How Often Should a Dental Practice Conduct a HIPAA Audit?
One of the most common questions from dental practice owners is how often they need to review their HIPAA compliance. The short answer: the Security Risk Analysis (SRA) must be completed at least annually, but a comprehensive compliance audit covers more ground and should happen on a defined schedule. This guide lays out exactly what OCR expects, what triggers an off-cycle audit, and what a realistic compliance calendar looks like for a dental practice.
Annual
Minimum frequency for Security Risk Analysis (SRA)
6 years
How long audit records must be retained
$50,000+
Typical OCR fine when SRA is missing or outdated
2026 Update: Common Mistake: Many dental practices complete their first SRA and then never repeat it. HIPAA requires the SRA to be conducted annually AND whenever significant changes occur — new software, new location, new staff management systems, or after a security incident.
Recommended for Dental Practice in your area
Could Your Practice Pass an OCR Audit Today?
Medcurity is built specifically for dental practices — guided Security Risk Analysis, BAA management, staff training, and documentation that holds up when OCR calls.
Start My Free Compliance Assessment →Dental-specific · Audit-ready documentation · No consultant needed
Get the 2026 HIPAA Compliance Checklist — Free
The 6 items OCR checks first in every dental audit. Sent instantly to your inbox.
What HIPAA Actually Requires (vs. What's Best Practice)
HIPAA sets minimum requirements. Best practice goes further. Here is the distinction:
- Required by HIPAA: Annual Security Risk Analysis, review and update of policies and procedures when changes occur, ongoing workforce training when policies change, and documentation of all compliance activities retained for 6 years.
- Best practice (not explicitly required, but expected by OCR): Quarterly BAA audits, semi-annual policy reviews, monthly review of access logs, annual penetration testing, and an annual staff HIPAA training refresher for all employees.
The Annual HIPAA Compliance Calendar for Dental Practices
The most effective approach is to put compliance activities on a fixed calendar so nothing is missed. Here is the schedule that covers both HIPAA requirements and OCR expectations:
- January (or practice anniversary month): Complete annual Security Risk Analysis. Update risk management plan based on findings. Review and update all HIPAA policies and procedures.
- February: Complete annual staff HIPAA training. Document all completions with employee name, date, and topics covered. Update NPP if any regulatory changes occurred.
- Quarterly (every 3 months): Audit Business Associate Agreement list — verify every active vendor has a current signed BAA. Review user access logs for any anomalies. Check that terminated employees have been removed from all systems.
- Monthly: Review system access logs, verify backups completed successfully, check that any new software or vendors have BAAs in place before going live.
- As needed (triggered reviews): Any time a new vendor is onboarded, new software is implemented, a staff member with PHI access leaves, or a security incident occurs — conduct a targeted compliance review of the affected area.
What Triggers an Off-Cycle HIPAA Audit
Beyond the annual schedule, specific events require an immediate compliance review — what HIPAA calls a review of policies and procedures "in response to environmental or operational changes."
- New practice management software: New PMS means new ePHI pathways. BAA must be in place before go-live. SRA must be updated to include the new system.
- Adding a new practice location: Each physical location is a separate facility with its own physical safeguard requirements — workstation policies, facility access controls, device inventory.
- Ransomware or security incident: Any ransomware attack, phishing incident, or unauthorized access triggers an immediate breach assessment and may require a full SRA update.
- Staff turnover in key roles: When a Privacy Officer, Office Manager, or IT contact leaves, their system access must be revoked and their responsibilities formally reassigned and documented.
- Patient or employee complaint: A complaint filed with OCR automatically opens an investigation. Having current audit documentation is the primary defense.
How Long to Retain Audit Documentation
HIPAA requires documentation to be retained for 6 years from the date of creation or the date it was last in effect, whichever is later. This applies to:
- Every completed Security Risk Analysis
- All signed Business Associate Agreements
- Staff training records (name, date, topics covered, signature)
- All versions of HIPAA policies and procedures
- Breach log (including incidents that were assessed and determined not to be reportable breaches)
- Notice of Privacy Practices (each version, with effective dates)
DIY Audit vs. Managed Compliance Platform
Dental practices have two practical options for managing the annual audit cycle: DIY using HHS free tools, or a managed compliance platform.
The DIY path using the HHS SRA Tool is legitimate and free — but it requires consistent time investment from someone in the practice who understands the requirements. The typical failure mode is completing the first SRA and then not repeating it annually.
Managed platforms like Compliancy Group and Medcurity automate the reminder cycle, guide you through the SRA, track BAA expirations, and provide documentation storage. For practices without a dedicated compliance staff member, this is often the more reliable path.
Recommended for Dental Practice in your area
Could Your Practice Pass an OCR Audit Today?
Medcurity is built specifically for dental practices — guided Security Risk Analysis, BAA management, staff training, and documentation that holds up when OCR calls.
Start My Free Compliance Assessment →Dental-specific · Audit-ready documentation · No consultant needed
Frequently Asked Questions
Is an annual HIPAA audit required by law?
The Security Risk Analysis must be conducted at least annually — this is explicitly required by 45 CFR § 164.308(a)(1). A broader compliance audit is not explicitly mandated on a specific schedule, but HIPAA requires policies to be reviewed and updated regularly, which effectively requires an annual review cycle.
Can a dental practice conduct its own HIPAA audit?
Yes. A self-conducted audit using the HHS SRA Tool satisfies the HIPAA requirement. The key is documentation — OCR needs to see a completed SRA with a date, risk ratings, and a corresponding risk management plan. An undocumented verbal review does not count.
What happens if a dental practice hasn't done a HIPAA audit in years?
Missing annual SRAs is one of the most common findings in OCR dental investigations. Fines for missing SRAs typically fall in the $50,000–$250,000 range depending on how many years were missed and the practice's size. The corrective action is to complete a current SRA immediately and implement an annual review schedule going forward.
Does a HIPAA audit need to be conducted by a third party?
No. HIPAA does not require a third-party auditor. A self-conducted SRA using the HHS tool satisfies the requirement. Third-party audits are best practice and provide an outside perspective, but they are not required unless OCR specifically mandates one as part of a Corrective Action Plan.
What is the difference between a HIPAA audit and an OCR investigation?
A HIPAA audit is something your practice conducts on itself — the annual SRA and compliance review. An OCR investigation is conducted by the federal government, typically triggered by a patient complaint or reported breach. OCR investigations can result in fines; your internal audits are what you use to demonstrate compliance if an investigation occurs.
Not Sure Where Your Practice Stands?
Take the free 5-question HIPAA Risk Assessment — get your estimated fine exposure in under 2 minutes.
Take the Free Risk Calculator →Get Your Practice Fully HIPAA Compliant
Medcurity's dental-specific platform walks you through your Security Risk Assessment, BAAs, and staff training — and keeps you audit-ready year after year.
Start My HIPAA Assessment with Medcurity →Dental-specific · Built for practices like yours · No long-term contract
HIPAA Compliance by Specialty & City
Find specific fine risks, violations, and tools for your practice type and location.
General Dentistry
Orthodontics
Pediatric Dentistry
References & Official Sources
- ↗HHS OCR — HIPAA Enforcement Actions & Settlements
- ↗HHS — HIPAA Security Rule Final Rule 2026
- ↗HHS OCR — HIPAA Audit Program
- ↗ADA — HIPAA Resources for Dental Practices
- ↗HHS — Breach Notification Rule
Content reviewed against HHS/OCR publications and ADA guidance. Last reviewed June 2026. Not legal advice.
All HIPAA Compliance Guides
Revenue Protection
The Hidden Cost of Dental Billing Errors in 2026
Cost Analysis
Staffing Shortage vs. Medical VAs: A Financial Comparison for Dental Practices in 2026
OCR Audit #1 Finding
Business Associate Agreements for Dental Practices: 2026 Complete Guide
Compliance Essentials
HIPAA Security Risk Analysis: Complete Guide for Dental Practices (2026)
Partner Review
Compliancy Group Review 2026: Pricing, Guard Platform, and Dental Practice Verdict
Audit Readiness
What Happens If a Dental Practice Fails a HIPAA Audit in 2026?
Product Comparison
Compliancy Group vs. Medcurity: 2026 HIPAA Compliance Comparison for Dentists
New Practice Guide
HIPAA Compliance Checklist for New Dental Practice Owners (2026)
Software Selection
HIPAA-Compliant Dental Software: Top Picks & Buying Guide 2026
Breach Response
Dental Patient Data Breach: What to Do in the First 72 Hours (2026 Guide)
HIPAA Basics
Does HIPAA Apply to Dentists? The Complete 2026 Answer
Staff Compliance
HIPAA Training for Dental Offices: 2026 Staff Requirements, Checklist, and Documentation
Compliance Alert
2026 HIPAA NPP Update for Dental Practices — Free Template Included
Compliance Basics
HIPAA Requirements for Dental Practices: The Complete 2026 Guide
Enforcement
HIPAA Violation Penalties for Dental Practices: 2026 Fine Structure Explained
Free Resources
Free HIPAA Compliance Templates and Resources for Dental Practices (2026)
Documentation
HIPAA Documentation Requirements for Dental Offices: What You Must Keep and How Long
Regulation Alert
HIPAA Security Rule Update 2026: What Dental Practices Must Do Before the Final Rule
Front-Desk Risk
HHS OCR Guidance: Responding to Online Reviews Without Disclosing PHI — Dental 2026
Patient Communication
HIPAA Compliant Texting for Dental Practices: 2026 Rules, Apps, and Requirements
Nashville IT
HIPAA IT Compliance for Nashville Dental Practices: 2026 Complete Guide