HIPAA Compliance Checklist for Small Businesses: 20 Essential Steps
Small businesses that handle health data face the same HIPAA rules as a hospital system — with a fraction of the staff, budget, and specialized expertise to meet them. That is the distinct challenge: HIPAA scales its requirements to your size in some places and not at all in others, and knowing the difference is what keeps a small practice or vendor out of trouble. There is no small-business exemption. A solo medical office, a two-person billing company, and a startup with one app all carry real obligations. The good news is that a focused checklist turns an intimidating regulation into a manageable list of decisions.
The 20 essential steps
Work through these in order; each builds on the one before it.
- Confirm whether you are a covered entity, a business associate, or neither — your status drives everything else.
- Inventory all PHI: what you collect, where it lives, and every system it touches.
- Complete a Security Risk Analysis (the foundation of the whole program).
- Document a written remediation plan for the risks the analysis surfaces.
- Appoint a HIPAA Privacy Officer and a Security Officer (one person can hold both roles in a small shop).
- Write and adopt Privacy Rule and Security Rule policies and procedures.
- Sign a Business Associate Agreement with every vendor that touches PHI.
- Enforce unique user accounts — no shared logins.
- Turn on encryption for data at rest and in transit.
- Require strong authentication, and multi-factor authentication wherever possible.
- Enable and periodically review audit logs.
- Apply minimum-necessary access so staff see only the PHI their role requires.
- Train every workforce member, and document that the training happened.
- Secure physical access to records, servers, and workstations.
- Establish a sanction policy for workforce violations.
- Create an incident response and breach notification procedure.
- Maintain a data backup and disaster recovery plan.
- Establish a process for honoring patients’ right of access to their records.
- Securely dispose of PHI on paper and on retired devices.
- Retain required documentation for at least six years and review the program annually.
For the clinical-practice angle on these same fundamentals, see our HIPAA compliance guide for small practices.
Start with the Security Risk Analysis
If you do only one thing from this list first, make it the Security Risk Analysis (SRA). It is both legally required and the step that tells you which of the other nineteen matter most for your specific operation. The Security Rule requires “an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability” of electronic PHI — 45 CFR § 164.308(a)(1)(ii)(A). For a small business with limited resources, the SRA is what prevents you from spending money in the wrong place: it prioritizes the handful of fixes that reduce the most risk, rather than chasing every theoretical threat. A failure to conduct or update the SRA is also one of the most frequently cited problems in Office for Civil Rights settlements, including against small organizations.
The proposed 2026 Security Rule update
Small businesses should know what is coming. In December 2024, the Office for Civil Rights published a Notice of Proposed Rulemaking (NPRM) that would strengthen the Security Rule — proposing to remove the longstanding “addressable” category so that measures like encryption, multi-factor authentication, and a maintained asset inventory become required for everyone, regardless of size. The proposal is not final; if adopted, organizations would generally have 240 days from the final rule’s publication to come into compliance. There would be no carve-out for being small, so the practical move is to adopt these controls now while you can do it on your own timeline.
How Medcurity helps
Medcurity was built for organizations that do not have a dedicated compliance department. The platform walks you through a thorough Security Risk Analysis, helps you generate the policies on this checklist, and tracks your remediation so you can show your work if a regulator or customer ever asks. Pricing is $499/year (about $42/month); larger or multi-entity organizations can request a quote for a tailored engagement. For a small business, that converts an overwhelming list into a guided, affordable process you can actually finish.
Frequently asked questions
Are small businesses exempt from HIPAA?
No. HIPAA applies to covered entities and business associates regardless of size. A solo practice or a two-person vendor has the same core obligations as a large system, though how you implement some safeguards can scale to your size and resources.
How much does HIPAA compliance cost a small business?
It varies with your environment, but it does not have to mean expensive consultants. A guided platform can cover the core requirements for a predictable annual fee, and the most important early investments — an SRA, policies, encryption, and training — are largely about process and configuration rather than costly tools.
How often do we need to update the checklist?
Review your program at least annually and whenever something material changes — a new system, vendor, location, or service line. The Security Risk Analysis in particular should be revisited regularly, not treated as a one-time event.
What happens if a small business ignores HIPAA?
Penalties apply regardless of size and can be severe, and the Office for Civil Rights has settled cases against small organizations — frequently citing a missing Security Risk Analysis. Beyond fines, a breach can cost patient trust and business relationships that a small company cannot easily replace.