HIPAA compliance checklist for small practices, 2026
This is the checklist we would work through with a practice of 1 to 50 people. It follows the three HIPAA rules that matter day to day, the Privacy Rule, the Security Rule, and the Breach Notification Rule, and ends with the records you should be able to produce on request.
Free preview before you pay. Editable Word files. 14 day refund.
Privacy Rule
- A named Privacy Officer, and a contact for patient complaints
- Written privacy policies and procedures covering uses and disclosures, patient rights, minimum necessary, and sanctions for staff who break the rules
- A current Notice of Privacy Practices, given at the first visit, posted in the office and on your website, with signed acknowledgments. Notices had to be updated by February 16, 2026 for the new substance use disorder record rules
- A process for patient requests: access to records within 30 days, amendments, restrictions, confidential communications, and an accounting of disclosures
- Authorization forms for uses that need one, such as most marketing
- Training for every workforce member, with dated records
Security Rule
- A named Security Officer. In a small office this is often the same person as the Privacy Officer
- A written security risk analysis, repeated at least yearly and after big changes, and a plan to reduce the risks it finds
- A unique login for every person, automatic screen lock, and access removed promptly when someone leaves
- Encryption on laptops, phones, and portable media, and encrypted email or a portal for sending records
- Audit logs turned on in the EHR, and reviewed
- Tested backups with a copy offsite or in the cloud, and a written plan for getting running again after an outage or ransomware
- Physical safeguards: locked network equipment, screens angled away from the public, and a documented disposal process
- Written security policies that describe what the practice actually does
Business associates
What a business associate agreement must include
- A list of every vendor that handles patient information
- A signed business associate agreement with each one
Breach Notification Rule
Our free breach notification deadline calculator works out the dates for you.
- A written breach procedure, including the four factor risk assessment used to decide whether an incident is a reportable breach
- A breach log
- Knowing the deadlines: individuals within 60 days of discovery, HHS on a timeline that depends on whether 500 or more people are affected, and the media for large breaches in one state
What to keep on file
HIPAA requires required documentation to be kept for six years from when it was created or last in effect, whichever is later. If someone asked tomorrow, you should be able to produce:
- Your current and past privacy and security policies
- Your security risk analysis and the plan that came out of it
- Signed business associate agreements
- Training records
- Signed Notice of Privacy Practices acknowledgments
- Your breach log and any breach risk assessments
Coming next: the Security Rule update
HHS has proposed the largest update to the HIPAA Security Rule in 20 years, now expected in 2027. It would make safeguards such as multifactor authentication, encryption, and 72 hour recovery mandatory for every practice, even solo offices. Starting on them now is inexpensive for a small practice.
State law
State privacy laws can be stricter than HIPAA, and where they are, you follow the stricter rule. California practices should also read our California HIPAA checklist.
Questions
Does HIPAA apply to small practices?
Yes. A health care provider that sends health information electronically in connection with a standard transaction, such as an insurance claim, is a covered entity regardless of size.
Is there an official HIPAA certification?
No. HHS does not certify practices or vendors as HIPAA compliant. Compliance is shown by your policies, your risk analysis, your records, and what the practice actually does.
How often should we review our HIPAA program?
At least once a year, and whenever you change systems, vendors, or locations.
Full HIPAA Policy Kit, $129
- Notice of Privacy Practices, updated for the 2026 rules, plus the acknowledgment form
- 22 Privacy policies and procedures
- 19 Security policies mapped to the Security Rule
- Breach Notification policy with a risk assessment form and log
- Business Associate Agreement for your vendors
- Workforce confidentiality agreement, training log, and access checklist
- Security Risk Analysis worksheet, pre filled from your answers
- Patient request forms, plus a California addendum for California practices
More guides
- HIPAA compliance for dental offices: what auditors actually check
- HIPAA compliance checklist for small medical practices in California
- The HIPAA security risk assessment, explained for small practices
- Notice of Privacy Practices template, updated for 2026
- HIPAA policies for chiropractic offices
- HIPAA policies for physical therapy practices
- HIPAA policies for mental health and behavioral health practices
- HIPAA policies for optometry practices
- HIPAA for med spas and aesthetics practices
- HIPAA policies and procedures for small medical practices
- HIPAA business associate agreement: what it must include
- HIPAA breach notification deadline calculator
- Free HIPAA policy templates: where to get them, and what they leave out
- HIPAA training requirements for small practices
- HIPAA policies for podiatry practices
- HIPAA policies for dermatology practices
- HIPAA policies for pediatric practices
- HIPAA for acupuncture practices
- HIPAA policies for speech therapy practices
Templates, not legal advice. Eaglizer IT is not a law firm and does not certify HIPAA compliance. Using templates does not by itself make a practice compliant; follow the policies, train your staff, and keep records.