HIPAA IT Compliance Checklist for Miami Medical Offices: 10 Things Your IT Company Should Have Done Already

HIPAA’s Security Rule doesn’t just apply to hospitals. If your medical office — whether you’re a primary care practice, a specialty group, a dental office, or a behavioral health provider — stores, transmits, or receives protected health information (PHI) electronically, you are a covered entity and you are subject to HIPAA’s technical safeguard requirements.

Most medical office IT problems we encounter at SKALS aren’t exotic. They’re the same basic gaps, repeated across practice after practice. Here’s a checklist of ten things your IT company should have addressed already — and a guide to what each one actually means.

What HIPAA’s technical safeguards actually require

The HIPAA Security Rule’s technical safeguards (45 CFR § 164.312) fall into four categories: access controls, audit controls, integrity controls, and transmission security. They don’t mandate specific technology — they require that you implement reasonable and appropriate measures to protect ePHI given your practice’s size, complexity, and resources.

The HIPAA IT compliance checklist

1. Unique user IDs for every staff member. Every person who accesses your EHR, email, or any system containing PHI must have their own unique login. Shared logins (“the office password”) make audit trails useless and are a direct HIPAA violation. Each staff member logs in as themselves, every time.

2. Automatic session timeout on workstations. Workstations in exam rooms, at the front desk, and in clinical areas must lock automatically after a period of inactivity — typically 5 to 15 minutes, depending on the location. A patient walking past a logged-in workstation with visible PHI is a breach. Your Group Policy or MDM should enforce this automatically.

3. Encrypted hard drives on all devices. Every laptop, desktop, and mobile device that could contain PHI must have full-disk encryption enabled. For Windows devices, this is BitLocker. For Macs, FileVault. Without encryption, a stolen or lost device is a reportable breach under HIPAA. With encryption, it’s typically not — the data is unreadable without the decryption key.

4. Audit logging on your EHR and network systems. HIPAA requires you to maintain records of who accessed PHI, when, and from where. Your EHR should have built-in audit logging — verify that it’s enabled and that logs are retained for at least six years. Your network firewall and Active Directory should also be logging authentication events.

5. Encrypted email for PHI transmission. Standard email is not a secure method for transmitting PHI. If your practice communicates clinical information by email — test results, referral letters, care coordination — that communication must be encrypted. Microsoft 365 Message Encryption is included in most M365 plans and can be configured to encrypt automatically when PHI keywords are detected.

6. Business Associate Agreements with all cloud vendors. If a vendor stores, processes, or transmits PHI on your behalf — your EHR vendor, your email provider, your backup service, your billing company — they are a Business Associate under HIPAA and must have a signed Business Associate Agreement (BAA) with your practice before they touch PHI. This is not optional, and many cloud vendors (including Microsoft, for M365 in healthcare configurations) will sign one upon request.

7. Offsite, encrypted backup with tested restores. A data loss event at a medical office isn’t just an operational problem — it may be a reportable breach and can affect patient care. Your backup must be encrypted, stored offsite or in the cloud, and tested with an actual restore at least quarterly. A backup that’s never been tested is not a compliant backup.

8. A documented procedure for lost or stolen devices. If a staff member loses a laptop or phone that could contain PHI, you need to be able to: remotely wipe it, determine what data it contained, and assess whether a breach occurred. This requires mobile device management (MDM) enrollment on all devices and a documented incident response procedure.

9. Separate patient Wi-Fi from your clinical network. Your patient waiting-room Wi-Fi should be on a completely separate network segment from the systems containing patient records. A patient (or anyone else) connecting to your guest Wi-Fi should have no path — even an indirect one — to your EHR or clinical workstations.

10. Annual HIPAA security awareness training for all staff. HIPAA requires workforce training on security policies and procedures. Annual training — covering phishing awareness, proper device handling, password policies, and incident reporting — is the minimum. Document the training, who attended, and when. This documentation is what an auditor will ask for first.

What to do if a device is lost or stolen

Act immediately. Use your MDM system to remote-wipe the device. Document the incident — device type, what data it contained, when it was last seen, circumstances of the loss. Conduct a risk assessment to determine whether the loss constitutes a reportable breach under the HIPAA Breach Notification Rule. If more than 500 Florida residents are affected, notify HHS and affected individuals within 60 days. Even for smaller incidents, document your assessment and keep it on file.


We offer HIPAA IT assessments for Miami medical practices — including a written compliance report at no charge. We’ll go through every item on this checklist with your practice and give you a clear action plan for anything that needs attention. Contact SKALS IT to schedule your assessment.

Leave a Comment

Your email address will not be published. Required fields are marked *