← Back to Compliance Insights

August 8, 2026  ·  Jonah Gobah

The HIPAA Risk Assessment Checklist Small Practices Actually Need

Ask ten small practice owners whether they've done a HIPAA risk assessment, and most will say something like "we're pretty careful with patient records." That's not the same thing, and it's usually the first gap an auditor finds.

The HIPAA Security Rule doesn't just expect you to be careful — it expects you to have systematically reviewed where electronic Protected Health Information (ePHI) lives, who can get to it, what could go wrong, and what you've done about it. That review is the risk assessment, and it's not optional. It's the foundation everything else in your compliance program sits on.

Here's what it actually covers, broken into the ten areas OCR expects a practice to have thought through.

1. Where does patient information actually live?

Before you can protect ePHI, you need a real inventory of everywhere it exists — not just the EHR. That usually includes practice management software, billing systems, Microsoft 365 or Google Workspace, employee laptops and phones, cloud storage, backup systems, and yes, the USB drive someone used once and forgot about. Most practices find at least one location they hadn't accounted for the first time they do this properly.

2. Who has access, and why

Excessive access is one of the most common findings in small-practice audits. Ask whether every employee's access matches what their job actually requires, whether terminated employees are removed immediately rather than "eventually," whether passwords are unique, and whether multi-factor authentication is actually turned on — not just available.

3. Physical security, not just digital

HIPAA covers paper as much as it covers servers. Are workstations positioned so screens aren't visible from the waiting room? Are devices locked when a provider steps away? Are paper charts stored somewhere more secure than an open shelf? This section gets skipped constantly because people think of HIPAA as purely a technology problem.

4. Technical safeguards

This is the part most practices do have some version of — antivirus, firewalls, encrypted disks, automatic updates, secured Wi-Fi, regular backups. The gap is usually less about whether these exist and more about whether they're documented and consistently maintained.

5. Administrative safeguards

This is where most audits actually get won or lost. Do you have a written security program, not just informal habits? Has someone been formally designated as your Security Officer? Is there a documented incident response plan? Are policies reviewed on some regular cadence, not written once in 2022 and never touched again?

6. Vendors and Business Associates

Any vendor that touches PHI — your billing company, IT provider, cloud backup service, email vendor — needs a signed Business Associate Agreement. This is consistently one of the most common gaps auditors find: practices that assumed a small vendor didn't need a BAA, or never followed up to get one signed.

7. Employee training

People remain the most common point of failure — not because staff are careless, but because training happened once, during onboarding, three years ago. Phishing recognition, password hygiene, and knowing how to report a suspected incident all need to be reinforced periodically, not covered once and assumed to stick.

8. Documenting the risks you find

Identifying a gap isn't the finish line — OCR wants to see that you documented it: what the risk is, how likely it is, what it would mean if it happened, what safeguards already exist, and what you plan to do about it, with a target date. A risk assessment that doesn't produce a written record of findings isn't one that will hold up under review.

9. Keeping the evidence somewhere real

Policies, training certificates, signed BAAs, audit logs, incident reports, prior risk assessments — all of it needs to live somewhere organized enough that you could produce it on short notice. The practices that struggle most during an actual audit aren't usually the ones with the worst security. They're the ones whose evidence is scattered across email threads, a shared drive, and someone's desk drawer.

10. Doing it again

A risk assessment isn't a one-time project. It should be revisited at least annually, and sooner after a major technology change, a security incident, a new vendor, or an office move. A risk assessment from three years ago that's never been updated tells an auditor more about your program than you'd like it to.

Where this usually goes wrong

The mistakes we see repeatedly aren't exotic — they're practices that did a risk assessment exactly once, let training lapse after the first year, never circled back to confirm a BAA actually got signed, and ended up with compliance documents spread across four different places by the time anyone needed to find them.

None of that requires bad intentions. It's just what happens when compliance depends on someone remembering to do it manually, on top of everything else running a practice involves.

How Truvidence helps small medical practices

Keeping up with HIPAA requirements is hard without a dedicated compliance officer — and most small practices don't have one. That's the problem Truvidence was built to solve.

Instead of spreadsheets, scattered documents, and manual reminders, Truvidence gives your practice one centralized place to manage HIPAA Security Rule compliance:

  • Complete an AI-guided HIPAA Security Rule risk assessment
  • Generate compliance documentation and security policies
  • Store audit evidence securely in one place
  • Track Business Associate Agreements
  • Monitor employee training
  • Receive automated compliance reminders
  • Generate annual compliance reports
  • Maintain an organized compliance timeline
  • Prepare audit-ready documentation whenever it's needed

Instead of wondering whether your compliance program is complete, you'll have a clear picture of where you stand and what needs attention — well before an audit forces the question.

FREE DOWNLOAD

HIPAA Security Rule Readiness Checklist

The 9-point checklist every practice needs. Delivered instantly to your inbox.

Truvidence

Ready to get your practice HIPAA compliant?

Truvidence gives you everything you need — risk assessments, policy documentation, staff training, and the Verified™ seal — without hiring a compliance consultant.

Get Started →More Articles