HIPAA Compliance Checklist for Dental Practices (2025)
DENTAL · Dec 23, 2025 · 8 min read
25-point technical safeguards checklist for dental HIPAA compliance. What auditors look for and how to be ready.
HIPAA Compliance Checklist for Dental Practices
This checklist covers the technical safeguards required by HIPAA Security Rule (45 CFR § 164.312). Use it to assess your current state and prepare for audits.
Access Controls (§164.312(a))
1. Unique User Identification
☐ Every staff member has their own login
☐ No shared accounts (even at front desk)
☐ Generic "admin" accounts disabled
2. Emergency Access Procedure
☐ Documented process for emergency access
☐ Break-glass accounts configured
☐ Emergency access is logged and reviewed
3. Automatic Logoff
☐ Workstations lock after 5-15 minutes idle
☐ Screen savers require password
☐ Policy enforced technically, not just written
4. Encryption
☐ Data encrypted at rest (full disk encryption)
☐ Data encrypted in transit (HTTPS, TLS)
☐ Encrypted email available for patient communication
Audit Controls (§164.312(b))
5. Audit Logging Enabled
☐ Login/logout events recorded
☐ File access events recorded
☐ System changes recorded
6. Log Retention
☐ Logs retained for 6+ years (recommended 7)
☐ Logs stored securely, tamper-evident
☐ Logs accessible for audit/investigation
7. Log Review Process
☐ Regular review of access logs
☐ Alerts for suspicious activity
☐ Documentation of reviews
Integrity Controls (§164.312(c))
8. Data Integrity Verification
☐ Backup integrity checks
☐ Checksums on critical files
☐ Protection against unauthorized alteration
9. Transmission Integrity
☐ Encrypted connections for data transfer
☐ Verification that data isn't modified in transit
☐ Secure file sharing methods
Authentication (§164.312(d))
10. Multi-Factor Authentication
☐ MFA required for remote access
☐ MFA required for cloud services
☐ MFA on admin accounts
11. Strong Password Policy
☐ Minimum 12+ characters
☐ Complexity requirements
☐ No password reuse (last 12)
12. Account Lockout
☐ Lockout after 5-10 failed attempts
☐ Lockout duration 15+ minutes
☐ Admin notification of lockouts
Transmission Security (§164.312(e))
13. Encrypted Email
☐ TLS encryption for email transmission
☐ Portal or encryption for PHI attachments
☐ Policy against PHI in unencrypted email
14. Secure Remote Access
☐ VPN or zero-trust access
☐ No open RDP to internet
☐ Session timeouts enforced
Device Security (Additional Best Practices)
15. Endpoint Protection
☐ Modern antivirus/EDR on all devices
☐ Real-time scanning enabled
☐ Centrally managed and monitored
16. Mobile Device Management
☐ Tablets and phones enrolled
☐ Remote wipe capability
☐ PIN/biometric required
17. Patch Management
☐ Operating systems updated monthly
☐ Applications patched regularly
☐ Critical patches within 72 hours
Network Security
18. Firewall Protection
☐ Business-class firewall (not consumer router)
☐ Intrusion detection/prevention
☐ Regular rule reviews
19. Network Segmentation
☐ X-ray systems on separate network
☐ Guest WiFi isolated from practice network
☐ IoT devices segmented
20. Wireless Security
☐ WPA3 or WPA2-Enterprise
☐ No WEP or open networks
☐ Hidden SSID for practice network
Backup and Recovery
21. Regular Backups
☐ Daily backups minimum
☐ Multiple backup locations
☐ At least one offline/air-gapped copy
22. Backup Testing
☐ Monthly restore tests
☐ Full recovery test annually
☐ Documented recovery procedures
23. Disaster Recovery Plan
☐ Written plan exists
☐ RTO and RPO defined
☐ Plan tested annually
Documentation
24. Risk Assessment
☐ Completed annually
☐ Covers all systems with PHI
☐ Remediation plan for findings
25. Policies and Procedures
☐ Written security policies
☐ Staff acknowledgment signatures
☐ Annual policy review
Scoring Your Practice
20-25 checkmarks: You're in good shape. Regular maintenance needed.
15-19 checkmarks: Gaps exist. Prioritize MFA, encryption, and logging.
10-14 checkmarks: Significant risk. Audit could be painful.
Under 10 checkmarks: Critical exposure. Address immediately.
What Auditors Actually Ask
When OCR (Office for Civil Rights) audits, they request:
- Most recent risk assessment
- Security policies and procedures
- Evidence of staff training
- Audit logs for random date ranges
- Business associate agreements
- Incident response documentation
Can you produce all of this in 48 hours? If not, you're not ready.
Not sure where you stand? We'll assess your practice against this checklist and tell you exactly what's missing. Get Free Assessment
Need Help With Your Practice’s Security?
Free assessment, no obligation, real answers.
(469) 306-9520 • Serving Dallas-Fort Worth