Back to resources

HIPAA compliance sounds like a big project. Policies, training programs, risk analyses, business associate agreements across every vendor you've ever used. And if you want to be fully compliant, it is a project.

But the majority of HIPAA enforcement actions against small practices trace back to the same handful of gaps. Not exotic, hard-to-fix vulnerabilities. Basic controls that weren't in place or weren't documented.

If you're a solo or small practice and you're not sure where to start, start here. These five controls won't make you fully compliant on their own, but they'll address the most common reasons practices get hit with fines and they're the baseline every practice should have before anything else.

A note on terminology: HIPAA uses the term "Protected Health Information" (PHI). This means any information that could identify a patient and relates to their health, care, or payment for care. Everything from intake forms to email threads to billing records counts as PHI.

The five controls

01
Access control

Unique logins for every staff member

Every person who touches patient data needs their own account with their own password. No shared logins. No "we all use the same login for the EHR."

This matters for two reasons. First, if something goes wrong, you need to know who accessed what and when. Shared accounts make that impossible. Second, when staff leave, you need to cut off their access without disrupting everyone else. You can't do that with a shared login.

Apply this to your EHR (electronic health record) system, practice management software, email accounts, and any cloud storage where patient files live.

02
Encryption

Encrypt devices that hold patient data

A stolen laptop or phone with unencrypted patient files is a reportable HIPAA breach. Full stop. The encryption doesn't prevent the theft, but it makes the data unreadable to whoever has the device, which removes the HIPAA liability.

On Windows, this is BitLocker. On Mac, it's FileVault. On iPhone, encryption is on by default if you have a passcode. On Android, it depends on the device, but most modern Android phones encrypt by default too.

Turn it on. Write down that it's on. If you're not sure whether it's on, check today.

03
Risk analysis

A written risk analysis

This is the one HIPAA control that gets practices in trouble most often. A risk analysis is not optional. It's a specific HIPAA requirement, and it's one of the first things an auditor asks for.

What it needs to be: a written document that identifies where PHI lives in your practice, what threats could affect it, and what you're doing (or planning to do) about those threats. It doesn't need to be long. A thorough one-page document is better than a 20-page one that doesn't actually address your specific setup.

Update it when something significant changes: new software, a new staff member, a new location, a breach. An undated risk analysis from five years ago won't help you in an audit.

04
Business associates

Business Associate Agreements with every vendor who touches PHI

A Business Associate Agreement (BAA) is a contract between you and any vendor who accesses, handles, or stores PHI on your behalf. Your EHR vendor has one. Your billing service has one. Your cloud storage provider may or may not.

The problem: most small practices use software that wasn't designed for healthcare and has never been asked to sign a BAA. AI transcription tools, note-taking apps, scheduling software, and communication tools all potentially touch PHI, and most of them don't have BAAs available.

If a vendor won't sign a BAA, you have two options: stop using them for anything that involves PHI, or accept the compliance risk. The latter is not really an option if you're treating patients covered by HIPAA.

05
Incident response

A written breach response plan

HIPAA requires you to have a documented process for responding to a breach. In practice, this means knowing: who makes decisions when something goes wrong, who you need to notify (and within what timeframe), and how you'll document what happened.

HIPAA's breach notification rule requires you to notify affected individuals within 60 days of discovering a breach. If the breach affects 500 or more people in a state, you also have to notify the media. The HHS Office for Civil Rights gets notified regardless of size.

Your plan doesn't need to be complex. It needs to exist, be written down, and be somewhere your team can find it when they're panicking at 9pm on a Friday.

The documentation problem

Having these controls in place is necessary. Proving you have them in place is what protects you in an audit.

HIPAA enforcement operates on a "reasonable good faith effort" standard. If you can show a documented risk analysis, signed BAAs, a breach response plan, and evidence that you've implemented the technical controls, you're in a much stronger position than a practice with better security but nothing written down.

Auditors don't give you credit for what you haven't documented.

Quick self-check: do you have these in place?

  • Every staff member has their own login to all systems that hold PHI
  • All devices with patient data have encryption enabled
  • You have a written risk analysis, dated within the last 12 months
  • You have signed BAAs with every vendor who handles PHI
  • You have a written breach response plan with notification timelines

Five controls. All of them documentable. None of them require a dedicated IT team. If you can check all five boxes with evidence, you've addressed the most common reasons small practices face HIPAA enforcement actions.

If you're not sure which of these you have in place, or you want someone to verify your setup against the full HIPAA framework, that's exactly what a security assessment covers.

Want to know where your practice stands?

The free Cyber Health Score includes questions across all five of these areas and gives you an instant read on your biggest gaps. Takes 5 minutes.

Get your free Cyber Health Score