HIPAA compliance for small practices: a plain-English checklist
What small practices and business associates need for HIPAA: risk analysis, policies, BAAs, training, safeguards and breach response, in plain English.
If you run a small clinic, therapy practice, dental office or a business that handles patient data for one, HIPAA applies to you whether you have three staff or three hundred. The good news: compliance for a small organization is mostly about doing a handful of things consistently and writing them down.
This checklist explains the core requirements in plain English. It is a starting point, not legal advice; for your specific situation, work with a qualified HIPAA professional.
Who HIPAA applies to
- Covered entities: healthcare providers who bill electronically, health plans and clearinghouses.
- Business associates: anyone who handles protected health information (PHI) on their behalf, such as billing companies, IT providers, cloud software vendors, transcription services and consultants.
If you touch PHI, you need a compliance program, and business associates are directly liable too.
The checklist
1. Do a security risk analysis, and repeat it
The HIPAA Security Rule requires a risk analysis: where electronic PHI lives (EHR, email, laptops, phones, backups, vendors), what could go wrong, how likely it is and what you do about it. It is the single most common gap found in investigations. Update it at least yearly and whenever you change systems.
2. Write your policies and procedures
Covering access control, passwords, device use, email and texting, data backup, disposal of records, sanctions for violations and incident response. Keep them short enough that staff will actually read them, and keep records for six years.
3. Name a privacy and security officer
In a small practice this is often the office manager. Someone has to own it.
4. Sign Business Associate Agreements (BAAs)
Every vendor that handles your PHI needs a signed BAA: your EHR, email provider, cloud storage, billing service, IT support and answering service. No BAA, no PHI.
5. Put the safeguards in place
- Administrative: training, access reviews, the risk analysis itself.
- Physical: locked rooms and cabinets, screen privacy, secure disposal.
- Technical: unique logins, multi-factor authentication, encryption of laptops and phones, automatic logoff, audit logs, backups.
6. Train your team every year
Most breaches start with people: a phishing email, a lost phone, a chart shared in the wrong chat. Train at hiring and yearly, and keep a record of who completed it.
7. Give patients their rights
A Notice of Privacy Practices, and a process for patients to access and request corrections to their records, generally within 30 days.
8. Be ready for a breach
Have a written incident response plan. If unsecured PHI is breached, affected individuals must be notified without unreasonable delay and no later than 60 days after discovery. Breaches are also reported to the Department of Health and Human Services: within the same 60 days if 500 or more people are affected (along with local media), otherwise in a yearly report due within 60 days of the end of the calendar year.
Why small practices get fined
Enforcement cases against small organizations most often cite a missing or outdated risk analysis, lost unencrypted devices, missing BAAs and slow responses to patients’ requests for their records. None of these are expensive to fix; they just need someone to do them.
Getting help without hiring a compliance department
Many small practices combine software that handles the paperwork with an expert who checks it. One Guy Consulting works this way: its software runs the security risk assessment and generates a gap analysis, and a certified HIPAA professional guides you personally. It has worked with small practices and business associates since 2015 and offers a free 30-minute review, with no patient information required.
Practices that use cloud software should also check their vendors. For example, if you move documents into a new system such as a document management system, confirm where the data is stored and get a BAA before any PHI goes in.
Your first week
- List every place PHI lives and every vendor who touches it.
- Collect or sign BAAs for each vendor.
- Turn on multi-factor authentication and device encryption everywhere.
- Book a risk analysis, yourself with a template or with a professional.
- Schedule staff training and write down that you did.
Find help
Need a HIPAA consultant, IT support for a clinic or compliant software? Post what you need and let qualified providers respond, or browse the offers board.