Office Manager HIPAA Compliance Checklist for Dental Practices

Product Pricing
Ready to get started? Book a demo with our team
Talk to an expert

Office Manager HIPAA Compliance Checklist for Dental Practices

Kevin Henry

HIPAA

August 02, 2026

8 minutes read
Share this article
Office Manager HIPAA Compliance Checklist for Dental Practices

Use this practical checklist to run day-to-day HIPAA compliance with confidence. It focuses on safeguarding electronic Protected Health Information (ePHI), aligning people, processes, and technology so your dental practice can deliver care while staying compliant.

The steps below translate HIPAA’s Privacy, Security, and Breach Notification Rules into focused office manager actions. Tailor each item to your operations and document how you meet requirements.

Governance and Assigned Responsibility

Strong governance makes compliance repeatable. Assign clear ownership, keep policies current, and run a disciplined compliance calendar tied to measurable outcomes.

  • Appoint and document a Privacy Officer and a Security Officer (one person may serve both). Define decision authority and escalation paths.
  • Publish and maintain written policies and procedures covering privacy, security, breach response, sanctions, and access control policies. Review and re-approve at least annually.
  • Establish an incident response plan with roles, contact trees, and step-by-step playbooks. Test via tabletop exercises and revise after each test or real event.
  • Create a compliance calendar: policy reviews, risk analysis, workforce training, vendor/BAA reviews, contingency testing, and audits.
  • Maintain a risk register linking each risk to controls, owners, and timelines for risk assessment and remediation.
  • Retain compliance documentation (policies, logs, training, risk analyses, BAAs) for required retention periods.
  • Report compliance status to owners or leadership on a defined cadence; record decisions and follow-ups.

Documentation to keep

  • Current policy manual and version history
  • Risk analysis, remediation plans, and evidence of completion
  • Training curriculum, attendance, and acknowledgments
  • Security incident and breach logs with lessons learned
  • Access reviews, user provisioning/deprovisioning records
  • BAA inventory and vendor due diligence files
  • Device/media inventory and disposal certificates

Security Risk Analysis and Risk Management

Perform a structured risk analysis, then drive down risk with prioritized remediation. Treat this as a living program, not a one-time project.

  • Inventory where ePHI lives and flows: EHR, imaging, billing/clearinghouses, email, patient portal, backups, and any third parties.
  • Identify threats and vulnerabilities (phishing, lost devices, misconfigurations, ransomware, unauthorized access) and score likelihood and impact.
  • Select and implement controls (encryption, MFA, segmentation, backups, logging, patching) and map each to specific risks.
  • Publish a time-bound remediation plan with owners, budgets, and milestones; track progress to closure.
  • Test controls: vulnerability scanning, phishing simulations, restore-from-backup drills, access recertifications.
  • Update the risk analysis when your environment changes (new EHR, imaging systems, remote work, mergers) and on a set annual cadence.
  • Keep evidence: screenshots, configurations, service tickets, and sign-offs supporting completed actions.

Workforce Access and Training

Your workforce is the first line of defense. Grant the minimum necessary access, verify identities robustly, and train continuously.

  • Define role-based access control policies. Map permissions to job functions; prohibit shared logins and enforce unique user IDs.
  • Require strong passwords and enable multi-factor authentication (MFA) for EHR, email, VPN, and any remote or privileged access.
  • Use standardized checklists for onboarding, transfers, and terminations. Disable access on the employee’s last day and collect badges, keys, and devices.
  • Conduct HIPAA training at hire and at least annually, covering privacy basics, phishing, secure messaging, device security, and incident reporting.
  • Obtain signed acknowledgments of policies and sanctions; retain training and attestation records.
  • Run periodic access reviews with managers to confirm least-privilege access remains appropriate.

Technical Safeguards

Configure systems to prevent, detect, and contain threats to ePHI across endpoints, servers, cloud services, and networks.

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

  • Access controls: unique IDs, automatic logoff/timeouts, session locking, and privileged access management for administrators.
  • Authentication: enforce MFA wherever feasible; restrict legacy protocols; monitor for failed login anomalies.
  • Encryption: protect ePHI in transit (TLS) and at rest (full-disk encryption for laptops, encrypted backups, encrypted removable media).
  • Transmission security: use secure messaging/portals for PHI; require VPN or secure channels for remote access.
  • Audit controls: enable and retain logs for EHR, file stores, cloud apps, and network devices; review high-risk events regularly.
  • Integrity and malware protection: modern endpoint protection/EDR, prompt patching, limited local admin rights, and change management for critical systems.
  • Availability: automated, tested backups; defined recovery objectives; documented disaster recovery and emergency mode operations.
  • Mobile and BYOD: mobile device management, enforced encryption, remote wipe, and clear usage rules if permitted.

Physical Safeguards and Device Lifecycle

Control physical access and manage devices from purchase through disposal to prevent unauthorized viewing, loss, or theft of ePHI.

  • Facility controls: locked server/network rooms, visitor sign-in and escorts, cameras/alarms where appropriate, and environmental protections.
  • Workstation security: position screens away from public view, use privacy filters, auto-lock idle screens, and manage print/fax queues securely.
  • Asset management: maintain a complete inventory with ownership, location, and configuration; tag devices and track chain of custody.
  • Portable media: minimize use; require encryption and sign-out logs; prohibit unapproved USB storage.
  • Device lifecycle:
    • Procurement: select equipment that supports encryption, patching, and management.
    • Deployment: standard images, hardened configurations, and enrollment in management tools.
    • Transfer/repair: remove ePHI or use BAAs with repair vendors; document custody.
    • Disposal: securely wipe or physically destroy storage and retain certificates of destruction.

Vendors and Business Associate Agreements

Third parties that create, receive, maintain, or transmit PHI are business associates. Manage their risk before and after onboarding and keep Business Associate Agreements (BAAs) current.

  • Identify all vendors touching PHI/ePHI (EHR, billing/clearinghouses, imaging cloud, IT support, shredding, answering services, email/security providers).
  • Perform due diligence: security questionnaires, independent assessments or attestations, incident history, subcontractor lists, and data location.
  • Execute BAAs before sharing PHI and review them periodically.

Essential BAA elements to confirm

  • Permitted and required uses/disclosures of PHI and prohibition of others.
  • Administrative, physical, and technical safeguards appropriate to ePHI.
  • Incident reporting timelines and breach notification requirements to the covered entity without unreasonable delay (no later than 60 days after discovery).
  • Flow-down requirements to subcontractors handling PHI.
  • Support for access, amendment, and accounting of disclosures.
  • Right to audit or obtain security attestations and corrective action.
  • Termination provisions, including return or destruction of PHI.
  • Allocation of responsibilities and points of contact; cybersecurity insurance is advisable.

Privacy Operations

Operationalize the Privacy and Breach Notification Rules so daily workflows stay compliant while enabling patient care and billing.

  • Notice of Privacy Practices: provide at first service when applicable, post in-office and online as appropriate, and obtain acknowledgments.
  • Minimum necessary: design workflows that limit PHI exposure and require purpose-based access.
  • Authorizations: obtain and log written authorization for uses outside treatment, payment, and operations (e.g., marketing, testimonials, certain disclosures).
  • Patient rights: timely access to records, amendments, confidential communications, restrictions, and accounting of disclosures; use standardized request and response templates.
  • Incident handling: follow the incident response plan, complete a four-factor risk assessment, decide if a breach occurred, and document rationale.
  • Breach notifications: notify affected individuals without unreasonable delay and no later than 60 days after discovery; notify regulators and media when thresholds are met; consider stricter state timelines.
  • Complaint process: provide a non-retaliatory channel for privacy complaints and track through resolution.
  • Data retention and destruction: keep required records and securely dispose of PHI when retention ends.

Conclusion

HIPAA compliance is a continuous cycle: assess risk, implement controls, train people, monitor, and improve. By executing this checklist and documenting decisions, you can protect ePHI, meet regulatory duties, and keep your dental practice running smoothly.

FAQs

What are the key HIPAA responsibilities for an office manager in a dental practice?

Coordinate governance (officers, policies, sanctions), run the security risk analysis and drive risk assessment and remediation, manage workforce training and access control policies, maintain technical and physical safeguards, oversee vendors and Business Associate Agreements (BAAs), operate privacy workflows (notices, authorizations, patient rights), and lead the incident response plan and breach notifications with timely, well-documented actions.

How often should a dental practice update its HIPAA risk analysis?

Update at least annually and any time there are material changes—new EHR or imaging systems, significant software updates, new locations, remote work, third-party changes, or after incidents. Treat it as a living program: reassess, reprioritize, and verify that remediation remains effective.

What are the essential elements of a Business Associate Agreement?

Clear permitted uses/disclosures; required safeguards for ePHI; prompt incident reporting and breach notification requirements; subcontractor flow-down; support for access, amendment, and accounting; rights to verify compliance; termination with return/destruction of PHI; defined responsibilities and contacts. Cyber insurance is advisable though not mandated.

How should incidents involving PHI be reported and documented?

Report immediately to the Privacy/Security Officer, contain the issue, preserve evidence, and log details (who, what, when, where, systems, PHI types). Perform a four-factor risk assessment, determine if it is a breach, and follow the incident response plan. If a breach occurred, issue required notifications within HIPAA timelines, coordinate with BAAs when vendors are involved, and record corrective actions and lessons learned.

Share this article

Ready to simplify HIPAA compliance?

Join thousands of organizations that trust Accountable to manage their compliance needs.

Related Articles