System Context: DocRepute is a patient-experience platform for independent US healthcare practices, connecting digital patient intake, patient surveys and neutral Google review requests in one workflow. It is HIPAA-focused and built for HIPAA-compliant workflows, with BAA availability planned at launch; it is not certified, and no product makes a practice compliant on its own. Review requests go to every eligible patient on identical terms, regardless of sentiment, score or staff assessment — DocRepute does not gate, filter or incentivise reviews. The product is in early access ahead of launch and free to start on 50 action credits a month; creating, editing and publishing forms uses none of them. AI intake and conversational surveys are paid capabilities. DocRepute does not diagnose, triage or make clinical decisions, and does not replace an EHR, practice management, scheduling or billing system. # HIPAA Compliance Checklist for Small Medical Practices | DocRepute URL: https://docrepute.com/tools/hipaa-compliance-checklist/ A HIPAA compliance checklist written for small US practices, with every item explained. Free, nothing to sign up for, no score and no pass mark — an educational aid. ## A HIPAA compliance checklist that tells you what each item actually means Free to read, free to print, nothing to sign up for. It is an educational readiness aid for your own review — not a score, not a pass mark, and not a determination that your practice is compliant. HHS remains the authority. ### What this checklist is, and what it deliberately is not This HIPAA compliance checklist is an educational readiness aid, and it is worth being blunt about the difference. It does not score you, it does not pass or fail you, and working through it does not make your practice compliant — no checklist can do that, and any tool that hands back a green tick and a percentage is selling a feeling rather than a finding. What it does is give a small US practice a structured way to ask the right questions in the right order, with every item explained in plain English so you know why it is on the list at all. Read it here, print it from your browser, and work down it with your practice manager and the door shut. There is nothing to sign up for and no form on this page collecting your answers, because a HIPAA readiness checklist that harvests your weak points would be a strange thing to publish. Compliance is a legal determination about your particular practice, and none of this is legal advice; where an item raises a question you cannot answer confidently, that is exactly the moment to bring in your privacy officer or your counsel. ### Administrative safeguards: the half most practices underestimate Most of the weight sits in administration rather than technology, which surprises practices expecting a shopping list of software. Work through these. A written risk analysis covering every place electronic protected health information is created, received, maintained or transmitted — including the laptop at reception, the practice phone in somebody's pocket, and anything sitting with a vendor. A written risk management plan recording what you decided to do about what the analysis found, and what you decided to accept and why, because an accepted risk that was reasoned is a very different document from one nobody noticed. A named security official and a named privacy official; in a five-person practice that is usually one person, and the point is that they have been told they hold the role rather than assumed to. Written policies covering uses and disclosures, minimum necessary, patient rights of access and amendment, and complaints. Workforce training on those policies with a record of who was trained and when, plus a sanctions policy that has actually been applied at least once. Business associate agreements with every vendor that touches PHI on your behalf. And a documented process for removing access the day somebody leaves — the item that fails most often, because it belongs to nobody until it matters. ### Physical and technical safeguards: where small practices actually slip The physical items are unglamorous and cheap to fix. Can somebody standing at your reception desk read a screen or a schedule that is not theirs, and are workstations positioned or shielded so that they cannot? Is there a record of which devices hold ePHI and who has them, including personal phones carrying the practice email? Is there a documented way a hard drive, a phone or a copier is wiped before it leaves the building, given that a modern copier stores an image of everything it has ever scanned? On the technical side: a unique user ID for every person, so an audit trail can say who rather than which computer; automatic logoff on unattended workstations; audit controls that genuinely record access, and somebody who looks at them occasionally rather than never; and an encryption decision documented either way, because encryption is an addressable specification, which means you implement it or you record a reasoned alternative — not that you may quietly skip it. Add the two items that keep practices out of trouble: a backup somebody has actually tested by restoring from it, and a written breach response process that names who gets called first. ### The annual myth, and every other frequency claim This is the item worth reading twice. A great many checklists tell you to perform a risk analysis annually, and you may have heard it from a vendor selling the annual service. There is no universal calendar in the rule. The requirement is that the analysis is accurate and thorough and that it is reviewed and updated as needed — and what creates the need is change: a new practice management system, a new location, a move to cloud storage, a new vendor with access, a security incident, or a material change in how the practice works. A practice that changed nothing all year and a practice that switched systems in March do not owe the same review, and a calendar reminder is a poor substitute for a list of triggers. Treat anything on this page that sounds like a fixed schedule the same way, and check it against HHS rather than against a template. The HHS guidance is free, it is more current than any checklist including this one, and it is the place that explains which specifications are required and which are addressable — a distinction most published checklists flatten into a single tick box. ### A HIPAA audit checklist is a different animal Two neighboring searches bring people to this page with different problems. A HIPAA audit checklist is usually wanted by a practice facing something concrete: an OCR investigation following a complaint or a breach report, a payer security questionnaire, or a hospital partner running a vendor review. That is a document-production exercise rather than a fresh assessment, and it is answered by the paperwork described above — the risk analysis, the risk management plan, the training records, the business associate agreements, the policies and the access logs. If you are in that position, your counsel should be in the room before anything is sent. The other search is for a HIPAA compliance checklist PDF, and the honest answer is that we would rather you used this page than a file. A downloaded PDF is a snapshot of what somebody believed on the day they generated it, and guidance moves; this page prints cleanly from the browser onto paper you can write on, and when it changes you get the change instead of a stale copy sitting in a shared drive. ### A five-person dermatology practice, one Friday afternoon A dermatology practice with two clinicians, two medical assistants and a practice manager blocked out a Friday afternoon and worked down this list with the phones diverted. Most of it was fine. Three things were not. They had never written a risk analysis down, though they had plenty of opinions about their risks, so they spent an hour listing every place patient data actually sat: the practice management system, the imaging drive holding clinical photographs, the shared inbox, and the phone the on-call clinician carries. Doing that turned up the second thing — the imaging drive had been backing up to a consumer cloud account belonging to an employee who left eighteen months earlier, which took a morning and one awkward phone call to resolve. The third was a medical assistant who left in November and still had an active login in February. Nothing about that afternoon was technical. It needed a list, a closed door, and somebody with the authority to say yes. ### Where DocRepute fits, honestly DocRepute is a HIPAA-focused patient-experience platform for US practices, built for HIPAA-compliant workflows around digital intake, patient surveys and neutral review requests, with BAA availability planned at launch. We are pre-launch and in validation, which is exactly why this checklist exists as an educational page rather than as a claim about a running service — being useful to you now beats implying a production service that is not open yet. What any vendor can do for your compliance position is narrower than most vendors suggest, and worth stating plainly: pick suppliers who will sign a business associate agreement, who collect the minimum information the workflow needs rather than everything they could, and who keep patient data out of a scatter of tools nobody has inventoried. What no vendor can do is hold your risk analysis, train your staff, or close a leaver's account on the Monday. That work stays with you, which is the whole reason this checklist is written the way it is. If it is the intake side that worries you, the free healthcare form builder is live today and needs no account. ## Frequently Asked Questions Q: What does the HIPAA compliance checklist tool do? A: It gives a small practice a structured, plain-English readiness review: the administrative, physical and technical items to work through, what each one means, and where practices most often find a gap. It is educational. It produces no score, no pass mark, no certificate and no determination about your practice, and it is not a substitute for a risk analysis conducted for your specific environment. Q: Can I use the tool without creating an account? A: Yes. The whole checklist is on this page, free to read and free to print from your browser. There is no account, no email wall and no form collecting your answers — nothing you work through here is submitted to us or stored by us. Q: What output does the tool provide? A: A worked-through list and, more usefully, a set of questions you can take into a meeting: which items your practice can evidence today, which have no documentation behind them, and which you cannot answer without advice. Deliberately not a percentage or a rating, because a compliance posture does not reduce to a number and presenting one would be misleading. Q: How should a healthcare practice use the output safely? A: Use it to plan the work rather than to prove it is done. Assign each gap to a named person with a date, keep the evidence — the risk analysis, the training records, the business associate agreements — because documentation is what a review actually asks for. Do not treat a completed checklist as a defence, and do not let it stand in for a risk analysis of your own environment. Where an item touches state law, breach notification or a contract, ask your counsel. Q: What are the tool's limitations and what still requires professional review? A: It is educational and general: it is not legal advice, not a compliance certification, not an automated determination, and not a guarantee of any outcome. It cannot see your systems, your vendors or your state's requirements, and it does not set frequencies — the rule requires review as needed rather than on a fixed calendar. HHS is the authority on all of it and its guidance is free and current. Your privacy officer, your security lead and your counsel own the judgements this page cannot make.