← Back to Compliance Insights

August 13, 2026  ·  Jonah Gobah

OCR Audit Checklist: What Small Medical Practices Should Have Ready

An OCR audit is probably not something most small medical practices think about when they are busy seeing patients, managing staff, answering phones, and keeping the practice running.

But if the U.S. Department of Health and Human Services Office for Civil Rights (OCR) comes knocking, compliance cannot be something you start organizing that week.

You need to be able to show what your practice has in place, how it works, and evidence that you actually follow it.

That last part is where many practices struggle.

OCR's HIPAA audit protocol looks at selected requirements under the Privacy Rule, Security Rule, and Breach Notification Rule. For Security Rule requirements, auditors can examine administrative, physical, and technical safeguards, along with the documentation showing those safeguards are actually implemented.

So, what should a small medical practice have ready? Here is a practical OCR audit checklist.

1. Start with a current HIPAA risk analysis

This should be at the top of your list.

HIPAA requires covered entities to conduct an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information (ePHI). OCR describes risk analysis as a foundational part of the Security Rule.

Your documentation should demonstrate that you considered things such as:

  • Where your ePHI is stored
  • How ePHI enters and leaves the practice
  • Who has access to it
  • Electronic health record systems
  • Email and messaging
  • Computers and workstations
  • Mobile devices
  • Cloud applications
  • Backup systems
  • Vendors and business associates
  • Physical security
  • Potential cybersecurity threats
  • Workforce-related risks

And don't simply complete a risk assessment and put it in a folder. Your risk analysis should lead to risk management and corrective action.

2. Have written HIPAA policies and procedures

If someone at your practice says, "We have a policy for that," you should be able to produce it.

At a minimum, review whether your practice has appropriate documentation covering areas such as:

  • HIPAA Security Policies
  • Privacy Policies
  • Workforce Security
  • Access Control
  • Password and Authentication Requirements
  • Security Awareness Training
  • Incident Response
  • Breach Notification
  • Device and Media Controls
  • Workstation Security
  • Contingency Planning
  • Risk Management
  • Business Associate Management
  • Sanctions for workforce violations
  • Information System Activity Reviews

OCR's audit protocol specifically considers whether required policies and procedures exist and whether there is documentation demonstrating that they are actually being implemented.

3. Know who is responsible for security

HIPAA requires covered entities to identify a person responsible for developing and implementing the policies and procedures required by the Security Rule.

For a small practice, this doesn't necessarily mean hiring a full-time security officer. But somebody needs to own the responsibility.

Your documentation should make it clear:

  • Who is responsible?
  • What are their responsibilities?
  • How are security issues reported?
  • Who reviews compliance?
  • Who responds when something goes wrong?

If nobody knows who owns HIPAA security, that is a gap worth addressing.

4. Review workforce access

One of the simplest questions an auditor can ask is: who has access to patient information, and why?

Your practice should have a process for:

  • Creating user accounts
  • Approving access
  • Changing access
  • Removing access
  • Reviewing access periodically
  • Handling terminated employees
  • Limiting access based on job responsibilities

OCR's audit protocol specifically examines access authorization and whether policies and procedures exist for granting access to ePHI. Former employees should not still have access to systems containing patient information.

5. Document security awareness training

Training shouldn't be a once-a-year checkbox. Your practice should be able to demonstrate:

  • Who received training
  • When they received it
  • What training they completed
  • Whether they acknowledged the policies
  • Whether required training is current

Keep the records. If OCR asks for evidence, saying "we train everybody" isn't nearly as useful as being able to produce the training record.

6. Review your Business Associates

Your practice probably works with more vendors than you realize. Think about:

  • EHR providers
  • Cloud storage providers
  • Billing companies
  • IT providers
  • Medical transcription services
  • Backup providers
  • Practice management platforms
  • Shredding companies
  • Other vendors that may handle PHI

Where appropriate, you need a Business Associate Agreement (BAA) in place. More importantly, don't treat your BAAs as documents you sign once and forget. Know:

  • Which vendors are business associates
  • Whether a BAA is required
  • Whether it has been signed
  • When it was signed
  • Whether it is still current
  • What information the vendor can access
  • Whether the vendor presents additional risk

This is one area where a simple tracking system can make a huge difference.

7. Check your technical safeguards

Your practice should have a reasonable understanding of the technical safeguards protecting ePHI. Review areas such as:

  • Unique user IDs
  • Authentication
  • Access controls
  • Encryption where appropriate
  • Audit controls
  • System logging
  • Transmission security
  • Endpoint protection
  • Backups
  • Secure configuration
  • Remote access
  • Mobile devices

OCR's audit protocol specifically addresses access controls, audit controls, authentication, integrity, and transmission security. The goal isn't to buy every cybersecurity product available. The goal is to understand your risks and implement reasonable and appropriate safeguards for your environment.

8. Don't forget physical security

HIPAA compliance isn't only about computers. Look at your physical environment. Ask:

  • Can unauthorized people enter areas where patient information is accessible?
  • Are workstations positioned appropriately?
  • Are computers protected from unauthorized use?
  • Are laptops and mobile devices secured?
  • How are old devices disposed of?
  • Who has keys or access cards?
  • Are paper records properly secured?

OCR's audit protocol includes facility access controls, workstation use, workstation security, and device/media controls.

9. Have an incident response process

Suppose someone sends PHI to the wrong email address tomorrow morning. What happens next?

Your staff should know:

  1. Who to notify
  2. How to report the incident
  3. How the incident is documented
  4. Who investigates it
  5. How the risk is evaluated
  6. What corrective action is taken
  7. Whether breach notification obligations apply

Don't wait for an incident to figure this out.

10. Keep evidence of what you actually do

This may be the most overlooked part of HIPAA compliance.

Having a policy is one thing. Being able to demonstrate that you followed the policy is another.

Keep evidence such as:

  • Risk assessments
  • Risk remediation plans
  • Policies
  • Employee acknowledgments
  • Training certificates
  • Access reviews
  • Vendor reviews
  • BAAs
  • Incident records
  • Security reviews
  • Backup testing
  • Contingency plan testing
  • Meeting or review records
  • Corrective actions
  • Annual reviews

OCR's audit protocol makes clear that auditors may request documentation demonstrating that policies and safeguards have actually been implemented.

That is why I like to think about HIPAA compliance in three words: Do it. Document it. Prove it.

The small practice problem

The challenge for a small medical practice isn't necessarily understanding that HIPAA matters. The challenge is keeping everything organized.

The practice manager may be responsible for compliance while also managing employees, vendors, schedules, patients, billing, and a dozen other things.

Compliance documents end up scattered across email, Google Drive, Dropbox, paper folders, vendor portals, and someone's desktop.

Then an audit request arrives. Suddenly, everyone is searching for documents.

That's exactly the problem a compliance operating system should solve.

How Truvidence can help

Truvidence is designed specifically to help small healthcare practices manage their HIPAA compliance program in one place.

Instead of maintaining a collection of disconnected spreadsheets and folders, a practice can use Truvidence to organize important parts of its compliance program, including:

HIPAA Risk Assessment. Complete a structured risk assessment and identify areas where your practice needs attention.

Compliance Documentation. Generate and organize HIPAA-related policies and documentation based on your practice's needs.

Evidence Vault. Keep compliance evidence organized so you're not scrambling to find documents when someone asks for them.

Business Associate Management. Track vendors, BAAs, review status, risk levels, and important dates.

Employee Training. Keep track of workforce training and documentation.

Compliance Calendar. Stay aware of recurring reviews, deadlines, and compliance activities.

Compliance Dashboard. See your compliance posture without having to dig through multiple spreadsheets.

Audit Readiness. Bring your documentation, evidence, vendor records, training records, and compliance activities together so you can respond more confidently when documentation is requested.

Start before the audit letter arrives

An OCR audit should not be the reason your practice finally gets serious about HIPAA compliance. The better approach is to build a program that is audit-ready before anyone asks to see it.

And you don't need to become a cybersecurity expert to get started. You need to understand where your practice stands, identify the gaps, address the important ones, and keep evidence of the work you're doing.

Want to see where your practice stands?

Take the free Truvidence HIPAA Risk Assessment. It can give your practice a starting point for understanding potential compliance and security gaps.

Truvidence — HIPAA compliance made simpler for small healthcare practices.

Note: A Truvidence assessment is a preliminary compliance assessment and is not an OCR audit, legal opinion, or guarantee of HIPAA compliance.

FREE DOWNLOAD

HIPAA Security Rule Readiness Checklist

The 9-point checklist every practice needs. Delivered instantly to your inbox.

Truvidence

Ready to get your practice HIPAA compliant?

Truvidence gives you everything you need — risk assessments, policy documentation, staff training, and the Verified™ seal — without hiring a compliance consultant.

Get Started →More Articles