Compliance
Become HIPAA compliant, and stay that way.
A checklist for a small clinic: what to put in place once, and the habits that keep it in place. Written for the owner or the office manager, not the lawyer.
Compliance
A checklist for a small clinic: what to put in place once, and the habits that keep it in place. Written for the owner or the office manager, not the lawyer.
Nobody sells HIPAA compliance. There is no government stamp for software, no certificate a vendor can hand you, and no product that makes a clinic compliant by being installed. HIPAA puts its duties on the practice: what you write down, what you train, what you sign, and how the front desk behaves on a busy Thursday.
That sounds like bad news. It is actually the good news. A small clinic can do all of it with a few afternoons of setup and a short list of habits. This page is that list.
A few words first, because HIPAA is full of them. PHI is protected health information: anything that says who a patient is, tied to their care or their bill. HHS is the Department of Health and Human Services, the federal agency behind the rules. OCR is its Office for Civil Rights, the office that takes complaints and investigates. A BAA is a Business Associate Agreement, the contract you sign with any vendor that handles PHI for you. This page is a plain-words guide, not legal advice. For anything unusual, ask a lawyer who knows healthcare.
Read a few years of the enforcement actions OCR publishes and the same causes come up again and again. Not exotic hacking. Ordinary things left undone.
If the disk was encrypted, that is a lost device. If it was not, it is a reportable breach of every chart on it.
It is the first document an investigator asks for, and the one most often missing.
Someone looked up a neighbour, a relative or a well-known patient. Shared logins make it impossible to say who.
Finding out and then waiting months to tell patients is treated as a separate failure from the breach itself.
Right-of-access cases are among the most common, and the simplest to avoid.
Every item on the checklist below is there because one of those happened to somebody.
Do these once, in roughly this order. Each has a reason, and a way a clinic with four or five staff actually does it.
Why: HIPAA requires one, and everything else on this list needs an owner.
How: Usually the practice owner or the office manager. Write the name and the date on one page. One person can hold both jobs.
Why: The Security Rule requires it, and it is the document OCR asks for first.
How: List where PHI lives (computers, phones, paper, vendors), what could go wrong with each, how likely and how bad, and what you will do about it. The free Security Risk Assessment Tool from HealthIT.gov walks you through it question by question.
Why: A rule that lives only in someone’s head is not a policy.
How: Short documents in plain words: who may see what, how people sign in and out, what happens when a device is lost, how a records request is answered. Date them and keep every version.
Why: Training is required for everyone who touches PHI, and the record is what proves it happened.
How: One session at hire and one refresher a year. Write down who, when and what was covered, and have people sign.
Why: Unique user identification is required. A shared password means nobody is accountable.
How: No shared accounts anywhere: the practice software, email, the computer itself. Each role sees only what the job needs.
Why: An open chart at an empty front desk is a disclosure waiting to happen.
How: Set the operating system and the practice software to lock after a short idle time. Shorter at the front desk, longer in a private office.
Why: PHI that was encrypted and then lost is not treated as a reportable breach. PHI that was not is.
How: BitLocker or device encryption on every Windows computer, encryption on every phone and tablet, and no PHI on a USB stick that is not encrypted. Keep the recovery keys somewhere safe that is not the device.
Why: PHI on the move is exposed on any network you do not control.
How: Send PHI only over connections that use TLS, the same protection your bank’s website uses. Do not text or email charts from a personal account.
Why: The Security Rule requires a record of activity in systems that hold PHI, and a log nobody reads catches nothing.
How: Make sure your software records who opened, exported or changed what. Name the person who reviews it and how often.
Why: The rule asks for a retrievable exact copy of PHI and a plan for getting it back.
How: An encrypted backup on a schedule, a copy kept somewhere other than the building, and one real restore onto a clean machine with the date written down.
Why: It is required, and a missing one is among the most common findings.
How: Make a list: practice software, billing service, clearinghouse, email provider, cloud storage, shredding company, IT support, answering service. Each one either signs a BAA or never sees PHI.
Why: The Privacy Rule requires the notice, and gives every patient the right to a copy of their record.
How: Give the notice at the first visit, post it in the waiting room and on your website, and keep a signed acknowledgement. Answer a records request within 30 days, and sooner when you can.
Why: The Privacy Rule says use and share only as much PHI as the task needs.
How: The front desk does not need clinical notes to book an appointment. A referral letter carries the relevant history, not the whole chart.
Why: A paper chart on a counter or a server in an unlocked closet is as much a HIPAA problem as a weak password.
How: Screens angled away from the waiting room, paper in locked cabinets, a locked room for any server, and a visitor rule for the back office.
Why: The Breach Notification Rule sets an outer limit of 60 days after discovery for telling affected patients, and slowness is treated as its own failure.
How: One page: who is called first, how you work out what was exposed, who writes to patients, who tells HHS, and where the record of it all is kept. Log every incident, including the ones that turned out to be nothing.
Why: Old hard drives, copiers with a disk inside and boxes of paper have all produced breaches after they left the building.
How: Wipe or destroy drives before a computer leaves, shred paper, and get a certificate from the disposal company, which should also have signed a BAA.
Becoming compliant is a project. Staying compliant is a calendar. Put these on it and the yearly review stops being frightening.
Screens lock when people walk away. Nobody signs in as someone else. Paper with PHI on it goes back in the cabinet or into the shredder, never the recycling bin.
The named person skims the security log: exports, backups, sensitive-record views, anything at odd hours. Check that the backup ran and that the newest copy is where it should be.
New person: their own login, the right role, and training done and recorded before they touch a chart. Leaving person: access removed the same day, keys and devices returned, a note in the file.
Review who has access to what, and remove anything that no longer fits the job. Confirm every computer and phone is still encrypted and still up to date.
A restore drill: bring a backup up on a spare machine, open a chart, write the date down. Walk the building once as if you were a visitor. What can be seen or picked up? Read the latest OCR cybersecurity newsletter. It is short, and written for practices like yours.
Update the risk analysis, and again whenever something big changes: a new location, new software, a new kind of service. Refresh training for everyone and record it. Re-read the policies and procedures and date the review, even if nothing changed. Review the vendor list and every BAA. Add the new vendor, drop the one you stopped using. Check the sanction record: any policy violation, what happened, what was done. An empty record is fine. A missing one is not.
Software cannot make a practice compliant, but it can make the right thing the default. LogBlues keeps patient records on the computers in your practice, encrypted with AES-256-GCM under a key held in Windows’ own protected store, and it checks that disk encryption and a screen lock are on before it trusts a machine. Each person signs in as themselves, with a role that limits what they see, and the workspace locks after an idle time the clinic sets. A security log records exports, backups, sensitive-result views and policy changes, with what happened and when. Backups are encrypted before they leave the building, with a restore preview, and we never hold the key. We sign a Business Associate Agreement with any clinic that asks, free. The Compliance area keeps your policies, procedures and safety checks as dated records, and exports the written security policy as a document you can hand to an auditor or an insurer. How LogBlues handles HIPAA, rule by rule →
Ten pages worth an hour, from the people who write the rules and the people who explain them. All are free.