This checklist is for the owner, office manager or compliance officer of a Utah medical or dental practice. It covers the IT side of the Security Rule under HIPAA (the Health Insurance Portability and Accountability Act) and what you should be able to show if someone asks.
HIPAA is a federal law, and its rules come from the U.S. Department of Health and Human Services (HHS). It applies in Utah as it does everywhere else. Utah may add state obligations, so ask your attorney.
What the HIPAA Security Rule covers
The Security Rule protects electronic protected health information (ePHI). That is protected health information (PHI), meaning individually identifiable health information, that a practice creates, receives, maintains or transmits electronically. In a dental office that means the practice management database, digital X-rays, scanned insurance cards, patient email and their backups. PHI on paper or spoken aloud is outside the Security Rule and falls under the Privacy Rule instead.
The rule aims to protect the confidentiality, integrity and availability of ePHI. Ransomware that locks the chart system is an availability failure even if nobody reads a record.
HHS ransomware guidance also says that ePHI encrypted by ransomware is presumed to be a breach unless the practice documents a low probability that the data was compromised. That means the breach notification rules below can apply. The guidance adds that notification is not required if the ePHI was already encrypted in line with HHS standards for securing PHI. See the HHS ransomware fact sheet for the details.
Covered entities and business associates
A covered entity is a health plan, a clearinghouse, or a health care provider that transmits health information electronically for standard transactions such as insurance claims. A practice that bills insurance electronically is one.
A business associate is a person or company that creates, receives, maintains or transmits PHI for a covered entity. It can also be one that provides services such as consulting or administration that involve disclosure of PHI. Business associates must follow the Security Rule directly.
An IT provider that can reach ePHI is one, whether it supports a server remotely, manages backups or hosts practice software. You need a signed business associate agreement (BAA) with it before it handles patient data.
The three safeguard families
The rule sorts its requirements into three families. The numbers in parentheses are section numbers in Part 164 of Title 45 of the Code of Federal Regulations (CFR), the federal rulebook, cited as 45 CFR Part 164.
- Administrative safeguards (164.308): policies and management, including risk analysis, training and contingency planning.
- Physical safeguards (164.310): control of the rooms, workstations and devices where ePHI is kept.
- Technical safeguards (164.312): the technology that controls access, records activity and protects data at rest and in transit.
Required and addressable
Where a standard has implementation specifications, each is either required or addressable. Required means implement it.
Addressable does not mean optional. The practice assesses whether the item is reasonable and appropriate in its own environment. If it is, implement it. If not, document why and implement an equivalent alternative where reasonable.
The rule also lets a practice weigh its size, technical setup, cost and risk. That is why the written risk analysis matters: it records why you chose what you chose.
The IT checklist
Each item shows how the rule treats it. Not named means the rule lists no such control by name, but a risk analysis will point to it. Section numbers are from 45 CFR Part 164.
Administrative safeguards
Written security risk analysisRequired164.308(a)(1)(ii)(A)
Assess the risks to ePHI wherever it lives: servers, workstations, laptops, phones, cloud apps, imaging systems and backups. Keep it current: update it when you add a system, change a vendor, move offices or have an incident. The Office of the National Coordinator for Health Information Technology (ONC) and the HHS Office for Civil Rights offer a Security Risk Assessment Tool for small and medium practices. Using it does not guarantee compliance.
Risk management plan and security officialRequired164.308(a)(1)(ii)(B), 164.308(a)(2)
For each risk, record the fix, the owner and the date. Name one person responsible for the security policies.
Workforce security trainingRequired164.308(a)(5)
Train all staff, including management, on phishing, passwords and reporting problems. Repeat on a schedule you set and keep attendance records.
Sanction policyRequired164.308(a)(1)(ii)(C)
Write down the consequences for staff who break security policies and apply them consistently.
Secure backups and a tested contingency planRequired and addressable164.308(a)(7)
Three plans are required: data backup, disaster recovery and emergency mode operation. Encrypt backups and keep one copy ransomware cannot reach or change. Test a restore and record it. Testing is addressable. See our backup and recovery service.
Vendor management with signed BAAsRequired164.308(b)
List every vendor that can touch ePHI: IT, cloud backup, practice software, billing, e-fax. Each needs a signed BAA requiring the vendor to follow the Security Rule, bind subcontractors and report incidents to you.
Incident response and breach notificationRequired164.308(a)(6)
Write down how you spot suspected incidents, limit the harm and document the outcome. Name who decides and who to call. Timelines are below.
Documentation retentionRequired164.316(b)
Keep policies, procedures and records of actions in writing for 6 years from creation or the date last in effect, whichever is later. Update them when your environment changes.
Technical safeguards
Unique user IDs and role-based accessRequired and addressable164.312(a)(2)(i)
Everyone signs in with their own account, with no shared front desk login. Give each role only the access it needs and remove access the day someone leaves. Also document emergency access to ePHI.
Multi-factor authentication (MFA) where feasibleNot named164.312(d)
The rule requires verifying who is signing in but does not name MFA. MFA adds a second proof of identity, such as a code from a phone app, on top of the password. It is a common way to meet the requirement for email, remote access and cloud apps. If a legacy system cannot support it, document the gap and your alternative control.
Automatic logoffAddressable164.312(a)(2)(iii)
End sessions after inactivity. Set screen locks on every workstation and timeouts in the practice software. Front desk PCs need shorter timeouts than locked offices.
Encryption of laptops, portable media and data in transitAddressable164.312(a)(2)(iv), 164.312(e)(2)(ii)
Encrypt laptops, phones and USB drives. Encrypt data in transit with a VPN (a private encrypted connection) or TLS (the encryption used for secure web connections). Under HHS guidance, properly encrypted ePHI counts as secured, so a lost encrypted laptop generally does not trigger breach notification if the key stayed safe.
Audit logs and their reviewRequired164.312(b), 164.308(a)(1)(ii)(D)
Turn on logging in the practice software, servers, firewall and email. Someone must review the logs on a set schedule and record that they did.
Patching and supported operating systemsNot named
Keep operating systems, practice software, firewalls and imaging workstations updated. Replace systems the vendor no longer supports, or isolate them and document why.
Endpoint protectionAddressable164.308(a)(5)(ii)(B)
Run managed antivirus or endpoint detection on every workstation and server, and know who receives the alerts.
Email securityNot named
Filter phishing and malicious attachments, require MFA on every mailbox, and set a rule for what patient information may be emailed.
Medical devices on segmented networksNot named
Imaging sensors, CBCT units (cone beam CT, a 3D X-ray scanner) and other clinical devices may not be able to run security software or be patched on your schedule. Put them on their own network segment, allow only the traffic they need, and keep guest WiFi separate. HHS voluntary cybersecurity performance goals list segmentation as an enhanced goal.
Physical safeguards
Device and media disposalRequired164.310(d)(2)(i)-(ii)
Wipe or destroy drives before any computer, server, copier or USB drive leaves the office. HHS guidance points to NIST SP 800-88, the National Institute of Standards and Technology guide to wiping and destroying media. Record what was destroyed and when.
Workstation and server room securityRequired and addressable164.310(a)-(c)
Position screens away from patients, lock unattended workstations, and keep servers, network gear and backup drives in a locked room. Keep a list of who has keys or codes.
A proposed update to the Security Rule
In January 2025 HHS published a proposed rule in the Federal Register to update the Security Rule. It would remove the addressable category and require MFA, encryption and network segmentation, with limited exceptions.
A proposed rule is not law. As of September 26, 2026, HHS has not issued a final rule, so the current Security Rule still applies. Check HHS.gov for the latest status. MFA, encryption and network segmentation are already on the checklist above, so treating them as your baseline now also prepares you for the proposal.
Breach notification: what the rule requires
The Breach Notification Rule (45 CFR 164.400 to 164.414) applies when unsecured PHI is used or disclosed in a way the Privacy Rule does not permit. That is presumed to be a breach unless a documented risk assessment shows a low probability of compromise. The clock starts when the breach is known or should reasonably have been known.
- Individuals: Notify each affected person without unreasonable delay and no later than 60 calendar days after discovery.
- HHS: For 500 or more people, notify HHS with the individual notices. For fewer than 500, notify no later than 60 days after the end of the calendar year of discovery.
- Media: If more than 500 residents of one state are affected, notify prominent media outlets there within the same 60 days.
- Business associates: A business associate notifies the covered entity without unreasonable delay and within 60 calendar days of discovery.
Sixty days is the outer limit, not a target. The HHS Breach Notification Rule page has the exact requirements and the reporting portal.
Where WITS fits in HIPAA IT support for Utah practices
WITS is a managed IT provider headquartered in Lehi, Utah. For medical and dental practices we provide managed IT services and sign a business associate agreement. The practice still owns the risk analysis and the decisions in it. See our pages on IT support for medical practices, IT support for dental offices and IT compliance services.
We can support several of the technical items on this checklist:
- Network design and segmentation: separate networks for clinical devices, workstations and guest WiFi.
- Managed backups: encrypted server and workstation backups, with restore tests.
- Patching and monitoring: 24/7 monitoring, automated patching and threat alerts.
- Documentation support: monthly IT reports and help gathering the technical records your risk analysis needs.
WITS Command is $85 per user per month. WITS Inner Circle is $125 per user per month and adds annual penetration testing, security awareness training, an incident response plan and a quarterly compliance review. Both are month-to-month with a 5 user minimum.
Our engineers hold Cisco CCIE Enterprise Infrastructure and Kali Linux Professional (KLCP) certifications. Those are networking and security credentials, not HIPAA credentials. We do not promise that a practice will be compliant or will pass a review. A $200 flat-fee on-site assessment, credited toward the project if you proceed, shows where your technical gaps are. Call 385-242-2514.

