Home Health Clinics HIPAA Checklist
Free Download · 2026 Edition

Is Your Clinic Actually HIPAA Compliant — Or Just Hoping?

Most clinics, therapists, and small medical practices fail at least 5 of 15 critical HIPAA items — usually without knowing it. This focused checklist surfaces the gaps OCR auditors look for first, with plain-English explanations and remediation steps.

15 critical items most practices miss
Direct HIPAA regulation citations
Self-audit scoring system
Print-ready 25-page PDF

Get Your Free Copy

Instant access · No spam, ever

Hipaa Checklist Download

🔒 Your email stays private. We don't share, ever.

What You'll Get

15 Items. 3 Categories. Zero Fluff.

Organized exactly the way HHS organizes the HIPAA Security Rule, so your work transfers directly to a formal compliance program.

Administrative · 5 items

The policies, procedures, and training requirements that form the backbone of every HIPAA program.

  • Documented Security Risk Analysis
  • Designated Security Officer
  • Workforce Training Documentation
  • Sanction Policy
  • Business Associate Agreements

Physical · 4 items

Physical access controls and device protections that keep PHI safe from theft, loss, or unauthorized viewing.

  • Device Encryption
  • Auto-Lock Screen Policy
  • Device & Media Disposal
  • Visitor Sign-In & Escort

Technical · 6 items

The digital and network-level controls that protect ePHI in motion and at rest. Where most modern HIPAA failures happen.

  • Unique User Accounts
  • Multi-Factor Authentication
  • Encrypted Email
  • Audit Logs (Quarterly Review)
  • Patch Management
  • Backup & Disaster Recovery

By the Numbers

$2M+
Maximum HIPAA penalty per violation category, per year
80%
Of small practices fail at least one risk-analysis requirement
3+
Years OCR can audit findings retroactively
94%
Of HIPAA breaches involve preventable safeguard failures

Sources: HHS OCR Resolution Agreements, HHS 2024 Annual Report to Congress, Verizon 2024 Data Breach Investigations Report.

Built For

Practices Where Compliance Falls Between the Cracks

If your practice is too small for a dedicated compliance officer but too large to wing it, this checklist is for you.

🏥

Medical Clinics

🦷

Dental Practices

🧠

Therapists & Mental Health

💪

Chiropractors

👓

Optometrists

📋

Medical Billing

Inside Each Item

Every checklist item answers four questions.

Most HIPAA resources tell you what to do but leave you guessing on the how. This one walks through each item with the same structure.

1

What this requirement actually is

Plain-English explanation with the regulatory citation.

2

Why most practices miss it

The real-world patterns we see during HIPAA assessments.

3

How to fix it

Specific tools, vendors, and procedures — not vague guidance.

4

Self-audit checkbox

Mark YES / PARTIAL / NO for each item to calculate your overall score.

SAMPLE
1 ITEM 1 OF 15

Documented Security Risk Analysis (Less Than 12 Months Old)

WHAT THIS REQUIREMENT IS

A written assessment that identifies risks to ePHI, evaluates likelihood and impact, and documents the controls you have in place. Required by 45 CFR § 164.308(a)(1)(ii)(A).

WHY MOST PRACTICES MISS IT

Most small practices either skip this entirely or treat it as a one-time exercise. HHS audits explicitly ask: "When was your last risk analysis?" — and dates older than 12 months are flagged automatically.

HOW TO FIX IT

Schedule an annual risk analysis. Document it in writing — Word doc is fine. Include: assets handling ePHI, threats, vulnerabilities, current controls, residual risk, and remediation plan.

Self-audit: ☐ YES   ☐ PARTIAL   ☐ NO

Reference: 45 CFR § 164.308(a)(1)(ii)(A) · HHS OCR Guidance

Common Questions

Before You Download

Is this really free? What's the catch?

+

100% free. The PDF will download immediately after you submit the form, and you'll also get an emailed copy. The only "catch": if you find significant gaps and want help fixing them, we'd love to be considered. No follow-up calls or aggressive sales sequences — just one short welcome email and you decide if you want to talk.

Does this cover the entire HIPAA Security Rule?

+

No, and that's intentional. The full Security Rule has dozens of requirements. This checklist focuses on the 15 items that, in our experience auditing dozens of Miami-area practices, catch most clinics off-guard. It's a great starting point — not a substitute for a formal HIPAA compliance program.

Is this legal advice?

+

No. This is educational content based on the HIPAA Security Rule and our experience as a HIPAA-aligned IT services provider. For legal interpretation specific to your practice, consult a qualified HIPAA attorney. The PDF includes a full disclaimer on the final page.

Will you spam me?

+

No. One welcome email with your PDF. Maybe an occasional helpful update (no more than monthly). One-click unsubscribe in every email. We don't sell, rent, or share your information with anyone, ever.

My IT person says we're "HIPAA compliant." Do I still need this?

+

Probably yes. "HIPAA compliant" isn't a certification — it's an ongoing state that requires documentation, training, policies, and regular review. Many IT vendors handle the technical safeguards well but miss the administrative ones (training records, sanction policies, BAAs). Run through the checklist; if you can confidently check every item, you're in good shape.

Find out where your practice stands
in the next 30 minutes.

Free, instant download. No credit card. No sales call required.

Get My Free Checklist

25 pages · 15 critical items · Self-audit scoring · ITva Technologies, Miami