Two months free. Download LogBlues and let us prove it — no card, no contract. Start free →
LogBlues

Compliance

Become HIPAA compliant, and stay that way.

A checklist for a small clinic: what to put in place once, and the habits that keep it in place. Written for the owner or the office manager, not the lawyer.

Compliance is a routine, not a purchase

Nobody sells HIPAA compliance. There is no government stamp for software, no certificate a vendor can hand you, and no product that makes a clinic compliant by being installed. HIPAA puts its duties on the practice: what you write down, what you train, what you sign, and how the front desk behaves on a busy Thursday.

That sounds like bad news. It is actually the good news. A small clinic can do all of it with a few afternoons of setup and a short list of habits. This page is that list.

A few words first, because HIPAA is full of them. PHI is protected health information: anything that says who a patient is, tied to their care or their bill. HHS is the Department of Health and Human Services, the federal agency behind the rules. OCR is its Office for Civil Rights, the office that takes complaints and investigates. A BAA is a Business Associate Agreement, the contract you sign with any vendor that handles PHI for you. This page is a plain-words guide, not legal advice. For anything unusual, ask a lawyer who knows healthcare.

What actually gets a clinic in trouble

Read a few years of the enforcement actions OCR publishes and the same causes come up again and again. Not exotic hacking. Ordinary things left undone.

An unencrypted laptop or phone goes missing

If the disk was encrypted, that is a lost device. If it was not, it is a reportable breach of every chart on it.

No written risk analysis

It is the first document an investigator asks for, and the one most often missing.

No BAA with a vendor that turned out to hold PHI: a billing service, a shredding company, a cloud drive
Staff snooping

Someone looked up a neighbour, a relative or a well-known patient. Shared logins make it impossible to say who.

A slow or silent breach response

Finding out and then waiting months to tell patients is treated as a separate failure from the breach itself.

Ignoring a patient’s request for their own records

Right-of-access cases are among the most common, and the simplest to avoid.

Every item on the checklist below is there because one of those happened to somebody.

Part 1: Become compliant

Do these once, in roughly this order. Each has a reason, and a way a clinic with four or five staff actually does it.

  • 1
    Name a privacy and security officer

    Why: HIPAA requires one, and everything else on this list needs an owner.

    How: Usually the practice owner or the office manager. Write the name and the date on one page. One person can hold both jobs.

  • 2
    Do a written risk analysis

    Why: The Security Rule requires it, and it is the document OCR asks for first.

    How: List where PHI lives (computers, phones, paper, vendors), what could go wrong with each, how likely and how bad, and what you will do about it. The free Security Risk Assessment Tool from HealthIT.gov walks you through it question by question.

  • 3
    Write your policies and procedures

    Why: A rule that lives only in someone’s head is not a policy.

    How: Short documents in plain words: who may see what, how people sign in and out, what happens when a device is lost, how a records request is answered. Date them and keep every version.

  • 4
    Train staff, and keep a record

    Why: Training is required for everyone who touches PHI, and the record is what proves it happened.

    How: One session at hire and one refresher a year. Write down who, when and what was covered, and have people sign.

  • 5
    Give every person their own login, and a role

    Why: Unique user identification is required. A shared password means nobody is accountable.

    How: No shared accounts anywhere: the practice software, email, the computer itself. Each role sees only what the job needs.

  • 6
    Turn on automatic screen lock

    Why: An open chart at an empty front desk is a disclosure waiting to happen.

    How: Set the operating system and the practice software to lock after a short idle time. Shorter at the front desk, longer in a private office.

  • 7
    Encrypt every device

    Why: PHI that was encrypted and then lost is not treated as a reportable breach. PHI that was not is.

    How: BitLocker or device encryption on every Windows computer, encryption on every phone and tablet, and no PHI on a USB stick that is not encrypted. Keep the recovery keys somewhere safe that is not the device.

  • 8
    Encrypt what travels

    Why: PHI on the move is exposed on any network you do not control.

    How: Send PHI only over connections that use TLS, the same protection your bank’s website uses. Do not text or email charts from a personal account.

  • 9
    Keep an audit log, and decide who reads it

    Why: The Security Rule requires a record of activity in systems that hold PHI, and a log nobody reads catches nothing.

    How: Make sure your software records who opened, exported or changed what. Name the person who reviews it and how often.

  • 10
    Back up, then prove you can restore

    Why: The rule asks for a retrievable exact copy of PHI and a plan for getting it back.

    How: An encrypted backup on a schedule, a copy kept somewhere other than the building, and one real restore onto a clean machine with the date written down.

  • 11
    Sign a BAA with every vendor that touches PHI

    Why: It is required, and a missing one is among the most common findings.

    How: Make a list: practice software, billing service, clearinghouse, email provider, cloud storage, shredding company, IT support, answering service. Each one either signs a BAA or never sees PHI.

  • 12
    Post a Notice of Privacy Practices, and answer records requests

    Why: The Privacy Rule requires the notice, and gives every patient the right to a copy of their record.

    How: Give the notice at the first visit, post it in the waiting room and on your website, and keep a signed acknowledgement. Answer a records request within 30 days, and sooner when you can.

  • 13
    Apply the minimum necessary rule

    Why: The Privacy Rule says use and share only as much PHI as the task needs.

    How: The front desk does not need clinical notes to book an appointment. A referral letter carries the relevant history, not the whole chart.

  • 14
    Handle the physical side

    Why: A paper chart on a counter or a server in an unlocked closet is as much a HIPAA problem as a weak password.

    How: Screens angled away from the waiting room, paper in locked cabinets, a locked room for any server, and a visitor rule for the back office.

  • 15
    Write a breach response plan

    Why: The Breach Notification Rule sets an outer limit of 60 days after discovery for telling affected patients, and slowness is treated as its own failure.

    How: One page: who is called first, how you work out what was exposed, who writes to patients, who tells HHS, and where the record of it all is kept. Log every incident, including the ones that turned out to be nothing.

  • 16
    Dispose of devices and media properly

    Why: Old hard drives, copiers with a disk inside and boxes of paper have all produced breaches after they left the building.

    How: Wipe or destroy drives before a computer leaves, shred paper, and get a certificate from the disposal company, which should also have signed a BAA.

Part 2: Stay compliant

Becoming compliant is a project. Staying compliant is a calendar. Put these on it and the yearly review stops being frightening.

Every day

Screens lock when people walk away. Nobody signs in as someone else. Paper with PHI on it goes back in the cabinet or into the shredder, never the recycling bin.

Every week

The named person skims the security log: exports, backups, sensitive-record views, anything at odd hours. Check that the backup ran and that the newest copy is where it should be.

Whenever staff join or leave

New person: their own login, the right role, and training done and recorded before they touch a chart. Leaving person: access removed the same day, keys and devices returned, a note in the file.

Every month

Review who has access to what, and remove anything that no longer fits the job. Confirm every computer and phone is still encrypted and still up to date.

Every quarter

A restore drill: bring a backup up on a spare machine, open a chart, write the date down. Walk the building once as if you were a visitor. What can be seen or picked up? Read the latest OCR cybersecurity newsletter. It is short, and written for practices like yours.

Every year

Update the risk analysis, and again whenever something big changes: a new location, new software, a new kind of service. Refresh training for everyone and record it. Re-read the policies and procedures and date the review, even if nothing changed. Review the vendor list and every BAA. Add the new vendor, drop the one you stopped using. Check the sanction record: any policy violation, what happened, what was done. An empty record is fine. A missing one is not.

Where LogBlues helps

Software cannot make a practice compliant, but it can make the right thing the default. LogBlues keeps patient records on the computers in your practice, encrypted with AES-256-GCM under a key held in Windows’ own protected store, and it checks that disk encryption and a screen lock are on before it trusts a machine. Each person signs in as themselves, with a role that limits what they see, and the workspace locks after an idle time the clinic sets. A security log records exports, backups, sensitive-result views and policy changes, with what happened and when. Backups are encrypted before they leave the building, with a restore preview, and we never hold the key. We sign a Business Associate Agreement with any clinic that asks, free. The Compliance area keeps your policies, procedures and safety checks as dated records, and exports the written security policy as a document you can hand to an auditor or an insurer. How LogBlues handles HIPAA, rule by rule →

Further reading

Ten pages worth an hour, from the people who write the rules and the people who explain them. All are free.

  1. HHSSummary of the HIPAA Security Rule. The government's own short version of what the Security Rule asks for. Read this one first.
  2. HHSSummary of the HIPAA Privacy Rule. Who may see and share PHI, the minimum necessary rule, and what patients have a right to.
  3. HHSBreach Notification Rule. What counts as a breach, who must be told, and the deadlines. The page to have open when something goes wrong.
  4. HHSGuidance on Risk Analysis. What a risk analysis has to contain, in the words of the office that will ask you for it.
  5. HealthIT.govSecurity Risk Assessment Tool. A free program from the government that walks a small practice through the risk analysis question by question.
  6. NISTSP 800-66 Rev. 2: Implementing the HIPAA Security Rule, a Cybersecurity Resource Guide. The long, practical guide to each safeguard, with tables you can work through with whoever looks after your computers.
  7. HHSCyber Security Guidance Material. Ransomware guidance, a cybersecurity checklist, and the archive of the OCR newsletters mentioned in the calendar above.
  8. HHSTraining Materials. Free training aids and short guides you can use for the yearly staff refresher.
  9. American Medical AssociationHIPAA security rule and risk analysis. A physician-side explanation of the Security Rule and the risk analysis, written for practices rather than IT departments.
  10. HIPAA JournalHIPAA Compliance Checklist. A long, regularly updated checklist from an established news site that follows HIPAA enforcement.