Running a medical practice in the Hudson Valley means juggling patient care, staffing, billing โ and somewhere on that list, HIPAA compliance. It’s easy for the IT side of compliance to get pushed to “we’ll deal with it later,” but with HIPAA violation fines ranging from $100 to over $50,000 per violation, later can get expensive fast.
Here’s a practical checklist we walk through with medical and dental practices across Poughkeepsie, Hyde Park, Fishkill, and the surrounding area.
1. Risk Assessment
Have you conducted a formal HIPAA Security Risk Assessment in the last 12 months? This is required annually and is often the first thing auditors ask for.
2. Data Encryption
- Is patient data encrypted both at rest (on servers/devices) and in transit (email, file transfers)?
- Are laptops and mobile devices that access patient data encrypted in case of loss or theft?
3. Access Controls
- Does each staff member have their own login (no shared credentials)?
- Is access to patient records limited based on role (front desk vs. clinical staff)?
- Are former employees’ accounts deactivated immediately upon departure?
4. Backup & Disaster Recovery
- Are patient records backed up daily?
- Have you tested restoring from a backup in the last 6 months?
- Do you have a documented disaster recovery plan?
5. Audit Logging
- Can you produce a log of who accessed a specific patient record and when?
- Are logs retained for the required period?
6. Employee Training
- Has staff been trained on phishing recognition and safe email practices in the last year?
- Do employees know how to report a suspected breach?
7. Business Associate Agreements (BAAs)
- Do you have signed BAAs with every vendor that touches patient data (IT provider, cloud storage, billing software, etc.)?
8. Secure Email & Messaging
- Is patient information sent via encrypted, HIPAA-compliant email โ not standard Gmail or Outlook?
9. Endpoint Security
- Are all devices (workstations, laptops, tablets) protected with managed antivirus/EDR?
- Are software and security patches applied promptly?
10. Incident Response Plan
- Do you have a written plan for what happens if a breach occurs, including required notification timelines?
If You Checked “No” on Any of These
You’re not alone โ most practices we assess are missing at least a few of these pieces, often without realizing it. The good news: these are all fixable, usually without disrupting your day-to-day operations.
We work specifically with medical and dental practices throughout Dutchess County and the Hudson Valley to close these gaps and keep you audit-ready year-round.
