The operational reality

What Makes Healthcare Different

Your clinical software decides most of your security posture, and you did not choose it for security. athenahealth, eClinicalWorks, NextGen, Dentrix, Eaglesoft, Tebra - session timeout, audit logging, and multi-factor enforcement are whatever your vendor supports and whatever your practice turned on. Generic IT advice assumes you can change the application. You cannot.

Your named Security Officer is your office manager. The Security Rule requires you to designate one (45 CFR 164.308(a)(2)). In a three-to-fifteen provider practice, that person also runs scheduling, billing questions, and the front desk. The requirement is real and so is the bandwidth problem.

Protected health information leaves your practice through channels nobody audits. Referrals and prior authorizations still move by fax through leased multifunction copiers with internal drives. Staff text patients because patients expect it. Reminder platforms, cloud fax, backup, and your IT provider are all Business Associates. Most practices cannot produce the list on request.

Two clocks run on a breach, not one. HIPAA gives you 60 days for individual notice (45 CFR 164.404). Florida gives you 30 (Fla. Stat. §501.171). The shorter one governs, and it starts before you have finished the investigation.

Failure patterns

What Usually Goes Wrong

  • The Security Risk Analysis is a blank template, or four years old. It is the first artifact OCR requests, and the absence of a current one is what turns an incident into an enforcement matter.
  • The EHR vendor's BAA is treated as practice-wide coverage. It covers the EHR. It does not cover your backup provider, your cloud fax, your reminder platform, or your IT company.
  • PHI leaves through fax and copiers. The lease ends, the multifunction device goes back to the lessor, and the internal drive goes with it.
  • Staff text patient information from personal phones because no secure messaging platform was ever provided. The demand is real; the channel is the problem.
  • Behavioral health practices apply HIPAA consent rules to Part 2 records and disclose in good faith to a coordinating provider.
  • Nobody can produce the vendor list. Not the contracts - just the list of who touches PHI. That question is where most readiness exercises stall.
  • Training records are undated or missing. Training happened. Proving it happened on a specific date to specific people is a different exercise.
  • Only the EHR and the perimeter get assessed. Everything above lives outside both.

Questions people ask

Frequently Asked Questions

Do I need a HIPAA risk assessment if I am a solo practice?
Yes. The Security Rule's risk analysis requirement applies to every covered entity regardless of size, and HHS has stated that it is required rather than an optional best practice. Scope scales with your practice; the obligation does not. See the HHS guidance on risk analysis at hhs.gov.
Is a Security Risk Analysis actually required, or just recommended?
Required. It sits in the Security Rule's administrative safeguards at 45 CFR 164.308(a)(1)(ii)(A), and it is the document OCR asks for first. A vendor checklist or a purchased template with blanks in it does not satisfy the requirement.
Does my EHR vendor handle HIPAA for me?
No. Your EHR vendor is a Business Associate responsible for its own compliance and for the terms of its BAA with you. Your risk analysis, workforce training, access management, incident response, and the agreements with your other vendors remain yours. This is the single most expensive misconception in small-practice healthcare IT.
Am I a covered entity or a business associate?
If you provide treatment and bill electronically, you are almost certainly a covered entity. If you perform a service for a covered entity that involves protected health information - billing, transcription, IT - you are a business associate. Some organizations are both, in different relationships. HHS publishes the definitions at hhs.gov/hipaa.
Do I need a BAA with my IT company?
If they can access systems containing PHI, yes. That includes remote support tools and backup. An IT provider who will not sign one is telling you something useful.
What does OCR actually ask for in an audit?
The audit protocol is published on the HHS website, so you can read the questions in advance. In practice it is a document production exercise: the current risk analysis, the risk management plan, policies and procedures, dated training records, signed BAAs, and your incident log.
Is texting patients a HIPAA violation?
Standard SMS is not a secure channel, and sending PHI over it without safeguards or a documented patient decision creates exposure. The practical fix is a secure messaging platform plus a written policy - not asking staff to stop doing something patients expect.
Do I have to report a breach, and to whom?
HIPAA requires notice to affected individuals and to HHS, with timing and thresholds set out in the Breach Notification Rule. Separately, Florida's §501.171 requires notice to affected Floridians within 30 days and, above a statutory threshold, to the Department of Legal Affairs. The shorter clock governs your planning.
What is 42 CFR Part 2 and does it apply to my practice?
Part 2 protects records of substance use disorder treatment held by federally assisted programs, with consent requirements stricter than HIPAA's. If you diagnose or treat SUD, it likely applies. The regulation text is on eCFR.
How often do I need to update my risk assessment?
There is no fixed interval in the rule. HHS guidance frames it as an ongoing process - reviewed periodically and updated when something material changes: a new EHR, a new location, a merger, a new remote-work arrangement, or an incident.