All articlesOB/GYN

HIPAA Risk Assessment Checklist for Independent Medical Practices

9/30/2026
HIPAA Risk Assessment Checklist for Independent Medical Practices
## A Useful Assessment Starts Beyond Your EHR A prenatal ultrasound saved to a workstation, a billing spreadsheet downloaded at home, and a patient message forwarded to a personal inbox have something in common: each can put electronic protected health information (ePHI) outside the workflows your practice normally monitors. A HIPAA risk assessment should uncover those paths—not simply confirm that your EHR has a password. For independent practices, the goal is a documented understanding of where ePHI lives, what could compromise it, and which safeguards need attention first. This checklist focuses on the HIPAA Security Rule’s risk analysis requirement. Related privacy issues appear where they affect everyday OB/GYN workflows, but a security risk analysis does not replace a broader HIPAA compliance program. ## 1. Define the Scope and Assign Responsibility HIPAA requires an accurate and thorough assessment of potential risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI. That includes information your practice creates, receives, maintains, or transmits—not just records inside your main clinical system. ### Start with a written assessment plan - [ ] Identify the security official responsible for coordinating the analysis. - [ ] Include clinical, front-desk, billing, and IT perspectives. - [ ] List every practice location, remote-work arrangement, and relevant vendor. - [ ] Record the assessment date, methods, participants, and evidence reviewed. - [ ] Define how findings will be approved, assigned, and tracked. An outside consultant can help, but the practice still needs to understand the findings and own the response. A vendor questionnaire alone is not your practice’s risk analysis. ## 2. Map Where Patient Information Travels Follow a patient encounter from scheduling through payment. Include systems that seem peripheral: scanners, multifunction printers, ultrasound equipment, email, fax services, and backup storage. ### Build a simple ePHI inventory For each system or workflow, record: - [ ] What information it contains. - [ ] Where information is stored, including local downloads and cloud copies. - [ ] Who can access it and from which devices. - [ ] How it moves between people, systems, and organizations. - [ ] Which vendor supports it and who manages security settings. - [ ] How records are retained, archived, and securely disposed of. **Hypothetical OB/GYN example:** An ultrasound workstation exports images to a shared folder before staff upload them to the chart. The folder retains years of images, and former employees still have access. The assessment should address the folder—not just the upload process. Validate the inventory through staff interviews, configuration reviews, and observation. Written procedures may not reflect what happens during a busy clinic session. ## 3. Identify Threats, Vulnerabilities, and Existing Safeguards A device inventory is necessary, but it is not a complete risk analysis. For each ePHI location, describe what could go wrong, why it could happen, and what currently reduces the risk. ### Keep these concepts separate - **Threat:** A potential cause of harm, such as ransomware, theft, accidental disclosure, or a power outage. - **Vulnerability:** A weakness the threat could exploit, such as unsupported software or excessive access permissions. - **Safeguard:** A control that reduces likelihood or impact, such as restricted access, encryption, or tested backups. Check for: - [ ] Unsupported operating systems and overdue updates. - [ ] Shared accounts, weak authentication, and unnecessary administrator access. - [ ] Unprotected exports, email attachments, and removable media. - [ ] Missing logs or logs nobody reviews. - [ ] Single points of failure that could interrupt care. Document evidence, not assumptions. “Backups enabled” is weaker evidence than a dated report showing successful restoration of a sample record set. ## 4. Review Access and Patient Communication OB/GYN practices handle information that patients may be especially concerned about disclosing. Proxy accounts, shared contact details, and family involvement deserve deliberate review. ### Check workforce access - [ ] Give each workforce member an individual account. - [ ] Match access to job responsibilities and review it after role changes. - [ ] Remove access promptly when employment or vendor relationships end. - [ ] Evaluate multifactor authentication, especially for remote and privileged access. - [ ] Configure appropriate session timeouts and workstation locking. - [ ] Assign responsibility for reviewing suspicious access activity. ### Check patient-facing workflows - [ ] Verify identity before account recovery or contact-detail changes. - [ ] Review how proxy access is authorized, limited, and revoked. - [ ] Check whether notifications expose sensitive information on shared devices. - [ ] Establish procedures for confidential communication requests. **Hypothetical OB/GYN example:** A patient previously authorized a partner’s access but later requests confidential communications. Staff need a clear process to review proxy permissions and contact preferences rather than merely changing the telephone number. Rules involving minors, personal representatives, and reproductive health disclosures can depend on current law and circumstances. Escalate uncertain cases to qualified counsel. ## 5. Evaluate Vendors, AI, and Connected Workflows Determine which vendors create, receive, maintain, or transmit PHI on your behalf and whether they are business associates. Where required, execute business associate agreements before sharing PHI. An agreement is necessary, but it does not prove a service is configured safely. ### Ask operational questions - [ ] What data does the service receive, including recordings and metadata? - [ ] Which subcontractors can access it? - [ ] What are the retention, deletion, and permitted-use terms? - [ ] How are security incidents reported to the practice? - [ ] Can the practice retrieve its data during an outage or contract termination? - [ ] Who controls authentication, permissions, and audit records? For practices evaluating IKON EMR, include its AI scribe, telemedicine, billing, and patient portal workflows in this review. Ask how each handles ePHI and supports your HIPAA compliance responsibilities; do not assume that choosing an integrated platform completes the assessment. For an AI scribe, specifically examine audio retention, transcript access, model-training uses, and clinician review before notes become final. For telemedicine, assess patient identity verification, private surroundings, and recording settings. Never enter PHI into an unapproved AI tool. ## 6. Test Physical Security and Downtime Readiness Security includes keeping information available for care, not just preventing unauthorized access. - [ ] Check device encryption, screen visibility, and secure equipment storage. - [ ] Restrict physical access to networking equipment and stored media. - [ ] Define secure disposal procedures for devices containing ePHI. - [ ] Document backup frequency, access restrictions, and restoration procedures. - [ ] Test restoration and record the results. - [ ] Maintain an incident response plan with current contacts. - [ ] Establish downtime procedures for appointments, documentation, and urgent results. **Hypothetical OB/GYN example:** During a system outage, a clinician needs recent prenatal laboratory results. A useful downtime exercise tests how authorized staff obtain essential information and reconcile temporary documentation afterward without creating uncontrolled copies. Include incident escalation instructions. Staff should know whom to contact immediately; they should not independently decide whether an event requires breach notification. ## 7. Turn Findings into a Prioritized Action Register Use a consistent method to estimate each risk’s likelihood and impact, considering existing safeguards. Low, medium, and high ratings can work if you define them and document your reasoning. HIPAA does not prescribe one universal scoring formula. | Finding | Potential harm | Action | Owner | Closure evidence | |---|---|---|---|---| | Former employee account remains active | Unauthorized record access | Disable account and review termination process | Practice manager | Deactivation record and access review | | Ultrasound workstation lacks tested backup | Lost images and interrupted care | Implement backup and perform restoration test | IT lead | Successful test record | | Broad access to billing exports | Unnecessary disclosure | Restrict folder permissions and review exports | Billing lead | Permission report | Add target dates, interim safeguards, and residual risk after remediation. Address serious exposure promptly rather than waiting for the entire assessment to finish. Keep the assessment, supporting evidence, and action register together. Retain documentation required by the Security Rule for six years from creation or the date it was last in effect, whichever is later. This is not a universal medical-record retention period. ## Short FAQ ### Is a HIPAA risk assessment required every year? The Security Rule requires risk analysis and ongoing review, but does not specify one universal annual interval. A yearly review is a practical baseline, supplemented by updates after significant changes, incidents, or newly identified threats. Check for additional applicable program requirements. ### Can a small practice use a free assessment tool? Yes. The federal HealthIT.gov Security Risk Assessment Tool can help organize the work. It does not replace a complete, practice-specific analysis or remediation. The [HHS risk analysis guidance](https://www.hhs.gov/hipaa/for-professionals/security/guidance/guidance-risk-analysis/index.html) is another useful starting point. ### What should we have when we finish? A scoped ePHI inventory, documented threats and vulnerabilities, an evaluation of existing safeguards, reasoned risk ratings, and a tracked remediation plan. The strongest assessment is one your practice uses—not one it files away.

Ready to transform your practice?

Join thousands of providers saving 15%+ on their EMR costs with IKON.