Dental HIPAA HubGet Compliant →
Risk Management

How Often Should a Dental Practice Conduct a HIPAA Audit?

One of the most common questions from dental practice owners is how often they need to review their HIPAA compliance. The short answer: the Security Risk Analysis (SRA) must be completed at least annually, but a comprehensive compliance audit covers more ground and should happen on a defined schedule. This guide lays out exactly what OCR expects, what triggers an off-cycle audit, and what a realistic compliance calendar looks like for a dental practice.

Annual

Minimum frequency for Security Risk Analysis (SRA)

6 years

How long audit records must be retained

$50,000+

Typical OCR fine when SRA is missing or outdated

2026 Update: Common Mistake: Many dental practices complete their first SRA and then never repeat it. HIPAA requires the SRA to be conducted annually AND whenever significant changes occur — new software, new location, new staff management systems, or after a security incident.

Recommended for Dental Practice in your area

Could Your Practice Pass an OCR Audit Today?

Medcurity is built specifically for dental practices — guided Security Risk Analysis, BAA management, staff training, and documentation that holds up when OCR calls.

Start My Free Compliance Assessment →

Dental-specific · Audit-ready documentation · No consultant needed

Not sure where you stand? Take the free 2-min risk quiz →

📋

Get the 2026 HIPAA Compliance Checklist — Free

The 6 items OCR checks first in every dental audit. Sent instantly to your inbox.

What HIPAA Actually Requires (vs. What's Best Practice)

HIPAA sets minimum requirements. Best practice goes further. Here is the distinction:

  • Required by HIPAA: Annual Security Risk Analysis, review and update of policies and procedures when changes occur, ongoing workforce training when policies change, and documentation of all compliance activities retained for 6 years.
  • Best practice (not explicitly required, but expected by OCR): Quarterly BAA audits, semi-annual policy reviews, monthly review of access logs, annual penetration testing, and an annual staff HIPAA training refresher for all employees.

The Annual HIPAA Compliance Calendar for Dental Practices

The most effective approach is to put compliance activities on a fixed calendar so nothing is missed. Here is the schedule that covers both HIPAA requirements and OCR expectations:

  • January (or practice anniversary month): Complete annual Security Risk Analysis. Update risk management plan based on findings. Review and update all HIPAA policies and procedures.
  • February: Complete annual staff HIPAA training. Document all completions with employee name, date, and topics covered. Update NPP if any regulatory changes occurred.
  • Quarterly (every 3 months): Audit Business Associate Agreement list — verify every active vendor has a current signed BAA. Review user access logs for any anomalies. Check that terminated employees have been removed from all systems.
  • Monthly: Review system access logs, verify backups completed successfully, check that any new software or vendors have BAAs in place before going live.
  • As needed (triggered reviews): Any time a new vendor is onboarded, new software is implemented, a staff member with PHI access leaves, or a security incident occurs — conduct a targeted compliance review of the affected area.

What Triggers an Off-Cycle HIPAA Audit

Beyond the annual schedule, specific events require an immediate compliance review — what HIPAA calls a review of policies and procedures "in response to environmental or operational changes."

  • New practice management software: New PMS means new ePHI pathways. BAA must be in place before go-live. SRA must be updated to include the new system.
  • Adding a new practice location: Each physical location is a separate facility with its own physical safeguard requirements — workstation policies, facility access controls, device inventory.
  • Ransomware or security incident: Any ransomware attack, phishing incident, or unauthorized access triggers an immediate breach assessment and may require a full SRA update.
  • Staff turnover in key roles: When a Privacy Officer, Office Manager, or IT contact leaves, their system access must be revoked and their responsibilities formally reassigned and documented.
  • Patient or employee complaint: A complaint filed with OCR automatically opens an investigation. Having current audit documentation is the primary defense.

How Long to Retain Audit Documentation

HIPAA requires documentation to be retained for 6 years from the date of creation or the date it was last in effect, whichever is later. This applies to:

  • Every completed Security Risk Analysis
  • All signed Business Associate Agreements
  • Staff training records (name, date, topics covered, signature)
  • All versions of HIPAA policies and procedures
  • Breach log (including incidents that were assessed and determined not to be reportable breaches)
  • Notice of Privacy Practices (each version, with effective dates)

DIY Audit vs. Managed Compliance Platform

Dental practices have two practical options for managing the annual audit cycle: DIY using HHS free tools, or a managed compliance platform.

The DIY path using the HHS SRA Tool is legitimate and free — but it requires consistent time investment from someone in the practice who understands the requirements. The typical failure mode is completing the first SRA and then not repeating it annually.

Managed platforms like Compliancy Group and Medcurity automate the reminder cycle, guide you through the SRA, track BAA expirations, and provide documentation storage. For practices without a dedicated compliance staff member, this is often the more reliable path.

Recommended for Dental Practice in your area

Could Your Practice Pass an OCR Audit Today?

Medcurity is built specifically for dental practices — guided Security Risk Analysis, BAA management, staff training, and documentation that holds up when OCR calls.

Start My Free Compliance Assessment →

Dental-specific · Audit-ready documentation · No consultant needed

Not sure where you stand? Take the free 2-min risk quiz →

Frequently Asked Questions

Is an annual HIPAA audit required by law?

The Security Risk Analysis must be conducted at least annually — this is explicitly required by 45 CFR § 164.308(a)(1). A broader compliance audit is not explicitly mandated on a specific schedule, but HIPAA requires policies to be reviewed and updated regularly, which effectively requires an annual review cycle.

Can a dental practice conduct its own HIPAA audit?

Yes. A self-conducted audit using the HHS SRA Tool satisfies the HIPAA requirement. The key is documentation — OCR needs to see a completed SRA with a date, risk ratings, and a corresponding risk management plan. An undocumented verbal review does not count.

What happens if a dental practice hasn't done a HIPAA audit in years?

Missing annual SRAs is one of the most common findings in OCR dental investigations. Fines for missing SRAs typically fall in the $50,000–$250,000 range depending on how many years were missed and the practice's size. The corrective action is to complete a current SRA immediately and implement an annual review schedule going forward.

Does a HIPAA audit need to be conducted by a third party?

No. HIPAA does not require a third-party auditor. A self-conducted SRA using the HHS tool satisfies the requirement. Third-party audits are best practice and provide an outside perspective, but they are not required unless OCR specifically mandates one as part of a Corrective Action Plan.

What is the difference between a HIPAA audit and an OCR investigation?

A HIPAA audit is something your practice conducts on itself — the annual SRA and compliance review. An OCR investigation is conducted by the federal government, typically triggered by a patient complaint or reported breach. OCR investigations can result in fines; your internal audits are what you use to demonstrate compliance if an investigation occurs.

Not Sure Where Your Practice Stands?

Take the free 5-question HIPAA Risk Assessment — get your estimated fine exposure in under 2 minutes.

Take the Free Risk Calculator →

Get Your Practice Fully HIPAA Compliant

Medcurity's dental-specific platform walks you through your Security Risk Assessment, BAAs, and staff training — and keeps you audit-ready year after year.

Start My HIPAA Assessment with Medcurity →

Dental-specific · Built for practices like yours · No long-term contract

HIPAA Compliance by Specialty & City

Find specific fine risks, violations, and tools for your practice type and location.

References & Official Sources

Content reviewed against HHS/OCR publications and ADA guidance. Last reviewed June 2026. Not legal advice.

All HIPAA Compliance Guides

Revenue Protection

The Hidden Cost of Dental Billing Errors in 2026

Cost Analysis

Staffing Shortage vs. Medical VAs: A Financial Comparison for Dental Practices in 2026

OCR Audit #1 Finding

Business Associate Agreements for Dental Practices: 2026 Complete Guide

Compliance Essentials

HIPAA Security Risk Analysis: Complete Guide for Dental Practices (2026)

Partner Review

Compliancy Group Review 2026: Pricing, Guard Platform, and Dental Practice Verdict

Audit Readiness

What Happens If a Dental Practice Fails a HIPAA Audit in 2026?

Product Comparison

Compliancy Group vs. Medcurity: 2026 HIPAA Compliance Comparison for Dentists

New Practice Guide

HIPAA Compliance Checklist for New Dental Practice Owners (2026)

Software Selection

HIPAA-Compliant Dental Software: Top Picks & Buying Guide 2026

Breach Response

Dental Patient Data Breach: What to Do in the First 72 Hours (2026 Guide)

HIPAA Basics

Does HIPAA Apply to Dentists? The Complete 2026 Answer

Staff Compliance

HIPAA Training for Dental Offices: 2026 Staff Requirements, Checklist, and Documentation

Compliance Alert

2026 HIPAA NPP Update for Dental Practices — Free Template Included

Compliance Basics

HIPAA Requirements for Dental Practices: The Complete 2026 Guide

Enforcement

HIPAA Violation Penalties for Dental Practices: 2026 Fine Structure Explained

Free Resources

Free HIPAA Compliance Templates and Resources for Dental Practices (2026)

Documentation

HIPAA Documentation Requirements for Dental Offices: What You Must Keep and How Long

Regulation Alert

HIPAA Security Rule Update 2026: What Dental Practices Must Do Before the Final Rule

Front-Desk Risk

HHS OCR Guidance: Responding to Online Reviews Without Disclosing PHI — Dental 2026

Patient Communication

HIPAA Compliant Texting for Dental Practices: 2026 Rules, Apps, and Requirements

Nashville IT

HIPAA IT Compliance for Nashville Dental Practices: 2026 Complete Guide