HIPAA compliance checklist for small medical practices in California
California practices carry two layers of obligation: federal HIPAA and the California Confidentiality of Medical Information Act (CMIA), which is stricter in several areas and carries its own penalties. This checklist covers the essentials for a practice of 1 to 50 staff.
Free preview before you pay. Editable Word files. 14 day refund.
Administrative safeguards
- A completed and documented security risk analysis, reviewed at least once a year
- A named Privacy Officer and Security Officer (in a small office this can be one person)
- Written privacy and security policies, including sanctions, incident response, and access removal when someone leaves
- Training for every workforce member, with signed records
- Signed business associate agreements with every vendor that handles patient information
Technical safeguards
- A unique login for every person, no shared accounts
- Automatic screen lock on every workstation
- Encryption on laptops, phones, and portable media that hold patient information
- Encrypted email or a patient portal for sending records
- Audit logging turned on in the EHR, and reviewed
- Tested backups, with at least one copy offsite or in the cloud
Physical safeguards
- Servers and network equipment in a locked room or cabinet
- Screens positioned away from patients at check in
- A documented disposal process for paper and devices
California rules on top of HIPAA
- Record access: let patients inspect records within 5 working days and provide copies within 15 days of a written request (Health and Safety Code section 123110), shorter than the HIPAA 30 day limit.
- Authorization forms: must be handwritten by the signer or typed in at least 14 point type, and state a specific expiration date (Civil Code section 56.11).
- Breach notice: California residents must be notified under Civil Code section 1798.82, and a sample notice goes to the Attorney General when more than 500 residents are affected. Licensed clinics and facilities have a 15 business day reporting rule under Health and Safety Code section 1280.15.
- Sensitive services: electronic records about abortion, contraception, and gender affirming care must be segregable and protected from out of state disclosure (Civil Code section 56.101).
The honest question
If an auditor emailed tomorrow asking for your risk analysis and policy documents, could you produce them? If not, that is the gap to close first. California practices that build a kit get a California Addendum covering the rules above, and their patient forms use the California deadlines and authorization format.
Questions
Is California law stricter than HIPAA?
In several areas, yes. Where both apply, follow the stricter rule. Record access deadlines, authorization form requirements, and breach reporting are the most common differences.
Does the kit include California rules?
Yes. When you enter a California address, the kit adds a California Addendum and adjusts the patient forms.
Full HIPAA Policy Kit, $129
- Notice of Privacy Practices, updated for the 2026 rules, plus the acknowledgment form
- 22 Privacy policies and procedures
- 19 Security policies mapped to the Security Rule
- Breach Notification policy with a risk assessment form and log
- Business Associate Agreement for your vendors
- Workforce confidentiality agreement, training log, and access checklist
- Security Risk Analysis worksheet, pre filled from your answers
- Patient request forms, plus a California addendum for California practices
More guides
- HIPAA compliance for dental offices: what auditors actually check
- The HIPAA security risk assessment, explained for small practices
- Notice of Privacy Practices template, updated for 2026
- HIPAA policies for chiropractic offices
- HIPAA policies for physical therapy practices
- HIPAA policies for mental health and behavioral health practices
- HIPAA policies for optometry practices
- HIPAA for med spas and aesthetics practices
- HIPAA policies and procedures for small medical practices
Templates, not legal advice. Eaglizer IT is not a law firm and does not certify HIPAA compliance. Using templates does not by itself make a practice compliant; follow the policies, train your staff, and keep records.