Skip to content
All guides

Healthcare & compliance

HIPAA technical safeguards: a practical checklist for small practices

The five HIPAA Security Rule technical safeguards explained in plain language, with the practical steps a small medical or dental office takes for each.

By AttiaTechnology · Updated · 7 min read

Where the technical safeguards fit

The HIPAA Security Rule protects electronic protected health information (ePHI) with three kinds of safeguards: administrative, physical, and technical. This guide covers the technical ones, the part IT is directly responsible for.

Some specifications are required. Others are addressable, which means you must implement them if they're reasonable and appropriate for your practice, or document why you chose an equivalent alternative. In practice, for a small office, most addressable items should simply be done.

HHS proposed changes to the Security Rule in January 2025 that would make more of these safeguards, including encryption and multi-factor authentication, explicitly required. Check the current status of that rule with your compliance advisor.

1. Access control

Only the right people should be able to reach ePHI.

  • Give every person their own login. No shared front-desk accounts. (Required)
  • Have a documented way to get into systems in an emergency. (Required)
  • Lock screens automatically after a few minutes of inactivity. (Addressable)
  • Encrypt laptops and workstations that store or access ePHI. (Addressable)
  • Remove access the same day someone leaves.

2. Audit controls

You need a way to record and review activity in systems that contain ePHI. (Required)

  • Turn on sign-in and activity logging in your EHR, email, and file storage
  • Keep logs long enough to investigate an incident
  • Have someone actually review alerts, such as sign-ins from unusual locations

3. Integrity

Protect ePHI from being altered or destroyed improperly.

  • Limit who can edit or delete records
  • Keep backups that can't be changed by ransomware, and test restoring them
  • Use endpoint protection that detects tampering and malicious software

4. Person or entity authentication

Confirm that people are who they say they are before they get access. (Required)

  • Turn on multi-factor authentication for email, the EHR, remote access, and any cloud portal with patient data
  • Ban shared and reused passwords; use a business password manager

5. Transmission security

Protect ePHI while it moves over a network.

  • Use encrypted email or a secure portal to send patient information
  • Require encrypted connections (VPN or secure remote access) for working from home
  • Separate guest Wi-Fi from the network your workstations use

What technology can't do for you

HIPAA compliance also requires a documented risk analysis, written policies, workforce training, business associate agreements, and breach procedures. An IT provider can implement and document the technical safeguards and give you evidence for your program. No vendor can make a practice “HIPAA compliant” on its own, and you should be wary of any that claims to.

Tell us what's getting in the way.

Pick a time on our calendar, call, or send a short note. We typically reply within one business day, and a first conversation doesn't commit you to anything.