HIPAA guide
HIPAA Security Rule: an IT checklist for dental offices
A plain-English guide to the HIPAA Security Rule for dental offices: what it covers, what “addressable” really means, and an IT checklist for each type of safeguard.
If your dental office is covered by HIPAA, the HIPAA Security Rule sets the national standards for protecting the patient information on your computers. Much of what it asks for touches your IT: your network, computers, backups and logins. Use the checklists below to see where your office stands.
This guide is general information, not legal advice.
What the HIPAA Security Rule covers
The Security Rule is set out in 45 CFR Part 164, Subpart C. It protects electronic protected health information (ePHI): individually identifiable health information your practice creates, receives, maintains or transmits electronically. In a dental office, that includes the practice management database, charts, digital X-rays, billing records and emails about patients.
The rule applies to covered entities and their business associates. A dental practice of any size is a covered entity if it sends health information electronically for a transaction HHS has set a standard for, such as an insurance claim or eligibility check, directly or through a billing service. Filing claims electronically puts your office in that group.
Under 45 CFR 164.306, you must protect the confidentiality, integrity and availability of all ePHI, guard against reasonably anticipated threats, and make sure your workforce complies. The rule is flexible on purpose: you choose measures by weighing your practice’s size, complexity and capabilities, your technical setup, the cost of each measure, and how likely and serious each risk is.
The safeguards come in three groups: administrative (164.308), physical (164.310) and technical (164.312).
Required vs. addressable: what the labels mean
Each group is made up of standards, and many standards list implementation specifications that spell out how to meet them. Each specification is labeled required or addressable. Every standard must be met, and where a standard lists no specifications, the standard itself is the requirement.
Required means you must implement it. Addressable does not mean optional. Under 45 CFR 164.306(d)(3), for each addressable specification you must:
- Assess it, deciding whether it is a reasonable and appropriate safeguard for your practice.
- Implement it if it is reasonable and appropriate.
- If it is not, document why, and implement an equivalent alternative measure if that is reasonable and appropriate.
An addressable item you simply ignored is a gap, not a decision.
| Question | Required | Addressable |
|---|---|---|
| Do you implement it? | Yes, always | Yes, if reasonable and appropriate |
| Can you decide not to? | No | Only after assessing it and writing down why |
| What do you document? | Your policies and procedures for it | Your assessment, your decision and any alternative |
In the checklists below, “required” marks a requirement you must meet as written. Treat unmarked items as addressable: assess each one and record your decision.
Administrative safeguards checklist (45 CFR 164.308)
Administrative safeguards are the management side of security: responsibility, risk, training, and planning for when things go wrong.
Risk analysis and risk management
Everything builds on the risk analysis, a required specification: an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of your ePHI. Risk management, also required, means security measures that reduce those risks to a reasonable and appropriate level.
HHS offers a free Security Risk Assessment (SRA) Tool for small and medium-sized practices that walks you through the analysis and records your answers. Using it does not by itself guarantee compliance.
Security awareness training
The training program itself is required for your whole workforce, including dentists, managers and part-time staff. Its addressable specifications cover security reminders, protection from malicious software, log-in monitoring and password management.
Contingency plan
The contingency plan covers emergencies that damage systems holding ePHI, from a failed server to a fire or power outage. A data backup plan, a disaster recovery plan and an emergency mode operation plan are required. Testing and revising the plan, and ranking which applications and data matter most, are addressable. Our guides to backing up a dental office and power outage and surge protection cover the practical side.
Business associate contracts
Any vendor that creates, receives, maintains or transmits ePHI on your practice’s behalf is a business associate, and an IT provider with access to your systems usually is one. Under 45 CFR 164.308(b) and 164.314(a), you need a written business associate agreement (BAA) in which the vendor agrees to safeguard that information. Business associates must also follow the Security Rule themselves. When you compare IT companies, a signed BAA belongs on your checklist for choosing a dental IT provider.
Your administrative checklist:
- Name a security official responsible for your policies (required).
- Complete a written risk analysis and a risk management plan (required).
- Apply a sanction policy to staff who break security rules (required).
- Regularly review audit logs and access reports (required).
- Limit access to what each job needs, and remove it promptly when someone leaves.
- Train every workforce member, including the dentists (required).
- Send regular security reminders about phishing and passwords.
- Write down how you report and respond to security incidents (required).
- Keep backup, disaster recovery and emergency mode plans (required).
- Test your restores and update the plan afterward.
- Evaluate your safeguards periodically and after major changes (required).
- Sign a BAA with every business associate that handles ePHI (required).
Physical safeguards checklist (45 CFR 164.310)
Physical safeguards protect the places and equipment that hold ePHI: your office, the server closet, workstations and devices.
Facility access controls
Limit physical access to your systems while letting authorized people in. All four specifications here are addressable: contingency operations, a facility security plan, access control and validation procedures, and records of security-related repairs, such as to doors and locks.
Workstation use and security
Two required standards cover workstations. Workstation use means policies on how computers that access ePHI are used and where they sit, such as front desk screens angled away from the waiting room. Workstation security means physical safeguards that restrict them to authorized users.
Device and media controls
Disposal and media re-use are required: remove ePHI before a computer or drive is thrown away or reused. Tracking where hardware and media go and who is responsible, and making a retrievable copy of ePHI before you move equipment, are addressable.
Your physical checklist:
- Keep the server and network equipment in a locked room or cabinet.
- Control keys and door codes, and change them when staff leave.
- Write workstation policies, including where screens face, so patients cannot read them (required).
- List every computer, tablet and drive that holds ePHI.
- Wipe or destroy drives before disposal or reuse (required).
- Make a backup copy before moving or replacing equipment.
Technical safeguards checklist (45 CFR 164.312)
Technical safeguards are the technology, and the policies for using it, that protect ePHI and control who can reach it.
Access control
Unique user identification and an emergency access procedure are required: every person gets their own login, and you can reach ePHI in an emergency. Shared logins make it impossible to tell who did what. Automatic logoff and encryption and decryption are addressable. If you decide not to encrypt laptops and backup drives that leave the building, you need a written reason and, where reasonable, an equivalent alternative, and few alternatives protect the data on a lost device.
Audit controls and integrity
Audit controls are required: hardware, software or procedures that record and examine activity in systems that contain ePHI. The integrity standard requires policies that protect ePHI from improper alteration or destruction; electronic checks that confirm it is unchanged are addressable.
Authentication and transmission security
Person or entity authentication is required: you must verify that anyone seeking access to ePHI is who they claim to be. Transmission security protects ePHI sent over a network, such as email and remote connections, with addressable specifications for integrity controls and encryption. A securely configured office network and carefully set up remote and home office connections support both.
Your technical checklist:
- Give every person a unique login, with no shared accounts (required).
- Document how to reach ePHI in an emergency (required).
- Set computers to lock or log off automatically when idle.
- Encrypt laptops and portable drives, or document why not and your alternative.
- Record activity in your practice software and server (required).
- Protect records from improper changes or deletion (required).
- Verify everyone who logs in (required), for example with strong passwords plus a second factor for remote and email access.
- Protect ePHI you send by email or over remote connections.
Policies, documentation and regular review
Under 45 CFR 164.316, you must keep written policies and procedures for your safeguards and a written record of any action, activity or assessment the rule requires, including your addressable decisions.
Keep that documentation for six years from the date it was created or last in effect, whichever is later. Make it available to the people who carry it out, review it periodically, and update it when your office, systems or risks change.
Where to start with the HIPAA Security Rule
The work runs in a cycle, not a straight line.
- Risk analysis
- Safeguards
- Policies
- Review
The three safeguard groupsIn short
- AdministrativeResponsibility, risk analysis, training and planning
- PhysicalYour office, workstations and devices
- TechnicalLogins, activity records and data in transit
Write down every decision, including addressable ones
Start with the risk analysis, because it shows which safeguards matter most in your practice. Then work through the three checklists, write down what you decided and why, and set a date to review it all.
Your IT provider can put many technical and physical safeguards in place, but the risk analysis, the policies and the decisions remain your practice’s responsibility. For help with the IT side, talk to My Dental IT about your office.
How My Dental IT helps
We sign a formal HIPAA business associate agreement with every customer. Read how our business associate agreement works.
We configure your office network to be secure and protect it against intruders and unauthorized users, install and maintain malware and virus protection, and set up backup systems and recovery software so vital data is not lost. We also keep you informed of every change to your network, planned maintenance and system updates.
Questions
HIPAA Security Rule questions from dental offices
Does the HIPAA Security Rule apply to paper records?
No. The Security Rule covers electronic protected health information only. Paper charts and printed schedules fall under the HIPAA Privacy Rule, which protects health information in any form. If your office keeps charts, schedules and billing on computers, the Security Rule reaches most of the patient information you handle.
Do we need a business associate agreement with our IT company?
If your IT company creates, receives, maintains or transmits ePHI for your practice, it is a business associate, and the Security Rule requires a written agreement in which it promises to safeguard that information. An IT provider with access to your server, workstations or backups usually falls into that group. My Dental IT signs a HIPAA business associate agreement with every customer.
How often should a dental office update its risk analysis?
The Security Rule does not set a fixed schedule, and HHS guidance treats risk analysis as an ongoing process. The rule also requires periodic evaluations of your safeguards and a fresh look when your environment or operations change (45 CFR 164.308(a)(8)). A sensible habit is a regular review date, such as once a year, plus a revisit after a new server, new practice software, an office move or a security incident.
Related
More on HIPAA and protecting patient data
HIPAA
Our HIPAA business associate agreement
What a signed BAA covers and how we protect your patients’ data.
Guide
How to back up a dental office
What to protect, the 3-2-1 rule and why a backup only counts once you have tested the restore.
Guide
How to protect a practice from ransomware
The habits and safeguards that make an attack less likely and recovery faster.
Get help with the IT behind your HIPAA checklist
Tell us about your office and we’ll talk through your network, backups and malware protection. Every customer gets a signed HIPAA business associate agreement.