πŸ₯ US Federal Regulation

HIPAA Compliance

If your small practice handles protected health information (PHI), HIPAA applies β€” and the penalties are steep. Here is what you need to do, written for practitioners who did not go to IT school.

⚑ Quick Facts

What it is: Health Insurance Portability and Accountability Act
Key rules: Privacy Rule, Security Rule, Breach Notification Rule
Enforced by: HHS Office for Civil Rights (OCR)
Penalty: $100 – $50,000 per violation, up to $1.5M/year per violation category
Applies to: Covered entities (providers, plans, clearinghouses) AND business associates
Key document: Risk Analysis (required annually under Security Rule)

HIPAA Basics: The Three Rules That Matter for Small Practices

πŸ“‹ The Privacy Rule β€” Who Can See PHI and When

Governs the use and disclosure of Protected Health Information. Key requirements: provide patients with a Notice of Privacy Practices, obtain written acknowledgment, honor patient requests for access to their records (within 30 days), and limit PHI use/disclosure to the "minimum necessary" to accomplish the intended purpose. Train all staff on these rules.

πŸ”’ The Security Rule β€” How to Protect Electronic PHI (ePHI)

Requires administrative, physical, and technical safeguards for electronic PHI. This is where most small practices stumble. You need: a Risk Analysis (updated annually), access controls (unique user IDs + MFA), audit controls (logging who accessed what), integrity controls (ensuring ePHI is not altered), transmission security (encrypted email), and a contingency plan (backup + disaster recovery).

🚨 The Breach Notification Rule β€” When PHI Is Exposed

If unsecured PHI is breached, you must: notify affected individuals within 60 days, notify HHS (immediately if >500 individuals; annually if fewer), and in some cases notify local media. Failure to notify can multiply penalties significantly.

Free Security Assessment for Healthcare Practices

20 questions covering HIPAA Security Rule basics β€” access controls, encryption, backups, and risk analysis readiness.

Start Free Assessment β†’

Who HIPAA Applies To

Covered Entities

Healthcare providers who transmit health information electronically (doctors, dentists, therapists, chiropractors, pharmacies, clinics), health plans (insurance companies, HMOs, employer group health plans), and healthcare clearinghouses.

Business Associates

Any person or entity that creates, receives, maintains, or transmits PHI on behalf of a covered entity. This includes: IT support companies, cloud storage providers, billing services, shredding companies, answering services, and email providers (if they store PHI). Business Associates must sign a Business Associate Agreement (BAA) and are directly liable for HIPAA violations under the 2013 Omnibus Rule.

HIPAA Security Checklist for Small Practices

  1. 1
    Complete an annual Security Risk Analysis (SRA).

    This is requirement #1 and the most commonly missed. An SRA identifies where ePHI lives, what threats exist, and what safeguards are missing. The HHS OCR provides a free SRA Tool (download from HealthIT.gov). Document your findings and your remediation plan. Do this every year.

  2. 2
    Encrypt ALL devices and communications containing ePHI.

    Laptops, desktops, servers, USB drives, backup drives β€” if ePHI is on it, it must be encrypted. Email containing PHI must be encrypted in transit. Use a HIPAA-compliant email service (many practices use Paubox, Virtru, or MDOfficeMail) that handles encryption automatically.

  3. 3
    Implement unique user IDs and MFA.

    Every staff member must have their own login credentials. Shared logins ("frontdesk / password123") are a common HIPAA violation. Enable MFA on any system accessing ePHI β€” EHR systems, email, cloud storage.

  4. 4
    Sign BAAs with ALL vendors handling PHI.

    IT support, cloud EHR vendors, billing companies, email providers, remote backup services β€” each one needs a signed BAA before they touch your PHI. If they won't sign a BAA, do not use them. Keep BAAs in a file; OCR will ask for them in an audit.

  5. 5
    Create and test your backup and disaster recovery plan.

    HIPAA requires you to have a data backup plan, disaster recovery plan, and emergency mode operation plan. Your EHR data must be backed up daily with off-site storage. Test a full EHR restore at least annually. Ransomware hitting an unbacked-up practice is a career-ending event.

  6. 6
    Train your staff β€” and document it.

    HIPAA training is mandatory for all workforce members. Cover: what is PHI, the minimum necessary rule, phishing awareness, password security, and breach reporting procedures. Keep signed training attendance records.

  7. 7
    Have a breach response plan β€” before you need it.

    Who is your designated HIPAA Security Officer? What happens if the EHR goes down? How do you notify patients if their PHI is exposed? Write this down and put it somewhere everyone can find it when things go wrong.

Employee Security Training β€” 30-Minute HIPAA-Ready Script

A ready-to-use training session covering phishing, passwords, PHI handling, and incident reporting. Designed for medical and dental office staff.

Get the Training Script β†’

Common HIPAA Mistakes Small Practices Make

  • ❌ No Risk Analysis: This is the #1 finding in OCR investigations. You cannot protect PHI if you do not know where it is and what threatens it.
  • ❌ Shared login credentials: Every user needs a unique ID. No exceptions. This is auditable.
  • ❌ Texting PHI on personal phones: Regular SMS is not HIPAA-compliant. Use a secure messaging platform with a BAA (TigerConnect, Spruce, etc.).
  • ❌ No BAA with IT support: If your IT guy can see PHI while fixing a computer, they need a BAA. Period.
  • ❌ Unencrypted laptops and backup drives: The single most common breach scenario for small practices β€” a stolen laptop or lost backup drive with no encryption.