HIPAA Compliance Checklist for Memphis Dental Practices
A practical HIPAA compliance checklist for dental practices in Memphis. Learn the key requirements, common violations, and how to protect patient data.
Running a dental practice in Memphis means juggling patient care, staff management, and a growing list of compliance requirements. HIPAA often falls to the bottom of the priority list—until something goes wrong.
The Office for Civil Rights (OCR) has increased enforcement actions against dental practices in recent years. Fines range from $100 to $50,000 per violation, with annual maximums reaching $1.5 million. For a practice already operating on tight margins, even a small penalty can be devastating.
This checklist covers the HIPAA compliance requirements that matter most for Memphis dental practices, based on what we see working with practices across Germantown, Collierville, Bartlett, and the greater Memphis area. If you also own an adjacent aesthetics business, the same covered-entity rules can apply there too—our medical spa HIPAA compliance IT checklist walks through exactly when a med spa falls under HIPAA and what to do about it.
The Security Risk Assessment: Your Foundation
Every HIPAA compliance program starts with a Security Risk Assessment (SRA). This isn’t optional—it’s required by the HIPAA Security Rule, and it’s the first thing auditors look for.
Your SRA should document:
- All systems that store or transmit PHI — This includes your practice management software (Dentrix, Eaglesoft, Open Dental), digital imaging systems, email, and even that old computer in the back office nobody uses anymore
- Potential threats to each system — Ransomware, employee errors, physical theft, natural disasters
- Current safeguards in place — Firewalls, antivirus, encryption, access controls
- Risk levels and remediation plans — What needs fixing, in priority order
Many practices we work with haven’t updated their SRA in years. If yours is more than 12 months old, it’s time for a refresh—especially with the 2026 HIPAA Security Rule changes eliminating addressable safeguards and making dozens of controls mandatory.
Pro Tip
Access Controls: Who Can See What
Who in your practice can open a patient’s chart—and could you prove it if an auditor asked? Not everyone needs that access. HIPAA requires you to limit it based on job roles, not convenience.
Checklist items:
- Each staff member has a unique login (no shared passwords)
- Access permissions match job responsibilities
- Former employees are removed from all systems within 24 hours of departure
- Login attempts are logged and reviewed
- Automatic session timeouts are enabled (15 minutes or less)
Most Common Violation
Encryption: Protecting Data at Rest and in Transit
Encryption converts patient data into unreadable code without the proper key. If an encrypted laptop is stolen, the data is useless to the thief—and you may avoid breach notification requirements entirely.
Checklist items:
- Full-disk encryption on all computers and laptops
- Encrypted email for sending patient information
- Encrypted backups (both local and cloud)
- Secure (HTTPS) connections for web-based applications
- Encrypted connections for remote access
Windows BitLocker and macOS FileVault provide free full-disk encryption. There’s no excuse for leaving workstations unencrypted in 2026.
Get the Complete 54-Point Checklist
This article covers the highlights. Download our full Dental Practice IT Security Checklist with scoring guide and prioritization framework.
- 54-point self-assessment checklist
- Covers HIPAA, security, backups, and more
- Score interpretation guide included
- Immediate PDF download via email
Backup and Disaster Recovery
94%
increase in ransomware attacks against healthcare organizations in 2024
Dental practices are frequent targets because attackers know you’ll pay to get patient records back. A proper backup strategy is your insurance policy.
Checklist items:
- Daily automated backups of all patient data
- Backups stored offsite or in a HIPAA-compliant cloud
- Regular backup restoration tests (at least quarterly)
- Documented disaster recovery plan
- Recovery time objective (RTO) defined and achievable
The 3-2-1 Rule
Staff Training: Your First Line of Defense
90% of data breaches start with human error — usually a phishing email that tricks someone into clicking a malicious link or revealing credentials.
90% of data breaches start with human error—usually a phishing email that tricks someone into clicking a malicious link or revealing login credentials.
Checklist items:
- Annual HIPAA training for all staff members
- Documented training records (keep for 6 years)
- Phishing awareness training
- Clear procedures for reporting suspected breaches
- Training updates when policies change
Training doesn’t have to be complicated. A 30-minute annual session covering the basics—what PHI is, how to spot phishing emails, and what to do if something seems wrong—makes a measurable difference.
Our cybersecurity services include the threat monitoring and incident response that dental practices need to stay protected.
Business Associate Agreements
If your billing company or imaging vendor mishandled a patient record tomorrow, would your paperwork hold up? Anyone who handles PHI on your behalf needs a Business Associate Agreement (BAA)—your IT provider, cloud software vendors, billing companies, and answering services.
Checklist items:
- BAAs in place with all vendors who access PHI
- BAAs reviewed and updated annually
- Vendor security practices verified
- Subcontractor agreements documented
No BAA means you’re both liable if something goes wrong. Make sure your agreements are current — older BAAs may not cover risks that have emerged in the last few years.
No BAA means you’re both liable if something goes wrong. Make sure your agreements are current—HIPAA requirements have evolved, and older BAAs may not cover current risks. Cyber insurance carriers now require many of the same controls as HIPAA—MFA, endpoint protection, and documented incident response plans. If you’re approaching a policy renewal, review our cyber insurance requirements checklist to see what carriers will verify.
Physical Security
Digital security gets most of the attention, but physical security matters too. An unlocked server room or an unattended workstation can expose patient data just as easily as a hacking attack.
Checklist items:
- Server room or closet locked and access-controlled
- Workstations positioned away from patient view
- Automatic screen locks enabled
- Visitor access logged
- Paper records secured in locked cabinets
- Proper disposal of paper records (shredding)
- Tier 1 (Unaware): $100 - $50,000 per violation
- Tier 2 (Reasonable Cause): $1,000 - $50,000 per violation
- Tier 3 (Willful Neglect, Corrected): $10,000 - $50,000 per violation
- Tier 4 (Willful Neglect, Not Corrected): $50,000+ per violation
- Annual Maximum: $1.5 million per category
Incident Response Plan
When something goes wrong—and eventually, something will—you need a documented plan for responding quickly and appropriately.
Checklist items:
- Written incident response procedures
- Designated incident response team
- Contact information for key parties (IT provider, legal counsel, insurance)
- Breach notification templates ready
- Timeline documentation procedures
HIPAA requires you to report breaches affecting 500 or more individuals within 60 days. Smaller breaches must be reported annually. Having a plan in place means faster response and potentially lower penalties. The most common trigger is a staff member clicking a malicious link, so your written procedures should include a step-by-step phishing incident response action plan that anyone in the office can follow in the first 30 minutes.
The pressure to “just get back to seeing patients” during an outage is exactly when shortcuts—shared logins, paper charts left on counters, unencrypted USB drives ferrying images—create new HIPAA exposure. If you’ve never quantified the stakes, our breakdown of what dental practice downtime really costs a Memphis office shows why a tested incident response plan pays for itself the first time you use it.
What This Looks Like in Practice
A Memphis dental practice we provide healthcare IT support for came to us after a near-miss: an employee clicked a phishing link, and only quick action prevented ransomware from spreading to their Dentrix server.
We helped them implement this checklist over 90 days. The result:
- Security Risk Assessment completed and documented
- All workstations encrypted
- Staff trained on phishing recognition
- Automated daily backups with weekly restoration tests
- Incident response plan documented and tested
They passed their next insurance audit with zero findings and renewed their cyber liability policy at a lower premium.
Getting Started with HIPAA Compliance in Memphis
You don’t have to tackle everything at once. Start with the highest-risk items:
- Complete or update your Security Risk Assessment — This tells you where you’re most vulnerable
- Enable encryption on all workstations — Low effort, high impact
- Verify your backups are working — Test a restoration this week
- Schedule staff training — Even a basic session helps
If you’re unsure where your practice stands, a HIPAA gap assessment can identify your specific risks and prioritize remediation. We offer these assessments for Memphis-area dental practices, with a clear report you can use whether you work with us or not.
Schedule Your Free HIPAA Gap Assessment
If you’re a veterinary practice in Memphis, we’ve also written a HIPAA compliance guide specifically for vet clinics — the requirements overlap, but vet practices face unique challenges around DEA logs, lab integrations, and after-hours emergency access.
For a printable version of the key security controls, download our Dental IT Security Checklist.
We support dental practices across the Memphis metro, including Germantown, Collierville, and Bartlett.
HIPAA compliance isn’t about perfection—it’s about demonstrating reasonable efforts to protect patient data. Start with this checklist, address the gaps you find, and document everything. That’s what auditors want to see.
- Every dental practice needs a current Security Risk Assessment — update yours annually
- Unique logins and role-based access controls are the most common compliance gap we see
- Encrypt all workstations with BitLocker or FileVault — it’s free and high-impact
- Test your backups quarterly — a backup you haven’t tested is a backup you can’t trust
- Staff training on phishing recognition prevents 90% of data breaches
- Document everything — auditors want to see reasonable effort, not perfection
Common Questions
Frequently Asked Questions
What's the first step to HIPAA compliance for a dental practice?
What are the HIPAA fines for a Memphis dental practice?
What's the most common HIPAA violation you see in dental practices?
Do I need to encrypt every workstation?
Does my IT provider need a Business Associate Agreement?
Dentrix crashing mid-appointment? We fix that.
Get a no-obligation review of your dental practice IT — network, Dentrix performance, imaging, and HIPAA compliance. Most assessments uncover 3-5 gaps.