Is My Office WiFi HIPAA Compliant? 7-Point Checklist

Is My Office WiFi HIPAA Compliant? A Quick Audit Guide for Medical & Dental Practices

If your office WiFi was set up by your internet provider and has never had a professional review, there's a good chance it falls short of what HIPAA expects, even if everything seems to work. The seven checks below will tell you where you stand.

WiFi is one of the most overlooked weak spots in a medical or dental practice. Many owners assume that if the internet works and the router has a password, they're covered. Usually they aren't. The HIPAA Security Rule requires practices to assess risks to electronic protected health information (ePHI) and put reasonable safeguards in place for how it is transmitted, stored and accessed. The rule is technology-neutral and doesn't name specific products or settings, but a default router from your internet provider rarely meets that bar out of the box. (A proposed update to the Security Rule, published in January 2025, would make requirements such as encryption and multi-factor authentication more explicit; it was still a proposal at the time of writing.)

In this episode of NerdSquad Tech Tips, our CEO walks through the checklist we use when reviewing a practice's wireless network. It's fast, practical and written for practice owners and office managers, not IT staff.

One caveat before the checklist

No wireless network is perfectly secure. Where you can, run workstations that handle patient data over wired connections rather than WiFi. That isn't always practical, since modern practices depend on wireless, but it's the stronger option and worth building toward.

The HIPAA WiFi checklist

1. Change default addresses and passwords

Default router logins are publicly documented and easy to exploit. If your router still uses its factory admin password, or a default address such as 192.168.0.1, fix that first. Use a strong, unique admin password stored in a password manager, not on a sticky note in the network closet.

2. Check your encryption standard

Your wireless network should use WPA2 at minimum, and WPA3 where your equipment supports it. For the staff network, enterprise authentication (WPA2-Enterprise or WPA3-Enterprise, which gives each person their own login) is stronger than one shared password. If you see WEP or an open, unencrypted network anywhere, data sent over it is exposed and needs fixing now.

3. Don't advertise your staff network

Some practices hide the name (SSID) of the staff network so it doesn't show up in the list on every patient's phone. That's fine as a tidy-up, but it isn't a security control: hidden networks are easy to find with free tools, and HIPAA doesn't require it. Give the staff network a name that doesn't identify the practice or its purpose, and rely on strong encryption, individual logins and network separation for the actual protection.

4. Separate guest and staff networks

This is one of the most common gaps we find. Patients, vendors and visitors should never be on the same network as your clinical systems. Use separate networks, ideally with separate VLANs and firewall rules, so a guest device has no path to your EHR, imaging or practice management software. Our article on firewalls and network security explains how that separation works.

5. Turn on logging and monitoring

The Security Rule requires audit controls: the ability to record and examine activity in systems that contain or use ePHI. Your network equipment should keep access logs, and those logs should be reviewed or sent to a monitoring system that flags unusual activity. If your router can't log at all, it's time to replace it with business-class equipment.

6. Physically secure your equipment

Routers, switches and access points belong in a locked location, not in the waiting room or on an open shelf behind the front desk. Physical access to network hardware can bypass your software controls. Keep firmware updated on all of it.

7. Use stronger sign-ins

Move away from passwords alone wherever you can. Multi-factor authentication (MFA) through an authenticator app, or passwordless sign-in, greatly reduces the risk of someone getting into systems that hold patient data.

A few more tips from our experience

  • Wire it where you can. Ethernet is more secure and more reliable than WiFi for desks that don't move.
  • Limit guest bandwidth. A busy guest network shouldn't be able to slow down your clinical systems.
  • Fix coverage properly. Cheap consumer range extenders often weaken security settings; see mesh WiFi vs. range extenders.
  • Document your network. Know what connects where and who has access. Your HIPAA risk analysis and any auditor will expect that documentation.
  • Good security doesn't require a huge budget. A modest upgrade from a default ISP router to properly configured business-class equipment can make a large difference.

Who this is for

This episode is for medical and dental practice owners and office managers running out-of-the-box network setups without a dedicated IT team. If that's you and you haven't had a professional network assessment, this checklist is a good place to start.

NerdSquad provides IT support for medical and dental practices across Southwest Florida, including HIPAA compliance support in Naples. We assess existing networks, find the gaps and put the technical safeguards and documentation in place that support your HIPAA compliance program. NerdSquad is not a law firm; confirm your obligations with your compliance counsel.

More short videos are collected in NerdSquad Tech Tips, and our blog has a companion post: Is my WiFi HIPAA compliant?


Talk to NerdSquad

Already a client? Call (239) 465-0079 or submit a ticket. If something is down, call so we can start right away.

Not a client yet? NerdSquad Managed IT Services is a Managed Service Provider (MSP) based in Naples, Florida. We support businesses onsite across Southwest Florida and remotely nationwide. Book a discovery call or call (239) 465-0079.

Related: IT support for medical and dental practices