Skip to content
(888) 538-6881Client Portal
The Network Gurus

Blog

HIPAA compliance checklist for dermatology practices

The technical safeguards, in the order an auditor would ask about them, explained for a practice manager rather than an engineer.

A dermatology clinician consulting with a patient

October 7, 2026 · The Network Gurus

Dermatology practices carry an unusual amount of protected health information in images. Every clinical photo, every dermoscopy capture, every before-and-after is PHI, and it lives on more systems than most practices realize: the imaging workstation, the EHR, the camera's memory card, the backup, and sometimes a staff phone.

This checklist covers the HIPAA Security Rule's technical safeguards in plain language. Work through it with whoever manages your IT. If they can't answer a line, that's your gap.

Access controls

  • [ ] Every staff member has their own login. No shared "frontdesk" accounts.
  • [ ] Access is role-based: a medical assistant can't open billing, a biller can't open imaging.
  • [ ] Accounts are disabled the day someone leaves, including EHR, email, imaging, and the VPN.
  • [ ] Multi-factor authentication is enforced on email, remote access, and the EHR where supported.
  • [ ] Screens lock automatically after a short idle period in exam rooms and at the front desk.

Encryption

  • [ ] Laptops and any device that leaves the building have full-disk encryption turned on and verified.
  • [ ] Email containing PHI is sent through an encrypted channel, not plain Gmail or Outlook.
  • [ ] Backups are encrypted at rest and in transit.
  • [ ] Clinical cameras and memory cards are either encrypted or their images are moved to the EHR and wiped on a schedule.

Audit logging

  • [ ] The EHR's audit log is turned on and someone reviews it periodically for unusual access.
  • [ ] Logins to imaging and file servers are logged.
  • [ ] Logs are kept for at least six years, the HIPAA documentation retention period.

Backup and recovery

  • [ ] Patient records and images are backed up daily to an off-site, encrypted location.
  • [ ] A restore has been tested in the last 90 days, not just a backup job completing.
  • [ ] Backups are immutable, so ransomware can't encrypt or delete them.
  • [ ] A written recovery plan states who does what, and how long recovery should take.

Business Associate Agreements

  • [ ] Signed BAAs exist with your IT provider, EHR vendor, billing company, cloud storage provider, and any marketing vendor that touches patient data.
  • [ ] BAAs are stored where you can find them during an audit.

Training and awareness

  • [ ] Every staff member completes HIPAA training at hire and annually.
  • [ ] Staff receive periodic phishing simulations, because email is how most breaches start.
  • [ ] There's a simple, known process for reporting a suspected incident, including a lost phone.

Risk assessment and documentation

  • [ ] A written risk assessment was completed in the last 12 months.
  • [ ] Identified gaps have an owner and a date.
  • [ ] Policies exist for access, device use, incident response, and breach notification.

What we do for dermatology practices

We own the technical side of this list for our healthcare clients: role-based access, MFA, encryption, logging, tested backups, and a signed BAA, plus annual risk assessments and gap tracking through our Compliance add-on. We coordinate with your compliance officer or consultant on the policy side. Download the printable checklist or request a free assessment and we'll walk through it with you.

Keep reading

More from the blog

Questions we hear

Frequently asked questions

Don’t see your question? Call us and a real person will answer.

Does my IT provider make us HIPAA compliant?

No single vendor can. Compliance is a program covering policy, training, and technology. Your IT provider should own the technical safeguards below and sign a Business Associate Agreement. The policies and the designated privacy and security officers are yours.

How often should we do a risk assessment?

At least annually, and after any major change: a new EHR, a new location, a merger, or an incident.

Free IT assessment

Know where you stand before something breaks

A plain-English review of your security, backups, and support experience. No cost, no obligation, and the report is yours to keep.

HIPAA Compliance Checklist for Dermatology Practices | The Network Gurus