HIPAA Risk Assessment Checklist for Dental and Medical Practices in Texas
A clear HIPAA risk assessment checklist gives Texas clinics a plain-English way to protect patient information, meet HIPAA expectations in Texas, and build patient trust. If you run a dental or medical practice in Houston, Katy, or Sugar Land, starting with a practical, step-by-step list turns healthcare cybersecurity into daily habits—not a once-a-year scramble.
What is a HIPAA risk assessment checklist in one line? It’s a structured list of tasks that helps Texas dental and medical practices identify where PHI is stored, evaluate security controls, and prioritize fixes to support HIPAA compliance and PHI security. In short, it translates the HIPAA Security Rule into clear, clinic-ready steps.
Core steps at a glance
- Inventory all PHI locations and data flows
- Enforce unique logins, least privilege, and MFA
- Encrypt devices, servers, and backups
- Patch operating systems and clinical software
- Filter email and train staff on phishing
- Automate, encrypt, and test backups; define RPO/RTO
- Harden networks and endpoints; segment Wi‑Fi
- Secure workstations and control physical access
- Track vendors and maintain Business Associate Agreements
- Enable logging, monitoring, and an incident response plan
- Maintain policies, procedures, and workforce training
- Reassess at least annually and after major changes
What Is a HIPAA Risk Assessment Checklist?
Purpose, scope, and how it supports the HIPAA Security Rule
- Purpose: Identify risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI, then select reasonable and appropriate safeguards.
- Scope: People, processes, and technology that touch PHI—front desk through providers; servers to cloud apps; imaging devices to backups.
- Security Rule alignment: This checklist maps to Administrative, Physical, and Technical Safeguards so you can demonstrate due diligence and document decisions. See the HHS HIPAA Security Rule guidance.
How Texas-focused considerations fit into your assessment
- State nuance: Texas law can be more protective in some areas than federal HIPAA. While this article isn’t legal advice, best practice in Texas is to maintain clear privacy notices, minimum necessary access, rapid breach identification/notification workflows, and secure disposal of PHI-bearing devices.
- Local operations: Many Houston-area practices use a cloud EHR plus on-prem imaging PCs. That hybrid footprint makes strong backups, network segmentation, and tested recovery essential.
Who should be involved
- Practice owner/administrator: accountable for decisions and resources
- Compliance lead/Privacy Officer: coordinates policies, training, and documentation
- IT partner: designs controls, maintains systems, and provides evidence
- Key vendors/Business Associates: EHR, imaging, clearinghouses, billing, MSPs, shredding services, and secure messaging providers
How to Use This Texas HIPAA Risk Assessment Checklist
Frequency, documentation, and prioritization
- Frequency: Complete a full assessment at least annually and after major changes (new EHR, office move, mergers, or security incidents). Review high-risk items quarterly.
- Documentation: Keep a living risk register with assets, threats, controls, likelihood, impact, owners, and due dates.
- Prioritization: Address high-likelihood/high-impact risks first. Balance quick wins (MFA, email filtering) with larger projects (network segmentation).
Risk rating basics
- Likelihood: Low/Medium/High—How often could this occur given your environment?
- Impact: Low/Medium/High—What’s the patient, financial, and compliance harm if it happens?
- Remediation: Choose reasonable, effective controls; set clear owners and deadlines; track verification evidence.
The HIPAA Risk Assessment Checklist (Step-by-Step)
Inventory PHI and Systems
- Identify where PHI lives: EHR, imaging software, practice management, email, patient messaging, lab portals, cloud storage, local servers, encrypted USBs, backups, mobile devices, and paper.
- Map data flows: From patient intake and imaging capture to claims, referrals, patient communications, and archival. Note every handoff, system, and user role.
- Include dental specifics: PHI often sits on X‑ray/CBCT workstations, Dexis image folders or databases, and shared network paths.
Access Controls and Authentication
- Unique logins: No shared accounts; each user has their own credentials.
- Least privilege: Restrict access by role; for example, front desk staff shouldn’t see provider-only notes unless required.
- MFA: Enable for remote access, EHR portals, email (Microsoft 365/Google Workspace), and admin panels. Prioritize owners and billing roles with elevated rights.
Encryption and Data Protection
- Full-disk encryption: Laptops, workstations handling PHI, and on-site servers.
- Backup encryption: Onsite and cloud backups must be encrypted at rest and in transit.
- Secure transfer: Use TLS for portals and VPNs for remote access; avoid unencrypted file shares across VLANs.
- Email filtering: Reduce PHI leakage and block malicious payloads.
Patch and Vulnerability Management
- Keep operating systems, browsers, and office suites up to date.
- Patch clinical software: Dentrix, Eaglesoft, Open Dental, Dexis, and Sidexis/Sirona; include device firmware for scanners, sensors, and firewalls.
- Scan routinely: Identify outdated apps and known vulnerabilities; patch on a schedule.
Secure Email, Messaging, and Fax Workflows
- Email filtering plus DMARC/DKIM/SPF hardening.
- Phishing simulations with short, recurring staff refreshers.
- Use secure messaging or patient portals for PHI instead of standard email.
- eFax services with BAAs; disable legacy analog fax modems on PHI networks if not needed.
Backup and Disaster Recovery
- Automate daily backups for EHR databases, imaging repositories, and file shares.
- Encrypt all backups and store at least one immutable or offline copy.
- Test recoveries quarterly; document recovery time objective (RTO) and recovery point objective (RPO).
- Maintain a written downtime plan for patient check-in, scheduling, and imaging.
Network and Endpoint Security
- Next-gen firewall with properly configured rules; block unnecessary inbound/outbound services.
- Endpoint protection with behavior-based detection and web filtering.
- Wi‑Fi segmentation: Separate guest, office, and clinical devices; change default router credentials.
- Restrict USB where practical; use approved encrypted media when necessary.
Physical Safeguards
- Control access to server/network closets; keep doors locked and logged.
- Use screen locks and privacy filters at front desk and operatories.
- Ensure secure device disposal with certificates of destruction; wipe or shred drives.
Vendor Risk and Business Associate Agreements
- Inventory all Business Associates (EHR, imaging, billing, labs, marketing, shredding, IT).
- Maintain signed BAAs and review vendors’ security practices annually.
- Limit vendor access to the minimum necessary; require MFA and logging on vendor remote tools.
Logging, Monitoring, and Incident Response
- Enable audit logs on EHR, imaging, email admin consoles, and firewalls.
- Centralize alerts for suspicious logins, malware, or large data transfers.
- Maintain an incident response plan with defined roles and a breach notification process aligned to HIPAA and Texas timelines.
Policies, Procedures, and Workforce Training
- Maintain up-to-date policies covering access, passwords, email use, mobile devices, backups, and disposal.
- Onboard new staff with role-specific training; refresh annually with documented attestations.
- Conduct tabletop drills for phishing and downtime events.
Dental Software & Imaging Considerations
- Dentrix/Eaglesoft/Open Dental: Confirm role-based permissions, regular patching, secure SQL/database backups, and tested restore procedures.
- Dexis/Sidexis/Sirona: Harden imaging workstations, secure shared image paths, and validate that image archives are included in backups.
- Acquisition PCs in operatories: Use dedicated clinical VLANs, disable local admin where possible, and enforce auto-lock.
Ongoing Review and Improvement
- Perform quarterly checks on logs, backups, and vendor access.
- Conduct an annual reassessment with updated risk ratings and remediation status.
- Use change management: Re-evaluate risks after adding equipment, moving offices, or adopting new software.
Common Gaps We See in Houston Dental and Medical Practices
Missing MFA, untested backups, no vendor inventory
- Email and remote access without MFA are still common.
- Backups exist but restores haven’t been tested in months.
- No centralized list of Business Associates or current BAAs.
Shared logins and outdated imaging workstations
- Shared front-desk accounts break audit trails and increase PHI exposure.
- Imaging PCs run outdated OS versions and unsupported drivers, creating unnecessary risk.
Email phishing and unsecured file sharing
- Staff click through spoofed messages that bypass basic filters.
- Teams “temporarily” use personal cloud storage for large files without encryption or a BAA.
Myth vs. Fact (Quick Clarity)
- Myth: “We’re a small Texas clinic—attackers won’t target us.” Fact: Automated attacks and phishing don’t discriminate by size. Basic controls like MFA and filtering stop many incidents.
- Myth: “Our vendor handles HIPAA for us.” Fact: Vendors are Business Associates, but the practice remains responsible for PHI security and due diligence.
- Myth: “If data is in the cloud, we don’t need backups.” Fact: Cloud platforms reduce some risks but do not replace your responsibility to have recoverable, tested backups.
Documentation Made Simple

Risk register elements to track
- Asset: EHR database, imaging PC, email tenant
- Threat: Phishing, ransomware, theft, misconfiguration
- Control: MFA, encryption, patching, firewall rules
- Likelihood/Impact: Low/Medium/High with notes
- Owner/Due date: Accountable person and timeline
- Status/Evidence: Screenshots, reports, change tickets
Evidence checklist to keep current
- Screenshots of MFA settings, encryption status, and firewall rules
- Policy copies and training records with dates and attestations
- Backup job logs and recovery test reports
- Vendor BAA files and annual security review summaries
- Audit logs and alert reports with periodic reviews
When to Call a Specialist
Indicators you may need outside support
- You can’t confirm where all PHI lives or if it’s backed up.
- MFA is missing on email/EHR or you still use shared logins.
- Imaging systems or practice software haven’t been patched in months.
- No tested recovery plan; RTO/RPO are unknown.
- You’re unsure which vendors need BAAs or how to review them.
How CompTSS helps Houston practices
CompTSS is a Houston-based team supporting dental and healthcare providers with HIPAA-focused cybersecurity, automated encrypted backups with tested disaster recovery, and expert dental software support across Dentrix, Eaglesoft, Open Dental, Dexis, and Sidexis/Sirona. Our flat-rate Assurance plans scale with your workstations, and we offer fast remote response with on-site support when needed. Explore our Houston dental IT support and HIPAA-compliant IT services on our main page: Houston dental IT support.
Local Insight from the Field
On a recent Houston clinic engagement, we helped a practice map PHI across their EHR, imaging PCs, and a backup NAS, then enabled MFA and encrypted their backups. The biggest win came from fixing a shared front-desk login, which tightened access and simplified audit logs—simple steps that delivered real risk reduction without disrupting care.
Next Steps: Put This HIPAA Risk Assessment Checklist Into Action Today
- Block a 60-minute working session this week to inventory PHI locations and data flows.
- Turn on MFA for email and any remote access immediately; it’s a quick, high-impact win.
- Confirm backups are encrypted and run a small restore test; document the results.
- List your Business Associates and gather BAAs; start with EHR, imaging, billing, and IT.
Go deeper with these Houston-ready resources
- For a broader security review, use our cybersecurity audit checklist with endpoint protection and Zero Trust guidance.
- Build tested resilience with cloud backup best practices and disaster recovery planning.
- Strengthen response plans and run tabletop exercises using our ransomware recovery planning guide.
- For dental software workflows and secure imaging integration, see our secure dental IT solutions.
- Need quick help today? Our team offers fast remote response.
- For HIPAA and EHR insights tailored to clinics, read our overview of healthcare IT trends.
Quick answer for scheduling your reviews
Q: How often should a HIPAA risk assessment be done in Texas dental and medical practices?
A: Perform a full risk assessment at least annually and after any major change (new EHR, office move, mergers, or security incidents). Review high-risk items quarterly to confirm controls, training, and backups remain effective.
A Calm, Workable Plan for Texas Clinics
Use this HIPAA risk assessment checklist as your ongoing Texas playbook for PHI security and dental HIPAA best practices. Start with the high-impact basics—MFA, encrypted and tested backups, email filtering—and build from there with clear documentation and quarterly touchpoints. If you want a steady, hands-on partner in Houston or Greater Houston, CompTSS can help you apply this HIPAA risk assessment checklist at a sensible pace that fits patient care.
Image alt: HIPAA risk assessment checklist steps for Houston clinics
Frequently Asked Questions
What is a HIPAA risk assessment checklist?
Short answer: It’s a step-by-step list that helps you find where PHI lives, evaluate safeguards, and prioritize fixes for HIPAA Security Rule alignment.
Expanded: A HIPAA risk assessment checklist translates the HIPAA Security Rule into practical, clinic-ready actions. It covers people, processes, and technology—front desk to providers; imaging devices to backups—so Texas practices can document risks, apply reasonable controls, and show due diligence.
How often should our Texas clinic complete a HIPAA risk assessment?
Short answer: At least annually and after any major change; review high-risk items quarterly.
Expanded: Texas dental and medical practices should perform a full assessment yearly and whenever you adopt a new EHR, move offices, merge, or have a security incident. Quarterly touchpoints confirm MFA, backups, and training remain effective.
Who needs to be involved in the assessment?
Short answer: The practice owner/administrator, Privacy/Compliance lead, your IT partner, and key Business Associates.
Expanded: Accountability sits with leadership, while the Privacy/Compliance lead coordinates policies and training. Your IT partner designs and maintains controls, and vendors—EHR, imaging, billing, clearinghouses, and shredding—provide evidence and sign Business Associate Agreements (BAAs).
What Texas-specific points should we consider?
Short answer: Texas can be more protective than federal HIPAA—focus on clear privacy notices, minimum necessary access, fast breach workflows, and secure disposal.
Expanded: For Houston-area practices with hybrid setups (cloud EHR plus on‑prem imaging PCs), emphasize strong backups, Wi‑Fi segmentation, and tested recovery. While this isn’t legal advice, aligning with Texas privacy nuances reduces risk and supports compliance.
What systems and data should we inventory first?
Short answer: EHR, imaging software (e.g., Dexis, Sidexis/Sirona), practice management, email, portals, backups, mobile devices, and paper.
Expanded: Map data flows from intake to referrals and claims, including X‑ray/CBCT workstations, imaging folders or databases, and shared paths. This foundation drives accurate risk ratings and ensures nothing holding PHI is overlooked.
Which controls give the biggest early impact?
Short answer: MFA, encrypted and tested backups, and email filtering.
Expanded: Enforce unique logins with least privilege, enable MFA on email and remote access, encrypt devices and backups, and harden email (filtering plus DMARC/DKIM/SPF). These steps block common attacks and reduce PHI exposure with minimal disruption.
How should we handle backups and disaster recovery?
Short answer: Automate daily, encrypt, keep an immutable/offline copy, and test restores quarterly with defined RPO/RTO.
Expanded: Back up EHR databases, imaging repositories, and file shares. Document recovery time objective (RTO) and recovery point objective (RPO) and maintain a written downtime plan for check‑in, scheduling, and imaging. For deeper guidance, see our cloud backup and recovery planning resource: https://comptss.com/cloud-backup-unlock-it-success-cloud-backup-sys
What are common gaps in Houston practices?
Short answer: Missing MFA, untested backups, no vendor inventory, shared logins, and outdated imaging PCs.
Expanded: We frequently find email/remote access without MFA, backups that aren’t tested, incomplete BAAs, shared front‑desk accounts, and imaging workstations with outdated OS or drivers—issues that weaken audit trails and PHI security but are fixable with clear ownership and timelines.
How do we document the HIPAA risk assessment checklist effectively?
Short answer: Keep a living risk register and current evidence.
Expanded: Track assets, threats, controls, likelihood/impact, owners, due dates, and status/evidence. Maintain screenshots (MFA, encryption, firewall), policy/training records, backup logs and restore reports, BAAs, and audit/alert summaries. This proves due diligence and speeds audits and incident response.
When should we bring in a specialist—and how can CompTSS help in Houston?
Short answer: If PHI locations/backups aren’t clear, MFA or patching is missing, or recovery plans aren’t tested.
Expanded: Outside help is wise when you’re unsure about PHI inventory, vendor BAAs, or RPO/RTO. CompTSS supports Greater Houston (including Katy and Sugar Land) with HIPAA-focused cybersecurity, automated encrypted backups, disaster recovery testing, and dental software support (Dentrix, Eaglesoft, Open Dental, Dexis, Sidexis/Sirona). Explore our Houston dental IT support: https://comptss.com/ For broader assessments, see our cybersecurity audit checklist: https://comptss.com/cybersecurity-audit-ultimate-cybersecurity-audit and ransomware planning guide: https://comptss.com/ransomware-recovery-master-ransomware-recovery
A quick, real-world note from the field
Short answer: Fixing shared logins and enabling MFA can reduce risk fast.
Expanded: On a recent Houston clinic project, we mapped PHI across EHR, imaging PCs, and a backup NAS, turned on MFA, and encrypted backups. Replacing a shared front‑desk login with unique accounts immediately improved access control and simplified audit logs—meaningful gains without disrupting patient care.