Building a real HIPAA compliance program: Privacy, Security, Breach Notification.
A poster in the break room and a signed acknowledgment form in a new hire's file is not a HIPAA program — it's the appearance of one. A real program is documented, current, and would survive an actual OCR inquiry: a risk analysis on file, a BAA for every vendor that touches PHI, and workforce training that happened on a schedule, not once, years ago, for people who've since left. Here's what the three rules actually require and what a program that would hold up looks like.
HHS Office for Civil Rights enforces the Privacy, Security and Breach Notification Rules. Regulatory text is at 45 CFR Parts 160, 162 and 164.
Key takeaways
- There's no small-practice exemption. The Privacy, Security and Breach Notification Rules apply the same way to a solo provider as a hospital system — only program complexity scales with size.
- A documented Risk Analysis is a Security Rule requirement, not optional best practice. It has to identify real risks to ePHI confidentiality, integrity and availability, in writing.
- Every vendor that touches PHI needs a signed BAA on file — billing company, clearinghouse, EHR vendor, cloud storage, IT support, all of them.
- Billing is one of the highest-risk PHI touchpoints in the practice — PHI moves between the practice, the clearinghouse and the payer on every single claim.
The three rules, and why none of them scale down for size
Every HIPAA-covered entity — a solo provider included — is governed by three baseline rules enforced by the HHS Office for Civil Rights (OCR). None of them carries a small-practice exemption; the regulatory text at 45 CFR Parts 160, 162 and 164 applies the same substantive requirements regardless of how many providers or employees a practice has.
| Rule | What it requires |
|---|---|
| Privacy Rule | National standards protecting PHI, limits and conditions on its use and disclosure, and individual rights including timely access to one's own records. |
| Security Rule | Administrative, physical and technical safeguards for electronic PHI (ePHI), including a documented Risk Analysis of potential risks and vulnerabilities to its confidentiality, integrity and availability. |
| Breach Notification Rule | Requires covered entities and business associates to provide notification following a breach of unsecured PHI. |
What actually scales with practice size is the complexity of the program required to satisfy these three rules — more staff means more training records to keep current, more systems means a larger risk analysis surface, more locations means more physical safeguards to document. But the underlying obligation is identical whether the covered entity is a two-provider family practice or a multi-site health system.
The documented Risk Analysis: what it actually has to contain
The Security Rule requires a documented Risk Analysis, and "documented" is the operative word — an informal sense that "we're probably fine" doesn't satisfy the requirement, and it's the first thing an OCR inquiry asks to see. A real risk analysis identifies where ePHI lives across the practice's systems (EHR, practice management system, email, cloud storage, backup systems), the realistic threats and vulnerabilities to each, and the safeguards currently in place versus the gaps that remain. It should be reviewed and updated whenever a system changes — a new EHR, a new cloud vendor, a new remote-access tool — not filed away once and forgotten.
A risk analysis that was done years ago, before the practice added telehealth or switched EHR vendors, doesn't reflect the practice's actual current risk profile and won't hold up as evidence of an active program.
The BAA inventory: every vendor touching PHI needs one
A Business Associate Agreement is a signed contract that obligates any vendor handling PHI on the practice's behalf to protect it under HIPAA's rules. It has to be on file before that vendor ever has access to PHI — not requested after the fact once someone notices the gap.
- 1Billing company or RCM partner. Handles claims, remittances and patient billing data containing PHI on every claim it touches.
- 2Clearinghouse. Routes claims between the practice and every payer, seeing PHI on every transaction that passes through.
- 3EHR vendor. Stores and processes the clinical record itself, the largest single repository of PHI most practices have.
- 4Cloud storage and backup providers. Any service storing scanned documents, backups, or exports that include PHI.
- 5IT support. Any vendor with remote access to systems that store or process PHI, even for routine maintenance.
The inventory itself should be a simple, maintained list — vendor name, what PHI they touch, BAA signed date, and a renewal or review date — not scattered signed PDFs nobody can locate quickly if OCR or a cyber-insurance underwriter asks for them.
Workforce training: at hire, periodically, and when things change
Training isn't a one-time event completed during onboarding and never revisited. A real program trains workforce members at hire, on a periodic cadence thereafter, and again whenever policies or systems change materially — a new EHR rollout, a new remote-work policy, a new breach-response procedure.
- Keep a written risk analysis current and update it after every material system change.
- Maintain a single BAA inventory covering every vendor that touches PHI, with renewal dates tracked.
- Train every new hire on HIPAA before they touch PHI, not after their first week.
- Re-train the whole workforce periodically and immediately after any policy or system change.
- Don't assume a small practice is exempt from any of the three rules — it isn't.
- Don't let a vendor touch PHI before a signed BAA is on file.
- Don't treat a years-old risk analysis as still valid after switching EHR or adding telehealth.
- Don't rely on a single onboarding training session as the whole program.
Why billing is one of the highest-risk PHI touchpoints
Claims processing moves PHI across more hands, more systems, and more transmissions than almost any other function in a practice. A single claim travels from the practice's own system to a clearinghouse, then to the payer, and back again with remittance data — and a billing company or RCM partner sits in the middle of that flow for every claim it works. Every one of those points is a place PHI could be exposed if a safeguard fails or a vendor isn't under a signed BAA, which is exactly why the BAA inventory and the risk analysis both need to treat the billing workflow as a first-priority area, not an afterthought behind clinical systems.
Run the BAA inventory as a standing agenda item at whatever cadence the practice already meets on operations — quarterly is common. It's the single easiest way to catch a new vendor that started touching PHI without anyone remembering to get the agreement signed first.
Not sure your HIPAA program would hold up to an inquiry?
We help practices build the risk analysis, BAA inventory and training cadence that make up a real program — not just the paperwork that looks like one.
Frequently asked questions
Does a solo or two-provider practice really need a full HIPAA program?
Yes. The Privacy Rule, Security Rule and Breach Notification Rule apply to every HIPAA-covered entity regardless of size — there is no small-practice exemption written into the regulation. What changes with practice size is the complexity of the program needed to satisfy the requirements, not whether the requirements apply at all. A solo practice still needs a documented risk analysis, signed BAAs with every vendor touching PHI, and a workforce training record.
Who enforces HIPAA and where's the official source?
The HHS Office for Civil Rights (OCR) enforces the Privacy, Security and Breach Notification Rules. The official regulatory text is at 45 CFR Parts 160, 162 and 164, and HHS maintains professional guidance at hhs.gov/hipaa/for-professionals. That's the source to check directly rather than relying on any third-party summary, including this one, for anything you're relying on to make a compliance decision.
Why is billing specifically called out as high-risk for PHI exposure?
Because claims processing moves PHI across more hands than almost any other function in the practice — from the practice to a clearinghouse to the payer, and often to a billing company in between. Every one of those touchpoints is a place PHI could be exposed, and every vendor in that chain that touches PHI is required to have a signed Business Associate Agreement on file before it ever sees the data.
Confirm before you rely on this. Regulatory requirements, software options and best practices change. The process information on this page reflects standard industry practice as of August 2026 and is provided for general education — verify current requirements directly with HHS OCR, your accountant, or the relevant vendor before relying on it.