A small practice’s clinical team may struggle to explain where patient information goes, no matter their length of time working at the practice or their patient privacy savviness. A referral arrives by fax. A staff member saves a document to a laptop’s hard drive. A scheduling vendor sends appointment reminders by text. Each activity raises a different operational question. Buying software described as HIPAA compliant does not answer them all. This is an all too common trap!
This guide gives practice owners and managers a way to prepare for a focused review. It separates the legal framework from practical work products you can assemble. The checklist is a discussion aid, not a certification or a substitute for advice specific to your practice.
Start with the practice you actually operate
Confirm whether the practice is a covered entity under HIPAA before choosing a checklist. HIPAA applies to covered entities and their business associates, and a provider's electronic standard transactions matter to that assessment. A small headcount is not a blanket exemption. If your business uses a cash-pay or membership model, start with our DPC and HIPAA guide rather than assuming the billing label decides the issue.
Describe your actual services on one page. Include locations, remote work, outside billing, cloud records, patient messaging and any recently added technology. Ask each staff member to name one place they store patient information. A brief conversation often reveals a workflow missing from the official technology inventory.
Give each unresolved question an owner
Use a working list with three columns: issue, responsible person, and next action. “Review access” is too vague to finish. “Office manager compares current employee list with active system accounts” identifies an action someone can complete and discuss.
Under the HIPAA Security Rule, HIPAA covered entities must address administrative, physical and technical safeguards for electronic protected health information. The framework includes risk analysis and risk management. HHS explains that implementation is flexible and scalable; the work still needs to reflect the organization's risks. See the HHS Security Rule overview.
A practical evidence folder might contain the current system inventory, risk-analysis materials, relevant policies, training records, and a list of open corrective actions. Keep it in an approved location. Do not create a second unmanaged collection of patient records while documenting your processes.
Follow one patient information journey
Choose a hypothetical appointment and trace the information from booking through follow-up. Who receives the first message? What happens to attachments? Can staff send reminders from personal accounts? Is staff using personal accounts, such as their personal email address, to bypass technical inefficiencies? Who can download records? What happens when a device fails?
For example, an office might use an approved portal but allow a temporary worker to export the day's appointments into a personal spreadsheet. The useful next step is to understand and correct that workflow. Purchasing a second portal does not resolve why the export happens.
Ask for demonstrations using test information. A live screen share containing patient details is usually unnecessary for the first planning conversation. Record the process, the decision-maker and the unresolved question, rather than collecting screenshots of real records.
Review vendors and patient-facing processes
Create a vendor list that describes services, information handled, system permissions, and the contract owner. Where a business associate relationship exists, evaluate the appropriate agreement and the underlying service. Our business associate agreement checklist explains the questions to take into that review.
Patient-facing work deserves equal attention. Review how a person requests records, raises a privacy concern, or asks the practice to communicate in a particular way. HHS's Privacy Rule summary explains the broader privacy framework. Staff should know where to route a request; improvising at the front desk makes consistent handling harder and increases risk.
Turn policy into a rehearsal
Choose one scenario for a staff huddle: a misdirected message, a lost device, or a departing employee. Ask who receives the first report, how the team preserves relevant information, and who decides the next step. The rehearsal is useful even if it exposes uncertainty. Capture that uncertainty as work to resolve, not a reason to discourage reporting.
HHS OIG's General Compliance Program Guidance is a voluntary, nonbinding resource for broader healthcare compliance. It can support planning, but it does not replace the analysis of mandatory rules applicable to your organization.
Bring a short agenda to counsel
Start with the three questions that most affect operations. A focused agenda might be: whether a new vendor relationship needs further review, how staff should handle an incident report, and which policy needs revision before a service launches. Attach an inventory or issue list only through a channel agreed with counsel.
Kim Cunningham of Cunningham Law, LLC advises healthcare providers and businesses on compliance, privacy, contracts, and government oversight. Use the healthcare practice page to understand that work or request a free 30-minute consultation. Keep the first inquiry general. This federal overview does not resolve state confidentiality rules or every requirement affecting a particular practice.

