HIPAA compliance is not a one-time checkbox — it is an ongoing program that requires documented policies, trained staff, and tested technical controls. For Las Vegas medical practices, the consequences of non-compliance range from $100 to $50,000 per violation, with an annual cap of $1.9 million per violation category.
This checklist covers the core requirements your practice should have in place today.
Administrative Safeguards
Administrative safeguards are the policies and procedures that govern how your organization handles protected health information (PHI).
Security Management Process
- [ ] Conduct a formal Security Risk Assessment (required by 45 CFR 164.308(a)(1))
- [ ] Implement a risk management plan addressing identified vulnerabilities
- [ ] Review and update the risk assessment annually or after significant changes
- [ ] Document all security incidents and outcomes
Workforce Controls
- [ ] Designate a HIPAA Security Officer
- [ ] Conduct HIPAA security awareness training for all staff — document attendance
- [ ] Run simulated phishing campaigns at least quarterly
- [ ] Implement sanctions for policy violations
- [ ] Terminate access immediately upon employee departure
Access Management
- [ ] Grant access to PHI on a minimum necessary basis only
- [ ] Review user access levels at least annually
- [ ] Disable shared or generic login credentials
- [ ] Maintain an access log and review it regularly
Technical Safeguards
Technical safeguards are the technology controls that protect ePHI stored or transmitted electronically.
Access Controls
- [ ] Require unique user IDs — no shared accounts
- [ ] Implement multi-factor authentication (MFA) on all systems containing ePHI
- [ ] Deploy automatic logoff after a period of inactivity
- [ ] Use role-based access control (RBAC) in your EHR
Audit Controls
- [ ] Enable audit logging on EHR, email, and file servers
- [ ] Review audit logs regularly for suspicious activity
- [ ] Retain audit logs for a minimum of 6 years
Integrity Controls
- [ ] Use checksums or digital signatures to verify ePHI has not been altered
- [ ] Implement version control for critical clinical documents
Transmission Security
- [ ] Encrypt all ePHI in transit using TLS 1.2 or higher
- [ ] Use encrypted email for any communication containing PHI
- [ ] Prohibit transmission of PHI via standard SMS or consumer messaging apps
- [ ] Use HIPAA-compliant video conferencing for telehealth
Encryption at Rest
- [ ] Encrypt all workstation hard drives (BitLocker for Windows, FileVault for Mac)
- [ ] Encrypt mobile devices that access ePHI
- [ ] Encrypt backup media and verify encryption regularly
Physical Safeguards
Physical safeguards govern who can physically access your systems and facilities.
- [ ] Restrict access to server rooms and network equipment
- [ ] Use badge access or key locks on areas containing ePHI
- [ ] Implement a clean desk policy — no PHI left visible after hours
- [ ] Apply privacy screens to workstations in patient-facing areas
- [ ] Establish a workstation use policy (no personal use on clinical machines)
- [ ] Track and inventory all portable devices (laptops, tablets, USB drives)
- [ ] Implement a media disposal policy — degauss or shred drives before disposal
Backup and Disaster Recovery
- [ ] Implement automated daily backups of all ePHI
- [ ] Store at least one backup copy offsite or in the cloud
- [ ] Test backup restoration at least quarterly — document the results
- [ ] Maintain a documented Business Continuity Plan (BCP)
- [ ] Test the BCP at least annually
Business Associate Agreements
- [ ] Maintain a signed Business Associate Agreement (BAA) with every vendor who touches ePHI
- [ ] Common vendors requiring BAAs: cloud storage, EHR vendors, billing services, MSPs, email providers, shredding companies
- [ ] Review BAAs when contracts renew or vendor services change
Breach Response
- [ ] Maintain a documented Breach Notification Policy
- [ ] Breaches affecting 500+ individuals in Nevada must be reported to HHS within 60 days
- [ ] Breaches affecting fewer than 500 individuals must be reported annually
- [ ] Notify affected patients without unreasonable delay and within 60 days
- [ ] Document all breach investigations — even ones that turn out to be non-reportable
Common HIPAA Violations in Las Vegas Medical Practices
The most frequent violations OCR investigates:
- No risk assessment — the most cited violation; required annually
- Lack of access controls — shared passwords, no MFA
- Unencrypted devices — laptops and USB drives without encryption
- Improper disposal — PHI on devices sold or discarded without wiping
- No BAAs in place — vendors accessing data without a signed agreement
Need a HIPAA Security Risk Assessment?
Blue Water Networks performs formal HIPAA Security Risk Assessments for Las Vegas medical practices, producing the documented report required under 45 CFR 164.308(a)(1). We also remediate the findings — so you are not left with a list of problems and no path forward.
