Compliance Check

HIPAA Compliance Checklist for Solo Therapists

Interactive HIPAA safeguards checklist for solo therapy practices. Track administrative, physical, and technical safeguards, BAA coverage, breach readiness, and documentation — all saved locally in your browser.

HIPAA Compliance Checklist for Solo Therapy Practices

Walk through the administrative, physical, and technical safeguards every solo therapist should have in place. Progress saves locally so you can return any time.

HIPAA safeguards completed0 / 28 (0%)

Administrative Safeguards

The policies and procedures that govern how your practice protects PHI day to day.

  • Identify who is responsible for the practice's HIPAA program, including risk analysis, training, and incident response.

  • Document annual HIPAA training for yourself, any employees, contractors, billing services, or virtual assistants with PHI access.

  • Define who can access PHI, how access is granted, modified, and revoked, and how you verify identity before access is granted.

  • Plan for how you respond to a ransomware attack, natural disaster, or extended outage, including data backup and recovery steps.

  • Identify threats and vulnerabilities to the confidentiality, integrity, and availability of PHI in your practice.

  • Apply consistent consequences for HIPAA violations by employees, contractors, or business associates.

Physical Safeguards

Controls over the physical environment and devices that store or access PHI.

  • Document where and how workstations, laptops, and mobile devices may be used to access PHI, including rules for shared spaces.

  • Maintain an inventory of every laptop, phone, tablet, and external drive that contains PHI, and label them.

  • Enable screen lock, privacy filters, and policies that prevent unauthorized viewing during in-person or remote work.

  • Shred paper records, wipe or destroy hard drives, and document the disposal method for each device and record type.

  • Use locks, alarm systems, and visitor policies to limit who can enter the space where PHI is stored or discussed.

Technical Safeguards

The technology and access controls that protect electronic PHI.

  • Every account that touches PHI should have a unique login, a strong password, and multi-factor authentication where possible.

  • Turn on access logs in your EHR, cloud storage, and email. Review the logs periodically for unusual activity.

  • Use checksums, version history, and write-once storage to ensure ePHI cannot be silently modified or deleted.

  • Use TLS for email and messaging, full-disk encryption on devices, and HIPAA-compliant cloud storage for backups.

  • Set a short inactivity timeout (typically 15 minutes or less) for any device or app that displays PHI.

Business Associate Agreements

Every vendor that creates, receives, maintains, or transmits PHI on your behalf must sign a BAA.

  • List your EHR, telehealth platform, billing service, cloud storage, transcription, and any other vendor that touches PHI.

  • Store the BAA, including the date signed and version, and renew whenever the vendor updates their terms.

  • Ask vendors that subcontract (e.g., cloud hosting) whether they flow down HIPAA obligations to their subcontractors.

Breach Notification

Prepare to detect, respond to, and report a breach quickly and within HIPAA timelines.

  • Configure alerts for failed logins, mass downloads, or unusual access patterns in your EHR and cloud storage.

  • Document who you call, what you preserve, how you investigate, and how you document the incident for HHS.

  • A breach affecting more than 500 individuals must be reported to HHS within 60 days, with media notice in jurisdictions where required.

  • For every suspected incident, document the four-factor risk assessment that determines whether a breach is reportable.

Documentation & Policies

Keep written policies and proof of compliance ready for audits and questions.

  • Cover administrative, physical, and technical safeguards in a single accessible policy binder (digital or printed).

  • Make the NPP available on your website, in your intake paperwork, and posted in your office if applicable.

  • Store signed BAAs, SOC 2 reports, and vendor security questionnaires in a single, organized location.

  • Record every suspected incident, the investigation, the outcome, and any corrective action, even if it is not reportable.

  • Re-run the risk analysis, refresh training, and update policies at least once per year or whenever you add a new vendor or service.

Founder's Club offer

Founder's Club

Ready to start your practice? Join our exclusive community.

  • Lifetime access to EHR
  • Private community access
  • Priority support
$149$499Lifetime Access

Lock in lifetime pricing before we raise prices.

Related Tools

Compare this result with a few adjacent planning tools for pricing, overhead, or private-practice transition decisions.

How this HIPAA checklist is organized

HIPAA is built around three safeguard categories — administrative, physical, and technical — plus breach response, BAAs, and documentation. This checklist walks through each category with practical items that a solo therapist can complete in a single afternoon.

Progress is stored in your browser, so you can step away and return to the same checklist later. Nothing is uploaded to a server, which keeps the answers between you and your HIPAA program file.

Use it for situations like

  • A first-time HIPAA setup when you open a new solo practice.
  • An annual HIPAA refresh for an established practice.
  • Onboarding a new vendor that will touch PHI.
  • Preparing documentation before hiring a contractor or VA.

FAQ

Questions therapists ask before using this calculator

Does a solo therapist really need a HIPAA program?

Yes. The HIPAA Security Rule applies to every covered entity, even if you are the only person in the practice. A documented program — policies, risk analysis, training, and vendor tracking — is what HHS expects to see if a complaint or breach is investigated.

How long does it take to work through this checklist?

Most solo therapists can complete a first pass in 60 to 90 minutes. Plan to revisit the checklist annually, after onboarding a new vendor, or whenever you add a service (telehealth, billing service, AI notetaker) that touches PHI.

Do I need a Business Associate Agreement with my EHR?

Yes. Any vendor that creates, receives, maintains, or transmits PHI on your behalf must sign a BAA. Your EHR, telehealth platform, billing service, transcription, and cloud storage vendors should all be on your BAA list.

What is the four-factor risk assessment for breaches?

When you suspect a breach, document the four factors HHS uses: the nature and extent of the PHI involved, the unauthorized person who used or received it, whether the PHI was actually acquired or viewed, and the extent to which the risk has been mitigated. The conclusion determines whether you must notify HHS and the client.

Does this checklist make my practice HIPAA compliant?

Completing the checklist is a strong step, but compliance is an ongoing program. Use it to identify gaps, document your policies, and as a recurring annual review tool, then consult a HIPAA attorney or compliance specialist for high-risk scenarios.

Not legal, clinical, or professional advice
The free tools on this page are provided for general informational and educational purposes only. EasyMindCare does not collect, store, transmit, or process any data you enter here — everything runs in your browser unless you choose to print, download, or share the output yourself. Outputs are starting points, not substitutes for advice from a qualified attorney, tax professional, licensed clinician, or other expert appropriate to your situation. You are solely responsible for how you use these tools and for any data, records, or decisions that result from that use. Use at your own risk; no warranty is made as to accuracy, completeness, or fitness for a particular purpose.