Dental & Healthcare

How to Actually Conduct a HIPAA Security Risk Assessment

If you run a dental practice, you are expected to have done a HIPAA security risk analysis and to keep it current. Most office managers know the phrase. Far fewer have actually sat…

If you run a dental practice, you are expected to have done a HIPAA security risk analysis and to keep it current. Most office managers know the phrase. Far fewer have actually sat down and done one, because nobody ever explained what "doing one" looks like in practice, as opposed to what it looks like in a compliance binder nobody reads. This is that explanation.

A security risk analysis is not a form you fill out once and file away. It is a walkthrough of your practice: where electronic patient data lives, who can get to it, what could go wrong, and what you are doing about each of those things. Done honestly, it takes a few hours. Done as a favor to a future audit, it takes ten minutes and protects nobody.

What the HIPAA security risk analysis actually covers

The Security Rule applies to electronic protected health information, meaning data that lives on a computer, server, phone, or in the cloud. That includes your practice management software, your digital x-ray system, email that contains patient information, backups, and any device an employee uses to access patient records, including a personal phone checking the schedule from home.

Paper charts and paper superbills are real compliance concerns too, but they fall under the Privacy Rule, not the Security Rule, and they are handled differently: locked storage, controlled access, proper disposal. If your practice is still using paper alongside digital records, keep that on a separate checklist. Do not fold it into this analysis and assume you have covered it. You have not.

Step one: map where patient data actually lives

Most practices are surprised by this step, because the answer is rarely just "the practice management software." Walk through every system that touches patient information:

  • Your practice management software and its database, wherever it is hosted
  • Digital imaging and x-ray systems
  • Email accounts, especially if referral letters, insurance correspondence, or scheduling confirmations mention patient names or treatment
  • Backup systems, on site or cloud, and who can access them
  • Any cloud-based scheduling, patient communication, or billing tool
  • Laptops, tablets, and phones used by staff, including personal devices used to check email or the schedule

Write this down. Not because someone will ask to see the list, though they might, but because you cannot secure what you have not named.

Step two: figure out who can get to it

This is where the real gaps usually show up. Ask, for every system on your list: who has a login, and does that login match what they actually need to do their job? A hygienist rarely needs access to billing records. A front desk employee who left eight months ago should not still have an active account anywhere.

A pattern we see constantly in independent practices is one shared login used across several workstations because it was easier to set up that way years ago and nobody has revisited it since. It works, until someone needs to know who did what, or an employee leaves and the password has to change on every machine at once, or an insurer asks who accessed a specific record on a specific date and the honest answer is "we don't know, six people share that login."

Individual logins for every staff member, with access levels that match their actual role, is not a nice-to-have. It is the difference between being able to answer a basic question about your own data and not being able to.

Step three: check your safeguards against what could actually go wrong

For each system on your map, ask three questions: what could go wrong here, how likely is it, and what are we doing about it right now. A few areas worth specific attention:

Backups

A backup that has never been tested is a hope, not a safeguard. Confirm that backups are running, that they are stored somewhere separate from your main system, and that someone has actually restored a file from one recently to prove it works. If your answer to "when did we last test this" is a shrug, that is your first gap.

Devices

Every laptop and phone that can reach patient data should be protected by a password or PIN at minimum, and ideally by full disk encryption. If a staff member's laptop goes missing from a car, the question that matters is whether the data on it was protected. Encryption is what the Security Rule calls an addressable safeguard, meaning you are expected to implement it or document a reasonable alternative and why it fits your practice. For most small offices, there is no good reason not to just encrypt the devices. It is inexpensive and it removes the question entirely.

Email and messaging

Think about how patient information actually moves through your practice by email. A referral letter with a patient's name and treatment plan is a normal, permitted part of coordinating care, but it is worth evaluating whether it is going through a channel appropriate for that kind of detail, rather than assuming a regular inbox is fine simply because nothing looks obviously wrong. A secure patient portal or an encrypted email option gives you a clean answer to that question instead of a guess.

Remote access

If anyone can log into your systems from outside the office, whether from home, a second location, or a phone, confirm that connection is secured properly and not just a matter of typing a password into a browser from anywhere in the world.

Step four: write down the gaps and a timeline to close them

This is the part practices skip, and it is the part that actually matters. For every gap you find, write down what it is, how serious it is, and when you plan to fix it. You do not need to fix everything by Friday. You need a document that shows you found the problem and have a real plan, not a hope, for addressing it.

A simple table works fine: the gap, the risk it creates, who owns fixing it, and the target date. Keep it dated and update it when things change. This document, more than any policy binder, is what shows a genuine, ongoing effort at compliance rather than a one-time scramble before an audit.

A short list you can start this week

Before you call anyone, you can make real progress on your own:

  1. List every system that stores or transmits patient data, including phones and laptops.
  2. Check whether every staff member has an individual login, or whether logins are shared.
  3. Confirm your last backup and when it was last actually tested with a real restore.
  4. Check whether laptops and phones with access to patient data are password protected and encrypted.
  5. Pull up your last five outgoing emails containing patient information and see where they went.
  6. Write down every gap you find on a single page, with a rough date for fixing each one.

That page is the start of your risk analysis. It will not be complete, and it does not need to be yet. It needs to be honest.

Where practices usually get stuck

Two things stall this process almost every time. The first is not knowing what "good enough" looks like for a practice your size, so the whole thing gets postponed indefinitely in search of a standard that does not exist in the form people expect. The second is finding real gaps and not knowing which one to tackle first.

Neither problem requires guessing. If you want a second set of eyes on your list of systems and gaps, that is exactly the kind of thing HIPAA compliance support is for, and it is worth confirming with someone familiar with your state's specific requirements, since obligations can vary in the details even where the general shape is the same everywhere.

Dental practices have a specific set of systems and workflows, imaging software, treatment planning tools, insurance integrations, that generic IT advice does not always account for. That is the gap dental practice IT support is meant to close, and it is also true more broadly of healthcare IT for any small practice where the office manager doubles as the entire IT department.

What this actually buys you

A completed risk analysis is not paperwork for its own sake. It is the clearest picture you will ever have of where your practice's patient data actually lives, who can reach it, and what happens if a laptop is stolen or a server goes down on a Tuesday morning. Practices that do this well are not the ones with the fanciest tools. They are the ones who know, specifically, what they have and where the weak points are, and who are working through a real list instead of hoping nothing happens.

If you would rather walk through this with someone who has done it for other dental practices instead of building the list alone, we offer a short, no-pressure look at where your practice stands.

Book a free 15-minute Dental IT Risk Review and we will go through your systems, access, and backups together and tell you plainly where the real gaps are.

One accountable technology partner.

Tell us what's slowing your team down. We'll show you exactly how we'd fix it — no pressure, no jargon.

Book a Free Consultation
Book a Free Consultation