24-Question Self-Assessment

HIPAA readiness checklist for dental practices.

Review the technology and documentation areas that most often need clear ownership: risk analysis, access, devices, backups, vendors, training, incidents, and evidence. Score the checklist on-page, download the printable PDF, and use the result to prioritize follow-up work.

Current-rule framing

HHS states that the current HIPAA Security Rule remains in effect and requires reasonable and appropriate administrative, physical, and technical safeguards for ePHI. HHS describes the rule as flexible, scalable, and technology neutral.

Risk analysis comes first

HHS calls risk analysis foundational and says all ePHI created, received, maintained, or transmitted is in scope. The rule does not prescribe one universal risk-analysis methodology for every practice.

Not a certification

This score is an educational prioritization aid only. It does not certify compliance, replace a complete risk analysis, or resolve organization-specific legal and privacy questions.

Interactive Checklist

How ready is your current environment?

Select Yes, Partial, No, or Not sure for each question. Yes = 2 points, Partial = 1, and No/Not sure = 0. Maximum score: 48.

Section 1

Governance and risk analysis

Confirm the practice knows where ePHI lives, has a current risk analysis, and turns findings into tracked remediation work.

1. Have you documented where electronic protected health information (ePHI) is created, received, maintained, or transmitted across your practice?
2. Have you completed and documented an accurate and thorough security risk analysis that reflects your current systems, vendors, locations, and workflows?
3. Do you maintain a prioritized risk-management plan showing identified risks, owners, target actions, and completion status?
4. Do you review security documentation when material technology, vendor, location, ownership, or workflow changes occur?

Section 2

Identity, access, and workforce controls

Review individual accounts, privileged access, stronger authentication, and the access lifecycle for workforce changes.

5. Does every workforce member use an individual account for systems that handle ePHI instead of shared administrator credentials?
6. Are privileged and administrator rights limited to named people who need them and reviewed periodically?
7. Is multi-factor authentication enabled where supported for remote access, email, cloud administration, and other high-risk accounts?
8. Do you have documented onboarding, role-change, and offboarding steps that include timely access changes?

Section 3

Devices, systems, and technical safeguards

Check asset visibility, supported systems, endpoint/network ownership, and documented encryption decisions.

9. Do you maintain a current inventory of workstations, servers, laptops, network devices, cloud systems, and other technology that can store or reach ePHI?
10. Are supported operating systems and security updates managed on devices that access ePHI?
11. Are endpoint protection, secure remote access, firewall/network controls, and logging responsibilities clearly assigned and monitored?
12. Have you evaluated encryption at rest and in transit for systems that store or transmit ePHI, documenting decisions where the current rule treats specifications as addressable?

Section 4

Backup, recovery, and continuity

Make sure backups are complete, protected, restorable, and connected to a documented contingency process.

13. Do you know exactly which clinical and business data is backed up, including practice-management databases and imaging repositories where applicable?
14. Are backup administration and recovery copies protected from the same credentials or incidents that could affect production systems?
15. Have you completed and documented a real restore test using representative systems or data rather than relying only on a successful backup status?
16. Do you have documented procedures for data backup, disaster recovery, and emergency-mode operations during an outage or security incident?

Section 5

Vendors, business associates, and change control

Inventory PHI-touching vendors, confirm agreements where required, control remote access, and plan changes safely.

17. Do you maintain an inventory of vendors that create, receive, maintain, or transmit PHI/ePHI on behalf of the practice?
18. Have you confirmed appropriate business associate agreements are in place where required before sharing PHI/ePHI with a vendor?
19. Do you control and review vendor remote-access methods, administrator accounts, and support pathways?
20. Before major software, server, network, or cloud changes, do you verify backups, rollback options, vendor requirements, and responsibility boundaries?

Section 6

Training, incidents, and documentation

Verify that staff know what to do, incidents have an escalation path, and evidence is available when needed.

21. Do workforce members receive role-appropriate privacy/security training and security awareness education, with completion documented?
22. Do staff know how to report suspicious email, lost devices, unauthorized access, malware, or other security events promptly?
23. Do you have a documented incident-response process that identifies decision-makers, IT/vendor contacts, evidence-preservation steps, and escalation paths?
24. Can you produce current policies, procedures, risk-analysis records, training records, incident documentation, and other required Security Rule documentation when needed?

Your Result

0 / 48

Answer the questions above to build your readiness score.

Answered: 0 / 24

What To Do Next

Turn the score into owned remediation work.

40-48: Strong starting point. Validate the evidence behind the answers, test recovery, and address every Partial/No item.

28-39: Several controls are in place, but important gaps or documentation weaknesses likely need an assigned remediation plan.

0-27: Prioritize a documented risk analysis and focused remediation plan before treating the environment as ready.

The score is deliberately conservative and is not a regulatory threshold. HHS does not publish a universal checklist score that proves HIPAA compliance.

Request a personalized review

Submit your current score and contact details so our team can discuss the technical gaps that deserve attention first. This is not a compliance certification or legal review.

FAQ

HIPAA readiness checklist questions.

Does a high checklist score prove HIPAA compliance?

No. This checklist is an educational prioritization tool, not a certification, legal opinion, or substitute for a complete HIPAA Security Rule risk analysis. A high score should still be supported by current evidence and tested controls.

How often does a dental practice need a HIPAA security risk analysis?

The current Security Rule does not prescribe one universal calendar interval for every organization. HHS describes risk analysis as an ongoing process and says the frequency should reflect the organization and changes in its environment.

Is an addressable HIPAA Security Rule specification optional?

No. HHS guidance explains that addressable does not mean optional. The organization must evaluate whether the specification is reasonable and appropriate, implement it when appropriate, or document why an equivalent alternative is used when applicable.

Can the HHS Security Risk Assessment Tool certify a dental practice?

No. HHS and ONC provide the SRA Tool to help small and medium healthcare providers structure a security risk assessment, but use of the tool is not presented as certification or a guarantee of compliance.

Should backups be part of a HIPAA readiness review?

Yes. The current Security Rule includes contingency-plan implementation specifications for data backup, disaster recovery, and emergency-mode operations. Practices should also verify that their real recovery process works, not only that backup jobs report success.

Can Dental IT make a practice HIPAA compliant?

No IT provider can make a practice compliant by itself. Dental IT can help inventory systems, implement and document technical safeguards, validate backup and recovery ownership, and organize remediation work while the regulated organization retains its broader HIPAA responsibilities.

Need help turning findings into a roadmap?

Dental IT can help document the technology environment, clarify ownership, review technical safeguards, validate backup and recovery readiness, and prioritize remediation work for your dental practice.

Schedule an IT Assessment