These are great for individuals and work equally well for a small practice. Do as many of these as you possibly can. Really, make a strong effort. Work with all of your staff and new staff should be required to follow your documents’ rules. Revisit them across the entire staff every year. You'll be safer.
Reference: https://gizmodo.com/a-complete-guide-to-not-getting-hacked-1847400695/slides/13