HIPAA Compliance Checklist for Las Vegas Medical Offices
Cybersecurity

HIPAA Compliance Checklist for Las Vegas Medical Offices

By Blue Water Networks  ·  June 4, 2026

HIPAA compliance is not a one-time checkbox — it is an ongoing program that requires documented policies, trained staff, and tested technical controls. For Las Vegas medical practices, the consequences of non-compliance range from $100 to $50,000 per violation, with an annual cap of $1.9 million per violation category.

This checklist covers the core requirements your practice should have in place today.

Administrative Safeguards

Administrative safeguards are the policies and procedures that govern how your organization handles protected health information (PHI).

Security Management Process

  • [ ] Conduct a formal Security Risk Assessment (required by 45 CFR 164.308(a)(1))
  • [ ] Implement a risk management plan addressing identified vulnerabilities
  • [ ] Review and update the risk assessment annually or after significant changes
  • [ ] Document all security incidents and outcomes

Workforce Controls

  • [ ] Designate a HIPAA Security Officer
  • [ ] Conduct HIPAA security awareness training for all staff — document attendance
  • [ ] Run simulated phishing campaigns at least quarterly
  • [ ] Implement sanctions for policy violations
  • [ ] Terminate access immediately upon employee departure

Access Management

  • [ ] Grant access to PHI on a minimum necessary basis only
  • [ ] Review user access levels at least annually
  • [ ] Disable shared or generic login credentials
  • [ ] Maintain an access log and review it regularly

Technical Safeguards

Technical safeguards are the technology controls that protect ePHI stored or transmitted electronically.

Access Controls

  • [ ] Require unique user IDs — no shared accounts
  • [ ] Implement multi-factor authentication (MFA) on all systems containing ePHI
  • [ ] Deploy automatic logoff after a period of inactivity
  • [ ] Use role-based access control (RBAC) in your EHR

Audit Controls

  • [ ] Enable audit logging on EHR, email, and file servers
  • [ ] Review audit logs regularly for suspicious activity
  • [ ] Retain audit logs for a minimum of 6 years

Integrity Controls

  • [ ] Use checksums or digital signatures to verify ePHI has not been altered
  • [ ] Implement version control for critical clinical documents

Transmission Security

  • [ ] Encrypt all ePHI in transit using TLS 1.2 or higher
  • [ ] Use encrypted email for any communication containing PHI
  • [ ] Prohibit transmission of PHI via standard SMS or consumer messaging apps
  • [ ] Use HIPAA-compliant video conferencing for telehealth

Encryption at Rest

  • [ ] Encrypt all workstation hard drives (BitLocker for Windows, FileVault for Mac)
  • [ ] Encrypt mobile devices that access ePHI
  • [ ] Encrypt backup media and verify encryption regularly

Physical Safeguards

Physical safeguards govern who can physically access your systems and facilities.

  • [ ] Restrict access to server rooms and network equipment
  • [ ] Use badge access or key locks on areas containing ePHI
  • [ ] Implement a clean desk policy — no PHI left visible after hours
  • [ ] Apply privacy screens to workstations in patient-facing areas
  • [ ] Establish a workstation use policy (no personal use on clinical machines)
  • [ ] Track and inventory all portable devices (laptops, tablets, USB drives)
  • [ ] Implement a media disposal policy — degauss or shred drives before disposal

Backup and Disaster Recovery

  • [ ] Implement automated daily backups of all ePHI
  • [ ] Store at least one backup copy offsite or in the cloud
  • [ ] Test backup restoration at least quarterly — document the results
  • [ ] Maintain a documented Business Continuity Plan (BCP)
  • [ ] Test the BCP at least annually

Business Associate Agreements

  • [ ] Maintain a signed Business Associate Agreement (BAA) with every vendor who touches ePHI
  • [ ] Common vendors requiring BAAs: cloud storage, EHR vendors, billing services, MSPs, email providers, shredding companies
  • [ ] Review BAAs when contracts renew or vendor services change

Breach Response

  • [ ] Maintain a documented Breach Notification Policy
  • [ ] Breaches affecting 500+ individuals in Nevada must be reported to HHS within 60 days
  • [ ] Breaches affecting fewer than 500 individuals must be reported annually
  • [ ] Notify affected patients without unreasonable delay and within 60 days
  • [ ] Document all breach investigations — even ones that turn out to be non-reportable

Common HIPAA Violations in Las Vegas Medical Practices

The most frequent violations OCR investigates:

  1. No risk assessment — the most cited violation; required annually
  2. Lack of access controls — shared passwords, no MFA
  3. Unencrypted devices — laptops and USB drives without encryption
  4. Improper disposal — PHI on devices sold or discarded without wiping
  5. No BAAs in place — vendors accessing data without a signed agreement

Need a HIPAA Security Risk Assessment?

Blue Water Networks performs formal HIPAA Security Risk Assessments for Las Vegas medical practices, producing the documented report required under 45 CFR 164.308(a)(1). We also remediate the findings — so you are not left with a list of problems and no path forward.

Contact Us for a HIPAA Assessment

Questions? Talk to a Las Vegas IT Expert.

Blue Water Networks specializes in managed IT for medical and financial firms. Schedule a free consultation.