HIPAA Compliance Checklist for Solo Psychiatry Practices Starting Telehealth Visits
Security Risk Assessment
Start by mapping where electronic Protected Health Information (ePHI) is created, received, maintained, or transmitted across your solo psychiatry workflow. Include your telehealth platform, EHR, email, cloud storage, billing tools, laptops, smartphones, routers, and backup media.
- Inventory all systems handling ePHI and diagram data flows for scheduling, video sessions, notes, e-prescribing, and billing.
- Identify reasonably anticipated threats and vulnerabilities (e.g., home Wi‑Fi misconfiguration, lost devices, phishing, misrouted invites, platform missettings).
- Evaluate current safeguards (administrative, physical, technical) including encryption, access controls, and audit logs.
- Rate risks by likelihood and impact, then document a remediation plan with owners, timelines, and residual risk.
- Address telehealth specifics: disable public meeting links, lock sessions, restrict file sharing, verify patient identity, and control recording.
- Review and update the assessment at least annually and whenever technologies, vendors, or workflows change.
Translate results into an actionable risk management plan. For solo practices, keep it concise but thorough, and tie each high-risk item to concrete controls and verification steps.
Business Associate Agreements
Execute a Business Associate Agreement (BAA) with every vendor that creates, receives, maintains, or transmits ePHI on your behalf. Common business associates for telepsychiatry include your telehealth/video vendor, EHR, secure messaging service, e-fax provider, cloud storage, billing company, transcription, and IT support that may access systems with ePHI.
- Confirm a signed BAA is in place before any ePHI flows to the vendor.
- Verify the BAA covers permitted uses/disclosures, safeguards, subcontractor flow-down, breach notification duties, termination, and data return/destruction.
- Ensure the vendor supports encryption in transit (ideally end-to-end encryption), encryption at rest, access controls, and audit logging.
- Document vendor due diligence (security whitepapers, SOC reports, security questionnaires) in your risk file.
- Review BAAs on renewal or when services or data flows change.
Telehealth Platform Compliance
Select and configure a telehealth solution that aligns with HIPAA’s Security Rule. Favor platforms that provide a BAA, strong encryption, granular controls, and transparent security practices suitable for mental health care.
- Require a BAA and confirm end-to-end encryption or equivalent strong encryption in transit.
- Enable role-based access control with unique user IDs; even if you are solo, separate admin and daily-use accounts and enforce least privilege.
- Turn on audit logs and set a review cadence; ensure logs capture logins, settings changes, session starts/ends, and file shares.
- Use virtual waiting rooms, passworded or tokenized session links, lobby admits, and automatic meeting locks.
- Disable recording by default; if recording is clinically necessary, store securely within systems under your BAA and document patient consent and retention limits.
- Minimize identifiers in calendar invites and on-screen names to honor the minimum necessary standard.
- Test platform behavior on all devices you use, including bandwidth fallback, screen sharing defaults, and file transfer handling.
Privacy and Security Policies
Document practical policies you can consistently follow. As a solo psychiatrist, you are the privacy and security officer; keep policies lean, specific, and aligned to your actual tools and workflows.
- Access management: define how accounts are issued, changed, and terminated; apply the minimum necessary standard and role-based access control.
- Password and MFA: require strong passphrases and multifactor authentication for EHR, telehealth, email, and cloud services.
- Secure communications: specify approved channels for messaging and file exchange; prohibit personal texting with ePHI outside approved apps.
- Telehealth etiquette and environment: private space, sound masking, screen privacy, and identity verification steps at session start.
- Documentation rules: separate psychotherapy notes when appropriate, avoid unnecessary ePHI in messages and invites, and define retention schedules.
- Contingency planning: data backup, emergency access procedures, and downtime workflows for urgent patient needs.
- Sanctions and exceptions: outline corrective actions for policy violations and how to document exceptions.
Retain policies, risk analyses, and related documentation for at least six years and review them annually or upon major changes.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.
Staff Training
Even if it’s just you (and any contractor handling scheduling or billing), provide initial and periodic HIPAA training tailored to roles and your telehealth setup.
- Cover Privacy Rule basics, the minimum necessary standard, and how your practice applies them to telehealth.
- Teach secure session setup, ID verification, screen sharing hygiene, and how to avoid exposing ePHI inadvertently.
- Reinforce phishing awareness, safe link handling, and procedures for suspected incidents.
- Demonstrate device security steps: updates, encryption, automatic lock, and secure storage.
- Walk through your breach notification process and who to contact immediately.
- Maintain training logs with dates, content covered, and acknowledgments.
Device Security
Harden every endpoint that accesses ePHI. Focus on practical controls you can verify and maintain in a solo environment.
- Full-disk encryption on laptops and smartphones; enable device-level PIN/biometric and automatic screen lock.
- Keep operating systems, browsers, and apps patched; use reputable endpoint protection and enable firewall.
- Use a password manager and MFA; disable autofill for sensitive web forms.
- Segment home networks, prefer wired connections, and set strong router passwords with WPA3 where available.
- Avoid public Wi‑Fi; if unavoidable, use a vetted VPN and never access admin consoles over untrusted networks.
- Implement secure, tested backups; protect backups with encryption and access controls.
- Plan for loss/theft: remote locate/wipe, rapid credential rotation, and documentation of the event.
Breach Notification Plan
Define exactly how you will identify, investigate, mitigate, and report incidents involving ePHI. Treat ransomware and misdirected messages as potential breaches until a documented risk assessment shows a low probability of compromise.
- Detection and containment: stop the exposure, preserve evidence, and capture relevant audit logs immediately.
- Four-factor risk assessment: evaluate the nature/extent of ePHI, the unauthorized person, whether ePHI was actually viewed/acquired, and mitigation taken.
- Individual notice: notify affected patients without unreasonable delay and no later than 60 calendar days after discovery; include what happened, types of ePHI involved, steps you’re taking, and how patients can protect themselves.
- Regulatory notice: report to HHS; for fewer than 500 individuals, log and submit within 60 days after the end of the calendar year; for 500 or more in a state/jurisdiction, notify HHS contemporaneously and the media.
- Documentation: maintain investigation records, risk analyses, notices sent, and remediation steps; update policies and training based on lessons learned.
- Encryption safe harbor: if ePHI was encrypted and keys remained secure, the event may not be a reportable breach—document this determination.
Summary: Build your telehealth program on a documented risk assessment, execute BAAs, configure a secure platform with encryption, enforce practical policies and training, harden devices, and keep a clear breach notification playbook. These steps align HIPAA requirements with the realities of a solo psychiatry practice.
FAQs
What are the key steps in conducting a HIPAA security risk assessment?
Inventory all ePHI systems and data flows; identify threats and vulnerabilities; evaluate existing controls; rate risks by likelihood and impact; implement and document remediation; and review at least annually and after major changes. For telehealth, include platform settings, meeting link controls, identity verification, audit logs, and your home/remote work environment.
How do I ensure my telehealth platform is HIPAA compliant?
Choose a vendor that will sign a Business Associate Agreement (BAA), provides strong encryption in transit (preferably end-to-end encryption), supports role-based access control and unique user IDs, offers robust audit logs, and allows secure controls such as waiting rooms, locked meetings, and recording restrictions. Validate settings against your minimum necessary standard and document a configuration review.
What should be included in staff HIPAA training?
Cover Privacy and Security Rule essentials, the minimum necessary standard, secure telehealth workflows (session setup, identity checks, screen sharing), phishing awareness, device safeguards, incident reporting, breach notification basics, and practice-specific policies. Keep dated training records and refresh training periodically.
How do I handle breach notification under HIPAA regulations?
On discovery, contain the incident, preserve evidence, and perform a documented risk assessment. If a breach is confirmed, notify affected individuals without unreasonable delay and no later than 60 days, report to HHS per thresholds, notify media if 500+ individuals in a state/jurisdiction are affected, and record all actions taken. Use audit logs to support the investigation and strengthen safeguards to prevent recurrence.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.