Compliance & risk
HIPAA compliance for independent medical practices
HIPAA compliance for an independent practice comes down to five things: an annual documented risk assessment, active administrative/physical/technical safeguards, current BAAs with every PHI-touching vendor, workforce training with attestation, and a written breach-response plan. OCR fines are driven far more often by 'no risk assessment on file' than by the underlying incident.
By Jordan Alderman, MBA, CMPE · Reviewed by Rania Hassan, JD, CHC · Last reviewed · Methodology
Disclosure: Independent editorial. No pay-for-placement, no affiliate rankings. Full editorial standards.
This guide walks through the HIPAA obligations every independent practice must meet, based on HHS OCR enforcement patterns and Security Rule requirements. It is not legal advice — a healthcare attorney in your state should review your privacy program annually.
What HIPAA actually requires (in plain English)
HIPAA has three rules that matter operationally: the Privacy Rule (how you use and disclose PHI), the Security Rule (safeguards for electronic PHI), and the Breach Notification Rule (what happens when something goes wrong).
The Security Rule is where most independent practices fall short — not because they're insecure, but because the risk assessment is missing or stale.
The five things OCR looks for
- Annual documented risk assessment (dated, signed, with remediation plan)
- Written policies covering minimum-necessary, access, sanction, contingency
- Workforce training records with signed attestations
- BAA inventory covering every vendor touching PHI
- Written incident-response plan with named team
Common enforcement patterns (last 5 years)
HHS OCR consistently fines small practices for the same handful of failures: no risk assessment (~$100k–$150k typical), impermissible disclosure via unsecured email, and lack of a BAA with a cloud provider. The technical breach itself is usually secondary.
Practical safeguards for a small practice
- Full-disk encryption on every laptop and mobile device
- MFA on EHR, email, and remote access
- Automatic logoff after 15 minutes idle
- Secure messaging tool (not personal SMS or WhatsApp)
- Fax replaced with DirectTrust or eFax with BAA
- Endpoint protection with monthly patch cadence
- Backup with tested restore quarterly
Business Associate management
Every vendor that creates, receives, maintains, or transmits PHI on your behalf needs a signed BAA — billing services, EHR, IT support, cloud storage, shredding, secure messaging, telehealth. Missing one BAA on a breach is enough to escalate to willful neglect.
When a breach happens
- Contain and document within 24 hours
- Preserve logs and evidence
- Legal counsel + forensic vendor engaged
- Risk assessment: is this a reportable breach?
- If yes: patient notice within 60 days, HHS OCR within 60 days (500+) or annually (<500), media notice if 500+ in a state
Related buyer guide
Deeper vendor evaluation: ehr →