If you run a dental practice in Georgia, you already know HIPAA is something you have to deal with. But knowing you need to be compliant and actually being compliant are two very different things. The gap between them is where practices get into trouble.
The challenge isn't that HIPAA is impossible to understand. It's that the rules are spread across hundreds of pages of federal regulations, and most of the guidance out there is written by lawyers for lawyers. When you're busy running a practice (seeing patients, managing staff, keeping the lights on), sorting through all of that feels like a second full-time job.
So we put together this checklist. It covers the IT side of HIPAA compliance (which is where most dental practices have the biggest gaps) in plain language. No legal jargon. No 80-page PDFs. Just a clear, practical list of what your practice needs to have in place to protect patient data and stay on the right side of federal regulators.
At NGT Technology, we've been supporting dental practices across Georgia since 2019, and I've spent over 17 years working in IT. These are the areas where we consistently see the most problems, and the most risk.
What This Checklist Covers
This checklist focuses on the HIPAA Security Rule, the part that deals with how you protect electronic protected health information (ePHI) on your computers, servers, and in the cloud. There's also the Privacy Rule (how you handle and share patient information) and the Breach Notification Rule (what to do when something goes wrong). Those are important too, but the IT security piece is where dental practices tend to have the biggest blind spots.
One important note: this is practical IT guidance based on our experience working with dental offices, not legal advice. For specific legal questions about HIPAA, talk to a healthcare attorney.
Conduct a Risk Assessment (and Document It)
This is the single most important item on this list. HIPAA requires every covered entity, including your dental practice, to conduct a thorough risk assessment of how you handle electronic patient data. Not once. Regularly. The Department of Health and Human Services (HHS) recommends at least annually.
A risk assessment means looking at every place patient data lives in your practice: your practice management software, digital X-ray systems, email, cloud storage, even your phone system if it handles patient information. Then you ask two questions about each one: what could go wrong, and how bad would it be?
Your risk assessment checklist
- Identify every system that stores, processes, or transmits ePHI. This includes your practice management software (Dentrix, Eaglesoft, Open Dental, etc.), digital imaging systems, email, cloud storage, backup systems, and any mobile devices used for practice business.
- Document the potential threats to each system. Think about theft, malware, ransomware, accidental deletion, unauthorized access by employees, natural disasters, and hardware failure.
- Assess the likelihood and impact of each threat. A ransomware attack on your server has both high likelihood and high impact. A flood in your server room might have lower likelihood but equally devastating impact.
- Document what safeguards you currently have in place. Antivirus, firewalls, backups, access controls. Write down everything you're already doing.
- Identify the gaps. Where are you vulnerable? Where does your current protection fall short?
- Create an action plan with timelines. For each gap, document what you're going to do about it and when.
- Keep everything in writing. The documentation itself is a HIPAA requirement. If an auditor shows up or you experience a breach, the first thing they'll ask for is your risk assessment. If you don't have one, you're already in violation, regardless of how good your actual security is.
Set Up Proper Access Controls
Not everyone in your office needs access to everything. Your front desk staff needs to see scheduling and billing information. Your hygienists need access to clinical records. But does your front desk person need to see clinical notes? Does your billing coordinator need access to X-rays?
HIPAA calls this the "minimum necessary" standard: people should only have access to the patient information they need to do their specific job. Nothing more.
Your access control checklist
- Assign unique login credentials to every person who accesses patient data. No shared logins, ever. When three people use the same "FrontDesk" account, you have no way of knowing who accessed what, and no audit trail if something goes wrong.
- Set up role-based access so each staff member only sees the data relevant to their role. Most practice management software supports this natively. It just needs to be configured.
- Enable automatic screen lock after a short period of inactivity. We recommend 5 minutes or less. In a busy dental office, workstations get left unattended constantly.
- Turn on multi-factor authentication (MFA) on all systems that support it, especially email and cloud applications. It's one of the most effective ways to keep unauthorized users out of your accounts.
- Review access levels whenever someone changes roles. The part-time hygienist who picked up extra front desk shifts shouldn't accumulate access from both roles unless they need it for both.
- Disable accounts immediately when someone leaves. Not next week. Not when IT gets around to it. The same day. We've seen former employees accessing practice systems months after departure because nobody remembered to turn off their login.
Encrypt Everything That Holds Patient Data
Encryption scrambles data so that even if someone steals a laptop, a hard drive, or intercepts data in transit, they can't actually read any of it without the encryption key. HIPAA considers encryption an "addressable" safeguard. That doesn't mean optional. It means if you decide not to encrypt, you need a documented, justifiable reason and an equivalent alternative measure. In practice, there's almost never a good reason not to encrypt.
Your encryption checklist
- Enable full-disk encryption on every computer and laptop in your practice. BitLocker for Windows, FileVault for Mac. Both are built into the operating system at no extra cost.
- Verify your practice management software encrypts its database. Most modern dental software does this, but confirm it with your vendor.
- Use encrypted email (or a secure patient portal) when sending any patient information electronically. Standard email is not encrypted by default.
- Confirm that your cloud storage and backup solutions use encryption both in transit (while data is being sent) and at rest (while data is sitting on a server).
- Encrypt any portable devices (USB drives, external hard drives, tablets) that might contain patient data.
- Check your digital imaging systems. Confirm that X-ray images and other diagnostic files are stored in an encrypted format.
Here's a practical reason this matters beyond compliance: if a laptop with encrypted data gets stolen, it's generally not considered a reportable breach under HIPAA because the data is unreadable without the encryption key. If that same laptop wasn't encrypted? You're looking at breach notifications to every affected patient, a report to HHS, potential fines, and a whole lot of headaches.
Train Your Team (and Keep Records)
Your team is both your first line of defense and, honestly, your biggest vulnerability. It doesn't matter how good your technical safeguards are if someone on your staff clicks a phishing link, writes passwords on a sticky note taped to their monitor, or discusses patient information where others can overhear.
HIPAA requires security awareness training for all workforce members. That means dentists, hygienists, front desk staff, billing coordinators, and anyone else who handles patient information, including part-time employees and temps.
Your training checklist
- Conduct HIPAA security training for all staff at least annually. Quarterly is better if you can manage it.
- Cover the essentials: recognizing phishing emails, creating strong passwords, proper handling of patient information, what to do if they suspect a security incident, and who to report it to.
- Train new employees before they get access to any patient data systems. Not during their first week. Before they log in for the first time.
- Run simulated phishing tests to see how your team responds in real-world scenarios. This is one of the most effective training tools available.
- Document every training session: who attended, what topics were covered, and the date. Keep these records for at least six years (HIPAA's retention requirement).
Training doesn't need to be a day-long seminar. A focused 30-to-45-minute session covering real examples and practical tips is more effective than a marathon lecture. The important thing is that it happens regularly and that everyone participates.
Think Your Business Email Is Safe?
Credential stuffing attacks use stolen emails from past breaches. Our free dark web scan tells you in seconds if yours has been compromised.
Run a Free Dark Web ScanWorried About Your Business Security?
Get a discovery call and find out exactly where your vulnerabilities are.
Book a Discovery CallGet Your Business Associate Agreements in Order
Every vendor that handles patient data on your behalf is a "business associate" under HIPAA. That includes your IT company, your cloud backup provider, your practice management software vendor, your billing service, your answering service, and even your shredding company. HIPAA requires a signed Business Associate Agreement (BAA) with each one.
A BAA is a legal contract that says the vendor will protect patient data according to HIPAA's requirements and notify you if they experience a breach. Without one, you're both liable if something goes wrong. And you'll have a hard time explaining to an auditor why you were sharing patient data without a formal agreement.
Your BAA checklist
- Make a list of every vendor that accesses, stores, or transmits ePHI on your behalf. Be thorough. This often includes vendors people forget about, like the after-hours answering service or the IT consultant who comes in once a month.
- Verify that you have a signed BAA with each one. No handshake agreements. No "I'm sure they'll keep it safe." A signed document.
- Review your BAAs annually to make sure they're current and cover the services actually being provided.
- Before signing up with any new vendor, confirm they'll sign a BAA. If they won't or don't know what one is, that's a serious red flag.
- Keep copies of all BAAs organized and accessible. You need to be able to produce them quickly if asked.
Enable Audit Logging and Monitoring
HIPAA requires that you track who accesses patient data, when they access it, and what they do with it. This is called audit logging, and most modern systems support it. You just need to make sure it's actually turned on and someone is paying attention to it.
Audit logs serve two purposes: they help you detect suspicious activity before it becomes a full-blown breach, and they give you the evidence you need if an investigation happens after the fact.
Your audit logging checklist
- Enable audit logging in your practice management software. Most systems have this capability built in; it just needs to be activated.
- Turn on login and access logging for your email system. Both Microsoft 365 and Google Workspace support detailed audit logs.
- Log access to any file shares or cloud storage that contain patient data.
- Set up alerts for unusual activity: logins at odd hours, multiple failed login attempts, large file downloads or exports, access from unfamiliar locations or devices.
- Review logs regularly, at least monthly, for anything that looks unusual.
- Retain logs for at least six years per HIPAA requirements.
If you don't have the time or expertise to review logs yourself, this is something a Managed Cybersecurity provider can handle for you. They'll monitor your systems continuously and alert you when something needs attention.
Build an Incident Response Plan
Say something goes wrong: a ransomware attack, a stolen laptop, an employee accessing records they shouldn't have. What does your practice do? Who's in charge? Who do you call? How do you figure out what data was affected? How do you notify patients if required?
If you don't have answers to those questions written down somewhere, you're not prepared. And HIPAA requires that you are.
Your incident response checklist
- Create a written incident response plan that covers detection, containment, investigation, notification, and recovery.
- Designate a specific person (or role) responsible for leading the response. In a dental practice, this is often the practice owner or office manager.
- Include contact information for your IT provider, legal counsel, cyber insurance carrier, and any relevant regulatory bodies.
- Define what counts as a security incident and what triggers the HIPAA breach notification process. Not every incident is a breach, but every incident should be documented.
- Establish documentation procedures. Every incident, even minor ones that don't result in a reportable breach, should be recorded with what happened, when, what was affected, and what you did about it.
- Test the plan at least once a year. A tabletop exercise, where you walk through a hypothetical scenario as a team, is a practical way to do this without disrupting patient care.
The worst time to figure out your response plan is during an actual incident. When you're dealing with a cyberattack or data breach, you need to be executing a plan, not creating one from scratch.
Secure Your Physical Environment
HIPAA covers more than digital security. It also applies to the physical spaces where patient data can be accessed. This is easy to overlook in a dental office because the focus is on clinical operations, but it matters to auditors and it matters for patient privacy.
Your physical security checklist
- Keep your server in a locked room or closet, not sitting under someone's desk or in an unlocked supply room.
- Position computer screens so patients in the waiting area can't see them. Use privacy screen filters on monitors that face public areas.
- Lock workstations when staff step away. Windows key + L takes one second. Make it a habit across the whole team.
- Secure paper records in locked cabinets when not in active use.
- Shred paper documents containing patient information. Don't toss them in the recycling.
- Control access to areas where records are stored: badge access, locked doors, or at minimum sign-in requirements for non-staff.
Back Up Your Data the Right Way
Backups are not optional under HIPAA. You're required to have a plan for creating and maintaining retrievable exact copies of ePHI. That means if your server crashes, your building floods, or ransomware encrypts everything, you need to be able to get your patient data back quickly.
Your backup checklist
- Back up all systems containing ePHI daily at minimum. Many practices benefit from more frequent backups, even hourly for critical systems.
- Store backups in a separate location from your primary data. Ideally offsite or in a secure cloud environment. A backup sitting on the same server as your data doesn't help if that server gets encrypted by ransomware.
- Encrypt your backups both in transit and at rest.
- Test your backups regularly by actually restoring data. Don't just assume they're working. Verify it at least quarterly.
- Document your backup procedures and retention schedule.
- Make sure your backup provider has signed a BAA.
Keep Software and Systems Up to Date
Outdated software is one of the easiest ways for attackers to get into your systems. When software vendors release updates, those updates often include fixes for known security vulnerabilities. Skip the updates, and those vulnerabilities stay open for anyone who wants to exploit them.
Your patching checklist
- Enable automatic updates for Windows and macOS on all workstations.
- Keep your practice management software on the latest supported version. If your vendor has moved on from the version you're running, you may not be getting security patches anymore.
- Update digital imaging software and any connected devices (X-ray sensors, intraoral cameras) on the vendor's recommended schedule.
- Replace any systems running end-of-life operating systems. If Microsoft or Apple has stopped releasing security updates for your OS, it's time to upgrade.
- Keep your firewall firmware and antivirus definitions current.
- Assign someone responsibility for checking and applying updates on a regular schedule. If nobody owns it, it doesn't get done.
Putting It All Together
If you're looking at this checklist thinking "we're not doing half of this," you're not alone. Most dental practices we work with have some pieces in place but significant gaps in others. That's normal, and it's fixable. The important thing is to start closing those gaps now, before an incident or an audit forces you to.
Here's the good news: you don't have to tackle all of this yourself. A good dental IT services partner can handle most of what's on this list for you: the risk assessment, access controls, encryption, patching, backups, monitoring, and incident response planning. That frees you up to focus on what you actually went to school for: taking care of patients.
HIPAA compliance isn't a one-time project. It takes regular attention and updates as your practice grows and technology changes. But with the right systems and the right partner, it doesn't have to eat up your nights and weekends.
If you want someone to look at your current setup and tell you honestly where the gaps are, we're happy to help. We've been working with dental practices and small businesses across Georgia since 2019, and we specialize in making compliance straightforward. Give us a call at (404) 990-4540 or schedule a discovery call. We'll give you a clear, plain-language picture of where you stand and what needs to happen next.