Free Resource

Small Clinic HIPAA Starter Checklist

28 action items across 5 phases. Built for small clinics starting HIPAA compliance from scratch: no risk assessment, no written policies, no compliance program yet. Print it, check items off, build your evidence binder.

Your Compliance Starting Point

If your small clinic has never completed a HIPAA Security Risk Assessment or does not have written policies and procedures, this checklist gives you the exact sequence of tasks to complete. Each item includes the documentation you need to produce as evidence of compliance.

Why this order matters: The Security Risk Assessment comes first because your policies should be informed by the risks you identify, not the other way around. Each phase builds on the one before it. Skipping ahead creates gaps that are commonly cited as compliance findings.

This checklist covers the minimum required actions. It does not replace a comprehensive compliance program, but it closes the two highest-impact gaps identified in OCR enforcement actions: (1) no documented risk assessment and (2) no written policies.

Small Clinic HIPAA Starter Checklist

1

Security Risk Assessment (SRA)

  • Inventory all systems, devices, and workflows that store, transmit, or access ePHI Document
  • Identify threats and vulnerabilities to each system (unauthorized access, malware, theft, natural disaster, human error) Document
  • Rate likelihood and impact of each identified threat (High / Medium / Low) Document
  • Create prioritized risk mitigation plan with assigned owners and target dates Document
  • Compile written SRA report with date completed and assessor signature Retain 6 years

Required by 45 CFR 164.308(a)(1)(ii)(A). Most commonly cited deficiency in OCR enforcement actions.

2

Policy Development

  • Write Access Control and Authorization policy — who can access what ePHI and under what circumstances
  • Write Security Management Process policy — how your practice prevents, detects, contains, and corrects security violations
  • Write Workforce Training policy — when and how staff are trained, topics covered, attestation requirements
  • Write Device and Media Controls policy — disposal, re-use, and movement of devices containing ePHI
  • Write Incident Response and Breach Notification policy — detection, reporting, investigation, and HHS notification timelines
  • Write Facility Access Controls policy — physical safeguards for areas where ePHI is accessible
  • Write Contingency and Disaster Recovery policy — data backup, emergency operations, and recovery procedures
  • Write Sanctions policy — consequences for workforce members who violate HIPAA policies
  • Write Business Associate Agreement policy — when BAAs are required and how they are executed and tracked
  • Write Notice of Privacy Practices — patient-facing document describing PHI uses and individual rights
  • Formally adopt all policies with dated leadership signature Retain 6 years

Required by 45 CFR 164.316(a). Policies must reflect your actual operations — generic templates do not satisfy the requirement without customization.

3

Assign Ownership

  • Designate a Privacy Officer responsible for Privacy Rule compliance Document
  • Designate a Security Officer responsible for Security Rule compliance (may be same person in small practices) Document
  • Document both designations with effective date and signed acknowledgment Retain 6 years

Privacy Officer required by 45 CFR 164.530(a)(1). Security Officer required by 45 CFR 164.308(a)(2).

4

Staff Training

  • Deliver initial HIPAA training to all workforce members before they access PHI
  • Cover: Privacy Rule, Security Rule, breach reporting, phishing awareness, and your practice-specific procedures
  • Collect signed training attestation from each workforce member Retain 6 years
  • Schedule annual refresher training and set calendar reminder Document
  • Record training dates, topics covered, and attendee names in training log Retain 6 years

Required by 45 CFR 164.308(a)(5)(i). OCR does not accept verbal-only training — signed attestations are the minimum standard.

5

Documentation and Retention

  • Assemble compliance binder (physical or digital): SRA report, adopted policies, training records, BAA inventory, incident log Retain 6 years
  • Set 6-year retention schedule and document destruction procedures for expired records
  • Inventory all Business Associate Agreements — confirm each is signed, dated, and on file Retain 6 years
  • Create incident log template for tracking potential breaches, investigations, and outcomes Retain 6 years

Retention required by 45 CFR 164.530(j). Six years from date of creation or date last in effect, whichever is later.

Maintaining Compliance

Completing this checklist gives your clinic a defensible compliance baseline. It does not make you "done" — HIPAA compliance is an ongoing obligation. After completing all 28 items, your next priorities are:

  • Review and update your SRA annually (or when significant changes occur)
  • Review and update policies annually
  • Deliver annual refresher training to all workforce members
  • Monitor for security incidents and document your response
  • Update your BAA inventory when vendors change

Read the full step-by-step HIPAA starting guide | Next: the HIPAA audit readiness checklist

Need Help Working Through This Checklist?

One Guy Consulting walks small practices through every item on this checklist — including writing the SRA, drafting customized policies, and setting up documented training. No software to figure out on your own.

Book Your Free 30 Minute HIPAA Compliance Review