How to Prepare Your Small Dental Practice for an OCR HIPAA Desk Audit: Step-by-Step Checklist
An OCR HIPAA desk audit focuses on whether your documentation proves compliance. As a small dental practice, you succeed by producing the right evidence—clearly organized and up to date—on short notice.
This step-by-step checklist shows exactly what to prepare: a current Security Risk Assessment, your Notice of Privacy Practices, executed Business Associate Agreements, Workforce Training Records, Access Controls Documentation, an Audit Log Review routine, and an Incident Response Plan with a Breach Notification Log.
Conduct HIPAA Security Risk Assessment
Your Security Risk Assessment (SRA) is the foundation OCR asks for first. It identifies where ePHI resides, what can go wrong, how likely it is, and how you will reduce risk to a reasonable and appropriate level.
- Inventory systems and data flows containing ePHI (EHR, imaging, backups, email, mobile devices).
- Identify threats and vulnerabilities (loss/theft, phishing, misconfigurations, improper disposal).
- Rate risk by likelihood and impact; document rationale and residual risk.
- Create a risk management plan with prioritized actions, owners, and due dates.
- Keep proof of completion: SRA report, worksheets, remediation tickets, and sign-off.
- Revisit the SRA periodically and whenever you add technology, change vendors, or experience an incident.
Maintain Notice of Privacy Practices
Your Notice of Privacy Practices (NPP) explains how you use and disclose PHI. OCR expects a current, patient-facing notice and evidence that you distribute it consistently.
- Use a clear, current NPP and post it prominently in your office and patient intake materials.
- Provide the NPP to each new patient and make a good-faith effort to obtain acknowledgment of receipt.
- Retain acknowledgments or document why one could not be obtained.
- Version-control the NPP; keep prior editions and dates of use to show change history.
- Update and redistribute the NPP when you make material changes to your privacy practices.
Manage Business Associate Agreements
Business Associate Agreements (BAAs) prove you require vendors with PHI access to safeguard it. OCR commonly requests your BAA inventory plus executed agreements.
- Identify business associates: EHR and imaging vendors, billing and collections, IT support, cloud backup, email or texting platforms handling PHI, shredding/disposal, and external transcription.
- Maintain executed BAAs with all such vendors before granting access to PHI.
- Confirm BAAs address permitted uses, safeguards, breach notification duties, and subcontractor flow-down.
- Track effective dates, renewals, and termination; remove access when a vendor relationship ends.
- Centralize your BAA inventory for rapid retrieval during an audit.
Document Workforce Training
OCR will ask for Workforce Training Records that show who was trained, when, on what topics, and by whom. Training must occur for new hires before PHI access and periodically thereafter.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.
- Cover core topics: HIPAA Privacy and Security basics, minimum necessary, passwords/MFA, phishing, device/media handling, and incident reporting.
- Record dates, attendees, roles, trainer, curriculum, and completion results (e.g., quiz scores).
- Maintain sign-in sheets or electronic attestations and copies of training materials.
- Retrain when policies, systems, or roles change, and document those refreshers.
Implement Access Controls
Access Controls Documentation shows you grant the least necessary access and can revoke it promptly. OCR looks for evidence that each user is unique, rights are role-based, and controls actually operate.
- Assign unique user IDs; prohibit shared logins; enable multi-factor authentication where supported.
- Define role-based access with an authorization matrix and approval workflow.
- Configure session timeouts, automatic logoff, and device encryption on laptops and mobile devices.
- Document provisioning and termination checklists; remove access the same day employment ends.
- Conduct periodic user-access reviews and keep sign-offs as part of your Access Controls Documentation.
Review Audit Logs Regularly
Regular Audit Log Review helps you detect inappropriate access early and proves ongoing monitoring. OCR may request your procedures and recent review records.
- Enable audit logging on EHR, e-prescribing, imaging, and critical network systems.
- Define review cadence (e.g., daily exception alerts, weekly spot checks, monthly summaries).
- Flag anomalies: access to VIPs or staff records, access outside duty hours, mass exports, repeated failed logins.
- Document each review with date, reviewer, findings, and corrective actions taken.
- Retain logs and review records for your chosen retention period to support investigations.
Establish Incident Response Plan
An Incident Response Plan documents how you detect, triage, contain, investigate, and recover from security or privacy events. OCR also expects a Breach Notification Log that tracks decisions and notifications.
- Define what constitutes an incident and how staff report it (immediately, via named contacts).
- Assign roles for triage, forensics, patient care continuity, and communications.
- Use a standard form to capture facts, timelines, systems affected, and evidence preserved.
- Perform a breach risk assessment and document your determination and rationale.
- Record notifications in your Breach Notification Log, including dates and recipients; notify affected individuals without unreasonable delay and consistent with required timelines.
- Conduct post-incident reviews and add corrective actions to your risk management plan.
By keeping these artifacts current, centralized, and test-ready, you reduce risk, improve care continuity, and can respond confidently to an OCR HIPAA desk audit with clear, defensible evidence.
FAQs.
What documents are required for an OCR HIPAA desk audit?
Common requests include your latest Security Risk Assessment and risk management plan, current Notice of Privacy Practices and patient acknowledgments, executed Business Associate Agreements, Workforce Training Records, Access Controls Documentation (policies, access matrices, and user reviews), Audit Log Review evidence, and an Incident Response Plan with a Breach Notification Log.
How often must a risk assessment be conducted?
Conduct an SRA initially, then periodically and whenever significant changes occur—such as adding systems, switching vendors, remodeling networks, or after an incident. Many practices reassess at least annually and update the risk management plan as they complete remediation.
What is included in workforce training for HIPAA compliance?
Training covers privacy and security fundamentals, minimum necessary use/disclosure, recognizing and reporting incidents, phishing and social engineering, secure passwords and MFA, mobile device and media handling, and practice-specific policies. Keep attendance, dates, materials, and completion evidence in your Workforce Training Records.
How should a dental practice manage business associate agreements?
Maintain a current inventory of all vendors that create, receive, maintain, or transmit PHI; execute BAAs before access; confirm required safeguards and breach-notification terms; flow down obligations to subcontractors; review renewals and terminations; and centrally store signed agreements for quick retrieval during an audit.
Ready to simplify HIPAA compliance?
Join thousands of organizations that trust Accountable to manage their compliance needs.