Compliance Check
HIPAA Compliance Checklist for Solo Therapists
Interactive HIPAA safeguards checklist for solo therapy practices. Track administrative, physical, and technical safeguards, BAA coverage, breach readiness, and documentation — all saved locally in your browser.
HIPAA Compliance Checklist for Solo Therapy Practices
Walk through the administrative, physical, and technical safeguards every solo therapist should have in place. Progress saves locally so you can return any time.
Administrative Safeguards
The policies and procedures that govern how your practice protects PHI day to day.
Identify who is responsible for the practice's HIPAA program, including risk analysis, training, and incident response.
Document annual HIPAA training for yourself, any employees, contractors, billing services, or virtual assistants with PHI access.
Define who can access PHI, how access is granted, modified, and revoked, and how you verify identity before access is granted.
Plan for how you respond to a ransomware attack, natural disaster, or extended outage, including data backup and recovery steps.
Identify threats and vulnerabilities to the confidentiality, integrity, and availability of PHI in your practice.
Apply consistent consequences for HIPAA violations by employees, contractors, or business associates.
Physical Safeguards
Controls over the physical environment and devices that store or access PHI.
Document where and how workstations, laptops, and mobile devices may be used to access PHI, including rules for shared spaces.
Maintain an inventory of every laptop, phone, tablet, and external drive that contains PHI, and label them.
Enable screen lock, privacy filters, and policies that prevent unauthorized viewing during in-person or remote work.
Shred paper records, wipe or destroy hard drives, and document the disposal method for each device and record type.
Use locks, alarm systems, and visitor policies to limit who can enter the space where PHI is stored or discussed.
Technical Safeguards
The technology and access controls that protect electronic PHI.
Every account that touches PHI should have a unique login, a strong password, and multi-factor authentication where possible.
Turn on access logs in your EHR, cloud storage, and email. Review the logs periodically for unusual activity.
Use checksums, version history, and write-once storage to ensure ePHI cannot be silently modified or deleted.
Use TLS for email and messaging, full-disk encryption on devices, and HIPAA-compliant cloud storage for backups.
Set a short inactivity timeout (typically 15 minutes or less) for any device or app that displays PHI.
Business Associate Agreements
Every vendor that creates, receives, maintains, or transmits PHI on your behalf must sign a BAA.
List your EHR, telehealth platform, billing service, cloud storage, transcription, and any other vendor that touches PHI.
Store the BAA, including the date signed and version, and renew whenever the vendor updates their terms.
Ask vendors that subcontract (e.g., cloud hosting) whether they flow down HIPAA obligations to their subcontractors.
Breach Notification
Prepare to detect, respond to, and report a breach quickly and within HIPAA timelines.
Configure alerts for failed logins, mass downloads, or unusual access patterns in your EHR and cloud storage.
Document who you call, what you preserve, how you investigate, and how you document the incident for HHS.
A breach affecting more than 500 individuals must be reported to HHS within 60 days, with media notice in jurisdictions where required.
For every suspected incident, document the four-factor risk assessment that determines whether a breach is reportable.
Documentation & Policies
Keep written policies and proof of compliance ready for audits and questions.
Cover administrative, physical, and technical safeguards in a single accessible policy binder (digital or printed).
Make the NPP available on your website, in your intake paperwork, and posted in your office if applicable.
Store signed BAAs, SOC 2 reports, and vendor security questionnaires in a single, organized location.
Record every suspected incident, the investigation, the outcome, and any corrective action, even if it is not reportable.
Re-run the risk analysis, refresh training, and update policies at least once per year or whenever you add a new vendor or service.
Founder's Club offer
Related Tools
Explore other therapist calculators
Compare this result with a few adjacent planning tools for pricing, overhead, or private-practice transition decisions.
Compliance Check
HIPAA Risk Assessment Quiz
Answer a short HIPAA readiness quiz for your therapy practice and get a risk-level snapshot, your top operational gaps, and a secure EHR next-step recommendation.
Open toolCompliance Check
Business Associate Agreement Tracker
List every software vendor and track the status, version, and expiration of your required HIPAA Business Associate Agreements.
Open toolLegal Compliance
Notice of Privacy Practices Builder
Generate a baseline Notice of Privacy Practices document covering required HIPAA disclosures and patient rights.
Open toolHow this HIPAA checklist is organized
HIPAA is built around three safeguard categories — administrative, physical, and technical — plus breach response, BAAs, and documentation. This checklist walks through each category with practical items that a solo therapist can complete in a single afternoon.
Progress is stored in your browser, so you can step away and return to the same checklist later. Nothing is uploaded to a server, which keeps the answers between you and your HIPAA program file.
Use it for situations like
- A first-time HIPAA setup when you open a new solo practice.
- An annual HIPAA refresh for an established practice.
- Onboarding a new vendor that will touch PHI.
- Preparing documentation before hiring a contractor or VA.
FAQ
Questions therapists ask before using this calculator
Does a solo therapist really need a HIPAA program?
Yes. The HIPAA Security Rule applies to every covered entity, even if you are the only person in the practice. A documented program — policies, risk analysis, training, and vendor tracking — is what HHS expects to see if a complaint or breach is investigated.
How long does it take to work through this checklist?
Most solo therapists can complete a first pass in 60 to 90 minutes. Plan to revisit the checklist annually, after onboarding a new vendor, or whenever you add a service (telehealth, billing service, AI notetaker) that touches PHI.
Do I need a Business Associate Agreement with my EHR?
Yes. Any vendor that creates, receives, maintains, or transmits PHI on your behalf must sign a BAA. Your EHR, telehealth platform, billing service, transcription, and cloud storage vendors should all be on your BAA list.
What is the four-factor risk assessment for breaches?
When you suspect a breach, document the four factors HHS uses: the nature and extent of the PHI involved, the unauthorized person who used or received it, whether the PHI was actually acquired or viewed, and the extent to which the risk has been mitigated. The conclusion determines whether you must notify HHS and the client.
Does this checklist make my practice HIPAA compliant?
Completing the checklist is a strong step, but compliance is an ongoing program. Use it to identify gaps, document your policies, and as a recurring annual review tool, then consult a HIPAA attorney or compliance specialist for high-risk scenarios.