How to Achieve HIPAA Compliance for Your Solo Therapist Practice: Step-by-Step Checklist

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

How to Achieve HIPAA Compliance for Your Solo Therapist Practice: Step-by-Step Checklist

Kevin Henry

HIPAA

July 31, 2026

7 minutes read
Share this article
How to Achieve HIPAA Compliance for Your Solo Therapist Practice: Step-by-Step Checklist

HIPAA compliance is achievable—even as a team of one—when you break it into clear, repeatable steps. This checklist walks you through what to do, what to document, and how to protect Electronic Protected Health Information (ePHI) without slowing down client care.

You will designate roles, assess risk, formalize policies, and apply administrative, physical, and technical safeguards, then finalize vendor protections with Business Associate Agreements (BAAs). Keep your documentation current and aligned with how you actually work.

Designate Privacy and Security Officers

HIPAA expects every covered entity to designate a Privacy Officer and a Security Officer. In a solo therapist practice, you can assign both roles to yourself, but you still need to define and document the responsibilities.

  • Privacy Officer Responsibilities: maintain the Notice of Privacy Practices; define minimum necessary use/disclosure; manage client rights (access, amendments, restrictions); oversee breach evaluation and notifications; handle complaints; and track training/compliance tasks.
  • Security Officer responsibilities: lead the Security Risk Analysis and ongoing risk management; set and enforce access controls; approve encryption standards; monitor audit logs and incidents; manage contingency planning; and vet vendors for security posture.
  • Document the designations: write a brief appointment memo, outline duties, list contact information, and set a review cadence (for example, quarterly self-checks) so nothing falls through the cracks.

Conduct Security Risk Assessment

This is the foundation of your Security Rule program. Perform a Security Risk Analysis (often called a “risk assessment”) to identify where ePHI lives, what could go wrong, and how you will reduce those risks to a reasonable and appropriate level.

  1. Inventory ePHI: list systems, devices, apps, paper-to-digital flows, backups, and telehealth tools that create, receive, maintain, or transmit ePHI.
  2. Map data flows: note how ePHI enters, moves, is stored, and leaves (client portal, email, e-fax, cloud storage, billing, exports).
  3. Identify threats and vulnerabilities: unauthorized access, lost devices, weak passwords, misdirected email, unpatched software, office break-ins, phishing.
  4. Estimate likelihood and impact: rate each risk and prioritize high-likelihood/high-impact items first.
  5. Plan risk management actions: choose controls (encryption, MFA, audit logs, training) and timelines; assign yourself as the owner.
  6. Document and implement: record findings, decisions, and evidence of completion; track open items until closed.
  7. Reassess regularly: revisit at least annually and whenever technology, vendors, or workflows change.

Develop Written Privacy and Security Policies

Your policies should reflect how you actually operate. Keep them concise, practical, and aligned to HIPAA’s Privacy, Security, and Breach Notification Rules. Retain policies and related documentation for at least six years from the date of creation or last effective date.

  • Privacy policies: uses and disclosures, minimum necessary standards, Notice of Privacy Practices, client rights, authorizations, and complaint handling.
  • Security policies: access control, authentication, encryption, device and media handling, audit logging and reviews, incident response, Security Risk Analysis and risk management, and contingency planning.
  • Operationalizing: include who does what, when you do it, the forms/templates you use, and how you track completion and updates.

Implement Administrative Safeguards

Administrative Safeguards Implementation turns your risk decisions into action. Emphasize training, accountability, and repeatable processes that fit a solo workflow.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

  • Workforce measures: complete initial and periodic security and privacy training; apply a sanctions standard for noncompliance (including for contracted helpers).
  • Access management: grant the minimum necessary access in each system; promptly adjust or revoke any shared or temporary access.
  • Contingency planning: maintain an encrypted backup, a disaster recovery plan, and an emergency operations plan; test restores on a set schedule.
  • Incident response: define how you detect, document, and respond to suspected breaches or security events, including timelines and decision criteria.
  • Evaluation and audits: periodically review audit logs, policy effectiveness, vendor BAAs, and open risk items; document the results.

Establish Physical Safeguards

Physical Security Controls protect your office, devices, and paper records from loss, theft, or unauthorized viewing—whether you work in a suite, a home office, or on the go.

  • Facility access: lock doors and file cabinets; use visitor awareness or sign-in as appropriate; keep screens out of public view.
  • Workstation security: enable automatic screen lock; use privacy filters when needed; secure laptops with cable locks in shared spaces.
  • Device and media controls: track where ePHI-capable devices are; encrypt storage; securely dispose or wipe devices before reuse or recycling.
  • Mobile and travel: keep devices on your person, avoid unsecured Wi‑Fi for ePHI, and store paper records in locked containers during transport.

Utilize Technical Safeguards

Technical controls enforce who can access ePHI, what they can do, and how data stays confidential and intact. Prioritize settings that are built into your EHR, telehealth, and email systems.

  • Access controls: unique user ID, strong passphrases, and multi‑factor authentication on all ePHI systems.
  • Technical Safeguards Encryption: enable encryption for data at rest (full‑disk on laptops and phones; encrypted cloud storage) and in transit (TLS for portals, secure messaging, and e‑fax).
  • Audit controls: turn on logging; review sign‑ins, exports, and administrative actions on a schedule and after any incident.
  • Integrity and transmission security: patch operating systems/apps; use reputable anti‑malware; avoid sending ePHI by standard email/text unless you apply approved encryption or use a portal.
  • Automatic logoff and device controls: set short screen‑lock timers; enable remote lock/wipe and device‑finding features.
  • Backups and key management: keep encrypted backups separate from primary systems and protect encryption keys with strong authentication.

Execute Business Associate Agreements

Sign BAAs with vendors that create, receive, maintain, or transmit ePHI on your behalf. Typical business associates include EHR/practice management platforms, telehealth services, e‑fax providers, secure email or messaging vendors, cloud storage/backup, billing services, IT support with system access, and shredding/disposal services.

  • Business Associate Agreement Compliance essentials: permitted uses/disclosures, required safeguards, breach notification duties and timelines, subcontractor flow‑down, return/destruction of ePHI, and termination rights.
  • Due diligence: verify that the vendor’s security features match your risk management needs (encryption, MFA, audit logs, data locations, support commitments).
  • Recordkeeping: maintain signed BAAs and renewal dates; note any vendor‑specific security settings you enabled to meet your policies.
  • Clarify edge cases: some service providers (for example, payment processors performing standard transactions) may not be BAs; confirm whether ePHI is handled before insisting on a BAA.

Wrap up by verifying that each safeguard you selected in your Security Risk Analysis is implemented, documented, and reviewed on a routine cadence. With clear roles, practical policies, and disciplined follow‑through, your solo practice can sustain HIPAA compliance while protecting client trust.

FAQs

What are the key steps to HIPAA compliance for solo therapists?

Designate Privacy and Security Officers, complete a Security Risk Analysis, write privacy and security policies that match your workflow, implement administrative, physical, and technical safeguards, and execute BAAs with any vendor that touches ePHI. Keep evidence of training, risk decisions, configurations, and reviews.

How do I conduct a HIPAA security risk assessment?

Identify where ePHI resides and flows, list realistic threats and vulnerabilities, rate likelihood and impact, choose and implement controls, document everything, and reassess at least annually or when your tech or vendors change. Treat it as a living Security Risk Analysis paired with ongoing risk management.

What safeguards are required to protect patient information?

Administrative safeguards (training, access management, contingency and incident response), Physical Security Controls (locked spaces, device/media protection), and Technical controls (unique IDs, MFA, audit logging, patching, and encryption for data at rest and in transit). Select controls that are reasonable and appropriate for your practice and document how they are applied.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles