Checklist · 8 pages
HIPAA IT Checklist for Michigan Dental Practices
Thirty-six plain-English questions that map to the HIPAA Security Rule, so you can find your gaps before an auditor, an insurer, or an attacker does.
If your practice creates, stores, or transmits protected health information, you are a covered entity under HIPAA. That is true whether you are a single-doctor general practice, a two-chair pediatric dental office, or an oral surgery group with multiple locations. The Security Rule does not scale its requirements down for small practices. It scales the implementation down, which is a different thing entirely, and it is the part most dental practices get wrong.
This checklist walks the three categories of safeguards the Security Rule actually names, plus the everyday email and vendor traps that cause most of the real-world breaches we see in dental offices. Every question is written so a practice owner or office manager can answer it without an IT background. Where a question maps to a specific regulation, the citation is there so your attorney or compliance consultant can follow along.
Answer honestly. Not sure is a legitimate answer and it is more useful than a hopeful yes. In an audit or a breach investigation, "we thought our IT company was handling it" carries no weight at all.
Administrative safeguards
The paperwork half of HIPAA, and the half practices skip. These are also the items the Office for Civil Rights asks about first, because they are documented or they are not. There is no partial credit.
- Has a formal HIPAA Security Risk Analysis been completed for this practice? Not a vendor checklist and not this document. A written analysis of where PHI lives, in your practice management system, your imaging software, and your backups, what threatens it, and how likely each threat is. This is the single most cited HIPAA violation in OCR enforcement actions, and it is explicitly required.
- Was it completed or updated within the last 12 months, or after your last major system change? A risk analysis from four years ago that predates your move to cloud-based practice management or digital X-ray software does not describe your practice. Refresh it annually and after any significant change.
- Is there a written risk management plan showing what you did about the risks you found? Finding a risk and doing nothing is worse than not looking, because now it is documented that you knew. The plan is what shows due diligence.
- Has a named individual been assigned as your HIPAA Security Officer? Required by 164.308(a)(2). It can be the owner-dentist or the office manager. It cannot be nobody, and it cannot be a vague "our IT company."
- Is there a written, dated list of who has access to systems containing PHI, and at what level? If a hygienist or front-desk employee left eight months ago, can you prove their access was removed? Access authorization and review are separate requirements under 164.308(a)(3) and (a)(4).
- Is access reviewed on a schedule, and removed the same day someone leaves? Orphaned accounts are how a disgruntled former employee or a bought credential gets back in. Same-day removal, including email, practice management software, VPN, and any shared logins.
- Does every staff member, dentists, hygienists, dental assistants, and front desk, receive security awareness training at least annually, with records kept? Required by 164.308(a)(5). Staff are the entry point in the overwhelming majority of incidents. "We talked about it in a huddle" is not a training record.
- Is there a written incident response procedure that says who to call and what to do first? At 7:00am on the morning your operatory computers are encrypted, nobody improvises well. The procedure should name your IT contact, your cyber insurance carrier, and your attorney, with phone numbers that are not stored only on the network.
- Is there a written contingency plan covering data backup, disaster recovery, and emergency operations? 164.308(a)(7) requires all three. Emergency mode operation means: how do you keep seeing patients, checking charts, and confirming allergies and medical histories, while the systems are down?
- Do you have signed Business Associate Agreements with every vendor that touches PHI, including your IT provider? Sharing PHI without a BAA is itself a violation. That includes your IT company, your dental billing service, your cloud storage, your email platform, your backup vendor, and your shredding company. If your IT provider has not offered you a BAA, that tells you something.
- Is there a written sanctions policy describing what happens when a staff member violates the rules? Required by 164.308(a)(1)(ii)(C). It is short, it goes in the handbook, and its absence is an easy finding.
Physical safeguards
The least glamorous section and the one that produces the most avoidable losses. A laptop in a car is still the most common way patient data walks out of a practice.
- Is your network equipment in a locked room or cabinet rather than sitting on a shelf or under a desk? Servers, firewalls and network switches in an unsecured back room can be unplugged, tampered with, or carried off. Facility access controls under 164.310(a)(1) start here.
- Do workstations, including operatory computers, lock automatically after a short period of inactivity? A front-desk machine or an operatory computer left open to a patient chart while staff step away is an impermissible disclosure waiting for a walk-by. Ten to fifteen minutes is typical; front-desk and operatory machines should be tighter.
- Are screens positioned so patients and visitors cannot read them from the waiting area, reception counter, or an adjacent chair? Privacy filters cost about thirty dollars and solve most of this. It is a Privacy Rule issue as much as a Security Rule one, and it matters at the reception counter as much as in the operatory.
- Is full-disk encryption turned on for every laptop, desktop, and tablet that touches PHI? This is the highest-value item on the page. Under the Breach Notification Rule, properly encrypted data that is lost or stolen is generally not a reportable breach. Unencrypted, the same lost laptop can mean notifying every affected patient and HHS.
- Is there a documented process for wiping and disposing of old computers, drives, phones, and digital imaging sensors or workstations? Office copiers and multifunction printers store scanned documents on internal drives, and retired digital X-ray workstations can retain cached images. Device and media controls under 164.310(d)(1) cover all of it, and "the guy took it away" is not a disposal record.
Technical safeguards
What the software and the network actually do. This is the section an IT provider should own outright. If you are answering these yourself, that is worth noticing.
- Does every single user have their own named login, with no shared or generic accounts? Shared logins such as frontdesk or hygiene destroy accountability. If four people use one account, your audit log cannot tell you who opened a chart, and unique user identification is a required, not addressable, specification.
- Is multi-factor authentication enforced on email for every user, including the owner-dentist? One stolen password should not equal full access to patient communications. Owner- dentists are the most targeted accounts and the most likely to have been granted an exception. Exceptions are where breaches begin.
- Is MFA also enforced on remote access, your dental practice management software, and any cloud system holding PHI? Email is the usual starting point, not the finish line. Remote desktop and VPN access into systems like Dentrix, Eaglesoft, or Open Dental without MFA are actively scanned for by ransomware operators.
- Is logging turned on for access to systems containing PHI, and does anyone actually look at it? Audit controls under 164.312(b) are required. After an incident, logs are how you establish what was and was not accessed, which directly determines how much you have to report. Without them you may have to assume the worst.
- Does every computer, including operatory and imaging workstations, have managed antivirus or endpoint detection that someone monitors? Built-in antivirus with nobody watching the alerts is not monitoring. The value is in someone seeing the alert at 2:00am, not in the software existing.
- Are operating systems and applications patched on a defined schedule, with someone confirming it happened? Most successful attacks use a vulnerability with a patch already available. "Automatic updates are on" and "every machine is current" are not the same claim.
- Is every device running an operating system that still receives security updates? Windows 10 reached end of support in October 2025. An unsupported OS on the same network as your practice management system or digital X-ray software is an unfixable hole and a straightforward audit finding.
- Is PHI encrypted in transit whenever it leaves your network? Transmission security under 164.312(e)(1). Covers email to patients and referring specialists, digital X-ray and imaging files sent to labs or oral surgeons, and remote access sessions.
Email, files, and vendors
Not a formal Security Rule category, but this is where the real-world violations happen in small practices. Every item here is something we have walked into.
- Is all practice email on a business platform with a signed BAA, with no personal Gmail, Yahoo, or Hotmail accounts in use? A personal email account cannot be covered by a BAA. Sending or receiving PHI, including X-rays or referral letters, through one is a direct violation, and it is startlingly common, usually because it started before the practice grew.
- Are patient files and images stored only in practice-controlled systems, never in personal cloud storage? Personal Google Drive, personal Dropbox, and personal OneDrive accounts. If the practice cannot revoke access when someone leaves, the practice does not control the data, and that includes digital X-rays and intraoral photos.
- Does everyone use a business password manager instead of reusing passwords or keeping a list? The sticky note taped by the operatory computer is a cliche because it is real. Reused passwords are worse: one breach at an unrelated website hands an attacker a working credential for yours.
- Do you have a verbal callback procedure before changing any bank details or sending a wire? Business email compromise costs practices more money than ransomware does. The control is a phone call to a number you already had on file, never a number from the email itself.
- Have you confirmed which of your vendors can actually see PHI, rather than assuming? Answering services, dental labs, insurance clearinghouses, marketing agencies with inbox access, IT contractors, and shredding services all commonly touch PHI. Each needs a BAA.
- If a staff member uses a personal phone for practice email or messaging, is that device managed and can it be wiped remotely? Personal devices are permitted. Unmanaged personal devices holding PHI with no way to remove it when a hygienist or assistant quits are not a defensible position.
Backup, recovery, and breach readiness
Two questions decide how bad a ransomware event gets: can you restore, and can you prove what was accessed. Everything else is detail.
- Is every system holding PHI backed up automatically, including your practice management system, imaging software, and Microsoft 365? Microsoft and Google are explicit that they are not your backup. Their retention windows are short and are designed for accidental deletion, not for ransomware or a malicious insider, and neither backs up your dental practice management or imaging data.
- Is at least one backup copy stored offsite and kept immutable or offline? Modern ransomware hunts for and encrypts backups first. A backup drive plugged into the server is encrypted along with the server, taking your chart data and your digital X-ray library with it. Immutable means it cannot be altered or deleted, even with stolen administrator credentials.
- Has an actual restore been tested in the last 90 days, with someone confirming the patient chart and X-ray data opened correctly? A backup that has never been restored is a hypothesis. Practices discover failed backups at the exact moment they need them, which is the worst possible time.
- Do you know your recovery time objective, meaning how many hours of downtime the practice can absorb before it becomes a crisis? Put a number on it. If the answer is four hours and your current setup needs three days of rescheduled hygiene and treatment appointments, that gap is a business decision, not a technical one.
- Do you know who you would notify, in what order, and within what deadline, if PHI were exposed? The Breach Notification Rule sets deadlines for notifying individuals, HHS, and in larger breaches the media. Your state's own data breach notification law applies on top of HIPAA. Find this out now, not during the incident.
- Do you carry cyber liability insurance, and have you read what the policy requires you to already have in place? Policies increasingly require MFA, EDR, and tested backups as conditions of coverage. Answering the application inaccurately can give the carrier grounds to deny the claim you bought the policy for.
What we usually find
Across the dental practice assessments we run, the same handful of gaps come up again and again. None of them are exotic. All of them are fixable in weeks, not years.
The five most common critical gaps 1. No risk analysis has ever been done. The practice has good intentions and reasonable technology, but the one document HIPAA explicitly requires does not exist. This is also the fastest gap to close. 2. Nothing is backed up, or the backup was never tested. Often there is a backup of the practice management server and nothing covering the digital X-ray system or Microsoft 365, or a backup that quietly stopped running months ago because nobody was checking. 3. Multi-factor authentication is off, or on for staff but not for the owner-dentist. The exception is almost always the account with the most access. 4. PHI is moving through a personal email account. Usually a holdover from before the practice grew, and usually nobody has thought about it in years. 5. No Business Associate Agreements are on file, including with the IT provider. Practices are frequently surprised to learn their own IT company, and their dental lab, need one too.
Notice what is not on that list: expensive hardware, exotic attacks, or anything that requires a large budget. The gaps that create the most legal and financial exposure in a small dental practice are almost always configuration, documentation, and habit.
A reasonable order of operations 1. Stop the bleeding first. Turn on MFA everywhere. Get PHI off any personal email or personal cloud storage. Stand up real, tested, offsite backups covering both your practice management system and your imaging software. Sign BAAs with every vendor that touches PHI. These are days of work, not months. 2. Then get the documentation right. Complete a written risk analysis and risk management plan. Name a Security Officer. Write the incident response procedure and the sanctions policy. Start keeping dated training records. 3. Then harden the environment. Full-disk encryption on every device, managed endpoint protection, a real patching schedule, audit logging turned on and actually reviewed, and replacement of anything running an unsupported operating system. 4. Then keep it true. Annual risk analysis refresh, annual training, quarterly access reviews, and restore tests you can point to on a calendar. Compliance is a state you maintain, not a project you finish.
One thing worth being clear about No IT provider can make a dental practice HIPAA compliant, and any provider who tells you otherwise is selling something. A large part of HIPAA is administrative: policies, notices, training, patient rights, and workforce sanctions. Those belong to the practice. What a good IT provider does is own the technical and physical safeguards completely, produce the evidence that they work, and tell you plainly which items are still yours.
Score your practice
Count every question you answered No or Not sure. Treat those the same way. An unverified control is an uncontrolled risk, and it will be treated that way in an investigation.
- to 4 Solid footing You are ahead of most dental practices your size. Focus on documentation and on proving your controls work: tested restores, reviewed access lists, dated training records. Have your risk analysis refreshed annually.
- to 12 Real exposure This is where most practices land. You likely have decent technology and thin documentation, or the reverse. Nothing here is expensive to fix, but leaving it unfixed is what turns a routine incident into a reportable breach.
- or Address this now Gaps at this level usually mean core protections such as backups, multi- more factor authentication, or a compliant email platform are missing outright. A single ransomware event or one stolen password could end in permanent loss of patient records and mandatory notification to patients and to HHS.
Want the printable version?
Get the full checklist as a free PDF
Everything on this page, formatted to print or save, delivered straight to your inbox. No sales call required.
Download the free PDF