HIPAA Compliance for Private Practice: The Ultimate Checklist
The HIPAA compliance checklist for solo therapy practices: safeguards, business associate agreements, and the mistakes that get practices fined.
What HIPAA requires of your practice
If you transmit or store protected health information (PHI) electronically, HIPAA's Security Rule applies to you — even as a solo practitioner. Compliance rests on three pillars: administrative, technical, and physical safeguards.
You don't need enterprise infrastructure; you need documented, reasonable safeguards matched to your practice size.
Administrative safeguards
- Written privacy policies covering PHI use, disclosure, and breach response.
- Staff training (even if staff is just you) and a record of it.
- Risk analysis: identify where PHI lives and how it could leak.
- Business associate agreements with every vendor that touches PHI — EHR, telehealth, billing, email, AI documentation tools.
Technical safeguards
- Encryption for data at rest and in transit.
- Unique user accounts and strong passwords; role-based access where staff exist.
- Audit logs showing who accessed records and when.
- Automatic lockout after inactivity and secure backup.
- A documented breach response procedure.
The compliance checklist
- Privacy and security policies written down and dated.
- Signed BAAs for every PHI-touching vendor on file.
- Encryption enabled on devices, email, and your EHR.
- Unique logins with access controls and audit trails.
- Annual risk analysis and staff training records.
- Breach notification procedure ready to go.
Frequently asked questions
Does a solo therapist need to be HIPAA compliant?+
If you store or transmit protected health information electronically — which virtually every practice does — yes, HIPAA's Security Rule applies regardless of practice size.
Do I need a BAA with every software vendor?+
Any vendor that stores, transmits, or processes PHI on your behalf should sign a BAA: your EHR, telehealth platform, billing service, and any AI documentation tool. Email providers used for PHI may also require one.
What counts as a HIPAA violation for a therapist?+
Common violations include unauthorized PHI access, missing BAAs, unencrypted PHI, and untrained staff. Fines can be substantial, and breaches also damage client trust.
Generate clinical notes in minutes
Therazent turns session recordings into SOAP, DAP, BIRP, and progress notes you review and sign. Free 14-day trial.
Start free trial