PD Geek

HIPAA Compliance Checklist for Dental Practices (2025)

← Back to Blog

DENTAL · Dec 23, 2025 · 8 min read

25-point technical safeguards checklist for dental HIPAA compliance. What auditors look for and how to be ready.

HIPAA Compliance Checklist for Dental Practices

This checklist covers the technical safeguards required by HIPAA Security Rule (45 CFR § 164.312). Use it to assess your current state and prepare for audits.

Access Controls (§164.312(a))

1. Unique User Identification

☐ Every staff member has their own login

☐ No shared accounts (even at front desk)

☐ Generic "admin" accounts disabled

2. Emergency Access Procedure

☐ Documented process for emergency access

☐ Break-glass accounts configured

☐ Emergency access is logged and reviewed

3. Automatic Logoff

☐ Workstations lock after 5-15 minutes idle

☐ Screen savers require password

☐ Policy enforced technically, not just written

4. Encryption

☐ Data encrypted at rest (full disk encryption)

☐ Data encrypted in transit (HTTPS, TLS)

☐ Encrypted email available for patient communication

Audit Controls (§164.312(b))

5. Audit Logging Enabled

☐ Login/logout events recorded

☐ File access events recorded

☐ System changes recorded

6. Log Retention

☐ Logs retained for 6+ years (recommended 7)

☐ Logs stored securely, tamper-evident

☐ Logs accessible for audit/investigation

7. Log Review Process

☐ Regular review of access logs

☐ Alerts for suspicious activity

☐ Documentation of reviews

Integrity Controls (§164.312(c))

8. Data Integrity Verification

☐ Backup integrity checks

☐ Checksums on critical files

☐ Protection against unauthorized alteration

9. Transmission Integrity

☐ Encrypted connections for data transfer

☐ Verification that data isn't modified in transit

☐ Secure file sharing methods

Authentication (§164.312(d))

10. Multi-Factor Authentication

☐ MFA required for remote access

☐ MFA required for cloud services

☐ MFA on admin accounts

11. Strong Password Policy

☐ Minimum 12+ characters

☐ Complexity requirements

☐ No password reuse (last 12)

12. Account Lockout

☐ Lockout after 5-10 failed attempts

☐ Lockout duration 15+ minutes

☐ Admin notification of lockouts

Transmission Security (§164.312(e))

13. Encrypted Email

☐ TLS encryption for email transmission

☐ Portal or encryption for PHI attachments

☐ Policy against PHI in unencrypted email

14. Secure Remote Access

☐ VPN or zero-trust access

☐ No open RDP to internet

☐ Session timeouts enforced

Device Security (Additional Best Practices)

15. Endpoint Protection

☐ Modern antivirus/EDR on all devices

☐ Real-time scanning enabled

☐ Centrally managed and monitored

16. Mobile Device Management

☐ Tablets and phones enrolled

☐ Remote wipe capability

☐ PIN/biometric required

17. Patch Management

☐ Operating systems updated monthly

☐ Applications patched regularly

☐ Critical patches within 72 hours

Network Security

18. Firewall Protection

☐ Business-class firewall (not consumer router)

☐ Intrusion detection/prevention

☐ Regular rule reviews

19. Network Segmentation

☐ X-ray systems on separate network

☐ Guest WiFi isolated from practice network

☐ IoT devices segmented

20. Wireless Security

☐ WPA3 or WPA2-Enterprise

☐ No WEP or open networks

☐ Hidden SSID for practice network

Backup and Recovery

21. Regular Backups

☐ Daily backups minimum

☐ Multiple backup locations

☐ At least one offline/air-gapped copy

22. Backup Testing

☐ Monthly restore tests

☐ Full recovery test annually

☐ Documented recovery procedures

23. Disaster Recovery Plan

☐ Written plan exists

☐ RTO and RPO defined

☐ Plan tested annually

Documentation

24. Risk Assessment

☐ Completed annually

☐ Covers all systems with PHI

☐ Remediation plan for findings

25. Policies and Procedures

☐ Written security policies

☐ Staff acknowledgment signatures

☐ Annual policy review

Scoring Your Practice

20-25 checkmarks: You're in good shape. Regular maintenance needed.

15-19 checkmarks: Gaps exist. Prioritize MFA, encryption, and logging.

10-14 checkmarks: Significant risk. Audit could be painful.

Under 10 checkmarks: Critical exposure. Address immediately.

What Auditors Actually Ask

When OCR (Office for Civil Rights) audits, they request:

  1. Most recent risk assessment
  2. Security policies and procedures
  3. Evidence of staff training
  4. Audit logs for random date ranges
  5. Business associate agreements
  6. Incident response documentation

Can you produce all of this in 48 hours? If not, you're not ready.

Not sure where you stand? We'll assess your practice against this checklist and tell you exactly what's missing. Get Free Assessment

Need Help With Your Practice’s Security?

Free assessment, no obligation, real answers.

Get Free Assessment

(469) 306-9520 • Serving Dallas-Fort Worth

PD Geek is an operating brand of Pleasant Digital, LLC. © 2026 Pleasant Digital, LLC. Contact PD Geek through the Contact page.

Dental Practices · Therapy & Counseling · Churches & Nonprofits · Blog · Privacy Policy · Terms of Service