Most small practices believe one of two wrong things about HIPAA. Either "we're too small for anyone to care," or "our EHR vendor handles it." Both get practices fined.
The Office for Civil Rights settles cases with small and solo practices every year, often after something mundane: a stolen laptop, a misdirected fax, an employee snooping on a neighbor's chart, a complaint from an unhappy patient. And your EHR being HIPAA-compliant covers exactly one system. It says nothing about your email, your file shares, your old server in the closet, or the billing service you never signed an agreement with.
Here is what actually matters, sized for a practice, not a hospital system.
The Document OCR Asks for First
When OCR investigates, their first request is almost always the same: show us your most recent Security Risk Assessment (SRA).
The SRA is a written analysis of where electronic patient data lives, what could go wrong, and what you're doing about it. It is explicitly required by the Security Rule, it's the thing practices most commonly don't have, and "we never did one" converts a warning letter into a settlement. In OCR's published enforcement actions, a missing or stale risk assessment shows up more than any other single failure.
If your practice has never done one, or the last one is gathering dust from your EHR attestation years ago, that's the gap to close first. Not the fancy firewall. The document.
The Minimum Viable HIPAA Program
Beyond the SRA, a defensible small-practice program comes down to six things:
1. Business Associate Agreements with everyone who touches PHI. Your billing company, IT provider, EHR vendor, transcription service, cloud storage, shredding company, answering service. A missing BAA is a violation by itself, even if nothing ever goes wrong. Most practices we assess are missing at least two.
2. Access control that matches reality. Each employee gets their own login (no shared accounts), with access scoped to their job. Terminated employees lose access the same day. MFA on email and anything reachable from the internet. Snooping by insiders is one of the most common small-practice violations, and unique logins are what make it detectable and provable.
3. Encryption on anything that leaves the building. Laptops, phones, backup drives. A stolen encrypted laptop is a non-event. A stolen unencrypted one is a reportable breach with patient notification letters and an OCR file. Turning on BitLocker costs nothing.
4. Training, documented. Short annual training plus reminders, with a sign-in sheet or completion record. When an employee clicks a phishing link, the difference between "an employee mistake" and "a systemic failure" is whether you can show they were trained.
5. Backups you have actually tested. Ransomware against small healthcare is routine now, and OCR treats a ransomware incident as a presumed breach. Tested, separated backups are both your recovery plan and part of your compliance posture.
6. A one-page incident response plan. Who do you call, what do you preserve, when does the breach-notification clock start. The 60-day notification deadline does not pause while you figure out who's in charge.
What You Can Skip
Honesty matters here: a 10-provider practice does not need a full-time compliance officer, a SIEM, or a 300-page policy binder from a template mill. Bloated paperwork nobody follows is its own risk, because OCR asks whether you follow your policies. Short policies you actually live by beat impressive ones you don't.
The Annual Rhythm
HIPAA compliance for a small practice is not a project, it's a calendar:
- Once a year: refresh the SRA, run training, review who has access to what, test a backup restore
- When anything changes: new vendor gets a BAA before they touch data; new system gets added to the SRA
- Ongoing: patches applied, MFA enforced, departures offboarded same-day
That rhythm, documented, is what "compliant" looks like at small-practice scale. It's a few days of focused work per year, not a department.
Where We Fit
We run HIPAA Security Risk Assessments for small and mid-size practices: we inventory where PHI actually lives, assess against the Security Rule, and hand you a prioritized findings report with fixes scoped to your size and budget, then help implement them if you want the help. No 300-page binder, no enterprise theater.
If your practice can't put its hands on a current SRA today, that's the conversation to have before OCR or a ransomware crew makes the schedule for you.