is how a practice actually delivers the access control, integrity, and transmission security the rule demands.

What the proposed 2025 Security Rule update changes

The Security Rule is being rewritten, and the direction is clear even though the final rule is not yet in force. On December 27, 2024 the Office for Civil Rights issued a Notice of Proposed Rulemaking, published in the Federal Register on January 6, 2025, that would tighten the rule in ways every medical practice should prepare for now. Treat the proposals as a preview of the controls auditors will expect, not as optional.

  • Multi-factor authentication becomes mandatory across all points of access to ePHI, closing the single biggest gap attackers exploit with stolen passwords.
  • Encryption becomes required for ePHI at rest and in transit, with only limited exceptions.
  • The addressable category disappears. The proposal removes the split between "required" and "addressable" specifications and makes nearly all of them required, so practices can no longer document their way out of a control.
  • Asset inventories and network maps would be required, along with tighter timelines for restoring systems after an incident and regular compliance verification.
MFA + encryption The proposed HIPAA Security Rule update would make multi-factor authentication and encryption of ePHI, at rest and in transit, explicit requirements and remove the "addressable" category that let practices skip controls with a written justification. HHS Office for Civil Rights NPRM Fact Sheet, 2025

The cost of getting HIPAA IT wrong

Compliance work is cheap next to the alternative. A healthcare breach carries the highest price tag of any industry, and it has held that position for well over a decade because medical records are dense with data that is valuable to criminals and slow to secure.

$7.42M was the average cost of a healthcare data breach in 2025, the highest of any industry for the 14th year in a row, and healthcare breaches took the longest to spot and contain at 279 days on average. HIPAA Journal / IBM Cost of a Data Breach, 2025

The scale is not theoretical. A single ransomware attack on the claims processor Change Healthcare in 2024 exposed the protected health information of roughly 192.7 million people, the largest healthcare data breach ever recorded in the United States, and a reminder that a vendor's weak control can put your patients' data on the internet.

192.7M individuals had their protected health information exposed in the 2024 Change Healthcare ransomware attack, the largest healthcare data breach in US history and a case study in why every vendor that touches ePHI needs a Business Associate Agreement and verified controls. HIPAA Journal 2025 Healthcare Data Breach Report

Then there are the fines. HIPAA civil penalties run in four tiers based on culpability, and the amounts rise with inflation each year. After the cost-of-living adjustment effective January 28, 2026, an uncorrected willful-neglect violation starts at $73,011, and the maximum annual penalty for repeated identical violations reaches $2,190,294. Add the reputational damage of a public breach notice and the patient trust it costs, and a practice that skips the checklist is gambling with far more than an audit finding.

How a managed IT partner keeps a practice compliant

Running every control on this list well is more than a busy medical office can sustain alone, which is where a specialized partner earns its place. A managed IT provider handles the technical safeguards that need constant attention, MFA, encryption, patching, endpoint protection, backups, and log review, and produces the documentation that proves each control was in place. Tuminto delivers these controls as coordinated healthcare IT services, mapping your environment to the HIPAA Security Rule, keeping your risk analysis current, and signing a Business Associate Agreement so your IT vendor is a compliant part of your program rather than a gap in it.

The goal is not to chase every clause in the regulation, but to reliably close the controls that stop breaches and satisfy auditors: a current risk analysis, encryption everywhere ePHI lives, multi-factor authentication on every door into patient data, and evidence you can hand a regulator on request. Get those right, and the rest of the checklist follows.

Who must follow the HIPAA Security Rule

Every healthcare provider that transmits health information electronically must follow the HIPAA Security Rule, and the size of the practice does not change that duty. HIPAA binds two groups. A covered entity is a health plan, a healthcare clearinghouse, or a healthcare provider that sends claims, eligibility, or referral data electronically, which describes almost every medical and dental practice. A business associate is any vendor that creates, receives, maintains, or transmits ePHI on your behalf, including your IT provider, cloud host, billing company, email service, and electronic health record vendor. A solo practice and a hospital answer to the same rule, so a small office cannot treat the checklist as optional. The practical move is to list every function that touches patient data and every vendor behind it, then confirm each one is either your responsibility to secure or covered by a signed Business Associate Agreement. A name missing from that list is a gap an auditor will find, and a business associate carries its own direct liability under the rule.

HIPAA compliance for cloud, email, and EHR tools

Cloud and SaaS tools are allowed under HIPAA when the vendor signs a Business Associate Agreement and you configure the service correctly. HIPAA never bans a technology; it holds you accountable for how ePHI is protected inside it. Mainstream platforms support compliant use: Microsoft 365 and Google Workspace both offer a Business Associate Agreement on their paid business tiers, and electronic health record platforms such as Epic, Oracle Health, and athenahealth are built for regulated data. Signing the agreement is only the first step. You still enable encryption, turn on multi-factor authentication, set role-based access so staff reach only the records their job requires, and switch on the audit logging each platform provides. Email is the most common weak point, because a message carrying ePHI sent without encryption, or sent to the wrong address, is a reportable breach. Treat every cloud service that touches patient data as part of your HIPAA environment, not a shortcut around it, and keep each one inside the same risk analysis and vendor inventory as your on-site systems.

What a HIPAA security risk analysis should include

A HIPAA security risk analysis should map every place ePHI is created, received, stored, and transmitted, then rate the threats and vulnerabilities to each one. It sits first on the checklist because it drives every other control, and a missing or outdated risk analysis is the failure the Office for Civil Rights cites most often in enforcement. A thorough analysis inventories systems and devices, documents the safeguards already in place, identifies gaps such as unencrypted laptops or shared logins, assigns a likelihood and an impact to each risk, and feeds a written remediation plan with owners and dates. Small and mid-size practices can start with the free Security Risk Assessment Tool published by HHS and the Office of the National Coordinator, which walks through the Security Rule question by question. Update the analysis at least once a year and again after any material change, such as a new electronic health record, an office move, a merger, or a security incident.

Breach notification: what your IT response must deliver

When a breach of unsecured ePHI happens, the Breach Notification Rule sets firm deadlines your IT and compliance response has to meet. A practice notifies affected individuals without unreasonable delay and no later than 60 calendar days after discovering the breach. A breach involving 500 or more individuals is reported to the HHS Office for Civil Rights within that same 60 days and requires notice to prominent local media, while smaller breaches are logged and reported to HHS once a year. This is where the technical controls pay off twice. Strong audit logging lets you determine what data an intruder actually reached, which sets the scope of the notice, and encryption that meets HHS guidance provides safe harbor, meaning a lost or stolen device holding properly encrypted ePHI may not count as a reportable breach at all. Build the incident response plan before you need it, with defined roles, a tested timeline, and the log data to reconstruct exactly what happened.

Related reading

FAQ

What is a HIPAA IT compliance checklist?

A HIPAA IT compliance checklist is the set of controls the HIPAA Security Rule requires to protect electronic protected health information, grouped into administrative safeguards such as risk analysis, policies, training, and business associate agreements, physical safeguards such as facility and device controls, and technical safeguards such as access controls, audit logs, encryption, and authentication. A medical practice works through all three groups and documents each one.

What are the technical safeguards under the HIPAA Security Rule?

The technical safeguards are access control with unique user IDs, automatic logoff, and emergency access, audit controls that log activity on systems holding ePHI, integrity controls that prevent improper data changes, authentication that confirms who is logging in, and transmission security that protects ePHI as it moves across networks. Encryption supports several of these controls, at rest and in transit.

Does HIPAA require multi-factor authentication?

The current Security Rule requires authentication but does not name multi-factor authentication specifically. The proposed HIPAA Security Rule update, published by the Office for Civil Rights on January 6, 2025, would make multi-factor authentication mandatory across all points of access to ePHI, so a practice should treat MFA as an expected control now rather than wait for the final rule.

Does HIPAA require encryption of patient data?

Under the current rule, encryption is an addressable specification, meaning a practice must implement it or document a reasonable alternative. The proposed 2025 update would require encryption of ePHI at rest and in transit with limited exceptions and remove the addressable category, so encryption is effectively becoming mandatory. Encrypting devices also provides safe-harbor protection under the Breach Notification Rule.

What are the penalties for a HIPAA violation?

Civil penalties run in four tiers based on culpability. After the cost-of-living adjustment effective January 28, 2026, the minimum per-violation amount ranges from $145 for a lack of knowledge up to $73,011 for uncorrected willful neglect, and the maximum annual penalty for identical violations reaches $2,190,294. Serious violations can also carry criminal penalties.

How often does a medical practice need a HIPAA risk analysis?

HIPAA requires the risk analysis to stay accurate and current, so a practice reviews and updates it at least annually and again after any material change, such as a new electronic health record system, an office move, a merger, or a security incident. A missing or outdated risk analysis is one of the failures the Office for Civil Rights cites most often in enforcement.

Do small medical practices have to comply with HIPAA?

Yes. Every healthcare provider that transmits health information electronically must comply with HIPAA, and the size of the practice does not matter. A solo physician office and a large hospital answer to the same Security Rule, so a small practice completes the same administrative, physical, and technical safeguards. The Office for Civil Rights enforces the rule against practices of every size, and a missing risk analysis is one of the failures it cites most often.

Are cloud-based systems and SaaS tools allowed under HIPAA?

Yes. Cloud storage, email, and SaaS applications are allowed under HIPAA when the vendor signs a Business Associate Agreement and you configure the service to protect ePHI. Microsoft 365 and Google Workspace offer a Business Associate Agreement on their business tiers, and electronic health record platforms such as Epic, Oracle Health, and athenahealth are built for regulated data. You still enable encryption, multi-factor authentication, role-based access, and audit logging inside each tool.

What is the difference between a covered entity and a business associate?

A covered entity is a health plan, a healthcare clearinghouse, or a healthcare provider that transmits health information electronically, which covers most medical and dental practices. A business associate is a vendor that creates, receives, maintains, or transmits ePHI on behalf of a covered entity, such as an IT provider, cloud host, or billing company. Both must comply with the HIPAA Security Rule, and a covered entity signs a Business Associate Agreement with every business associate.

What should a HIPAA security risk analysis include?

A HIPAA security risk analysis should map where ePHI is created, received, stored, and transmitted, inventory the systems and devices involved, document current safeguards, identify gaps, rate the likelihood and impact of each risk, and feed a written remediation plan with owners and dates. Small and mid-size practices can start with the free Security Risk Assessment Tool from HHS and the Office of the National Coordinator, and should update the analysis at least annually and after any material change.

Compliance you can prove, not just claim

Get a HIPAA IT readiness assessment

We will review your practice against the HIPAA Security Rule, flag the technical gaps, and show you exactly where managed IT closes them, with no obligation.

Book a Consultation