HIPAA Compliance Checklist for a Small Dental Practice with Two Locations

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

HIPAA Compliance Checklist for a Small Dental Practice with Two Locations

Kevin Henry

HIPAA

September 03, 2026

8 minutes read
Share this article
HIPAA Compliance Checklist for a Small Dental Practice with Two Locations

Running a dental practice across two locations adds coordination challenges to HIPAA compliance. This checklist shows you exactly what to put in place so both sites protect electronic Protected Health Information (ePHI), respect patient privacy, and pass audits with confidence.

Use these steps to assign clear ownership, complete a security risk assessment, formalize Business Associate Agreements, and implement administrative, physical, and technical safeguards. You will also build a breach response plan, maintain comprehensive documentation, and keep both offices aligned day to day.

Designate Privacy and Security Officers

Define clear ownership

  • Appoint a HIPAA Privacy Officer to oversee privacy policies, patient rights, and complaint handling.
  • Appoint a HIPAA Security Officer to lead security risk management for systems that store or transmit ePHI.
  • Document duties, decision authority, and escalation paths for both roles.

Two-location structure

  • Name one enterprise Privacy Officer and one Security Officer for both sites.
  • Assign a site coordinator at each location to handle daily tasks, distribute updates, and report issues.
  • Hold a standing monthly cross-site compliance huddle with minutes and action items.

Immediate actions

  • Create role descriptions, appointment letters, and an org chart.
  • Publish a shared compliance calendar for training, audits, and policy reviews.
  • Establish a single email inbox for HIPAA questions and incident reporting.

Conduct Annual Security Risk Assessment

Scope and methodology

  • Inventory assets: EHR, practice management, imaging, email, file servers, cloud apps, laptops, mobile devices, and backups.
  • Map ePHI data flows between locations, vendors, and systems.
  • Identify threats and vulnerabilities, then rate likelihood and impact.
  • Document findings and create a prioritized risk treatment plan with owners and due dates.

What “good” looks like

  • Written security risk assessment covering both sites and remote access.
  • Risk register with remediation tasks (patching, encryption, access cleanup, configuration hardening).
  • Evidence of progress: change tickets, screenshots, and updated policies.

When to reassess

  • Complete a security risk assessment at least annually and after material changes such as a new EHR, network redesign, or opening/relocating an office.
  • Run targeted mini-assessments after incidents or major vendor changes.

Execute Business Associate Agreements

Identify who needs agreements

  • Vendors that create, receive, maintain, or transmit ePHI: EHR providers, imaging cloud services, billing companies, IT support, email encryption, cloud storage, shredding, and transcription.
  • Confirm which services are in scope at each location and ensure coverage for both sites.

What to include in Business Associate Agreements

  • Permitted uses and disclosures of PHI and ePHI.
  • Required safeguards and audit logging expectations.
  • Breach notification protocols with time frames and required details.
  • Subcontractor flow-down clauses, right to audit, and termination/return-or-destroy provisions.
  • Incident cooperation and minimum cybersecurity controls (encryption, access control, multi-factor authentication where feasible).

Centralized control

  • Maintain a single BAA register listing vendor, services, locations covered, renewal dates, and contact info.
  • Standardize BAAs so both locations operate under the same terms.

Implement Administrative Safeguards

Policies and workforce management

  • Adopt written administrative safeguards covering access management, minimum necessary use, onboarding/offboarding, sanctions, and security awareness.
  • Apply role-based access so staff see only what they need to do their jobs.
  • Terminate access the same business day when employment ends or roles change.

Training and awareness

  • Provide HIPAA and security training at hire and annually for all workforce members, including dentists, hygienists, and front desk teams.
  • Reinforce with short quarterly refreshers on phishing, secure messaging, and handling imaging with ePHI.
  • Record attendance and comprehension checks for both sites.

Contingency and incident processes

  • Maintain a contingency plan with data backup, disaster recovery, and emergency operations procedures for each location.
  • Define security incident procedures, including triage, evidence preservation, and escalation to your Security Officer.
  • Test backups and restore procedures at least annually and document the results.

Establish Physical Safeguards

Facility access controls

  • Restrict server/network closets; keep visitor logs for vendors and maintenance personnel.
  • Use key, fob, or code controls and promptly recover keys from departing staff.
  • Post clean desk and screen privacy expectations in areas where ePHI may be visible.

Workstations, devices, and media

  • Auto-lock workstations; use privacy screens at reception and in open-bay operatories.
  • Secure portable devices with cable locks and store laptops when not in use.
  • Maintain an equipment inventory for both locations, including serial numbers and assigned users.
  • Sanitize or shred media before disposal; document chain-of-custody when moving devices between sites.

Environmental considerations

  • Protect imaging equipment and local servers from water, dust, and power fluctuations with surge protection and UPS where needed.
  • Control public Wi‑Fi separately from clinical and business networks at each office.

Apply Technical Safeguards

Access control and authentication

  • Assign unique user IDs; prohibit shared logins in EHR, imaging, and billing systems.
  • Implement strong passwords and multi-factor authentication for remote access, email, cloud apps, and any system hosting ePHI.
  • Enable automatic logoff and emergency access procedures.

Audit controls and monitoring

  • Turn on audit logging for EHR, practice management, imaging, file storage, and email.
  • Centralize log retention; review high-risk events (after-hours access, bulk exports, failed logins) monthly.
  • Document reviews and follow-up actions for both locations.

Integrity and transmission security

  • Encrypt ePHI at rest on servers, workstations, laptops, and mobile devices; enforce full-disk encryption.
  • Use TLS-encrypted connections for data in transit; enable secure email or patient portals for PHI exchange.
  • Deploy endpoint protection, timely patching, and restricted admin privileges.
  • Segment networks, apply firewalls, and disable unused services and ports at both sites.

Mobile and remote work

  • Use mobile device management to enforce encryption and remote wipe on phones and tablets accessing ePHI.
  • Require VPN with multi-factor authentication for remote connections between locations or from home.

Develop Breach Response Plan

Define incidents and breaches

Establish criteria for what constitutes a security incident versus a breach of unsecured PHI. Include a standardized risk assessment that considers the nature of the data, who received it, whether it was actually viewed, and mitigation steps taken.

Ready to assess your HIPAA security risks?

Join thousands of organizations that use Accountable to identify and fix their security gaps.

Take the Free Risk Assessment

Step-by-step breach response

  • Detect and contain: isolate affected systems, preserve logs, and stop further exposure.
  • Investigate: determine scope, data elements involved, and individuals affected; document every action.
  • Notify: follow breach notification protocols—inform affected individuals without unreasonable delay and no later than 60 days after discovery; notify HHS and, when required, local media for incidents affecting 500 or more residents.
  • Mitigate and prevent: offer appropriate support to patients, retrain staff, and remediate root causes.

Practice and improve

  • Run annual tabletop exercises that involve both locations and key vendors.
  • Keep an on-call contact list for after-hours incidents and a pre-approved message template for notifications.

Maintain Documentation and Policies

What to document

  • Policies and procedures for privacy and security, including administrative safeguards.
  • Security risk assessments, risk treatment plans, and evidence of remediation.
  • Training curricula, attendance logs, and sanction records.
  • BAA inventory, versions, and renewal dates.
  • Incident and breach logs, investigation notes, and notifications.
  • Device inventories, access reviews, backup and restore test results, and audit logging reports.

Retention and version control

  • Retain required HIPAA documentation for at least six years from the date of creation or last effective date.
  • Use version numbers, effective dates, and approval signatures; store the master record centrally for both sites.

Ensure Compliance Across Multiple Locations

Unified governance, local execution

  • Maintain a single policy set that applies to both locations; add site-specific SOPs only where needed.
  • Standardize technology (EHR, imaging, email, backup, security tools) to simplify training and auditing.
  • Appoint site coordinators who conduct walk-throughs, spot-check access, and verify signage and privacy practices.

Cross-site operations

  • Implement consistent onboarding/offboarding, key and badge control, and access reviews at both sites.
  • Use shared dashboards for ticketing, training completion, audit logging review, and incident tracking.
  • Schedule alternating quarterly audits—Site A reviews Site B and vice versa—to reduce blind spots.

Business continuity between offices

  • Design backups and communications so one site can support the other during outages.
  • Maintain spare workstations and label portable equipment for rapid redeployment across locations.

Conclusion

With clear ownership, an annual security risk assessment, solid BAAs, and layered administrative, physical, and technical safeguards, your two-location dental practice can protect ePHI and respond confidently to incidents. Central governance plus local accountability keeps daily operations compliant and efficient.

FAQs

What are the key HIPAA requirements for small dental practices?

You must protect PHI through administrative, physical, and technical safeguards; complete a security risk assessment; provide a Notice of Privacy Practices and honor patient rights; limit use to the minimum necessary; execute Business Associate Agreements with vendors; maintain audit logging; train your workforce; and follow breach notification protocols when incidents occur.

How often should a security risk assessment be conducted?

Perform a comprehensive security risk assessment at least once a year and whenever you introduce major changes—such as switching EHRs, adding new imaging systems, remodeling networks, or opening/relocating a site. Run targeted reassessments after any significant incident or vendor change and track remediation to completion.

What is included in a HIPAA breach response plan?

A breach response plan defines incident triage, investigation steps, documentation, a standardized risk assessment, clear roles, and breach notification protocols. It specifies timelines (including notifying affected individuals without unreasonable delay and no later than 60 days), communication methods, coordination with business associates, mitigation for patients, and post-incident improvements.

How can compliance be maintained across multiple locations?

Use centralized policies and shared systems, designate site coordinators, standardize onboarding/offboarding, require multi-factor authentication and consistent audit logging, run cross-site audits, track training and access reviews in one dashboard, and keep a unified BAA register. This model delivers consistency while allowing each office to manage day-to-day execution.

Share this article

Ready to assess your HIPAA security risks?

Join thousands of organizations that use Accountable to identify and fix their security gaps.

Take the Free Risk Assessment

Related Articles