Compliance

HIPAA self-assessment for independent practices

This self-assessment covers the HIPAA Security Rule, Privacy Rule, and Breach Notification Rule requirements applicable to a typical independent practice. It is not a substitute for a formal risk assessment, which HHS requires annually and after any significant change.

By Jordan Alderman, MBA, CMPE · Reviewed by Rania Hassan, JD, CHC · Last reviewed · Methodology

Disclosure: Independent editorial. No pay-for-placement, no affiliate rankings. Full editorial standards.

Who this is for: Practice administrators, HIPAA privacy officers, and physician-owners doing internal HIPAA reviews.

Administrative safeguards

  • Named Privacy Officer and Security Officer (can be same person)
  • Annual HIPAA risk assessment documented
  • Written policies covering minimum-necessary rule, access control, sanction policy
  • Workforce training completed within 90 days of hire + annually
  • Business Associate Agreements executed with every vendor touching PHI
  • Contingency plan (backup, disaster recovery, emergency mode)
  • Termination checklist including access revocation within 24 hours

Physical safeguards

  • Facility access controls (locks, alarm, visitor policy)
  • Workstation placement prevents screen viewing by unauthorized persons
  • Device inventory maintained
  • Media disposal policy (shred, wipe)
  • Portable device (laptop, phone) encryption + tracking

Technical safeguards

  • Unique user IDs for every workforce member
  • Automatic logoff after inactivity
  • Multi-factor authentication for remote access
  • Encryption of PHI at rest (disks) and in transit (TLS)
  • Audit logs enabled and reviewed at least quarterly
  • Integrity controls to detect unauthorized PHI alteration

Privacy Rule operations

  • Notice of Privacy Practices posted + given to new patients
  • Patient access request workflow (30-day fulfillment)
  • Accounting of disclosures process (6-year lookback)
  • Amendment request process
  • Restrictions and confidential communications handled per request

Breach notification readiness

  • Written incident response plan
  • Named incident response team
  • 60-day patient notification workflow
  • 500+ patient breach → HHS OCR + media notification workflow
  • Annual breach log maintained (under 500 patients)
  • Legal counsel identified for breach events

Business Associate management

  • Current BAA inventory (billing, EHR, IT, cloud, shredding, etc.)
  • Annual BA review — SOC 2 or equivalent requested
  • BA breach notification obligations in every BAA
  • Subcontractor language in every BAA

Related buyer guide

For deeper vendor evaluation criteria, see our ehr hub →