" HIPAA IT Compliance Checklist for Orange County Medical Practices (2026) | Shift Computer Services
Female doctor wearing glasses and stethoscope working on a laptop at a wooden desk with medical notes.

HIPAA IT Compliance Checklist for Orange County Medical Practices (2026)

September 25, 2026

If your practice stores patient records in Microsoft 365 or an EHR hosted in Azure, but nobody has ever signed a Business Associate Agreement with Microsoft or audited who can access that data, your practice is out of HIPAA compliance regardless of how secure the software itself is. This checklist maps each HIPAA IT requirement to what actually needs to happen inside your systems, written for small Orange County primary care, chiropractic, behavioral health, and dental practices without a dedicated IT team.

Why This Checklist Is Different From the Generic HIPAA PDFs You've Already Seen

Most HIPAA compliance checklists list regulatory requirements and stop there. This checklist maps each item to the specific IT configuration or action required, so an Orange County practice without a dedicated IT staff member knows what to actually do, not just what the rule says.

Shift Computer Services is a Los Alamitos-based managed IT provider serving Orange County medical practices across cloud management, cybersecurity, and IT compliance. This checklist is one component of Shift's broader healthcare IT services for Orange County practices, which covers cloud management, device security, and ongoing support alongside HIPAA compliance.

Orange County's concentration of small independent clinics (solo primary care physicians, chiropractic offices, behavioral health practices) means most are running Microsoft 365 self-managed by whoever set it up years ago. This checklist is built for that reality.

Step 1: Identify Every Place PHI Lives in Your IT Environment

Before checking any HIPAA box, map every location where protected health information (PHI, any patient data that could identify an individual) exists in your systems. Skipping this inventory is the most common reason small practices complete a checklist and still fail an audit.

Protected Health Information (PHI): Any individually identifiable health information created, received, maintained, or transmitted by a covered entity, including electronic records, email, fax, and voicemail.

Where PHI Hides in a Small Practice's IT Environment

  • EHR system: Cloud-hosted EHRs store the bulk of clinical PHI. Confirm whether your EHR is vendor-hosted or on-premises, because your responsibilities differ.
  • Microsoft 365 mailboxes: Patient emails, appointment confirmations, referral letters, and lab results frequently land in Exchange Online inboxes with no encryption or access controls applied.
  • SharePoint and Teams channels: Misconfigured sites and channels are a leading PHI exposure vector because of files shared broadly or externally without review.
  • Shared network drives: On-premises file servers or NAS devices often hold scanned records and billing documents with no audit logging.
  • Clinical workstations and tablets: Devices used at the point of care may cache patient data locally, especially if offline access is enabled.
  • Multifunction printers (MFPs): MFPs store print jobs and scanned documents internally, a frequently overlooked PHI repository.
  • Third-party apps: Any scheduling tool, patient portal, billing platform, or telehealth app that touches patient data requires a signed Business Associate Agreement.

This inventory directly satisfies the HIPAA Security Rule's risk analysis requirement (§164.308(a)(1)), which requires covered entities to identify where ePHI exists before assessing threats to it. Without the inventory, the risk analysis is incomplete.

Step 2: The Technical Safeguards Checklist (What Your IT Setup Must Enforce)

HIPAA technical safeguards are the specific IT controls required to protect ePHI: access controls, encryption, audit logging, and automatic logoff. The 2025 HIPAA Security Rule update moved several of these from "addressable" to explicit requirements, meaning practices can no longer document a reason for skipping them.

HIPAA Technical Safeguards: The technology controls and policies required under 45 CFR §164.312 to protect electronic PHI from unauthorized access, alteration, or transmission.

HIPAA Technical Safeguards Checklist

  • Multi-factor authentication (MFA) on all ePHI systems: Now an explicit HIPAA requirement. MFA must be enforced on Microsoft 365, Azure-hosted EHRs, and remote desktop sessions. Default Microsoft 365 tenants often have MFA disabled or set to legacy authentication; this requires deliberate configuration.
  • Automatic logoff on shared clinical workstations (§164.312(a)(2)(iii)): Workstations in exam rooms or at nursing stations must lock automatically after a defined inactivity period. The timeout must be documented in your policy.
  • Encryption of ePHI at rest and in transit: Data at rest (servers, laptops, SharePoint) and in transit (email, file transfers) must be encrypted. Microsoft's native encryption requires specific tenant and mailbox settings to meet HIPAA standards; defaults are not sufficient.
  • Unique user IDswith no shared logins (§164.312(a)(2)(i)): Every workforce member must have their own credentials. Shared accounts are a direct HIPAA violation and make audit logs useless.
  • Audit logs and access monitoring: Systems must record who accessed which patient record and when. Microsoft 365 Unified Audit Log and EHR audit trails both require active configuration; retention levels are not sufficient by default.
  • Signed Business Associate Agreements (BAAs) with cloud vendors: A BAA is a required HIPAA contract with any vendor handling ePHI on your behalf. Microsoft offers a BAA for Azure and Microsoft 365, but your organization must request and execute it. An unsigned BAA means your use of Microsoft 365 for patient data is non-compliant.

Self-managed Microsoft 365 deployments consistently fail OCR audits on at least three of these six items, closing the configuration gap between what M365 offers and what HIPAA actually requires is typically the first priority for practices starting a compliance review.

Step 3: Administrative and Physical Safeguards: The Policies Your Practice Must Actually Have

Administrative and physical safeguards are the documented policies and physical controls HIPAA requires alongside technical measures. A practice with strong IT security but no written policies or designated Security Officer is still non-compliant.

HIPAA Administrative Safeguards Checklist

  • Designated Security Officer: HIPAA requires every covered entity to name a Security Officer responsible for developing and enforcing security policies (§164.308(a)(2)). This role can be part-time or filled by a qualified outside party, but someone must be formally designated and documented.
  • Annual Security Risk Assessment (SRA): A documented evaluation of threats and vulnerabilities to ePHI, completed at least annually and retained on file. An SRA that exists only as a conversation does not satisfy OCR requirements.
  • Workforce training records: Documented evidence that all workforce members who handle PHI have received security awareness training. Completion logs, not just a training policy, must be on file.
  • Sanctions policy: A written policy specifying consequences for workforce members who violate HIPAA security policies. Verbal warnings do not satisfy this requirement.
  • Contingency plan and disaster recovery (§164.308(a)(7)): A tested, documented disaster recovery plan is a named HIPAA administrative safeguard. It must address data backup, recovery procedures, and emergency mode operations. "We have backups" is not a contingency plan.

HIPAA Physical Safeguards Checklist

  • Workstation use policy: PHI must not be accessed on personal devices unless enrolled in an MDM solution that enforces encryption and remote wipe capability.
  • Screen privacy filters in patient-facing areas: Monitors visible to patients in reception or exam rooms must use physical privacy filters.
  • Controlled physical access to servers and NAS devices: Server closets and on-premises storage must be physically secured, locked rooms with access logs.
  • Media disposal and sanitization: Retired hard drives, USB drives, and MFP storage units must be sanitized using a documented procedure before disposal. Physical destruction or certified degaussing are accepted methods.

California practices also operate under the California Confidentiality of Medical Information Act (CMIA), which applies stricter consent and disclosure requirements than HIPAA. Where CMIA and HIPAA conflict, the stricter standard applies, meaning HIPAA compliance alone does not equal full legal compliance for California-based practices.

Frequently Asked Questions

What does HIPAA require for IT systems in a small medical practice?

HIPAA requires small practices to implement technical safeguards (MFA, encryption, unique user IDs, audit logging, automatic logoff), administrative safeguards (risk assessments, security officer designation, workforce training), and physical safeguards (device controls, media disposal). Signed Business Associate Agreements with all cloud vendors handling patient data are also required.

Does Microsoft 365 require a Business Associate Agreement for HIPAA compliance?

Yes. If your practice uses Microsoft 365 or Azure to store, transmit, or process patient data, a signed Business Associate Agreement with Microsoft is required under HIPAA. Microsoft offers a BAA for covered entities, but your organization must actively request and execute it. Using Microsoft 365 without a signed BAA is a HIPAA compliance gap.

What is the difference between HIPAA administrative, physical, and technical safeguards?

Administrative safeguards are written policies, risk assessments, and training programs. Physical safeguards are controls over the physical spaces and devices where PHI is accessed: locks, screen filters, and media disposal. Technical safeguards are the IT configurations that protect ePHI: MFA, encryption, audit logs, and access controls.

Does California have additional medical privacy laws beyond HIPAA?

Yes. The California Confidentiality of Medical Information Act (CMIA) applies stricter consent and disclosure rules than federal HIPAA. Orange County medical practices must satisfy both. Where CMIA and HIPAA conflict, California's stricter standard applies, meaning HIPAA compliance alone does not equal full legal compliance for California-based practices.

Not Sure Your Orange County Practice Would Pass a HIPAA IT Audit?

Book a free 15-minute discovery call with Shift Computer Services. We'll identify the specific gaps in your current IT setup and show you exactly what it takes to get your practice to full HIPAA technical compliance.

Book Your Free Discovery Call