HIPAA Compliance Consulting for Medical Practices
Medical practices are covered entities under HIPAA whenever they transmit health information electronically as part of a covered transaction (45 CFR §160.103). That includes filing insurance claims, checking patient eligibility, sending electronic referrals, and processing billing through a clearinghouse. There is no size exemption. Solo physicians, multi-provider groups, urgent care clinics, outpatient surgery centers, and specialty practices all face the same rules. For a detailed look at what this investment often involves, see our HIPAA compliance cost breakdown.
HIPAA Requirements for Medical Practices
HIPAA applies equally to solo practitioners and large healthcare systems. There is no exemption based on practice size, patient volume, or revenue.
Medical practices that are covered entities must follow three core HIPAA rules:
- Privacy Rule (45 CFR Part 164, Subpart E) - Controls how protected health information (PHI) is used and shared. Medical practices must give patients a Notice of Privacy Practices (NPP), honor patient rights to access and amend records per §164.524 and §164.526, and share only the minimum PHI needed for the task at hand. This applies to every form of PHI - paper charts, electronic records, verbal discussions, and faxed documents.
- Security Rule (45 CFR Part 164, Subpart C) - Requires administrative, physical, and technical safeguards to protect electronic PHI (ePHI). For medical practices, this covers EHR systems, patient portals, lab interfaces, billing software, email, cloud backups, and any networked device that stores or transmits patient data. The Security Rule is where most enforcement actions begin, because it requires a documented security risk analysis that many practices have never completed.
- Breach Notification Rule (45 CFR Part 164, Subpart D) - You must notify affected patients within 60 days of discovering a breach of unsecured PHI (§164.404). Breaches affecting 500 or more people must also be reported to HHS and local media (§164.406, §164.408). Medical practices need a documented incident response plan that covers breach detection, the four-factor risk assessment under §164.402, and notification timelines so the 60-day window is never missed.
PHI in Medical Practices
Protected Health Information (PHI) in medical practices includes patient intake forms, medical histories, clinical notes, lab results, diagnostic imaging, prescription records, insurance claims, appointment schedules, and billing data. Any information that identifies a patient and relates to their health condition, treatment, or payment for care counts as PHI under 45 CFR §160.103. This also includes information patients share through a patient portal, over the phone, or via text message.
Electronic health records (EHR/EMR) are the central repository of ePHI for most practices. The EHR must be configured with unique user IDs for every staff member, automatic session timeouts, audit logging that tracks who viewed or modified each record, and encryption for data at rest and in transit. Shared logins are a common violation - they make audit logs useless and remove individual accountability. The EHR vendor must sign a Business Associate Agreement per §164.308(b)(1) before any PHI is stored in or transmitted through their system.
Patient portals that allow patients to view records, message providers, or schedule appointments must use encrypted transmission (TLS/SSL), strong authentication, and role-based access controls. The portal vendor needs a BAA, and the practice needs documented procedures for how staff assist patients with portal access and how portal-related security incidents are handled.
Connected medical devices - diagnostic equipment, remote monitoring tools, vital sign monitors, and any device integrated with the EHR - create, transmit, or store ePHI and fall under the Security Rule. These devices must be included in the practice's risk analysis, covered by facility access controls per §164.310(a), and their vendors must sign BAAs. Many practices overlook networked devices during their risk assessment, which creates undocumented gaps.
Required HIPAA Compliance Steps
These six steps apply to every medical practice that is a covered entity. Each ties to a specific CFR requirement and carries its own enforcement risk if left undone.
- Security Risk Analysis (SRA) - Required under §164.308(a)(1)(ii)(A). Must identify threats and vulnerabilities to all ePHI your practice creates, receives, stores, or sends. A documented risk analysis is the single most common missing item when OCR investigates medical practices. It is also the foundation for every other compliance step - without it, you cannot prioritize what to fix first.
- Gap analysis and remediation plan - Compare current safeguards against the full set of requirements in §164.308 (administrative), §164.310 (physical), and §164.312 (technical). A structured gap analysis ties each finding to the CFR rule it falls under, ranks issues by risk level, and produces a remediation plan with clear deadlines and ownership.
- Written policies and procedures - Required under §164.316(a). Must cover privacy, security, breach notification, and workforce conduct tailored to your practice's actual operations. Medical-practice-specific policy templates help practices avoid vague language and map policies to real workflows like patient check-in, lab result handling, prescription management, and records requests.
- Workforce training - Required under §164.308(a)(5)(i). Every person with PHI access - physicians, nurses, medical assistants, front desk staff, billing personnel, and IT support - must receive HIPAA training at hire and whenever policies change. Training records (date, topics, attendees) must be retained for six years per §164.530(j). OCR asks for these records in nearly every investigation.
- Business Associate Agreements - Required under §164.308(b)(1). Must be signed with every entity that handles PHI on behalf of the practice: EHR vendors, billing services, clearinghouses, IT providers, cloud storage vendors, shredding companies, answering services, and any other third party with PHI access. A BAA management process ensures no vendor is missed and agreements stay current.
- Documentation retention - HIPAA requires compliance records to be kept for six years per §164.530(j). This includes all policies, training records, risk assessments, BAAs, incident logs, and any written decisions about addressable implementation specifications. If you cannot produce these documents during an investigation, OCR treats it as a gap regardless of what you actually did.
Common HIPAA Compliance Gaps in Medical Practices
The most common gap is the missing or incomplete Security Risk Analysis. Many practices either have never done one, or completed a checklist-style assessment years ago that does not meet the standard OCR expects. Other frequent findings include:
- Shared EHR login credentials among staff, which violates the unique user ID requirement and makes audit trails meaningless.
- No BAAs with IT vendors, cloud backup providers, or answering services that handle PHI.
- Outdated policies that reference old systems or workflows and have not been reviewed since they were first written.
- Missing or incomplete training records - staff were trained but the practice has no records to prove it.
- Workstations in shared areas without automatic logoff or privacy screens, exposing ePHI to unauthorized viewing.
- No documented incident response procedure, so when a potential breach happens the practice does not know the required steps or timelines.
Multi-provider groups and practices with multiple locations face added challenges when building uniform policies across sites with different EHR systems, staffing levels, and physical layouts. A gap analysis at the organizational level is the right starting point before standardizing policies across locations.
HIPAA Regulatory Standards for Medical Practices
Key federal standards that define HIPAA duties for medical practices. Practices in states with additional health privacy laws should also review California HIPAA compliance requirements as an example of how state rules can layer on top of federal requirements.
| Standard | Key Requirements |
|---|---|
| 45 CFR §164.308 | Administrative safeguards: risk analysis, workforce training, access management, contingency planning, and security incident procedures. |
| 45 CFR §164.310 | Physical safeguards: facility access controls, workstation use and security, device and media controls for any hardware containing ePHI. |
| 45 CFR §164.312 | Technical safeguards: unique user IDs, emergency access procedures, automatic logoff, audit controls, integrity controls, and transmission security. |
| Privacy Rule (Subpart E) | Patient rights to access, amend, and receive an accounting of disclosures of their PHI. Requires a Notice of Privacy Practices and minimum necessary use standards. |
| Breach Notification (Subpart D) | Notification to affected individuals within 60 days, HHS reporting, and media notification for breaches affecting 500+ people. |
| Business Associate Contracts | Written BAAs required with every vendor that creates, receives, maintains, or transmits PHI - including EHR, billing, IT, cloud, and shredding services. |
Medical Practice HIPAA FAQ
How long does it take a medical practice to become audit-ready?
Most practices see meaningful progress in 30 to 60 days. The timeline depends on the size of the practice, the number of systems handling ePHI, and how many gaps the initial risk analysis turns up. Practices that complete the security risk analysis first and address high-priority findings right away often reach a defensible compliance posture within that window. The key is starting with the SRA, because it sets the remediation priority for everything else.
What EHR access controls does HIPAA require?
HIPAA's Technical Safeguard rules at 45 CFR §164.312 require unique user IDs for every person who accesses ePHI, automatic logoff after a period of inactivity, audit controls that log who accessed what and when, and encryption for data both in transit and at rest. Most EHR platforms support these controls out of the box, but they need to be configured correctly and reviewed on a regular basis. A common gap is shared login credentials among staff, which violates the unique user ID requirement and makes audit logs useless for tracking individual access.
How do we secure a patient portal for HIPAA?
Patient portals must use encrypted transmission (TLS/SSL), strong authentication such as multi-factor login, and role-based access controls. The portal vendor must sign a BAA before any PHI passes through their system. You also need documented procedures for how staff assist patients with portal access, how you handle portal-related complaints, and what happens if the portal experiences a security incident. If the portal stores messages, lab results, or appointment records, all of that data is ePHI and falls under the Security Rule.
Do connected medical devices create HIPAA duties?
Yes. Any device that creates, receives, transmits, or maintains ePHI is in scope for the HIPAA Security Rule. That includes connected diagnostic equipment, remote patient monitoring tools, wearables integrated with your EHR, and bedside devices that record vitals. Vendors providing those devices often need a BAA, and the devices themselves must be included in your facility access controls as required by 45 CFR §164.310(a). Many practices overlook networked devices during their risk analysis, which creates an undocumented gap that OCR can flag.
What is required when a staff member with PHI access leaves?
HIPAA requires that access to PHI be terminated promptly when employment ends, as part of the workforce clearance and termination procedures under 45 CFR §164.308(a)(3)(ii)(C). That means revoking EHR credentials, email access, VPN access, and any system where the employee could reach PHI. Physical items like keys, badges, and mobile devices with PHI access must also be recovered. Document every step taken and the date it was completed. Include access revocation in your standard offboarding and incident management procedures so nothing gets missed.
Does HIPAA apply to paper records in medical practices?
Yes. The Privacy Rule covers all PHI regardless of format, and the Security Rule's physical safeguard requirements under §164.310 apply to paper charts, printed lab results, prescription pads, and any physical media containing PHI. Practices must implement workstation use policies (§164.310(b)), device and media controls (§164.310(d)), and documented disposal procedures such as cross-cut shredding. Common gaps include printers in shared hallways, unlocked file cabinets, and sign-in sheets that expose patient names and appointment reasons in waiting areas.
How often must medical practice staff complete HIPAA training?
HIPAA requires training at hire and whenever policies or procedures change, per §164.308(a)(5)(i). Annual refresher training is not technically required by the rule, but it is considered best practice and is the standard OCR expects to see during investigations. Training records must include the date, topics covered, and each attendee's name, and must be retained for at least six years per §164.530(j). Missing training records is one of the most common findings in OCR investigations.
HIPAA Enforcement for Medical Practices
The Office for Civil Rights (OCR) enforces HIPAA for all covered entities, including medical practices of every size. Civil monetary penalties range from $145 to $2,190,294 per violation category per year under 45 CFR §160.404, with four penalty tiers based on the level of culpability. OCR has investigated medical practices for complaints involving unauthorized disclosures, missing risk assessments, failure to provide patients access to their records within 30 days per §164.524(b)(2), and insufficient safeguards on electronic systems. The most common trigger for an investigation is a patient complaint or a breach report, and the first document OCR often requests is the security risk analysis.
Chuck Weiselberg, Certified HIPAA Professional (C.H.P.). Zero client fines. Zero failed audits.
“One Guy Consulting is super easy to work with. I actually look forward to my implementation meetings for HIPAA.” — Samantha M.
Need HIPAA Support for Your Medical Practice?
One Guy Consulting works with solo physicians, multi-provider groups, urgent care clinics, outpatient surgery centers, and specialty practices. We are based in Queens, New York and work remotely with practices nationwide; see HIPAA compliance services near you.