Skip to main content
| 8 min read

HIPAA Compliance Checklist for Memphis Dental Practices

A practical HIPAA compliance checklist for dental practices in Memphis. Learn the key requirements, common violations, and how to protect patient data.

Running a dental practice in Memphis means juggling patient care, staff management, and a growing list of compliance requirements. HIPAA often falls to the bottom of the priority list—until something goes wrong.

The Office for Civil Rights (OCR) has increased enforcement actions against dental practices in recent years. Fines range from $100 to $50,000 per violation, with annual maximums reaching $1.5 million. For a practice already operating on tight margins, even a small penalty can be devastating.

This checklist covers the HIPAA compliance requirements that matter most for Memphis dental practices, based on what we see working with practices across Germantown, Collierville, Bartlett, and the greater Memphis area. If you also own an adjacent aesthetics business, the same covered-entity rules can apply there too—our medical spa HIPAA compliance IT checklist walks through exactly when a med spa falls under HIPAA and what to do about it.

The Security Risk Assessment: Your Foundation

Every HIPAA compliance program starts with a Security Risk Assessment (SRA). This isn’t optional—it’s required by the HIPAA Security Rule, and it’s the first thing auditors look for.

Your SRA should document:

  • All systems that store or transmit PHI — This includes your practice management software (Dentrix, Eaglesoft, Open Dental), digital imaging systems, email, and even that old computer in the back office nobody uses anymore
  • Potential threats to each system — Ransomware, employee errors, physical theft, natural disasters
  • Current safeguards in place — Firewalls, antivirus, encryption, access controls
  • Risk levels and remediation plans — What needs fixing, in priority order

Many practices we work with haven’t updated their SRA in years. If yours is more than 12 months old, it’s time for a refresh—especially with the 2026 HIPAA Security Rule changes eliminating addressable safeguards and making dozens of controls mandatory.

Pro Tip

Schedule your SRA at least 60 days before any insurance renewal or compliance audit. This gives you time to address findings before they become audit issues.

Access Controls: Who Can See What

Who in your practice can open a patient’s chart—and could you prove it if an auditor asked? Not everyone needs that access. HIPAA requires you to limit it based on job roles, not convenience.

Checklist items:

  • Each staff member has a unique login (no shared passwords)
  • Access permissions match job responsibilities
  • Former employees are removed from all systems within 24 hours of departure
  • Login attempts are logged and reviewed
  • Automatic session timeouts are enabled (15 minutes or less)

Most Common Violation

Practices using a single shared login for their practice management software. It’s convenient, but it makes it impossible to track who accessed what—and auditors notice.

Encryption: Protecting Data at Rest and in Transit

Encryption converts patient data into unreadable code without the proper key. If an encrypted laptop is stolen, the data is useless to the thief—and you may avoid breach notification requirements entirely.

Checklist items:

  • Full-disk encryption on all computers and laptops
  • Encrypted email for sending patient information
  • Encrypted backups (both local and cloud)
  • Secure (HTTPS) connections for web-based applications
  • Encrypted connections for remote access

Windows BitLocker and macOS FileVault provide free full-disk encryption. There’s no excuse for leaving workstations unencrypted in 2026.

Get the Complete 54-Point Checklist

This article covers the highlights. Download our full Dental Practice IT Security Checklist with scoring guide and prioritization framework.

  • 54-point self-assessment checklist
  • Covers HIPAA, security, backups, and more
  • Score interpretation guide included
  • Immediate PDF download via email

We'll email you the checklist immediately.

Backup and Disaster Recovery

94%

increase in ransomware attacks against healthcare organizations in 2024

Dental practices are frequent targets because attackers know you’ll pay to get patient records back. A proper backup strategy is your insurance policy.

Checklist items:

  • Daily automated backups of all patient data
  • Backups stored offsite or in a HIPAA-compliant cloud
  • Regular backup restoration tests (at least quarterly)
  • Documented disaster recovery plan
  • Recovery time objective (RTO) defined and achievable

The 3-2-1 Rule

Keep three copies of your data, on two different types of media, with one copy stored offsite. With proper backups, you can recover from ransomware without paying the ransom.

Staff Training: Your First Line of Defense

90% of data breaches start with human error — usually a phishing email that tricks someone into clicking a malicious link or revealing credentials.

90% of data breaches start with human error—usually a phishing email that tricks someone into clicking a malicious link or revealing login credentials.

Checklist items:

  • Annual HIPAA training for all staff members
  • Documented training records (keep for 6 years)
  • Phishing awareness training
  • Clear procedures for reporting suspected breaches
  • Training updates when policies change

Training doesn’t have to be complicated. A 30-minute annual session covering the basics—what PHI is, how to spot phishing emails, and what to do if something seems wrong—makes a measurable difference.

Our cybersecurity services include the threat monitoring and incident response that dental practices need to stay protected.

Business Associate Agreements

If your billing company or imaging vendor mishandled a patient record tomorrow, would your paperwork hold up? Anyone who handles PHI on your behalf needs a Business Associate Agreement (BAA)—your IT provider, cloud software vendors, billing companies, and answering services.

Checklist items:

  • BAAs in place with all vendors who access PHI
  • BAAs reviewed and updated annually
  • Vendor security practices verified
  • Subcontractor agreements documented

No BAA means you’re both liable if something goes wrong. Make sure your agreements are current — older BAAs may not cover risks that have emerged in the last few years.

No BAA means you’re both liable if something goes wrong. Make sure your agreements are current—HIPAA requirements have evolved, and older BAAs may not cover current risks. Cyber insurance carriers now require many of the same controls as HIPAA—MFA, endpoint protection, and documented incident response plans. If you’re approaching a policy renewal, review our cyber insurance requirements checklist to see what carriers will verify.

Physical Security

Digital security gets most of the attention, but physical security matters too. An unlocked server room or an unattended workstation can expose patient data just as easily as a hacking attack.

Checklist items:

  • Server room or closet locked and access-controlled
  • Workstations positioned away from patient view
  • Automatic screen locks enabled
  • Visitor access logged
  • Paper records secured in locked cabinets
  • Proper disposal of paper records (shredding)
HIPAA Violation Fine Tiers
  • Tier 1 (Unaware): $100 - $50,000 per violation
  • Tier 2 (Reasonable Cause): $1,000 - $50,000 per violation
  • Tier 3 (Willful Neglect, Corrected): $10,000 - $50,000 per violation
  • Tier 4 (Willful Neglect, Not Corrected): $50,000+ per violation
  • Annual Maximum: $1.5 million per category

Incident Response Plan

When something goes wrong—and eventually, something will—you need a documented plan for responding quickly and appropriately.

Checklist items:

  • Written incident response procedures
  • Designated incident response team
  • Contact information for key parties (IT provider, legal counsel, insurance)
  • Breach notification templates ready
  • Timeline documentation procedures

HIPAA requires you to report breaches affecting 500 or more individuals within 60 days. Smaller breaches must be reported annually. Having a plan in place means faster response and potentially lower penalties. The most common trigger is a staff member clicking a malicious link, so your written procedures should include a step-by-step phishing incident response action plan that anyone in the office can follow in the first 30 minutes.

The pressure to “just get back to seeing patients” during an outage is exactly when shortcuts—shared logins, paper charts left on counters, unencrypted USB drives ferrying images—create new HIPAA exposure. If you’ve never quantified the stakes, our breakdown of what dental practice downtime really costs a Memphis office shows why a tested incident response plan pays for itself the first time you use it.

What This Looks Like in Practice

A Memphis dental practice we provide healthcare IT support for came to us after a near-miss: an employee clicked a phishing link, and only quick action prevented ransomware from spreading to their Dentrix server.

We helped them implement this checklist over 90 days. The result:

  • Security Risk Assessment completed and documented
  • All workstations encrypted
  • Staff trained on phishing recognition
  • Automated daily backups with weekly restoration tests
  • Incident response plan documented and tested

They passed their next insurance audit with zero findings and renewed their cyber liability policy at a lower premium.

Getting Started with HIPAA Compliance in Memphis

You don’t have to tackle everything at once. Start with the highest-risk items:

  1. Complete or update your Security Risk Assessment — This tells you where you’re most vulnerable
  2. Enable encryption on all workstations — Low effort, high impact
  3. Verify your backups are working — Test a restoration this week
  4. Schedule staff training — Even a basic session helps

If you’re unsure where your practice stands, a HIPAA gap assessment can identify your specific risks and prioritize remediation. We offer these assessments for Memphis-area dental practices, with a clear report you can use whether you work with us or not.

Schedule Your Free HIPAA Gap Assessment

If you’re a veterinary practice in Memphis, we’ve also written a HIPAA compliance guide specifically for vet clinics — the requirements overlap, but vet practices face unique challenges around DEA logs, lab integrations, and after-hours emergency access.

For a printable version of the key security controls, download our Dental IT Security Checklist.

We support dental practices across the Memphis metro, including Germantown, Collierville, and Bartlett.

HIPAA compliance isn’t about perfection—it’s about demonstrating reasonable efforts to protect patient data. Start with this checklist, address the gaps you find, and document everything. That’s what auditors want to see.

Key Takeaways
  • Every dental practice needs a current Security Risk Assessment — update yours annually
  • Unique logins and role-based access controls are the most common compliance gap we see
  • Encrypt all workstations with BitLocker or FileVault — it’s free and high-impact
  • Test your backups quarterly — a backup you haven’t tested is a backup you can’t trust
  • Staff training on phishing recognition prevents 90% of data breaches
  • Document everything — auditors want to see reasonable effort, not perfection

Common Questions

Frequently Asked Questions

What's the first step to HIPAA compliance for a dental practice?
A Security Risk Assessment (SRA). It’s required by law and the first thing auditors look for. Your SRA documents every system that stores or transmits PHI — your practice management software (Dentrix, Eaglesoft, Open Dental), digital imaging, email, even that old back-office computer — plus the threats to each, your current safeguards, and a prioritized remediation plan. If yours is more than 12 months old, refresh it.
What are the HIPAA fines for a Memphis dental practice?
Fines range from $100 to $50,000 per violation depending on the tier, with an annual maximum of $1.5 million per category. For a practice operating on tight margins, even a small penalty can be devastating — and the Office for Civil Rights has increased enforcement against dental practices in recent years.
What's the most common HIPAA violation you see in dental practices?
A single shared login for the practice management software. It’s convenient, but it makes it impossible to track who accessed what — and auditors notice. HIPAA requires each staff member to have a unique login, with access permissions matched to their job role and former employees removed within 24 hours of departure.
Do I need to encrypt every workstation?
Yes. Full-disk encryption belongs on every computer and laptop, and it’s free — Windows BitLocker and macOS FileVault are built in. If an encrypted laptop is stolen, the data is useless to the thief, and you may avoid breach notification requirements entirely. There’s no excuse for leaving workstations unencrypted in 2026.
Does my IT provider need a Business Associate Agreement?
Yes. Anyone who handles PHI on your behalf needs a current Business Associate Agreement — your IT provider, cloud software vendors, billing companies, and answering services. No BAA means you’re both liable if something goes wrong, and older agreements may not cover risks that have emerged in the last few years, so review them annually.

How's your IT?

7 quick questions. Instant score. Personalized recommendations.

Get My Free IT Checkup

Dentrix crashing mid-appointment? We fix that.

Get a no-obligation review of your dental practice IT — network, Dentrix performance, imaging, and HIPAA compliance. Most assessments uncover 3-5 gaps.

Call Let's Talk