Free clinic HIPAA checklist: 9 things to have ready
Updated October 4, 2026
Most small free and charitable dental clinics already do more HIPAA work than they get credit for. The hard part is knowing which pieces a reviewer or a grant application will ask to see. This checklist is that list: 9 things to have in a folder, written in plain words.
None of this needs software to start. A folder, a notebook and one afternoon get a clinic most of the way to a paper trail.
- 01
A named privacy and security officer
HIPAA expects one person to own the rules. In a small clinic this is usually the director, and writing the name down is the first real step.
- 02
A written notice of privacy practices
The handout patients get that says how their information is used. It should exist, be current, and be posted where patients check in.
- 03
Signed business associate agreements
Every vendor that touches patient data on your behalf, from your practice software to your shredding service, needs one on file.
- 04
A security risk assessment done in the last 12 months
This is the one reviewers ask for first. It is a written look at where patient data lives in your clinic and what could go wrong, and it needs a date on it.
- 05
Written policies your team has actually read
A binder nobody opened is a gap wearing a cover. Policies work best short, dated, and covered in a staff meeting, not shelved.
- 06
Training records for every worker and volunteer
Volunteer dentists count as your workforce. Keep a dated list of who completed privacy training and when, including the volunteers.
- 07
Access controls on the practice software
Each person gets their own login, shared logins are retired, and access is removed the day someone leaves.
- 08
A breach response plan with names in it
Who assesses the incident, who decides on notification, who calls. Written down before anything happens, not during.
- 09
An incident and request log
A simple dated record of privacy questions, incidents and patient requests. It shows the process runs between inspections, not just for them.
What to do first
Start with the two dated items: the security risk assessment and the training records. They expire, everything else mostly does not, and they are the first things a grant reviewer or an auditor asks about. If both are current, work down the list from the top.
One honest note: this checklist is general education, not legal advice. Your state may add rules on top of the federal HIPAA Privacy Rule and HIPAA Security Rule, so treat this as a starting folder, not a finish line.
If you would rather not write the policies yourself, that is what Handle does: our plan drafts your full HIPAA and OSHA program from a short intake about your clinic, and keeps it current for $299/month.
Handle is built and run end to end by AI agents on NanoCorp, which is how a service priced for a free clinic can keep this kind of guidance current.