HIPAA · Solo practices

HIPAA Compliance Checklist for Solo Dental Practices: 7 Things You’re Probably Missing

Running a one-doctor dental office is hard enough — your compliance program shouldn’t add anxiety on top of it. Most HIPAA gaps at solo practices are tiny, fixable habits, not legal disasters. Here are the seven we see most often, and the quiet routine that keeps them from mattering.

2026-08-253 min read

1. A short, written list of who can see what

HIPAA doesn’t need a 60-page manual. It needs one page that names the people in your office, the systems they touch, and the minimum PHI each role actually needs to do the job. Write it once, review it once a year, and you’ve met the “workforce access” requirement without buying a binder.

2. A real password for the front-desk tablet

If the tablet in the lobby is still logged in from last Tuesday, a single patient peeking at the screen is technically a breach. Lock screens on every device that touches the schedule, set a 2-minute idle auto-lock, and move on. It’s a five-minute fix that makes an audit reviewer smile.

3. A signed Business Associate Agreement for every vendor

Your PMS company, your billing service, your claims clearinghouse, your IT contractor — each one that touches patient data needs a signed BAA on file. Pull up the vendor list, check the contracts, and email the two or three that aren’t covered yet. Most vendors will send a standard BAA within a day; it’s the easiest checkbox on the list.

4. A yearly security “walk-through” — 20 minutes, alone

Walk through the office once a year with your HIPAA hat on. Is the paper schedule in a drawer or on the counter? Is the backup laptop encrypted? Is the printer tray full of printed charts? Note three or four changes to make, do them, and you’re done. Solo practices don’t need a formal risk assessment — they need a curious walk-through once a year.

5. Staff training that takes an hour, not a course

Annual training has to be documented, but it doesn’t have to be a six-hour video. A one-hour, in-person walk-through of your one-page access list, your breach response plan, and what to do with a sticky note covers the required content. Track the date and signature in a single spreadsheet and the audit requirement is met.

6. A one-page “what to do if” card in the breakroom

You don’t need a breach response binder. You need one page taped next to the time clock that says: who to call, what to write down, and how to stop the leak. If something happens at 9 AM on a Tuesday, your team needs to spend zero minutes figuring out the playbook — they just read the card.

7. A read-and-sign attestation, kept on file

A simple log — date, name, signature — for every team member acknowledging your policies each year. One page, one signature, one file. If OCR ever asks, you answer with a folder, not an explanation.

Why bother?

OCR enforcement actions on small and solo practices have climbed steadily, and a single incident can run into six figures even without a true breach. None of the seven steps above is expensive — but doing all of them in a panic, after a phone call, is the pattern enforcement actions look for.

A shortcut that beats starting from scratch

Drafting policies, training scripts, and breach response cards doesn’t need to happen the hard way. Shieldnote’s intake generates a tailored, audit-ready HIPAA policy set — written to your specialty, your office size, and your EHR — in under ten minutes. You start from a working draft instead of a blank page; that’s why a few solo practices use it for the policy layer even when they don’t need the broader platform.