Jan 9, 2025

Resource

HIPAA Compliance Checklist for Practices

Three people brainstorming at a glass wall with sticky notes.

Running a medical office in Palm Beach, Broward, or Miami-Dade means your IT systems are held to a higher standard than a typical small business. A single misconfigured server or unencrypted laptop isn't just an inconvenience, it's a potential HIPAA violation with fines that start in the tens of thousands of dollars. Here's what a genuinely HIPAA-compliant IT setup actually covers.

1. Access controls. Every staff member should have their own login, never a shared front-desk password, with permissions limited to what their role needs. When someone leaves the practice, their access should be revoked the same day, not "whenever IT gets to it."

2. Encryption, everywhere. Patient data has to be encrypted both at rest (on servers, laptops, backup drives) and in transit (email, file transfers, patient portals). This is one of the most commonly missed requirements, especially on older workstations that were never upgraded.

3. Audit logging. You need a record of who accessed what patient data and when. If your current system can't produce that report in under five minutes, it's not compliant.

4. A real backup and disaster recovery plan. Not "we back up sometimes" but a tested, documented process with a defined recovery time, so a ransomware attack or hardware failure doesn't mean days of canceled appointments and lost records.

5. A signed Business Associate Agreement (BAA) with every vendor that touches patient data, your IT provider included. If your current MSP hasn't offered you one, that's worth asking about directly.

6. Staff training. The single most common cause of a breach isn't a hacker, it's a staff member clicking a phishing email. Annual training isn't optional under HIPAA's Security Rule.

UpsiteGroup builds and manages IT environments specifically for South Florida medical offices, compliance isn't an add-on, it's the baseline. If you're not sure where your practice stands on any of the six items above, that's exactly the kind of gap we help close first.

Get a free HIPAA IT compliance review →

Get expert clarity

Frequently asked questions

Can my staff use the free version of ChatGPT or Claude at work?

Yes, for tasks with no patient information at all, like drafting a generic handout or a job posting. Never for anything touching a patient’s chart or PHI, per both companies’ own consumer terms.

What is a BAA and why does it matter for AI tools?

A Business Associate Agreement is a signed contract required under HIPAA before any vendor can touch PHI on your behalf. Anthropic and OpenAI only offer BAAs on business-tier or API plans, and it must be separately executed, not assumed from a paid subscription.

Does paying for ChatGPT Plus or Claude Pro make it HIPAA-compliant?

No. Both companies state that even paid individual consumer accounts (Plus, Pro, Max) are not covered by a BAA and PHI should not be entered into them.

What should our practice do before letting staff use AI with patient information?

Confirm a business-tier account is provisioned with an executed BAA, set a written policy distinguishing PHI from non-PHI use cases, and fold AI access into your existing audit-logging and access-review process.

How does UpsiteGroup help with this?

We confirm which AI tools your staff can access, verify a BAA is actually on file (not just technically available), and manage AI access controls alongside your EHR’s existing security configuration.

Faded abstract map pattern behind the closing call to action

Build smarter systems and grow with confidence

Faded abstract map pattern behind the closing call to action

Build smarter systems and grow with confidence