What HIPAA Actually Requires From Your Practice's IT
Most small practices think HIPAA compliance is a binder on a shelf. This plain-English guide translates the Security Rule's technical safeguards into a concrete IT checklist your practice can actually use.
HIPAA Compliance Is Not a Binder on a Shelf
If you run a small medical or dental practice in Central Florida, you already know you're required to be HIPAA compliant. What many practice owners don't realize is that compliance isn't achieved by having a written policy sitting in a binder. The HIPAA Security Rule spells out specific technical safeguards — actual IT configurations and controls — that your practice must have in place.
The Department of Health and Human Services has been increasing enforcement, and penalties for non-compliance can reach tens of thousands of dollars per violation category, per year. But the bigger risk for most small practices is a breach itself. A single exposed patient record can trigger mandatory breach notification requirements, legal exposure, and reputational damage that takes years to overcome.
This guide translates the Security Rule's technical requirements into language a practice owner or office manager can actually act on — no legal jargon, no vague references to "appropriate safeguards." Just the specific IT controls you need and what each one means in practice.
Access Controls: Who Can See What
HIPAA requires that every person who accesses electronic Protected Health Information (ePHI) has a unique identifier. No shared logins, no generic "reception" accounts. The system must also automatically log off after a period of inactivity.
What this means in practice:
- Unique user accounts: Every staff member — including part-time and temporary employees — gets their own login. No exceptions.
- Role-based access: A front desk coordinator should not have the same access as a provider. Configure your EHR and network so staff can only see the records they need for their job.
- Automatic logoff: Workstations should lock after 10-15 minutes of inactivity. This is a specific Security Rule requirement, not a best practice suggestion.
Audit Logs: Knowing Who Did What and When
The Security Rule requires your systems to record and examine activity involving ePHI. If a breach happens, you need to be able to look back and see who accessed what, and when.
Most modern EHR systems have built-in audit logging, but it's often not enabled by default or not reviewed regularly. Your IT provider should confirm that audit logging is turned on for your EHR, your file servers, and any other systems that store or transmit patient data. Logs should be retained for at least six years per HIPAA documentation requirements.
Encryption: Protecting Data at Rest and in Transit
Encryption is one of the few Security Rule requirements that has a clear safe harbor. If a lost or stolen laptop had encrypted ePHI on it, that is generally not considered a reportable breach. If it wasn't encrypted, it is.
- Encryption at rest: Every device that could hold patient data — desktops, laptops, tablets, USB drives, backup drives — must be encrypted. BitLocker (Windows) and FileVault (macOS) are built in and free. Your IT provider should enforce this centrally.
- Encryption in transit: Any time patient data moves across a network — between your office and a cloud backup, between a tablet and your EHR, between your practice and a referring physician — it must be encrypted. This means using HTTPS, VPNs, or encrypted email for any transmission of ePHI.
Backup and Disaster Recovery
HIPAA requires a contingency plan that includes data backup and disaster recovery. But the rule doesn't just say "have a backup." It requires that backups are retrievable, that you have a documented recovery procedure, and that you test it.
A backup that has never been tested is an assumption, not a plan. If your IT provider can't show you the results of a recent test restore, ask them to run one.
Business Associate Agreements
Every vendor that touches your patient data — your IT provider, your cloud backup vendor, your EHR hosting company, your email encryption service — is a Business Associate under HIPAA. You are required to have a signed Business Associate Agreement (BAA) with each one.
This is one of the most commonly missed requirements in small practices. If your IT provider doesn't proactively offer a BAA, that's a red flag.
Your 12-Point HIPAA IT Self-Audit Checklist
Can you answer yes to every one of these?
- 1Unique logins: Every staff member has their own unique user account. No shared or generic accounts exist.
- 2Role-based access: Staff can only access records relevant to their role. Providers can see full charts; front desk staff can see scheduling and basic patient info.
- 3Automatic logoff: All workstations lock automatically after 10-15 minutes of inactivity.
- 4Audit logging enabled: Your EHR and file systems are logging who accesses each patient record.
- 5Audit logs reviewed: Someone reviews access logs at least monthly for unusual activity.
- 6Full-disk encryption: Every laptop, desktop, and mobile device that could store ePHI has encryption enabled (BitLocker or FileVault).
- 7Encrypted transmissions: Patient data sent by email is encrypted. Remote access uses a VPN. Your EHR uses HTTPS.
- 8Backup in place: You have automated backups running daily, with at least one copy stored offsite.
- 9Backup tested: You have documentation showing a successful test restore within the last 6 months.
- 10Documented recovery plan: You have a written procedure for how to restore systems and data after a failure.
- 11BAAs signed: You have a signed Business Associate Agreement with every vendor that handles patient data — including your IT provider.
- 12Staff training: Every employee has received HIPAA security training within the last year, and you have records of completion.
If you answered no to any of these, that's your starting point. Each gap is a specific, fixable IT problem — not an abstract compliance concept.
HIPAA compliance for a small practice comes down to having the right technical controls in place and documented. Dytech Group helps medical and dental practices across Central Florida implement and maintain these safeguards. We also work specifically with dental offices on the unique IT challenges dental practices face. If you want a hands-on assessment of where your practice stands, our data protection team can walk through each item on this checklist with you.

