JJC SystemsBook a Consultation
Industry Solutions · Healthcare

HIPAA-Compliant IT Checklist for Healthcare Practices

What does a HIPAA-compliant IT setup require? A practical checklist covering risk assessment, access control, encryption, and vendor BAAs — updated for the 2026 HIPAA Security Rule changes that made several previously "addressable" controls mandatory.

What does a HIPAA-compliant IT setup require? At minimum: a current, dated risk assessment identifying every system that stores or accesses ePHI; multi-factor authentication on all of them (now mandatory under the 2026 Security Rule update, not optional); encryption at rest and in transit; audit logging with a defined review cadence; signed Business Associate Agreements with every vendor touching patient data, including AI tools; workforce training; and a tested incident response and backup plan. A "HIPAA-compliant" product label alone does not satisfy these requirements — implementation and documentation do.

If your practice bought an EHR or cloud platform marketed as "HIPAA compliant" and assumed that checked the box, it's worth pausing on this: that label describes a vendor's willingness to sign a Business Associate Agreement and support the required safeguards — it does not describe your practice's actual compliance. That gets established through how the system is configured, who has access to what, and whether you can produce documented evidence of it. Here's the checklist that actually matters in 2026.

What Changed in 2026 (And Why It Matters Now)

Two developments this year should reset how any practice thinks about "good enough" HIPAA compliance. First, the 2026 HIPAA Security Rule updates made multi-factor authentication mandatory on all systems that access ePHI — for a small practice, that means your EHR or practice management software, your email system (especially where you communicate with patients), and any cloud storage or portal touching patient data. This is a meaningful shift from the older framework, where MFA and several other controls were treated as "addressable" — meaning a practice could document a risk-based reason for not implementing them. That flexibility is largely gone for MFA specifically.

Second, effective January 28, 2026, HHS increased the published civil monetary penalty amounts for HIPAA violations, adjusted for inflation as required by law. Penalty tiers still scale with the organization's level of knowledge, culpability, and corrective action, but the ceiling moved up. Criminal violations involving false pretenses or personal gain remain separately punishable by fines up to $250,000 and up to 10 years imprisonment. None of this is designed to be alarmist — it's simply the current backdrop against which "we'll get to it eventually" compliance gaps now carry more financial weight than they did even two years ago.

The Real Cost of Getting This Wrong

Beyond regulatory penalties, the operational cost of a healthcare breach has climbed to levels that make a structured compliance program look inexpensive by comparison. Recent industry breach-cost reporting has placed the average healthcare data breach cost between $7.4 million and $9.8 million depending on the reporting year and methodology — consistently the highest average of any industry studied, year over year. A structured, properly documented compliance program is materially cheaper than a single incident, even before regulatory penalties enter the picture.

The Checklist: Administrative, Physical, and Technical Safeguards

HIPAA's Security Rule organizes requirements into three categories, and a complete checklist should map cleanly to all three rather than treating IT security as a purely technical exercise disconnected from policy and physical controls.

Administrative Safeguards

Appoint a privacy officer and a security officer (these can be the same person at a small practice) with documented responsibility for compliance

Complete and date a comprehensive HIPAA risk assessment, identifying every location where ePHI is created, stored, transmitted, or accessed

Repeat the risk assessment at least annually, and after any material change — a new EHR, a new vendor, a new location

Maintain a current inventory of systems, applications, users, devices, and every ePHI location, including an ePHI data-flow diagram and network map

Identify every business associate — any outside vendor that handles, stores, or accesses PHI — and confirm a signed BAA is in place for each one

Deliver workforce training on privacy and security policies, on hire and on a recurring schedule, with documented completion

Physical Safeguards

Control physical access to workstations, servers, and any location where ePHI is stored or displayed

Implement device safeguards for laptops, mobile devices, and removable media that may contain or access ePHI, including remote wipe capability for lost or stolen devices

Establish secure disposal procedures for hardware and physical records containing PHI at end of life

Technical Safeguards

Require unique user identification for every individual accessing systems containing ePHI — shared logins are a common, easily avoidable gap

Deploy multi-factor authentication on every system accessing ePHI, now a mandatory requirement rather than a risk-based option under the 2026 rule

Apply role-based access control, limiting each user's access to only what their role requires, with a defined process for promptly terminating or adjusting access when roles change

Establish emergency access procedures and automatic logoff where appropriate

Encrypt ePHI at rest and in transit, across email, file storage, backups, and any system where patient data lives

Enable audit logging on all systems that store or process ePHI, with a defined review cadence for meaningful events, retained evidence, and controls to detect unauthorized alteration or deletion

Maintain tested backup and recovery capability, since data availability is itself a Security Rule requirement, not just a general IT best practice

Document a formal incident response and breach notification process, including how and when affected individuals and HHS would be notified if a breach occurs

The Vendor Gap Most Practices Miss: AI Tools and Add-Ons

Patient data increasingly moves beyond your primary EHR into AI tools, transcription services, and other add-ons connected to your core system. Each of those vendors needs its own signed BAA — if one was never brought under a BAA, that's a real compliance gap, even if your primary EHR provider is fully compliant on its own. This is one of the fastest-growing blind spots in 2026 specifically, as practices adopt AI-assisted charting, scheduling, and communication tools faster than their vendor management process can keep up with reviewing and signing the corresponding agreements.

The "HIPAA Compliant" Label Myth

It's worth stating plainly, because it trips up even careful practices: no software product, CRM, or cloud platform is inherently "HIPAA compliant" as a fixed property of the product. What a vendor can offer is a signed Business Associate Agreement and the underlying technical capability to support compliance — encryption, access controls, audit logging. Whether your specific deployment is actually compliant depends on how you configure and operate it: who has access, whether MFA is actually turned on, whether audit logs are actually being reviewed. A checklist item is only complete when your practice has dated evidence showing who implemented the control, when it was last reviewed, and how it was tested — not simply that the underlying software theoretically supports it.

Do Small Practices Really Need All of This?

Yes — and this is worth addressing directly, since it's the most common objection. Smaller practices are frequently targeted specifically because attackers expect weaker defenses than a hospital system maintains. The good news is that most of these protections scale down proportionally to fit a smaller practice's size and budget — a one-to-twenty-physician practice needs the same categories of control as a large health system, implemented at a scale appropriate to its actual environment, not a scaled-down version of the requirements themselves.

How Often Should This Be Reviewed?

At minimum annually, with additional review triggered by any material change: adding staff, adopting a new clinical or administrative tool, changing vendors, or opening a new location. A checklist completed once and filed away loses its value quickly as your practice's systems and vendor relationships evolve — the risk assessment specifically should be treated as a living document, not a one-time compliance project.

Frequently Asked Questions

What does a HIPAA-compliant IT setup require? At minimum: a current risk assessment identifying every ePHI location, mandatory MFA on all systems accessing ePHI, encryption at rest and in transit, audit logging with regular review, signed BAAs with every vendor touching patient data, workforce training, and a tested incident response and backup plan. A vendor's "HIPAA compliant" label alone doesn't satisfy these requirements.

Is MFA actually required for HIPAA compliance now, or still optional? Required. The 2026 HIPAA Security Rule updates made multi-factor authentication mandatory on all systems that access ePHI, removing the "addressable" flexibility that previously allowed some practices to document a risk-based reason for not implementing it.

What's the most commonly missed item on a HIPAA IT checklist? A current, dated risk assessment is the single most important — and most frequently cited — gap in enforcement actions against small practices, more than any individual missing technical control.

Do AI tools connected to our EHR need their own HIPAA agreement? Yes. Any vendor or add-on that handles, stores, or accesses PHI — including AI-assisted charting, transcription, or communication tools — needs its own signed Business Associate Agreement, separate from your primary EHR vendor's agreement.

How much did HIPAA violation penalties change in 2026? Effective January 28, 2026, HHS increased the published civil monetary penalty amounts for HIPAA violations, adjusted for inflation. Penalty tiers still scale with an organization's culpability and corrective action, but the maximum exposure increased.

Does a small practice really need the same HIPAA controls as a hospital system? Yes, in category — though not necessarily in scale or cost. Small practices need the same types of administrative, physical, and technical safeguards as larger organizations, implemented proportionally to their size, since attackers frequently target smaller practices expecting weaker defenses.

How much does a healthcare data breach actually cost? Recent industry reporting has placed the average healthcare data breach cost between $7.4 million and $9.8 million, consistently the highest average among industries studied — a figure that makes proactive compliance investment inexpensive by comparison.

How often should our HIPAA risk assessment be updated? At least annually, and immediately after any material change — a new system, a new vendor, added staff, or a new location. Treat it as a living document rather than a one-time project.

Not Sure Where Your Practice's IT Setup Actually Stands?

Most HIPAA IT gaps aren't visible until an assessment surfaces them — often the same ones cited most frequently in enforcement actions against small practices. Book a free IT assessment with JJC Systems, explore our full Healthcare industry solutions, revisit our Microsoft 365 Security Checklist for the identity and access controls this checklist builds on, or contact our team for a clear read on your current compliance gaps

Recognise the problem?

If this describes your situation, tell us where it hurts most. We will tell you what it would realistically take to fix in your environment, what we would measure, and whether we think it is worth doing at all.

Request a consultation See our Cybersecurity page We reply to every message within one business day.
Keep reading

Related articles

https://res.cloudinary.com/sakshichak1/image/upload/v1789984208/jjc-systems/df5tqyf6gg1ajzclu4j1.jpg
HealthcareSolutions

Dynamics 365 for Healthcare: Improving Patient and Practice Management

Can Dynamics 365 be used for healthcare practice management? Yes — as the CRM and operational layer for patient relationships, referrals, and care coordination, not as an EHR replacement. Here's what it actually does, and the compliance reality behind the marketing claims.

September 21, 2026 · 11Read
Get In Touch

Tell us what you're trying to fix

Describe the situation in your own words.

Please enter your first name.
Please enter your last name.
Please enter a valid email address.
Please enter your company name.
Please choose an option.
Please add a short description.

We reply to every message within one business day.