HIPAA IT Checklist for Dental Practices
The complete 2026 checklist covering risk analysis, administrative, technical, and physical safeguards, business associate agreements, training, and breach response. Work through it section by section — or download the printable PDF version.
This checklist is organized around the HIPAA Security Rule's safeguard categories, translated into what they actually mean for a dental office — your practice management software, imaging systems, network, and daily workflows. It is a practical starting point, not legal advice; for formal compliance documentation, work with a qualified provider. FlossByte builds every item below into its HIPAA compliance services for dental practices.
1. Risk Analysis & Documentation
The foundation everything else rests on. Without a current risk analysis, you can't prove — or even know — where your gaps are.
- Completed a formal HIPAA risk analysis covering all systems that store, process, or transmit PHI — servers, workstations, imaging devices, backups, email, and cloud services.
- Risk analysis is current — reviewed at least annually and updated after significant changes (new software, server replacement, new location, security incident).
- Risk management plan exists — identified risks have assigned owners, remediation actions, and target dates, not just a report sitting in a drawer.
- PHI inventory documented — you know exactly where patient data lives: Dentrix/Eaglesoft/Open Dental databases, imaging archives, backup sets, email, and any personal devices.
- Policies and procedures are written, current, and accessible — covering the safeguards below, reviewed annually.
2. Administrative Safeguards
The people and process controls — who can access what, and how access is granted and removed.
- Named security officer — one person is formally responsible for HIPAA security (even in a small practice).
- Role-based access — staff can only reach the PHI their job requires; front desk, hygienists, and billing have different access levels in your practice management software.
- Onboarding/offboarding procedure — accounts are created with least privilege on day one and fully deprovisioned (including remote access and email) when someone leaves.
- Unique user IDs — no shared logins on operatories or front-desk workstations; every action is attributable to a person.
- Periodic access reviews — user accounts and permissions are audited at least annually (and after role changes).
- Sanction policy — documented consequences for workforce members who violate security policies.
3. Technical Safeguards
The technology controls — this is where most dental practices have the biggest gaps.
- Encryption at rest and in transit — full-disk encryption on laptops and portable media, encrypted backups, and TLS for email or portals carrying PHI.
- Multi-factor authentication (MFA) — enabled on email, remote access, practice management logins, and any cloud service touching PHI.
- Automatic logoff — workstations lock after a short idle period so an unattended operatory doesn't expose patient records.
- Firewall + endpoint protection — business-grade firewall with intrusion prevention, plus managed antivirus/EDR on every workstation and server, with patching handled centrally.
- Encrypted, tested backups — automated off-site backups of your practice management database and imaging, with restore tests performed regularly (untested backups don't count). See our dental data backup services.
- Audit logging and monitoring — access to PHI is logged, logs are retained, and someone actually reviews them; 24/7 monitoring catches anomalies fast.
- Secure remote access — VPN or zero-trust access for anyone reaching practice systems from outside; no exposed RDP ports.
- Email safeguards — encrypted email for PHI, plus phishing protection and staff awareness (email is the #1 ransomware entry point).
4. Physical Safeguards
Often overlooked in small offices — who can physically touch your systems and media.
- Server/network closet secured — locked, with access limited to authorized staff and your IT provider.
- Workstation placement — screens positioned or fitted with privacy filters so patients in the waiting area or hallway can't read PHI.
- Media disposal procedure — old hard drives, USB sticks, and retired workstations are wiped or destroyed before leaving the practice (not just thrown out).
- Device inventory — every device that touches PHI is tracked, including who has it.
5. Business Associate Agreements
Every vendor that can touch your PHI needs a signed BAA — no exceptions.
- BAA with your IT provider — signed before they access any system. (FlossByte signs BAAs with every client during onboarding.)
- BAAs with all other vendors — practice management software, imaging, backup provider, email host, VoIP provider, shredding service, billing company.
- BAA inventory maintained — a current list of every business associate, reviewed annually or when vendors change.
6. Training & Policies
Your staff is your largest attack surface — and your best defense when trained.
- HIPAA training for all staff — completed at hire and refreshed at least annually, with attendance documented.
- Phishing awareness — staff can recognize suspicious emails and know exactly what to do (and not do) when one arrives.
- Acceptable use policy — covers personal devices, personal email, USB drives, and social media as they relate to PHI.
- Password policy enforced technically — complexity requirements and MFA, not just a written rule nobody follows.
7. Incident Response & Breach Notification
When — not if — something happens, the practices that recover fastest are the ones that planned.
- Written incident response plan — who does what in the first hour of a suspected breach or ransomware event, with contact numbers.
- Breach notification procedures — you know the HIPAA timelines for notifying patients, HHS, and (for large breaches) the media.
- Tested restore capability — you can actually recover your practice management database and imaging from backup, verified by test restores.
- Cyber insurance reviewed — coverage matches your risk, and you understand what the policy requires of you before an incident.
📋 Scored less than perfect? That's normal — most practices we assess miss items in at least three of these sections. FlossByte's HIPAA compliance services include a full risk assessment, remediation roadmap, and ongoing compliance management, backed by our dental cybersecurity and managed IT support plans. Prefer a printable version? Download the HIPAA IT checklist PDF.