Businessman in suit reviewing documents at desk with laptop, smartphone, and office supplies in modern workspace

HIPAA Compliance Checklist for Small Businesses in Kansas City

September 29, 2026

A Kansas City dental practice was fined after an unencrypted laptop was stolen from a front-desk workstation — not because they ignored HIPAA, but because no one had mapped that device as a PHI access point in their risk assessment. This HIPAA compliance checklist for small businesses is built to close exactly those gaps, before OCR comes looking.

Does Your Kansas City Business Actually Need to Follow HIPAA?

HIPAA applies to two categories of organizations: covered entities, which are healthcare providers, health plans, and clearinghouses that transmit protected health information (PHI) electronically, and business associates, which are any vendors or service providers that create, receive, maintain, or transmit PHI on a covered entity's behalf. Both categories carry full HIPAA liability.

Protected Health Information (PHI):Any individually identifiable health data — including names, dates of service, diagnosis codes, or billing records — that is created or held by a covered entity or business associate.

Several Kansas City business types are regularly caught off-guard by HIPAA obligations:

  • Medical billing companies: Handle PHI on behalf of provider clients, making them business associates regardless of whether they deliver care.
  • Chiropractic and behavioral health practices: Covered entities that often lack a dedicated compliance officer — compliance falls to the office manager.
  • IT vendors and MSPs serving clinics: Any managed service provider that accesses a PHI-containing system is a business associate and must comply accordingly.
  • Transcription and answering services: If the service touches patient-identifiable information, HIPAA applies.

Missouri has no separate state health privacy law that supersedes HIPAA, and neither does Kansas — federal HIPAA standards are the floor on both sides of the state line. If your Kansas City business touches PHI in any of these capacities, you need HIPAA compliance services in Kansas City structured around your specific environment, not a generic national checklist.

The HIPAA Compliance Checklist: 3 Safeguard Categories Every Small Business Must Complete

HIPAA organizes its security requirements into three safeguard categories — administrative, physical, and technical. Every covered entity and business associate must address all three. As of 2026, OCR has reclassified several previously "addressable" safeguards — including multi-factor authentication and encryption — as effectively mandatory for any PHI-touching environment.

Administrative Safeguards Checklist

Administrative Safeguards:The policies, procedures, and training programs an organization must put in writing to govern how PHI is managed, accessed, and protected by its workforce.
  • ☐ Risk analysis: Conduct and document a HIPAA risk assessment — a formal inventory of every system, device, and workflow that touches PHI. This is the item most commonly missing when OCR investigates small businesses.
  • ☐ Workforce training: Train all staff on PHI handling at hire and annually. Document completion dates and topics covered.
  • ☐ Incident response plan: Write a documented breach response procedure that names responsible roles and notification timelines.
  • ☐ Business Associate Agreements (BAAs): Execute a signed BAA with every vendor that touches PHI before any data sharing begins — covered in detail in the next section.

Physical Safeguards Checklist

  • ☐ Workstation screen positioning: Position monitors so PHI cannot be viewed by patients or visitors in waiting areas.
  • ☐ Device inventory: Maintain a current list of every device — laptops, tablets, printers — that can access PHI. The dental practice in the opening example lacked this.
  • ☐ Locked PHI storage: Physical records containing PHI must be secured in locked cabinets with access limited to authorized staff.
  • ☐ Secure device disposal: Hard drives and mobile devices must be wiped or destroyed before disposal — not simply deleted or factory-reset.

Technical Safeguards Checklist

Your MSP should be configuring and enforcing every item on this list across all PHI-touching systems. If your current IT provider cannot confirm these controls are active, that is a compliance gap.

  • ☐ Unique user IDs: Every staff member accesses PHI systems under their own login — no shared credentials.
  • ☐ Multi-factor authentication (MFA): MFA — which requires a second verification step beyond a password — is no longer an optional safeguard. Your MSP must enforce MFA on every PHI-touching system.
  • ☐ Role-based access control: Staff access only the PHI their role requires. A front-desk coordinator should not have access to clinical notes.
  • ☐ Encryption at rest and in transit: PHI stored on servers, laptops, and portable media must be encrypted. PHI transmitted over networks — including email — must use encrypted transport. Encryption is no longer addressable; it is expected.
  • ☐ Audit logs: Systems must generate and retain logs of who accessed PHI, when, and what action was taken.
  • ☐ Automatic session timeout: Workstations and applications must lock automatically after a defined period of inactivity.

TS Conard's cybersecurity services include configuring MFA enforcement, encryption policies, and audit logging across your environment — the technical layer most Kansas City small practices cannot maintain without a dedicated IT partner.

The Business Associate Agreement (BAA): The Checklist Item Most Kansas City SMBs Skip

A Business Associate Agreement (BAA) is a legally required contract between a covered entity and any vendor that creates, receives, maintains, or transmits PHI on its behalf. Executing a BAA is not optional — sharing PHI with a vendor before a signed BAA is in place is itself a HIPAA violation, regardless of whether a breach occurs.

The following vendor categories require a signed BAA before any PHI flows to them:

  • Cloud storage providers: Platforms like Microsoft OneDrive or SharePoint require a BAA if used to store PHI — consumer-grade versions of these products do not include one by default.
  • Email platforms: Email services used to transmit PHI require a BAA and must support encrypted transport.
  • EHR (Electronic Health Record) vendors: Most established EHR vendors provide BAAs, but the agreement must be active and current.
  • IT support providers and MSPs: Any managed service provider that remotely accesses, manages, or monitors a system containing PHI is a business associate. A BAA is required before that access begins — this is the item most Kansas City practices have not addressed with their IT company.
  • Medical billing services: Billing companies receive PHI by definition and must have a BAA on file with each provider client.

Unlike compliance software platforms that hand you a checklist and a self-service trial, TS Conard acts as your Business Associate — signing your BAA, managing your technical safeguards, and remaining accountable to OCR standards alongside you. Our IT compliance support includes BAA execution as a standard part of onboarding, not an add-on.

What Happens When a Kansas City Business Fails a HIPAA Audit

The Office for Civil Rights (OCR) — the federal agency that enforces HIPAA — can impose civil monetary penalties ranging from $100 to $50,000 per violation category, with an annual cap of $1.9 million per category. Penalty tier depends on culpability: "did not know" carries the lowest tier; "willful neglect uncorrected" carries the highest.

Three documentation gaps trigger the majority of OCR investigations against small businesses:

  • Missing risk assessment documentation: OCR's first request in any investigation is the written risk analysis. If a Kansas City practice cannot produce one, the penalty exposure increases immediately.
  • No BAA with the IT vendor: OCR has cited the absence of a BAA with an IT provider as a standalone violation — separate from any breach that may have occurred.
  • Unencrypted devices: Stolen or lost unencrypted laptops and mobile devices are among the most common breach triggers. The dental practice scenario at the top of this post illustrates exactly this pattern.

HIPAA also requires a contingency plan — a documented process for backing up PHI and restoring access after a disaster or ransomware event. TS Conard's data backup and recovery services are built to satisfy this requirement, with documented recovery procedures you can present to OCR if needed.

Compliance Gap Common Trigger How TS Conard Closes It
Missing risk assessment OCR investigation opener Documented PHI environment audit at onboarding
No BAA with IT vendor Standalone violation finding BAA signed before any system access
Unencrypted devices Stolen laptop, lost mobile device Encryption enforced across all PHI-touching endpoints
No backup/contingency plan Ransomware or hardware failure Managed backup with documented recovery procedures

Frequently Asked Questions

Does my small business need to comply with HIPAA if we only handle a few patient records?

Yes. HIPAA does not have a minimum-volume exemption. Any covered entity or business associate that handles even a single patient's PHI — regardless of practice size — carries full HIPAA obligations, including the requirement for a documented risk assessment, trained staff, and signed BAAs with vendors.

How much do HIPAA violations actually cost small businesses?

OCR civil monetary penalties range from $100 to $50,000 per violation category, with an annual cap of $1.9 million per category. The tier depends on culpability. Violations in the "willful neglect" category — such as operating without a BAA or a risk assessment — carry the highest per-violation amounts.

Can I use consumer cloud storage like Google Drive or Dropbox for patient data if I encrypt the files first?

No — encryption alone is not sufficient. The cloud storage provider must also sign a Business Associate Agreement with your practice. Consumer-tier Google Drive and Dropbox accounts do not include a BAA. You would need a HIPAA-eligible tier of the platform with a signed BAA before storing any PHI there.

How often should a small business conduct a HIPAA risk assessment?

HIPAA requires a risk assessment whenever there is a significant change to your environment — new software, new devices, staff changes, or a change in how PHI flows through your systems. Most small practices should conduct a formal review at least annually, and always before adding a new vendor or technology that touches PHI.

Written by

TS Conard Team

TS Conard Editorial Team

TS Conard is a managed IT services provider based in Saint Joseph, MO, serving Northwest Missouri businesses since 2003 with expertise in cybersecurity, IT compliance, data backup, and proactive technology support for industries including manufacturing, construction, and local government.

Not Sure If Your Kansas City Practice Is HIPAA-Ready? Let's Find Out.

Click through to TS Conard's HIPAA Compliance Services page to see exactly how we assess your PHI environment, sign your BAA, and implement the technical safeguards — so your next OCR audit isn't a surprise.

Schedule Your HIPAA Readiness Call