HIPAA · Solo practices

HIPAA Compliance Checklist for Solo Medical Practices: 7 Things You’re Probably Missing

Running a solo medical practice means the physician, front desk, biller, medical assistant, and contractors may all touch patient information. A repeatable set of everyday habits can make HIPAA work manageable. This educational checklist is a practical starting point, not legal advice or a guarantee of compliance.

2026-10-054 min read

1. A clear list of who can access which patient records

Start with the people who actually keep the practice moving: you, the front-desk worker, the medical assistant, the part-time biller, and any contractor. Write down which systems and records each role needs, then give each person the minimum access required for that work. Review the list when someone joins, changes responsibilities, or leaves, and remove access promptly instead of letting old accounts linger.

2. Lock down the EHR, telehealth, and mobile devices

Use a unique account for every person who signs into the EHR, telehealth platform, scheduling system, or patient portal. Turn on multi-factor authentication where the service offers it, lock screens when a device is unattended, and use encryption and remote-access controls supported by the platform. Do not share a physician login with a medical assistant or leave a tablet, laptop, or phone signed in where a patient or visitor can see it.

3. Put a Business Associate Agreement on every vendor that handles PHI

Make a vendor list and check which companies receive or can access protected health information. Depending on how your practice works, that may include the EHR, billing service, claims clearinghouse, telehealth provider, cloud fax service, transcription vendor, storage provider, or IT contractor. Keep the signed Business Associate Agreement with the vendor record and confirm that the service is willing and authorized to handle PHI before sending patient information through it.

4. Document a risk analysis that follows the real practice

A useful risk analysis follows information through the places your practice actually uses it: the exam room, reception desk, home office, paper chart, email or patient portal, telehealth visit, backup, and downtime workflow. For each risk, note the safeguard you use, who owns it, and what still needs attention. Revisit the document when you add a system, change a workflow, move work off-site, or discover that a safeguard is not working. The right level of detail depends on the practice; this checklist is not a substitute for qualified compliance advice.

5. Train every person who touches patient information

Training should cover more than a policy signature. Walk new employees and contractors through the EHR access rules, secure messaging and fax habits, telehealth setup, screen privacy, disposal of paper, and the first steps after a mistake. Repeat the training when workflows change and on the schedule your policies require. Keep the date, attendees, topics, and policy acknowledgements together so you can show what happened instead of trying to reconstruct it later.

6. Make the breach-response plan usable on a Tuesday morning

Write down what to do if a phone is lost, a message or fax goes to the wrong person, an account is compromised, or ransomware disrupts the practice. Name the first person to contact, the steps to contain the problem, what evidence to preserve, and where to record the timeline. The plan should also say when to involve your technology or legal advisers and who will review notification obligations. Practice the first few steps so the team can respond calmly before anyone knows the full scope.

7. Make patient-rights and release workflows repeatable

Patient requests should not depend on who happens to answer the phone. Create a consistent process for records requests, authorizations, amendments, disclosures, and questions about how information was shared. Decide where requests are logged, who verifies identity, what deadlines and applicable rules must be checked, and how the final response is documented. If a request is unusual or disputed, route it to qualified counsel or a compliance professional rather than improvising.

The goal is a repeatable system, not a compliance binder

The strongest starting point is a small set of habits that match the way your practice works: clear access, protected devices, documented vendors, a living risk analysis, practical training, a usable response plan, and consistent patient-rights workflows. HIPAA requirements can depend on your facts and the rules that apply to your organization, so use this article for orientation and get advice from qualified counsel or a compliance professional when you need a definitive answer.

Start with the workflow you actually run

You do not need to solve every policy question in one sitting. Start with the workflow that feels most fragile today, write down the people and systems involved, and turn the next fix into a documented practice. Shieldnote can help you start a tailored draft for your specialty and EHR, so you have something concrete to review with your own advisers instead of a blank page.