Top 5 HIPAA Violations We find in Dental & Healthcare Offices (And How to Avoid Them)
Small compliance mistakes can lead to big consequences. Learn what to watch for and how to protect your practice.

https://youtu.be/Zp-fDTMqfwY?si=NF4ytmSgi-gBc6nG
Transcript
We review healthcare offices across Oregon every week, and almost every office—even the really good ones—is making at least one of these five HIPAA mistakes.
The surprising part? Most teams don't even realize the potential consequences of these actions.
I'm Kelli Ngariki, CEO and Compliance Consultant with Healthcare Compliance Associates. We help dental and healthcare practices build practical compliance systems, and today I'm sharing the five HIPAA violations we see most often—and exactly how you can prevent them. And stick around until the end, because the fifth mistake is one that quietly contributes to almost all the others.
Top 5 HIPAA Violations We See Every Week
Here's the good news.
Most HIPAA violations aren't intentional.
They happen because offices get busy, shortcuts become routine, and new employees simply copy what they've always seen.
We call this Legacy Error—when incorrect habits get passed from one employee to the next. If you recognize one or two of these in your own practice, you're actually in good company.
The important thing isn't being perfect—it's identifying the risks before they become real problems.
So let's start with the one we probably see more than any other.
Violation #1
Staff Leaving Computers Unlocked
This is probably the number one thing I find during office visits.
Staff steps away...
- to answer a phone
- help a patient
- walk to sterilization
- grab supplies
…and their computer stays open with patient information visible.
Sometimes it's only for thirty seconds.
Sometimes it's several minutes.
It only takes a moment for curiosity to kick in. Before you know it, someone has started reviewing information they were never supposed to see.
At a clinic we worked with, a nurse stepped out of the exam room for just a couple of minutes to check on something and left the computer unlocked with the patient's chart open. When she came back, the patient's wife was sitting at the computer looking through her husband's medical record.
Now, we don't know exactly how much she saw or why she started looking, but that's really beside the point. The opportunity was there because the workstation had been left open. It created an awkward situation for everyone involved. The staff member was stressed, the clinic had to determine whether it was a reportable privacy incident, and it all could have been prevented by simply locking the computer before stepping out of the room.
That's why it’s good to remember—it only takes two seconds to lock your screen, but it can save hours of investigation and a lot of unnecessary stress.
Why it matters
Anyone walking by—including someone who has no business seeing that information—could potentially view:
- Patient names
- Treatment information
- Insurance details, or
- Financial information
Beyond compliance, situations like this can damage patient trust and create unnecessary investigations if questions arise later.
How to prevent this:
- Enable automatic screen locks (this locks the screen after a set number of minutes without activity)
- Lock your screen every single time you step away.
- Perform occasional spot checks and coach employees when needed.
VIOLATION #2
Password Sharing
One of the biggest issues we see isn't necessarily that staff are sharing their electronic health record passwords. In fact, many offices do have individual EHR logins.
The problem is that everyone shares the same computer login. So multiple employees sign into Windows or the workstation using one shared username and password, and then each person opens the practice management or EHR software with their own credentials.
While that may seem harmless, it creates unnecessary security risks. Shared computer logins make it harder to determine who was actually using the workstation if there's a security incident, unauthorized access, or malware event. It also makes it more difficult to demonstrate accountability for access to systems that contain protected health information.
The better practice is simple: every employee should have their own computer login and their own login for any software they use. That way, you know exactly who accessed the workstation and when.
How to protect your practice:
Every employee should have:
- Their own username
- Their own password
- Access only to the information they need to perform their job
This simple change helps protect:
- Your patients
- Your staff
- Your practice
VIOLATION #3
Missing Business Associate Agreements
"This one surprises a lot of practice owners."
If another company creates, receives, maintains, or transmits protected health information on your behalf, they generally need a Business Associate Agreement—or BAA.
Think about companies like:
- IT companies
- Cloud storage providers
- Billing companies
- Practice management software
- Backup services
- Answering services
- And increasingly, AI tools that help with documentation, transcription, or administrative tasks.
If they can access patient information...
In most cases, a Business Associate Agreement is required before that vendor handles protected health information on your behalf.
Start doing this ASAP:
Review every outside vendor.
Ask: "Do they have access to protected health information?"
If the answer is yes...
Verify that an appropriate Business Associate Agreement is in place and keep a copy with your HIPAA documentation.
Expert Tip
Anytime you're adding a new service, make it a habit to ask one question before you sign the contract: 'Will this company create, receive, maintain, or have access to protected health information on our behalf?' If the answer is yes, find out whether a Business Associate Agreement is required before moving forward.
Create a simple vendor checklist that includes:
- Vendor name
- PHI access? Yes or No
- BAA required?
- BAA signed?
- Date reviewed
This makes your annual HIPAA review much easier and helps ensure nothing falls through the cracks.
VIOLATION #4
No Current HIPAA Risk Assessment
This is probably the biggest documentation gap we find.
Many offices have:
Verbal expectations...
Training...
Notice of Privacy Practices and other basic forms...
But they've never completed—or regularly update— their HIPAA Risk Assessment.
The Risk Assessment helps identify:
- Technology vulnerabilities
- Physical security concerns
- Employee risks
- Workflow issues that could expose patient information
It's not something you complete once, file away, and forget.
Your Risk Assessment should be reviewed at least annually—and anytime your practice experiences significant changes, like implementing new software, moving offices, adding providers, or changing workflows.
If you haven't completed a Risk Assessment, or it's been sitting in a binder collecting dust, set aside some time to:
- Review your current risks and vulnerabilities.
- Update your documentation to reflect how your practice operates today.
- Create an action plan to address any gaps you identify.
Remember, the goal is to identify potential problems before they become a HIPAA breach.
VIOLATION #5
Inadequate Employee HIPAA Training
And this brings us to the issue that quietly contributes to almost every other violation we've discussed.
Many practices think HIPAA training means:
- "Watch a training video."
- "Sign this paper."
- Done.
But effective HIPAA training helps employees understand how privacy applies to the work they do every day.
Employees should understand how HIPAA applies to the conversations they have...
The emails they send...
The passwords they create...
The workstations they use...
And how they respond if something goes wrong.
The strongest HIPAA compliance programs don't rely on annual training alone.
They build compliance into everyday habits.
RECAP
Let's quickly review the five biggest HIPAA issues we consistently find.
1. Leaving computers unlocked.
2. Sharing passwords.
3. Missing Business Associate Agreements.
4. Outdated HIPAA Risk Assessments.
5. Treating HIPAA training as a one-time event.
The encouraging part?
Every one of these issues can be fixed with a little time and effort.
And most practices improve dramatically with a few practical changes and consistent follow-through.
CTA
Free OSHA Compliance Risk Review
If you recognized one—or maybe several—of these issues in your own practice, don't panic.
Like I said earlier, we rarely walk into an office that's got it all figured out. Most compliance gaps develop over time, and the important thing is identifying them before they become bigger problems.
While today's video focused on HIPAA, we know that strong compliance doesn't happen in silos. The same things that support HIPAA compliance—employee training, clear procedures, accountability, and consistent follow-through—also play a major role in OSHA and workplace safety.
Watch the full video here: https://youtu.be/Zp-fDTMqfwY?si=NF4ytmSgi-gBc6nG











