Compliance
HIPAA self-assessment for independent practices
This self-assessment covers the HIPAA Security Rule, Privacy Rule, and Breach Notification Rule requirements applicable to a typical independent practice. It is not a substitute for a formal risk assessment, which HHS requires annually and after any significant change.
By Jordan Alderman, MBA, CMPE · Reviewed by Rania Hassan, JD, CHC · Last reviewed · Methodology
Disclosure: Independent editorial. No pay-for-placement, no affiliate rankings. Full editorial standards.
Who this is for: Practice administrators, HIPAA privacy officers, and physician-owners doing internal HIPAA reviews.
Administrative safeguards
- Named Privacy Officer and Security Officer (can be same person)
- Annual HIPAA risk assessment documented
- Written policies covering minimum-necessary rule, access control, sanction policy
- Workforce training completed within 90 days of hire + annually
- Business Associate Agreements executed with every vendor touching PHI
- Contingency plan (backup, disaster recovery, emergency mode)
- Termination checklist including access revocation within 24 hours
Physical safeguards
- Facility access controls (locks, alarm, visitor policy)
- Workstation placement prevents screen viewing by unauthorized persons
- Device inventory maintained
- Media disposal policy (shred, wipe)
- Portable device (laptop, phone) encryption + tracking
Technical safeguards
- Unique user IDs for every workforce member
- Automatic logoff after inactivity
- Multi-factor authentication for remote access
- Encryption of PHI at rest (disks) and in transit (TLS)
- Audit logs enabled and reviewed at least quarterly
- Integrity controls to detect unauthorized PHI alteration
Privacy Rule operations
- Notice of Privacy Practices posted + given to new patients
- Patient access request workflow (30-day fulfillment)
- Accounting of disclosures process (6-year lookback)
- Amendment request process
- Restrictions and confidential communications handled per request
Breach notification readiness
- Written incident response plan
- Named incident response team
- 60-day patient notification workflow
- 500+ patient breach → HHS OCR + media notification workflow
- Annual breach log maintained (under 500 patients)
- Legal counsel identified for breach events
Business Associate management
- Current BAA inventory (billing, EHR, IT, cloud, shredding, etc.)
- Annual BA review — SOC 2 or equivalent requested
- BA breach notification obligations in every BAA
- Subcontractor language in every BAA
Related buyer guide
For deeper vendor evaluation criteria, see our ehr hub →