All free tools
Free tool

HIPAA compliance checklist for myo practices

What the Security and Privacy Rules actually require, in plain terms, mapped to the safeguard each item comes from. Written for a myofunctional practice with no compliance department and no IT team.

Free forever · No sign-up · Nothing stored
Security & Privacy Rules22 required
31
Safeguards, each mapped to its CFR section
Administrative safeguards164.308
Physical safeguards164.310
Technical safeguards164.312
0%complete
0/22
Required
0/9
Addressable
“Addressable” does not mean optional. Implement it, or document why an alternative is reasonable for your practice.

The checklist

Tap a section to expand it. Each item names the safeguard it comes from so you can cite it in your own documentation.
Where myo practices get caught out
None of this needs an IT department. The gaps that turn a small incident into a reportable one are ordinary practice habits — the same whether you see six clients a week or sixty.
Photos on a personal phone
Intraoral photos and progress videos syncing to a personal cloud account means PHI has left your control.
Texting from a personal number
A reminder that names the treatment discloses a treatment relationship. Standard SMS is not encrypted.
Vendors nobody counted as vendors
Scheduling tools, cloud storage, the accountant with spreadsheet access. No BAA is a gap today.
Exports that outlive their purpose
A client list pulled for one insurance question, still in Downloads two years later.
One login shared by the practice
Convenient, and it destroys the audit trail you would need after an incident.
If you do only three things: write the risk analysis down, get a signed BAA from every vendor that can see client information, and confirm you could actually restore your records.
ScopeGeneral regulatory information, not legal advice. This checklist follows the HIPAA Security and Privacy Rules but is not a substitute for a formal risk analysis or for counsel familiar with your state’s requirements, which may be stricter. Nothing you tick here is stored or transmitted — progress lives in your browser tab only, and clears when you leave.

Built compliance-first, not bolted on

MyoSimplified was built by a security and compliance professional for a HIPAA setting: row-level data isolation, audit logging on every PHI table, a BAA for covered entities, and HIPAA-eligible subprocessors throughout.

See how MyoSimplified worksOther free tools