Healthcare

Prove Your Practice Is Compliant on the Day Someone Asks

HIPAA compliance is not a firewall, an EHR contract, or a binder on a shelf. It is a set of documents you can produce on demand - a current Security Risk Analysis, the risk management plan tied to it, dated training records, and a signed agreement with every vendor that touches patient data.

Most practices fail on the paperwork, not the technology. The controls are often fine. The evidence that they were chosen deliberately, reviewed, and maintained does not exist.

The operational reality

What Makes Healthcare Different

Your clinical software decides most of your security posture, and you did not choose it for security. athenahealth, eClinicalWorks, NextGen, Dentrix, Eaglesoft, Tebra - session timeout, audit logging, and multi-factor enforcement are whatever your vendor supports and whatever your practice turned on. Generic IT advice assumes you can change the application. You cannot.

Your named Security Officer is your office manager. The Security Rule requires you to designate one (45 CFR 164.308(a)(2)). In a three-to-fifteen provider practice, that person also runs scheduling, billing questions, and the front desk. The requirement is real and so is the bandwidth problem.

Protected health information leaves your practice through channels nobody audits. Referrals and prior authorizations still move by fax through leased multifunction copiers with internal drives. Staff text patients because patients expect it. Reminder platforms, cloud fax, backup, and your IT provider are all Business Associates. Most practices cannot produce the list on request.

Two clocks run on a breach, not one. HIPAA gives you 60 days for individual notice (45 CFR 164.404). Florida gives you 30 (Fla. Stat. §501.171). The shorter one governs, and it starts before you have finished the investigation.

Frameworks

Your Compliance Landscape

Which of these apply depends on what you treat, what you prescribe, and how you get paid. This is educational, not legal advice - your counsel and your compliance officer make the determination.

Almost always applies

  • Requires an accurate, current risk analysis of every system holding electronic PHI, a plan to reduce what it finds, workforce training, and signed Business Associate Agreements. HHS has stated plainly that a risk analysis is required, not optional, and that installing a certified EHR does not satisfy it (HHS guidance on risk analysis). The OCR audit protocol is public - you can read the questions before you are asked them (OCR audit protocol).
  • Extended HIPAA obligations directly to Business Associates and set the breach notification structure. It is why your IT provider signs a BAA and carries its own liability rather than sheltering under yours.
  • You take cards, so you are a merchant. Version 4.0.1 adds requirements around scripts on payment pages, which matters if your website takes copays or deposits (PCI SSC document library).
  • Not required, but it is the vocabulary your cyber insurer and most questionnaires use (NIST Cybersecurity Framework). Mapping your HIPAA work to it saves you answering the same questions twice.

Applies in some cases

  • Applies if you diagnose or treat substance use disorder. Consent rules are stricter than HIPAA - a care-coordination disclosure that is entirely permissible under HIPAA can violate Part 2 (42 CFR Part 2). Practices treating both behavioral health and SUD patients are where this gets missed.
  • Any prescriber electronically prescribing controlled substances is subject to DEA identity proofing and two-factor authentication requirements (DEA e-prescribing rules). This is a separate obligation from HIPAA and it lands on the individual prescriber.
  • Not a law. It becomes relevant when a health system or payer partner requires third-party certification as a condition of the contract.
  • Applies to your EHR vendor, not to you - but it matters when you attest to using certified health IT.
  • Triggered when a practice extends or arranges patient financing - common in dental and elective care. The Safeguards Rule reaches non-bank financial activity (16 CFR Part 314).
  • Something you request from your billing company and health-tech vendors during diligence. Independent practices rarely need to hold one.

The information provided here is for educational purposes only and should not be considered legal advice. Requirements change and applicability depends on your specific circumstances - for specific compliance concerns, consult a qualified legal professional.

Failure patterns

What Usually Goes Wrong

  • The Security Risk Analysis is a blank template, or four years old. It is the first artifact OCR requests, and the absence of a current one is what turns an incident into an enforcement matter.
  • The EHR vendor's BAA is treated as practice-wide coverage. It covers the EHR. It does not cover your backup provider, your cloud fax, your reminder platform, or your IT company.
  • PHI leaves through fax and copiers. The lease ends, the multifunction device goes back to the lessor, and the internal drive goes with it.
  • Staff text patient information from personal phones because no secure messaging platform was ever provided. The demand is real; the channel is the problem.
  • Behavioral health practices apply HIPAA consent rules to Part 2 records and disclose in good faith to a coordinating provider.
  • Nobody can produce the vendor list. Not the contracts - just the list of who touches PHI. That question is where most readiness exercises stall.
  • Training records are undated or missing. Training happened. Proving it happened on a specific date to specific people is a different exercise.
  • Only the EHR and the perimeter get assessed. Everything above lives outside both.

Our services

How We Work With Healthcare

  • Governance, Risk & Compliance (GRC)

    The Security Risk Analysis, the risk management plan tied to it, the BAA inventory, and dated training evidence - produced, maintained, and refreshed on a schedule rather than rebuilt in a panic.

  • Cyber Risk Management

    The technical side OCR now focuses on: multi-factor on remote access, encryption status you can evidence, monitoring, and the controls your insurer conditions renewal on.

  • Helpdesk Support

    Day-to-day support from people who know that a practice cannot reboot a server at 10am and that your EHR vendor dictates what is possible.

  • Fractional CIO, CTO & CISO

    The Security Officer role, backed by someone who has read the audit protocol - so your office manager is not carrying a regulatory designation alone.

  • Digital Forensics & Incident Response

    When something happens, the 30-day Florida clock starts immediately. Investigation, containment, and the documented determination of whether a breach occurred.

  • Third-Party Assessments

    Diligence on the vendors that hold your PHI, and answers when a health system sends you their questionnaire.

Questions people ask

Frequently Asked Questions

Do I need a HIPAA risk assessment if I am a solo practice?
Yes. The Security Rule's risk analysis requirement applies to every covered entity regardless of size, and HHS has stated that it is required rather than an optional best practice. Scope scales with your practice; the obligation does not. See the HHS guidance on risk analysis at hhs.gov.
Is a Security Risk Analysis actually required, or just recommended?
Required. It sits in the Security Rule's administrative safeguards at 45 CFR 164.308(a)(1)(ii)(A), and it is the document OCR asks for first. A vendor checklist or a purchased template with blanks in it does not satisfy the requirement.
Does my EHR vendor handle HIPAA for me?
No. Your EHR vendor is a Business Associate responsible for its own compliance and for the terms of its BAA with you. Your risk analysis, workforce training, access management, incident response, and the agreements with your other vendors remain yours. This is the single most expensive misconception in small-practice healthcare IT.
Am I a covered entity or a business associate?
If you provide treatment and bill electronically, you are almost certainly a covered entity. If you perform a service for a covered entity that involves protected health information - billing, transcription, IT - you are a business associate. Some organizations are both, in different relationships. HHS publishes the definitions at hhs.gov/hipaa.
Do I need a BAA with my IT company?
If they can access systems containing PHI, yes. That includes remote support tools and backup. An IT provider who will not sign one is telling you something useful.
What does OCR actually ask for in an audit?
The audit protocol is published on the HHS website, so you can read the questions in advance. In practice it is a document production exercise: the current risk analysis, the risk management plan, policies and procedures, dated training records, signed BAAs, and your incident log.
Is texting patients a HIPAA violation?
Standard SMS is not a secure channel, and sending PHI over it without safeguards or a documented patient decision creates exposure. The practical fix is a secure messaging platform plus a written policy - not asking staff to stop doing something patients expect.
Do I have to report a breach, and to whom?
HIPAA requires notice to affected individuals and to HHS, with timing and thresholds set out in the Breach Notification Rule. Separately, Florida's §501.171 requires notice to affected Floridians within 30 days and, above a statutory threshold, to the Department of Legal Affairs. The shorter clock governs your planning.
What is 42 CFR Part 2 and does it apply to my practice?
Part 2 protects records of substance use disorder treatment held by federally assisted programs, with consent requirements stricter than HIPAA's. If you diagnose or treat SUD, it likely applies. The regulation text is on eCFR.
How often do I need to update my risk assessment?
There is no fixed interval in the rule. HHS guidance frames it as an ongoing process - reviewed periodically and updated when something material changes: a new EHR, a new location, a merger, a new remote-work arrangement, or an incident.

Florida & the Treasure Coast

Healthcare on the Treasure Coast

Florida adds a second breach clock. Fla. Stat. §501.171 requires notice to affected Florida residents within 30 days of determination, alongside - not instead of - HIPAA's 60-day requirement, with notice to the Department of Legal Affairs above the statutory threshold.

On the Treasure Coast the patient mix shapes the risk. Martin, St. Lucie, and Palm Beach counties carry a large retiree and seasonal population, which means telehealth across state lines, out-of-state records requests, concierge and direct-pay arrangements, and a steady volume of records moving between practices and family members. Each of those is a disclosure pathway that a generic risk assessment written for a single-state practice will not have considered.

[NEEDS: client proof for this vertical]