Is Your Clinic Actually HIPAA Compliant — Or Just Hoping?
Most clinics, therapists, and small medical practices fail at least 5 of 15 critical HIPAA items — usually without knowing it. This focused checklist surfaces the gaps OCR auditors look for first, with plain-English explanations and remediation steps.
Get Your Free Copy
Instant access · No spam, ever
🔒 Your email stays private. We don't share, ever.
15 Items. 3 Categories. Zero Fluff.
Organized exactly the way HHS organizes the HIPAA Security Rule, so your work transfers directly to a formal compliance program.
Administrative · 5 items
The policies, procedures, and training requirements that form the backbone of every HIPAA program.
- Documented Security Risk Analysis
- Designated Security Officer
- Workforce Training Documentation
- Sanction Policy
- Business Associate Agreements
Physical · 4 items
Physical access controls and device protections that keep PHI safe from theft, loss, or unauthorized viewing.
- Device Encryption
- Auto-Lock Screen Policy
- Device & Media Disposal
- Visitor Sign-In & Escort
Technical · 6 items
The digital and network-level controls that protect ePHI in motion and at rest. Where most modern HIPAA failures happen.
- Unique User Accounts
- Multi-Factor Authentication
- Encrypted Email
- Audit Logs (Quarterly Review)
- Patch Management
- Backup & Disaster Recovery
By the Numbers
Sources: HHS OCR Resolution Agreements, HHS 2024 Annual Report to Congress, Verizon 2024 Data Breach Investigations Report.
Practices Where Compliance Falls Between the Cracks
If your practice is too small for a dedicated compliance officer but too large to wing it, this checklist is for you.
Medical Clinics
Dental Practices
Therapists & Mental Health
Chiropractors
Optometrists
Medical Billing
Every checklist item answers four questions.
Most HIPAA resources tell you what to do but leave you guessing on the how. This one walks through each item with the same structure.
What this requirement actually is
Plain-English explanation with the regulatory citation.
Why most practices miss it
The real-world patterns we see during HIPAA assessments.
How to fix it
Specific tools, vendors, and procedures — not vague guidance.
Self-audit checkbox
Mark YES / PARTIAL / NO for each item to calculate your overall score.
Documented Security Risk Analysis (Less Than 12 Months Old)
A written assessment that identifies risks to ePHI, evaluates likelihood and impact, and documents the controls you have in place. Required by 45 CFR § 164.308(a)(1)(ii)(A).
Most small practices either skip this entirely or treat it as a one-time exercise. HHS audits explicitly ask: "When was your last risk analysis?" — and dates older than 12 months are flagged automatically.
Schedule an annual risk analysis. Document it in writing — Word doc is fine. Include: assets handling ePHI, threats, vulnerabilities, current controls, residual risk, and remediation plan.
Reference: 45 CFR § 164.308(a)(1)(ii)(A) · HHS OCR Guidance
Before You Download
Is this really free? What's the catch?
+
100% free. The PDF will download immediately after you submit the form, and you'll also get an emailed copy. The only "catch": if you find significant gaps and want help fixing them, we'd love to be considered. No follow-up calls or aggressive sales sequences — just one short welcome email and you decide if you want to talk.
Does this cover the entire HIPAA Security Rule?
+
No, and that's intentional. The full Security Rule has dozens of requirements. This checklist focuses on the 15 items that, in our experience auditing dozens of Miami-area practices, catch most clinics off-guard. It's a great starting point — not a substitute for a formal HIPAA compliance program.
Is this legal advice?
+
No. This is educational content based on the HIPAA Security Rule and our experience as a HIPAA-aligned IT services provider. For legal interpretation specific to your practice, consult a qualified HIPAA attorney. The PDF includes a full disclaimer on the final page.
Will you spam me?
+
No. One welcome email with your PDF. Maybe an occasional helpful update (no more than monthly). One-click unsubscribe in every email. We don't sell, rent, or share your information with anyone, ever.
My IT person says we're "HIPAA compliant." Do I still need this?
+
Probably yes. "HIPAA compliant" isn't a certification — it's an ongoing state that requires documentation, training, policies, and regular review. Many IT vendors handle the technical safeguards well but miss the administrative ones (training records, sanction policies, BAAs). Run through the checklist; if you can confidently check every item, you're in good shape.
Find out where your practice stands
in the next 30 minutes.
Free, instant download. No credit card. No sales call required.
Get My Free Checklist25 pages · 15 critical items · Self-audit scoring · ITva Technologies, Miami