Free compliance & forms tool

HIPAA Compliance Checklist for Small Practices

A HIPAA compliance checklist for a small practice covers three rule sets: the Privacy Rule (who may see patient information and what patients can request), the Security Rule (safeguards for electronic PHI, starting with a risk analysis) and the Breach Notification Rule (a 60-day clock). The 38 items below each cite the regulation, so you can check them off, print the list and show your work.

Prepared by Prospyr · Reviewed October 3, 2026 · Free, no sign-up, runs in your browser

HIPAA checklist for small practices: what each rule asks for

Privacy Rule. It governs when patient information may be used or shared. For a small practice the work is mostly administrative: name a privacy official, hand patients your Notice of Privacy Practices, train the team, limit access to the minimum necessary, answer access requests within 30 days, and keep it all in writing.

Security Rule. It covers electronic PHI in your EHR, email, text messages, laptops, phones and backups. The anchor requirement is a risk analysis. Everything else, such as unique logins, backups, encryption decisions and workstation controls, follows from what that analysis finds.

Breach Notification Rule. It sets the clock when unsecured PHI is used or disclosed in a way the Privacy Rule does not allow. You assess four factors, then notify patients, HHS and sometimes the media.

Does HIPAA apply to my practice?

HIPAA applies to covered entities (health plans, clearinghouses and health care providers that transmit health information electronically in a covered transaction) and to their business associates. A provider that bills insurance electronically is covered. A strictly cash-pay aesthetic practice may not be, but that is a legal question for your attorney, and many practices adopt HIPAA safeguards anyway because patients, partners and malpractice carriers expect them.

This checklist is written for covered practices. It is not legal advice, and state law can add requirements.

HIPAA checklist for med spas and aesthetic practices

Three items trip up aesthetic practices more than most.

  • Photos and testimonials. Before-and-after photos and patient reviews used to promote your practice are marketing, which needs a signed authorization under 45 CFR 164.508(a)(3).
  • Texting and email. Appointment reminders and photo sharing need a platform that signs a business associate agreement and encrypts messages, or a documented alternative.
  • Vendors everywhere. Scheduling, payment, marketing, chat and note-taking tools all see PHI. Each needs an agreement on file.

Prospyr's aesthetic EMR and digital intake keep consent forms and patient records in one place, which makes several of these items easier to document. See our HIPAA and BAA comparison for what to ask any software vendor.

Worked example: scoring your checklist

A 12-person aesthetic practice works through the 38 items. It marks 3 items not applicable to its setup. Of the remaining 35, it has completed 21. Progress is 21 ÷ 35 = 60%. The open items are the risk analysis, the risk management plan, the written breach procedure and the business associate agreements for two vendors. Those four go first, because the risk analysis is the requirement the Security Rule builds everything else on.

Next steps: run the HIPAA risk assessment questionnaire, and save the breach deadline calculator for the day you need it.

Frequently asked questions

What is on a HIPAA compliance checklist?

A HIPAA checklist covers the Privacy Rule, the Security Rule and the Breach Notification Rule. In practice that means a named privacy official and security official, a Notice of Privacy Practices, written policies, staff training, business associate agreements, a documented risk analysis, access and backup controls, and a breach response plan. The checklist above lists each item with its 45 CFR citation.

Does my med spa or cash-pay practice need to follow HIPAA?

HIPAA applies to a covered entity, and the regulation defines a covered health care provider as one that transmits health information electronically in connection with a covered transaction, such as billing insurance electronically. A practice that never bills insurance electronically may not be a covered entity, but state privacy laws and your own vendors' terms can still apply. Ask your attorney to confirm your status, and note that most practices follow HIPAA-style safeguards either way.

Is there an official HIPAA compliance certification?

No. HHS does not certify practices, software or training programs as HIPAA compliant. Compliance means you can show you meet each requirement, which is why the checklist keeps a record for each item and why the Security Rule requires written documentation kept for six years.

What is the difference between required and addressable in the Security Rule?

Required specifications must be implemented as written. Addressable ones, such as encryption and automatic logoff, must be implemented if reasonable, or you document why an equivalent alternative is reasonable, or why neither is. Addressable does not mean optional. Items marked Required or Addressable in the checklist follow the labels in 45 CFR 164.308, 164.310 and 164.312.

How often should I review my HIPAA checklist?

Review it at least once a year and whenever you change systems, add a vendor, move locations or have an incident. The Security Rule requires periodic evaluation and says to review and update documentation in response to environmental or operational changes. Put the review date on the printout and keep the signed copy.

Do I need a business associate agreement with my software vendors?

Yes, with any vendor that creates, receives, maintains or transmits PHI on your behalf, such as your EHR, texting platform, billing company, cloud storage and IT support. The agreement is a required part of the Security Rule's organizational standard. Keep a list of vendors with the signed agreement date next to each one.

How long do I have to report a breach?

Notify affected individuals without unreasonable delay and no later than 60 calendar days after discovery. HHS and the media may also need notice depending on how many people are affected. Use the HIPAA breach notification calculator on this site to turn a discovery date into each deadline.

Sources and scope

Educational checklist, not legal advice. It summarizes federal HIPAA regulations in plain language and does not certify compliance. State law may add requirements; confirm with your attorney or compliance officer.

Report a correction

Run your practice on one system