COMPLIANCE

HIPAA Compliance Checklist for a Small Medical Practice

By A to Z Tech Services — Wayne, NJ

HIPAA's Security Rule contains hundreds of requirements, but not all of them are equally critical for a small medical practice in New Jersey. This checklist focuses on the IT-related items that HHS auditors look for first and that carry the highest risk if missing.

Work through each category. Items marked as "required" have no flexibility — they must be implemented. Items marked as "addressable" require either implementation or a documented reason why a reasonable alternative is in place.

Access Controls

  • Unique user IDs for every staff member — no shared logins
  • Role-based access — each user only accesses the PHI they need
  • Automatic session timeout on workstations after inactivity
  • Emergency access procedures documented and tested

Audit Controls

  • Audit logging enabled on all systems that access PHI
  • Logs reviewed regularly for unusual access patterns
  • Log retention for minimum 6 years
  • Audit trail available for any PHI access or modification

Encryption & Transmission Security

  • Full disk encryption on all laptops and workstations (BitLocker or FileVault)
  • Encrypted email for all PHI communications (not standard Gmail or Yahoo)
  • HTTPS enforced on any patient portal or web application
  • Encrypted backup storage — both local and cloud

Authentication

  • Multi-factor authentication (MFA) on all business email accounts
  • MFA on all remote access (VPN, RDP, cloud applications)
  • Password policy: minimum 12 characters, complexity required
  • Password manager deployed — staff are not writing passwords down or reusing them

Backup & Disaster Recovery

  • Automated daily backup of all systems containing PHI
  • Backup stored offsite or in the cloud — not just on the same network
  • Backup restoration tested at least quarterly
  • Disaster recovery plan documented and distributed

Physical Safeguards

  • Workstations positioned so screens are not visible to patients or visitors
  • Screen privacy filters on monitors in patient-facing areas
  • Workstations locked when unattended
  • Physical media (USB drives, paper records) disposal procedures in place

Administrative Requirements

  • HIPAA Security Rule risk assessment conducted (required — not optional)
  • Policies and procedures documented for all HIPAA safeguard categories
  • Employee HIPAA training completed and documented
  • Business Associate Agreements (BAAs) in place with all vendors that touch PHI
  • Incident response plan with breach notification procedures documented

NJ-Specific Note

New Jersey's Health Insurance Portability and Accountability Act rules align with federal HIPAA, but NJ also has the Identity Theft Prevention Act and NJAC 13:45A-21 which require additional security safeguards for personal information. NJ medical practices dealing with breach incidents must notify the NJ Division of Consumer Affairs in addition to HHS.

Need Help Implementing This Checklist?

We provide HIPAA compliance IT services for medical practices throughout Wayne, Clifton, Parsippany, and North Jersey.

HIPAA IT Services