Dental Practice Security

HIPAA Checklist for Dental Offices

19 items, each labelled with who actually owns it. We build 8 of them. The rest is yours, and no vendor can do it for you.

What this is: a working checklist from an IT company that installs and secures dental networks in NYC. It is not legal advice and it is not a substitute for a compliance consultant or your own risk analysis. Where an item is a legal obligation rather than a technical recommendation, we say so — and for the obligations, verify the current requirement with HHS or your attorney rather than taking our word for it.

Technical safeguards

The infrastructure layer. This is the part we build.

  • A unique login for every person

    IT builds this

    No shared front-desk account, no sticky note on the monitor. Every staff member gets a named account, because audit logs are worthless if six people share one identity.

  • Automatic logoff on every workstation

    IT builds this

    Screens lock on a timer, including the operatory machines. An unattended charted patient record in a room a stranger can walk into is the most common physical exposure in a dental office.

  • Encryption at rest on anything holding records

    IT builds this

    Server drives, workstation drives, and every backup copy. This is the single control that turns a stolen laptop from a reportable breach into a non-event.

  • Encryption in transit

    IT builds this

    Anything leaving the building — backups going offsite, remote access, email carrying patient information — travels encrypted.

  • Audit logging that someone can actually read

    IT builds this

    Your practice management software logs record access. That logging needs to be switched on, retained, and reviewable, not left at defaults nobody has looked at since install day.

  • Network segmentation

    IT builds this

    Imaging, office workstations, and guest Wi-Fi on separate VLANs. A patient's phone on your guest network should have no path to the machine holding your records.

  • A backup you have restored from

    IT builds this

    Nightly, encrypted, with an offsite copy and at least one test restore you personally watched succeed. Ransomware turns an untested backup into a very expensive discovery.

  • Patching that actually happens

    IT builds this

    Operating systems, firmware, and the firewall. An unpatched edge device is how most small-practice intrusions start.

Physical safeguards

Mostly about where the hardware lives and who can touch it.

  • The server is behind a locked door

    Shared

    Not in the break room, not under the front desk where anyone waiting can reach it. A small locked closet or rack with proper ventilation.

  • Screens the waiting room cannot read

    Practice owns this

    Check the sight lines from every chair in your reception area. Privacy filters are cheap; reangling a monitor is free.

  • A documented disposal process

    Shared

    Drives from retired computers get wiped or destroyed, with a record that it happened. Handing an old front-desk machine to a staff member's kid is a breach.

  • Control of who gets a key

    Practice owns this

    Know who can access the space after hours, including the cleaning service and the landlord, and revoke access when people leave.

Administrative safeguards

Paperwork and process. Nobody can do this part for you, and it's the part auditors ask about first.

  • A written risk analysis

    Practice owns this

    This one is explicitly required, not optional, and it's the most commonly missing document in a small practice. HHS publishes a free Security Risk Assessment tool that walks you through it.

  • One named person responsible for security

    Practice owns this

    A specific human, written down. In a small practice this is usually the owner or the office manager.

  • Staff training, on the record

    Practice owns this

    Annual awareness training with attendance recorded. Most breaches at practices this size start with a staff member clicking something, not with a sophisticated attack.

  • Business Associate Agreements with every vendor touching records

    Shared

    Your IT company, your backup provider, your billing service, your cloud PMS host. If they can see patient information, you need a BAA on file. Ask us for ours — a vendor who hesitates at this question is telling you something.

  • A written incident and breach response plan

    Practice owns this

    Who you call, in what order, and on what clock. Notification deadlines are tight, and reading the rule for the first time during an incident is how practices miss them.

  • A contingency plan for losing the building

    Shared

    Fire, flood, extended power loss. How do you see patients, and how long until records are back? Your offsite backup is the technical half of this answer.

  • Periodic re-evaluation

    Practice owns this

    The rule expects you to revisit this as your practice changes. Adding operatories, changing software, or hiring staff all change your risk picture.

We Build the Technical Half Into Every Install

Encryption, per-user access control, audit logging, VLAN segmentation, and a backup we restore from with you watching — all included in the flat-rate packages, not sold as an upgrade. You get the documentation for your risk analysis at handover.

HIPAA Questions Dentists Ask Us

Related reading: FBI warning: hackers targeting dental practices  ·  Dental office network installation NYC  ·  Dentrix vs Eaglesoft vs Open Dental