HIPAA IT Checklist for Dental Practices

The complete 2026 checklist covering risk analysis, administrative, technical, and physical safeguards, business associate agreements, training, and breach response. Work through it section by section — or download the printable PDF version.

This checklist is organized around the HIPAA Security Rule's safeguard categories, translated into what they actually mean for a dental office — your practice management software, imaging systems, network, and daily workflows. It is a practical starting point, not legal advice; for formal compliance documentation, work with a qualified provider. FlossByte builds every item below into its HIPAA compliance services for dental practices.

1. Risk Analysis & Documentation

The foundation everything else rests on. Without a current risk analysis, you can't prove — or even know — where your gaps are.

  • Completed a formal HIPAA risk analysis covering all systems that store, process, or transmit PHI — servers, workstations, imaging devices, backups, email, and cloud services.
  • Risk analysis is current — reviewed at least annually and updated after significant changes (new software, server replacement, new location, security incident).
  • Risk management plan exists — identified risks have assigned owners, remediation actions, and target dates, not just a report sitting in a drawer.
  • PHI inventory documented — you know exactly where patient data lives: Dentrix/Eaglesoft/Open Dental databases, imaging archives, backup sets, email, and any personal devices.
  • Policies and procedures are written, current, and accessible — covering the safeguards below, reviewed annually.

2. Administrative Safeguards

The people and process controls — who can access what, and how access is granted and removed.

  • Named security officer — one person is formally responsible for HIPAA security (even in a small practice).
  • Role-based access — staff can only reach the PHI their job requires; front desk, hygienists, and billing have different access levels in your practice management software.
  • Onboarding/offboarding procedure — accounts are created with least privilege on day one and fully deprovisioned (including remote access and email) when someone leaves.
  • Unique user IDs — no shared logins on operatories or front-desk workstations; every action is attributable to a person.
  • Periodic access reviews — user accounts and permissions are audited at least annually (and after role changes).
  • Sanction policy — documented consequences for workforce members who violate security policies.

3. Technical Safeguards

The technology controls — this is where most dental practices have the biggest gaps.

  • Encryption at rest and in transit — full-disk encryption on laptops and portable media, encrypted backups, and TLS for email or portals carrying PHI.
  • Multi-factor authentication (MFA) — enabled on email, remote access, practice management logins, and any cloud service touching PHI.
  • Automatic logoff — workstations lock after a short idle period so an unattended operatory doesn't expose patient records.
  • Firewall + endpoint protection — business-grade firewall with intrusion prevention, plus managed antivirus/EDR on every workstation and server, with patching handled centrally.
  • Encrypted, tested backups — automated off-site backups of your practice management database and imaging, with restore tests performed regularly (untested backups don't count). See our dental data backup services.
  • Audit logging and monitoring — access to PHI is logged, logs are retained, and someone actually reviews them; 24/7 monitoring catches anomalies fast.
  • Secure remote access — VPN or zero-trust access for anyone reaching practice systems from outside; no exposed RDP ports.
  • Email safeguards — encrypted email for PHI, plus phishing protection and staff awareness (email is the #1 ransomware entry point).

4. Physical Safeguards

Often overlooked in small offices — who can physically touch your systems and media.

  • Server/network closet secured — locked, with access limited to authorized staff and your IT provider.
  • Workstation placement — screens positioned or fitted with privacy filters so patients in the waiting area or hallway can't read PHI.
  • Media disposal procedure — old hard drives, USB sticks, and retired workstations are wiped or destroyed before leaving the practice (not just thrown out).
  • Device inventory — every device that touches PHI is tracked, including who has it.

5. Business Associate Agreements

Every vendor that can touch your PHI needs a signed BAA — no exceptions.

  • BAA with your IT provider — signed before they access any system. (FlossByte signs BAAs with every client during onboarding.)
  • BAAs with all other vendors — practice management software, imaging, backup provider, email host, VoIP provider, shredding service, billing company.
  • BAA inventory maintained — a current list of every business associate, reviewed annually or when vendors change.

6. Training & Policies

Your staff is your largest attack surface — and your best defense when trained.

  • HIPAA training for all staff — completed at hire and refreshed at least annually, with attendance documented.
  • Phishing awareness — staff can recognize suspicious emails and know exactly what to do (and not do) when one arrives.
  • Acceptable use policy — covers personal devices, personal email, USB drives, and social media as they relate to PHI.
  • Password policy enforced technically — complexity requirements and MFA, not just a written rule nobody follows.

7. Incident Response & Breach Notification

When — not if — something happens, the practices that recover fastest are the ones that planned.

  • Written incident response plan — who does what in the first hour of a suspected breach or ransomware event, with contact numbers.
  • Breach notification procedures — you know the HIPAA timelines for notifying patients, HHS, and (for large breaches) the media.
  • Tested restore capability — you can actually recover your practice management database and imaging from backup, verified by test restores.
  • Cyber insurance reviewed — coverage matches your risk, and you understand what the policy requires of you before an incident.

📋 Scored less than perfect? That's normal — most practices we assess miss items in at least three of these sections. FlossByte's HIPAA compliance services include a full risk assessment, remediation roadmap, and ongoing compliance management, backed by our dental cybersecurity and managed IT support plans. Prefer a printable version? Download the HIPAA IT checklist PDF.

Frequently Asked Questions

A HIPAA IT checklist is a structured list of the administrative, technical, and physical safeguards a dental practice needs to protect patient health information (PHI). It covers risk analysis, access controls, encryption, backups, business associate agreements, staff training, and breach response — the core of the HIPAA Security Rule as it applies to a dental office's technology.
HIPAA requires a risk analysis, and OCR guidance expects it to be an ongoing process — not a one-time event. Most practices review and update their risk assessment at least annually, plus whenever there are significant changes: new practice management software, a server replacement, adding a location, or after any security incident.
Yes. Any IT provider that can access systems containing patient health information — including remote monitoring tools, backup systems, and help desk sessions — is a business associate under HIPAA and must sign a BAA. FlossByte signs BAAs with every client before accessing any systems.
HIPAA's Breach Notification Rule requires notifying affected individuals, and in larger breaches, HHS and potentially the media, within specific timeframes. Ransomware infections count as reportable breaches. Having a tested incident response plan — and encrypted, off-site backups — dramatically reduces both the damage and the notification burden.
Encryption is listed as "addressable" rather than "required" in the Security Rule, which means you must implement it unless you document why it's not reasonable and adopt an equivalent alternative. In practice, encrypting laptops, portable media, backups, and email containing PHI is the expected standard — unencrypted lost devices are one of the most common breach causes in dental practices.
A general IT company can handle the generic pieces — firewalls, patching, antivirus. The gap is usually dental-specific: securing Dentrix, Eaglesoft, or Open Dental databases; imaging software and devices; understanding how PHI flows through a practice; and producing the documentation OCR actually asks for. Dental-specialized providers build all of this into their standard processes.

Want This Checklist Handled For You?

Book a free HIPAA IT assessment. We'll walk through this checklist against your actual systems and give you a prioritized remediation plan — no commitment required.