You have nine employees, one part-time biller who works from her kitchen table, a cloud EHR, a scanner that emails PDFs to the front desk, and a phone system you have never thought about once. Nobody at your practice has "compliance" in their job title. That is the reality of small practice HIPAA compliance, and it is also the exact profile that shows up in Office for Civil Rights investigations — not because small offices are careless, but because nobody ever wrote anything down.

This article is the operator's version: what your practice must actually produce, who owns each piece, what the deadlines are, and what the evidence looks like when someone asks for it. No theory, no definitions.

What Small Practice HIPAA Compliance Actually Requires

There is no size exemption. A solo dermatologist and a 400-provider system are held to the same rule text; only the reasonableness analysis differs. At minimum, your practice must be able to produce:

  • A current security risk analysis covering every system that creates, receives, maintains, or transmits ePHI — with identified risks, likelihood, impact, and what you did about each one.
  • A risk management plan showing remediation decisions, owners, and dates.
  • Written policies and procedures for privacy, security, and breach notification that describe how your office actually operates.
  • Signed Business Associate Agreements with every vendor that touches PHI.
  • Workforce training records — who was trained, on what, on what date.
  • A named Privacy Official and Security Official (one person can hold both roles in a small office).
  • A Notice of Privacy Practices posted, available, and acknowledged.
  • Six years of retained documentation for everything above.

If you cannot hand those items to an investigator within a few business days, you do not have a compliance program. You have good intentions.

The Risk Analysis Is the Document OCR Asks For First

In resolution agreements published on the HHS site, the same finding appears again and again: the covered entity failed to conduct an accurate and thorough risk analysis of the potential risks to its ePHI. It is the opening question in almost every investigation, including investigations that started as something else entirely — a lost laptop, a misdirected fax, a patient complaint about a records request.

Understand what the requirement is not. It is not a vulnerability scan. It is not your IT vendor's security checklist. It is not a vendor certificate. HHS has been explicit that no product or service certifies HIPAA compliance — the government does not endorse or certify anyone, and a badge on a vendor's website is not evidence.

What a Defensible Risk Analysis Contains

Start with an asset and data-flow inventory. List every place ePHI lives: the EHR, the practice management system, the billing clearinghouse, the imaging modality, the fax service, the appointment reminder tool, the front-desk workstation, the doctor's phone, the backup drive in the supply closet, the biller's home laptop.

For each asset, document the threats that plausibly apply, the vulnerabilities that exist today, your current safeguards, the likelihood and impact if the threat lands, and the resulting risk level. Then record the decision: remediate, mitigate, transfer, or accept — with a name and a date attached.

Two free federal resources make this tractable. The ONC and OCR jointly publish a Security Risk Assessment Tool built specifically for small and medium practices. NIST's SP 800-66 Revision 2 maps each Security Rule standard to concrete implementation activities. Neither one produces a finished report, but they tell you what "thorough" means.

Reality check on effort: a genuine first-year risk analysis for a ten-person practice takes 15 to 30 hours of someone's attention if done manually — inventory, interviews, documentation, remediation planning. That is why most small offices skip it. If you would rather generate the risk analysis report, risk management plan, and full policy set from a structured intake instead of building the framework from scratch, do that — but review every finding against how your office actually works before you sign it. A generated document you have not read is worse than no document, because it proves you did not look.

Your Vendor List Is Longer Than You Think

Pull your accounts payable ledger for the last 18 months. Go line by line and mark every vendor with any access to patient information — including access they could have, not just access they use.

Typical small-practice list: EHR vendor, billing company, clearinghouse, IT support/MSP, cloud backup, secure messaging, transcription service, answering service, appointment reminder platform, shredding company, collections agency, offsite storage, and any consultant who logs into your systems. Your malpractice carrier and your bank generally are not business associates. Your cleaning crew is not, unless they handle records.

For each one, you need a signed BAA on file — and you need to be able to find it. "We signed something during onboarding in 2021" is not a control. Keep a single vendor register with vendor name, service, PHI accessed, BAA execution date, renewal or review date, and where the signed copy lives.

When a vendor sends you their paper, read the breach notification clause specifically. Many vendor-drafted BAAs give themselves 30 or 60 days to notify you — which leaves you no room inside your own 60-day patient notification clock. Negotiate that number down to 5 or 10 days. If you need to send an agreement rather than receive one, a signature-ready Business Associate Agreement generator will get you a clean document faster than editing a decade-old template someone left in a shared drive.

Three Clocks That Run Whether You Notice or Not

30 Days: The Right of Access

A patient asks for their records. You have 30 calendar days to provide them, with one 30-day extension available if you notify the patient in writing of the reason and the new date. Fees must be limited to a reasonable, cost-based amount. Format matters: if the patient asks for electronic delivery and you maintain the record electronically, you provide it electronically.

OCR's Right of Access Initiative has produced dozens of settlements, and the pattern is consistent — small practices, small dollar amounts, and requests that sat on someone's desk. Assign this to a named person, log every request with a received date and a fulfilled date, and review the log monthly.

60 Days: Breach Notification

Following discovery of a breach of unsecured PHI, you notify affected individuals without unreasonable delay and no later than 60 calendar days. For breaches affecting 500 or more individuals in a state or jurisdiction, you also notify HHS and prominent media within that same 60 days. For breaches under 500, you log them and report to HHS within 60 days after the end of the calendar year — meaning your 2025 small breaches are due by March 1, 2026.

The clock starts on discovery, and discovery includes what any workforce member should reasonably have known. Read the current requirements on the HHS breach notification page, and look at the public breach portal to see how practices your size get listed. Hacking/IT incidents and email compromise dominate.

Six Years: Retention

Every policy, every risk analysis, every training roster, every sanction, every access request log, every breach risk assessment — retained six years from creation or from the date it was last in effect, whichever is later. Superseded policies do not get deleted. They get archived with their effective and end dates.

Training and Sanctions: The Two-Page Evidence Trail

Train new workforce members within a reasonable period after hire, retrain when policies materially change, and refresh annually as a practical baseline. Include contractors and volunteers who touch PHI.

The evidence is not the slide deck. It is the roster: name, role, training topic, date, and an attestation signature. Add short targeted sessions when something happens — a phishing email that got clicked, a printout left in an exam room — and document those too. Five documented 15-minute huddles beat one undocumented annual session.

You also need a written sanctions policy and proof you apply it. If a medical assistant looked up a neighbor's chart and nothing happened, that is a finding. Document the investigation, the audit log evidence, the discipline imposed, and the retraining delivered.

A 12-Month Small Practice HIPAA Compliance Calendar

Spread the work so it does not collapse into a panic week. For a practice under 25 people, this is roughly two to four hours per month after the first-year build.

  1. January: Update the asset and ePHI inventory. Confirm small-breach log is ready for the March 1 HHS submission.
  2. February: Review user accounts across every system. Terminate access for anyone who left. Verify unique user IDs.
  3. March: Submit prior-year small breaches to HHS. Review the vendor register; identify BAAs older than three years.
  4. April: Annual security risk analysis refresh — or full analysis if you have never done one.
  5. May: Build or update the risk management plan from April's findings. Assign owners and target dates.
  6. June: Test the data backup. Actually restore a file. Document the test and the result.
  7. July: Annual workforce training. Collect signed attestations.
  8. August: Physical safeguards walkthrough — monitor angles, badge/key inventory, records room locks, disposal bins, unattended workstations.
  9. September: Review policies against actual workflow. Update anything that drifted. Log effective dates.
  10. October: Sample audit of EHR access logs. Look for same-surname lookups and after-hours access.
  11. November: Tabletop exercise: ransomware or a stolen laptop. 45 minutes, written notes, action items.
  12. December: Review right-of-access log fulfillment times. Confirm the Notice of Privacy Practices is posted, on the website, and current.

What Is Changing Heading Into 2026

HHS published a proposed overhaul of the Security Rule in January 2025. As of today it is still a proposal, not a final rule, and nothing in it is enforceable yet. But the direction is clear: the proposal would remove the "addressable" versus "required" distinction, mandate asset inventories and network maps, require multi-factor authentication, require encryption of ePHI at rest and in transit, and impose annual verification that business associates have deployed required safeguards.

Do not wait for a final rule to do those things. Every item on that list is defensible today under the existing reasonableness standard, and a practice that already runs MFA, encrypts laptops, and keeps an asset inventory will absorb a final rule as paperwork rather than a project.

Where Small Practices Actually Get Caught

Not exotic attacks. The recurring pattern is mundane: a departed employee whose EHR login stayed active for eight months; a laptop stolen from a car with an unencrypted local export; a business associate breach the practice learned about from a patient; a records request that went unanswered for four months; a phishing email that gave an attacker mailbox access to two years of referral correspondence.

Each of those has a corresponding control that costs almost nothing: a termination checklist, full-disk encryption, a vendor register with notification terms, an access request log, and MFA on email. The expensive part is never the control. It is the absence of documentation proving you considered it.

Your Next Two Hours

Name your Privacy Official and Security Official in writing today. Then pull the AP ledger and build the vendor register — that single spreadsheet will tell you more about your exposure than any assessment. Then schedule the risk analysis.

If the documentation load is the reason it keeps slipping, let the paperwork be generated for you: produce your risk analysis, risk management plan, and complete policy set, then spend your hours on the parts only you can do — reviewing the findings, fixing what they surface, and making sure the front desk knows what changed.