Compliance & risk

HIPAA compliance for independent medical practices

HIPAA compliance for an independent practice comes down to five things: an annual documented risk assessment, active administrative/physical/technical safeguards, current BAAs with every PHI-touching vendor, workforce training with attestation, and a written breach-response plan. OCR fines are driven far more often by 'no risk assessment on file' than by the underlying incident.

By Jordan Alderman, MBA, CMPE · Reviewed by Rania Hassan, JD, CHC · Last reviewed · Methodology

Disclosure: Independent editorial. No pay-for-placement, no affiliate rankings. Full editorial standards.

This guide walks through the HIPAA obligations every independent practice must meet, based on HHS OCR enforcement patterns and Security Rule requirements. It is not legal advice — a healthcare attorney in your state should review your privacy program annually.

What HIPAA actually requires (in plain English)

HIPAA has three rules that matter operationally: the Privacy Rule (how you use and disclose PHI), the Security Rule (safeguards for electronic PHI), and the Breach Notification Rule (what happens when something goes wrong).

The Security Rule is where most independent practices fall short — not because they're insecure, but because the risk assessment is missing or stale.

The five things OCR looks for

  • Annual documented risk assessment (dated, signed, with remediation plan)
  • Written policies covering minimum-necessary, access, sanction, contingency
  • Workforce training records with signed attestations
  • BAA inventory covering every vendor touching PHI
  • Written incident-response plan with named team

Common enforcement patterns (last 5 years)

HHS OCR consistently fines small practices for the same handful of failures: no risk assessment (~$100k–$150k typical), impermissible disclosure via unsecured email, and lack of a BAA with a cloud provider. The technical breach itself is usually secondary.

Practical safeguards for a small practice

  • Full-disk encryption on every laptop and mobile device
  • MFA on EHR, email, and remote access
  • Automatic logoff after 15 minutes idle
  • Secure messaging tool (not personal SMS or WhatsApp)
  • Fax replaced with DirectTrust or eFax with BAA
  • Endpoint protection with monthly patch cadence
  • Backup with tested restore quarterly

Business Associate management

Every vendor that creates, receives, maintains, or transmits PHI on your behalf needs a signed BAA — billing services, EHR, IT support, cloud storage, shredding, secure messaging, telehealth. Missing one BAA on a breach is enough to escalate to willful neglect.

When a breach happens

  • Contain and document within 24 hours
  • Preserve logs and evidence
  • Legal counsel + forensic vendor engaged
  • Risk assessment: is this a reportable breach?
  • If yes: patient notice within 60 days, HHS OCR within 60 days (500+) or annually (<500), media notice if 500+ in a state

Related buyer guide

Deeper vendor evaluation: ehr