Opens in a new tab
Home hero2
HIPAA Checklist

HIPAA Checklist

A 48-point technical safeguards checklist for medical and dental practices — built by Silver Storm Solutions to help DFW-area healthcare offices find and close HIPAA IT gaps before an audit or breach does. Your progress saves automatically in this browser.

48Checklist items
7Safeguard areas
~10 minTo complete


0%
Not started
0 of 48 safeguards in place

The HIPAA Security Rule requires every covered medical practice to implement specific technical, administrative, and physical safeguards to protect Protected Health Information (PHI). Most of the technical requirements fall on IT — access control, encryption, backups, network security, audit logging, and incident response.

Work through the checklist below and check off each item your office already has in place. Sections collapse as you go, and your live compliance score updates in the bar above.

Note: This checklist covers common IT/technical safeguards referenced under the HIPAA Security Rule. It is an operational self-assessment tool, not legal advice, and does not replace a formal HIPAA Security Risk Assessment. Administrative and physical safeguards (policies, training records, facility access, BAAs with non-IT vendors) should also be reviewed separately with your compliance officer or legal counsel.

Where does your practice stand?

0%

Not started

Check off items above to see your live compliance score and risk tier.

Frequently Asked Questions

Does checking every box on this list make our practice HIPAA compliant?

No. This checklist covers the technical safeguards IT typically owns. Full HIPAA compliance also requires administrative safeguards (policies, workforce training, sanctions), physical safeguards (facility access, device disposal procedures), and a documented, annual Security Risk Assessment. Think of this as your IT gap-finder, not your full compliance program.

How often should we run this checklist?

At minimum annually, and any time you add a new system, EHR platform, or major vendor. Many practices review it quarterly alongside their HIPAA Security Risk Assessment cycle.

What happens if we can’t check off several items?

Unchecked items are your remediation list. Prioritize Access Control, Backup/Disaster Recovery, and Audit Controls first — these are the areas OCR investigators and cyber insurers scrutinize most closely after a breach.

Our EHR vendor says they handle HIPAA for us — is that enough?

No. Your EHR vendor is responsible for their own systems, but your practice is still responsible for your network, endpoints, email, backups, staff training, and everything else outside the EHR itself. A signed BAA transfers some liability, not the underlying risk.

Have gaps on your checklist?

Silver Storm Solutions provides HIPAA-aligned managed IT for medical and dental practices across the Dallas-Fort Worth area. Tell us a bit about your practice and one of our specialists will follow up within one business day with specific guidance for the gaps you found — no obligation.







Your current checklist score is included automatically so we can give relevant guidance. We follow up once — no spam, no obligation.

© Silver Storm Solutions — Managed IT & Cybersecurity for Medical Practices in Dallas-Fort Worth