HIPAA safeguards checklist for a small practice
An educational checklist of common HIPAA Security and Privacy Rule safeguards for a small or solo mental health practice. Not legal advice or a compliance program; confirm current HHS rules and get counsel.
Current as of July 7, 2026. Laws, payer rules, and billing codes change, so confirm the current requirements for your jurisdiction and setting before you rely on it.
What's inside
Administrative safeguards
- A documented security risk analysis, revisited regularly
- Written policies, workforce training, and a sanction policy
- Signed business associate agreements with every vendor that touches protected health information
- A breach response and notification plan
Physical safeguards
- Control physical access to devices and any paper records
- Lock screens, secure workstations, and a clear policy for devices taken off site
Technical safeguards
- Unique user accounts and access limited to the minimum necessary
- Encryption of data at rest and in transit where reasonable and appropriate
- Audit logging, automatic logoff, and secure backups
- Secure messaging and a HIPAA-compliant telehealth platform
Privacy Rule basics
- A current Notice of Privacy Practices
- Honor patient rights, including access to their records
- Special handling for psychotherapy notes and other sensitive records
Note
This is a starting checklist, not a compliance program. Confirm current HHS Office for Civil Rights guidance and have your safeguards reviewed by qualified counsel.
About this resource
This checklist is part of the shrinkiatry resource library, a set of free, clinician-facing references and examples. It's reviewed by Shariq Refai, MD, MBA, FAPA, a board-certified psychiatrist, on a quarterly schedule. Next scheduled review: October 1, 2026. First published July 7, 2026, last reviewed July 7, 2026.
Browse the rest of the resource library, or verify who reviews this site. Spotted something out of date? Email corrections@shrinkiatry.com.