Tryon Computers logo

Free Resource

The HIPAA Compliance Checklist for Medical & Dental Offices

A practical, plain-English checklist covering the five areas where small practices actually get exposed — devices, passwords, backups, security, and documentation.

What's on the checklist

Devices & Data

  • Every device that holds patient data is encrypted (laptops, workstations, phones, drives)
  • Strict access controls — staff only see what their role requires
  • Devices that leave the office (laptops, tablets) are encrypted and tracked

Passwords & Access

  • Unique passwords for every system — no shared office passwords
  • Multi-factor authentication enabled on email, EHR, remote access, and backups
  • Former employees' access is removed on their last day

Backups & Recovery

  • Automated backups run daily with no manual steps
  • Backups are encrypted and stored securely (offsite or cloud)
  • A restore has been tested at least once in the last 90 days

Network & Security

  • Business firewall is active, patched, and managed (not the office Wi-Fi router)
  • All software and operating systems are current on patches
  • Antivirus/endpoint protection is on every device and updated
  • A documented plan exists for what to do if you're hit by ransomware

HIPAA Documentation

  • Business Associate Agreements in place with every vendor touching PHI
  • HIPAA policies exist and are written for YOUR office (not boilerplate)
  • Staff have completed HIPAA training in the last 12 months
  • A current risk assessment is on file

This is the same framework we use when assessing practices. If checking even three or four items gives you pause, a free 30-minute assessment will show you exactly where you stand.

Get the full checklist — free

Enter your details and we'll send the printable checklist straight to your inbox. No spam, no obligation.

No spam, no pressure. Your information stays private and is only used to contact you about your assessment.