Hipaa compliance services exist because HIPAA is genuinely complex legislation that most healthcare providers are expected to follow without practical guidance on what it means for their specific practice. This guide covers what is hipaa compliance, who it applies to, what hipaa compliance services help with in practice, and what happens when practices are not compliant.
What HIPAA is and what it covers
HIPAA is a US federal law passed in 1996 establishing national standards for the protection of patient health information. The privacy and security provisions are primarily enforced through two rules — the Privacy Rule and the Security Rule — both relevant to any healthcare practice handling patient records.
The Privacy Rule governs how protected health information (PHI) may be used and disclosed. The Security Rule governs specifically how electronic PHI (ePHI) must be protected. Understanding what is hipaa compliance in practice means understanding both rules and what each one requires your practice to do, document, and maintain.
Who HIPAA applies to
Covered Entities
A Covered Entity is a healthcare provider that transmits health information electronically as part of a covered transaction. This includes virtually every medical and dental practice that submits electronic insurance claims, uses electronic prescribing, or stores patient records digitally.
Physicians, dentists, therapists, pharmacists, chiropractors, and optometrists are all subject to the same HIPAA standards. HIPAA requirements for dentists and other healthcare providers apply equally to both small and large practices, regardless of size.
Business Associates
A Business Associate is any vendor or contractor that creates, receives, maintains, or transmits Protected Health Information (PHI) on behalf of a Covered Entity. Common examples include EHR vendors, medical billing companies, cloud storage providers, and IT support services.
Every Business Associate must sign a Business Associate Agreement (BAA) with each Covered Entity they support. Missing or incomplete BAAs are among the most common compliance issues identified during OCR investigations, making them a critical part of any HIPAA compliance program.
What HIPAA requires from a small practice
Risk analysis
A documented risk analysis is the foundational Security Rule requirement. It must identify every location where ePHI exists, every threat to that data, and the likelihood and impact of each threat. It must be reviewed annually and after significant environmental changes. Most small practices have never conducted one.
Administrative safeguards
Written policies and procedures governing how your practice manages patient data. Designating a HIPAA compliance officer, documenting workforce training, establishing access management procedures, and maintaining incident response procedures.
Technical safeguards and hipaa it requirements
The technical controls on systems accessing ePHI. Unique user accounts, automatic session timeouts, encryption of ePHI in transit and at rest, audit logs recording who accessed what and when, and emergency access procedures. Hipaa it requirements apply to every system and device in your practice handling patient records — not just your EHR.
Physical safeguards
Workstation use policies — screens not visible to patients, automatic timeout. Device and media disposal procedures — destroying hard drives when retiring computers. Facility access controls for areas where ePHI is stored or accessed.
The hipaa compliance checklist most practices are missing
No documented risk analysis
Required by the Security Rule. Without it every other compliance effort lacks a foundation and OCR treats its absence as a significant violation.
Missing Business Associate Agreements
Every vendor accessing patient data must have a signed BAA. This includes EHR vendors, billing companies, email providers, and cloud storage services.
Shared login credentials
Every staff member must have a unique user account. Shared logins make audit trails impossible and are a direct Security Rule violation.
No workforce training records
Training must be documented with dates and completion confirmation. Verbal training that cannot be proven never happened from OCR’s perspective.
ePHI stored without encryption
Laptop hard drives, USB drives, and cloud storage containing patient records must be encrypted. Loss of unencrypted devices is a reportable breach.
No breach response procedure
Every practice must have a documented process for identifying, containing, and reporting a breach. The clock to notify HHS starts the moment you discover it.
Frequently asked questions
Does a sole practitioner need full HIPAA compliance?
Yes. A solo physician, dentist, therapist, or other provider who transmits health information electronically is a Covered Entity. The scale of the compliance program can be proportionate to your practice size, but the legal obligations are identical to those of a large health system.
What triggers an OCR HIPAA investigation?
Most commonly: a breach notification submitted by the practice, a complaint filed by a patient, or a random OCR audit. Once an investigation begins, OCR requests evidence of your compliance program. Practices with no documentation are in a very difficult position.
How much do HIPAA violations cost in practice?
Fines range from $100 to $50,000 per violation, with a maximum of $1.9 million per violation category per year. A single breach affecting 500 or more patients requires notification to the HHS Wall of Shame — a public list. Beyond fines, OCR can require corrective action plans that involve years of monitoring and reporting.
How often does hipaa compliance need to be reviewed?
The risk analysis and all associated policies must be reviewed at least annually. They must also be updated whenever significant changes occur — new staff, new systems, office moves, or changes to how patient data is used. Annual review is the minimum requirement under HIPAA.
Can HIPAA compliance services help a practice that has already had a breach?
Yes. If your practice has experienced a breach and reported it, OCR typically expects evidence of corrective action. Engaging a compliance service to build a proper program after a breach demonstrates good faith and can significantly reduce the penalty assessment during an investigation.