Dermatology practices carry an unusual amount of protected health information in images. Every clinical photo, every dermoscopy capture, every before-and-after is PHI, and it lives on more systems than most practices realize: the imaging workstation, the EHR, the camera's memory card, the backup, and sometimes a staff phone.
This checklist covers the HIPAA Security Rule's technical safeguards in plain language. Work through it with whoever manages your IT. If they can't answer a line, that's your gap.
Access controls
- [ ] Every staff member has their own login. No shared "frontdesk" accounts.
- [ ] Access is role-based: a medical assistant can't open billing, a biller can't open imaging.
- [ ] Accounts are disabled the day someone leaves, including EHR, email, imaging, and the VPN.
- [ ] Multi-factor authentication is enforced on email, remote access, and the EHR where supported.
- [ ] Screens lock automatically after a short idle period in exam rooms and at the front desk.
Encryption
- [ ] Laptops and any device that leaves the building have full-disk encryption turned on and verified.
- [ ] Email containing PHI is sent through an encrypted channel, not plain Gmail or Outlook.
- [ ] Backups are encrypted at rest and in transit.
- [ ] Clinical cameras and memory cards are either encrypted or their images are moved to the EHR and wiped on a schedule.
Audit logging
- [ ] The EHR's audit log is turned on and someone reviews it periodically for unusual access.
- [ ] Logins to imaging and file servers are logged.
- [ ] Logs are kept for at least six years, the HIPAA documentation retention period.
Backup and recovery
- [ ] Patient records and images are backed up daily to an off-site, encrypted location.
- [ ] A restore has been tested in the last 90 days, not just a backup job completing.
- [ ] Backups are immutable, so ransomware can't encrypt or delete them.
- [ ] A written recovery plan states who does what, and how long recovery should take.
Business Associate Agreements
- [ ] Signed BAAs exist with your IT provider, EHR vendor, billing company, cloud storage provider, and any marketing vendor that touches patient data.
- [ ] BAAs are stored where you can find them during an audit.
Training and awareness
- [ ] Every staff member completes HIPAA training at hire and annually.
- [ ] Staff receive periodic phishing simulations, because email is how most breaches start.
- [ ] There's a simple, known process for reporting a suspected incident, including a lost phone.
Risk assessment and documentation
- [ ] A written risk assessment was completed in the last 12 months.
- [ ] Identified gaps have an owner and a date.
- [ ] Policies exist for access, device use, incident response, and breach notification.
What we do for dermatology practices
We own the technical side of this list for our healthcare clients: role-based access, MFA, encryption, logging, tested backups, and a signed BAA, plus annual risk assessments and gap tracking through our Compliance add-on. We coordinate with your compliance officer or consultant on the policy side. Download the printable checklist or request a free assessment and we'll walk through it with you.




