Simplify. Strategize. Secure.

Resource · dental practices

Review security readiness without losing sight of the patient day.

Use this checklist to connect HIPAA Security Rule safeguards to the people, workstations, imaging, practice-management systems, vendors, and recovery decisions a dental practice depends on.

01Administrative safeguards

Put responsibility, risk, and response in writing.

The checklist is a review aid, not a compliance determination. Record the evidence inspected, the person accountable, and the corrective action for each gap.

  • 01

    Risk analysis and risk managementIdentify where electronic protected health information is created, received, maintained, or transmitted; assess risks and vulnerabilities; prioritize reasonable and appropriate safeguards.

  • 02

    Assigned security responsibilityName the official responsible for developing and implementing required security policies and procedures, with clear coordination across leadership, IT, privacy, and vendors.

  • 03

    Workforce access lifecycleAuthorize access by role, change it when duties change, remove it promptly at separation, and review access to patient information and privileged systems.

  • 04

    Training and incident responseTrain the workforce on practice policies, phishing and safe reporting; document how suspected security incidents are identified, escalated, mitigated, and recorded.

  • 05

    Contingency planningMaintain plans for data backup, restoration, emergency-mode operations, criticality, testing, revision, communications, and the dependencies needed to keep essential care processes moving.

02Physical and technical safeguards

Follow patient data across rooms, devices, and vendors.

Inspect the actual workflow: front desk, operatories, imaging, consultation areas, server or network spaces, remote work, portable media, and service-provider access.

  • Are facility and workstation access appropriate for each location and role?

    Review public sight lines, unattended screens, device placement, restricted areas, visitors, after-hours access, disposal, and the physical handling of equipment that stores or accesses ePHI.

  • Does each person use a unique identity with appropriate access?

    Confirm named accounts, role-based authorization, authentication, administrator separation, session controls, and removal of dormant or former-worker access.

  • Can the practice examine system activity relevant to ePHI?

    Identify available audit controls in practice-management, imaging, Microsoft 365, endpoint, network, and vendor systems; assign review and escalation.

  • How is ePHI protected in transit, at rest, and during disposal?

    Document reasonable and appropriate protections for endpoints, servers, backups, email, portals, remote access, portable devices, media, and equipment leaving service.

  • Which vendors can reach systems or data, and under whose authority?

    Inventory remote-support paths, agreements, accounts, approval methods, logs, offboarding, and whether a business associate agreement is required and executed by the appropriate parties.

  • Can the practice continue and recover when a critical system is unavailable?

    Test downtime procedures and recovery for scheduling, charts, imaging, communication, payment, prescriptions, network, identity, and vendor dependencies according to the practice’s plan.

03Readiness boundary

Know what an IT review can and cannot establish.

HIPAA readiness is ongoing organizational work. No checklist or technology purchase certifies the practice.

Technology evidence

Inventories, configurations, access records, logs, patch status, recovery tests, vendor access, security findings, and documented technical corrective work.

Organizational evidence

Risk decisions, assigned responsibility, policies and procedures, training, sanctions, incident records, agreements, evaluations, and leadership approval.

Professional boundaries

ICT Solutions supports technical safeguards and readiness work. Legal interpretation, compliance determinations, and clinical-policy decisions remain with the practice and its qualified advisers.

04Primary guidance

Anchor the review to the current Security Rule.

HHS describes administrative, physical, and technical safeguards and requires regulated entities to assess risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI. HHS also identifies contingency planning, workforce training, access management, incident procedures, and ongoing evaluation within the rule.

Read the HHS Security Rule summary

Keep the review usable

Record status, evidence, risk, corrective action, owner, due date, dependency, approval, and validation for each gap. Protect the resulting document because it may contain sensitive security detail.

Reassess after material operational, system, location, vendor, ownership, or threat changes and on the practice’s documented review cadence.

05Prioritize the gaps

Turn the checklist into documented corrective work.

ICT Solutions can assess the technical environment, help prioritize safeguards, coordinate vendors, support remediation, and improve HIPAA Security Readiness. Scope and responsibilities stay defined in writing.

Or call (734) 772-9499 · A human answers