
How to Offer HIPAA Compliance as a Managed Service
Healthcare clients ask their IT provider about HIPAA sooner or later. This is what the answer has to include if it is going to be a service rather than a favor.
Day-to-day HIPAA compliance for practices that need the work done — risk analysis, BAAs, training, audits, policies, and the operational discipline behind each.
75 articles
Compliance Operations covers the recurring, evidence-producing work that keeps a practice in compliance year over year. It's the part of HIPAA that auditors actually examine — risk analyses with documented methodology, training records with completion timestamps, BAA inventories with current signatures, policy revisions tied to regulatory changes, and incident logs with response timelines. The articles below are written for the office manager, compliance officer, or solo practitioner who has to do the work, not just describe it.

Healthcare clients ask their IT provider about HIPAA sooner or later. This is what the answer has to include if it is going to be a service rather than a favor.

Testosterone is a Schedule III controlled substance. That single fact changes the entire compliance overlay for HRT/TRT clinics — DEA registration, prescription monitoring program reporting, state board scrutiny of telemedicine prescribing — none of which traditional HIPAA software was built to address.

GLP-1 clinics emerged as one of the fastest-growing independent healthcare categories in 2024-2026. The compliance workflow is genuinely new — no prior generation of HIPAA software anticipated the specific combination of compounding pharmacy supply, telehealth-first patient acquisition, state board scrutiny, and Schedule III-adjacent monitoring.

Dermatology practices run two compliance programs at once. The medical-dermatology side has biopsy chain-of-custody, dermatopathology lab BAAs, and skin cancer disclosure workflows. The cosmetic side adds photo PHI, before/after marketing, and social media exposure. Most platforms handle one side and ignore the other.

Psychiatric practice has the most heavily-layered confidentiality regime in U.S. healthcare. HIPAA is the floor — psychotherapy notes get separate handling, substance-use treatment has its own federal rule, state mental-health statutes overlap, and court-ordered disclosures are routine. Generic compliance platforms handle one of these well, sometimes two. None handle all four.

OCR doesn't ask whether you trained your staff. OCR asks for the documentation that proves you trained your staff, on what content, when, with what acknowledgment. Every practice has training. Very few practices have the documentation that survives an inquiry.

Concierge medicine pays a premium for unhurried, available, personal care. That premium attracts patients who are also higher-value targets for PHI theft — and the compliance exposure scales with the patient demographic, not just the practice volume.

Pediatric practices have a HIPAA exposure profile that adult-focused compliance software wasn't built for — the patient often cannot legally consent, the parent usually but not always controls access, the immunization registry adds disclosure complexity, and at some age the minor's privacy interests start mattering. The software needs to handle all four.

A HIPAA compliance plan is not a single document — it's the framework that organizes every other compliance document the practice maintains. Most templates online produce a list. The plan should produce a system.

Direct primary care eliminates the insurance company from the workflow but adds a layer of long-term continuous patient communication that traditional fee-for-service practices don't have. The HIPAA exposure shifts from claim transmission to message stream — and the compliance software needs to follow.

Most HIPAA risk assessment templates online are reformatted versions of the HHS SRA tool with the sharp edges sanded off. They satisfy a checkbox audit. They don't satisfy an investigator who reads the document and asks follow-up questions. This is the template format that does.

Urgent care runs a different operational model than family practice — same regulatory framework, very different exposure surface. The 200-patient day, walk-in registration without prior chart, and multi-clinician rotation create HIPAA failure modes that vendors built for primary care don't anticipate.

A free HIPAA policy template will satisfy a checkbox audit. It will not survive an actual OCR inquiry. The difference between the template and the policy is the operational detail — who specifically does what, when, with which system. That difference is where most independent practices have their actual exposure.

Every HIPAA compliance vendor sells the same metric: a green bar creeping toward 100. It answers exactly one question — how much of a form did you fill out — and none of the questions a practice owner actually needs answered.

Most telehealth platform comparisons rank by video quality. None of them quite live where the compliance work actually happens — in the BAA, the recording controls, the integration BAA chain, and the audit log retention. This is the comparison done the other way around.

HIPAA was designed for institutions. It gets applied unchanged to a solo dentist with no compliance department, no security team, and no dedicated IT staff. The failure mode this produces is quiet, and the industry has been solving the wrong problem.

The moment a healthcare website accepts patient information, it stops being a brochure and becomes part of the ePHI environment. Here is what most practices miss.

Most OneDrive HIPAA findings are not about the BAA. The BAA is signed. The findings are about the seventeen configuration toggles Microsoft leaves wide open by default. This is the step-by-step lockdown an independent practice should run within the first week of any Microsoft 365 deployment.

The patchwork of local voluntary self-disclosure policies is officially gone. Under DOJ's unified Corporate Enforcement Policy, an independent practice that receives an internal compliance report has approximately 120 days to investigate, decide whether to self-disclose, and act — before a whistleblower's external report closes the highest-value cooperation credit forever.

Most HIPAA platforms were built for a dental office. A med spa has the same regulatory exposure plus four others — consent for cosmetic procedures, photographic PHI, social-media marketing involving identifiable patients, and DEA-adjacent injectable tracking. The software that fits a dental office only covers half the surface area.

A pricing page is the easiest part of a vendor site to read and the hardest to interpret. Two platforms can include or exclude the same modules at very different prices, and the practice finds out which at renewal.

Three independent practices on the same block can pay $0, $2,400, and $18,000 for the same HIPAA risk assessment requirement. None of them are wrong. They are buying different things — and most are over- or underbuying without realizing it.

COVID-era enforcement discretion ended May 2023. Every telehealth session since must comply with HIPAA in full. This guide covers platforms, home offices, recordings, multi-state practice, and the complete compliance path.

Optometry practices face structurally unique HIPAA challenges: the retail-clinical access boundary, optical lab BAA gaps, dual-billing insurance coordination, and vision-medical record crossover. Here's the complete guide.

Eight criteria, three points each, applied to whatever you are evaluating. Derived from the proposed Security Rule and OCR's enforcement record — and the proposal is still a proposal, which the scoring says out loud.

Physical therapy practices face specific HIPAA risks most guides never address: home visit ePHI, PRN staff access gaps, workers' comp records, and exercise app BAAs. Here's the complete compliance path.

Salesforce covers HIPAA by named service rather than by edition. Sales Cloud, Health Cloud, Service Cloud and Marketing Cloud Engagement are all on the covered list — what matters is whether your BAA includes the service you are actually using, and that is where most practices create exposure.

Twilio can be HIPAA compliant on its HIPAA-eligible product set with a signed BAA, available only on Security or Enterprise Edition. SendGrid is not eligible and Twilio will not sign a BAA for it.

HubSpot can be HIPAA compliant on Enterprise tiers with a signed BAA. Lower plans are not HIPAA-eligible. Here is what is covered, what is not, and how to configure it.

ServiceNow will enter into a BAA once you tell Sales Support you intend to store ePHI and request one — no edition or tier gate appears in the controlling document. The Healthcare and Life Sciences product line adds healthcare-specific data models but is not what confers coverage. Standard tenants are not HIPAA-eligible by default.

OneDrive for Business is in scope under Microsoft's HIPAA offering, with the BAA attaching through the DPA. Personal OneDrive and home subscriptions are not. The configuration is where exposure gets created.

The widely repeated claim is that Notion carves AI out of its BAA. Notion's own documentation says the opposite. Here is what is actually excluded, and the administrator setting that decides whether the coverage holds.

Ten cloud storage providers that will sign a BAA, ranked by fit for independent healthcare practices. What each is built for, where each falls short, and the configuration trap behind most cloud breaches.

Seven practice management platforms used by independent practices, ranked by fit. Each handles scheduling, billing, and patient flow differently — and each leaves a different slice of HIPAA work back to the practice.

Chiropractic practices face specific HIPAA challenges most guides never address: personal injury records, open treatment environments, and high-volume billing vendor ecosystems. Here's the complete path to compliance.

Therapy practices handle the most sensitive category of protected health information. This guide covers psychotherapy notes, telehealth BAAs, 42 CFR Part 2, and the step-by-step path to full compliance.

OCR's enforcement data is a public dataset of what actually goes wrong. These are the 10 most-frequently cited violation categories — and the operational gaps behind each one.

Free Gmail fails HIPAA requirements. Google Workspace paid plans with a BAA and the right configuration can work — here is the full breakdown.

Google Workspace supports HIPAA compliance on paid plans with a BAA — but the default settings leave gaps. Here is the full configuration guide.

Dropbox offers HIPAA-eligible plans for healthcare — but only on Business tiers with a BAA. Here is what to configure before storing patient data.

Slack can carry PHI, but coverage does not follow the contract. Salesforce's BAA Restrictions require an enterprise plan, the HIPAA Enabled SKU, and the specific organization or workspace to be designated — coverage does not extend to every workspace you own.

Vendors sell HIPAA certification. The government does not offer one. Understanding the difference protects your practice from false confidence.

Faxing gets a pass under HIPAA that email does not — but cloud fax, online fax services, and email-to-fax gateways create compliance obligations most practices overlook.

Every HIPAA-covered entity must designate a privacy officer and a security officer. For independent practices, that is often one person wearing both hats.

AWS provides HIPAA-eligible infrastructure — Patient Protect runs on it. But using AWS does not automatically make your practice compliant.

HIPAA does not prohibit voicemail. But voicemail messages containing PHI must follow minimum necessary rules, and voicemail systems must meet security requirements.

Eight EHR platforms that sign BAAs and serve independent practices, ranked by fit. The compliance gap most practices miss: an EHR's BAA is the floor, not the ceiling.

There is no government agency that issues a HIPAA compliant stamp. HIPAA compliance is a continuous obligation. This guide covers the ten steps to achieve it and the system to maintain it.

OCR investigators don't fish for sophisticated vulnerabilities. They look for predictable operational gaps. These are the ten signs they find most often — visible to the practice long before the audit notice arrives.

The Security Rule's technical safeguards are the controls that actually protect ePHI inside your systems. This is the complete reference — every standard, every implementation specification, and what each one means for your practice.

A signed BAA is HIPAA's required floor — but most BAAs that practices sign protect the vendor far more than the practice. These are the six clauses that separate a real contract from a checkbox.

Docusign acts as a business associate for eSignature documents containing PHI, with a signed BAA. Its pricing comparison places HIPAA support through BAA behind Contact sales, not the self-service plans.

HIPAA training is not a video someone watches once. It is a workforce obligation that must be relevant, operational, and documented.

OCR investigations start somewhere. Knowing the triggers that begin the process — and the inputs the practice controls — is the difference between a managed program and a reactive one.

Notion can hold PHI on the Enterprise plan, with the BAA signed and HIPAA compliance enabled in workspace settings — and Notion states the AI features are covered too. Most practices using Notion are on plans that do not qualify.

QuickBooks Online states it is not compliant with the HIPAA privacy standards and recommends against entering individually identifiable health information. Billing data is where PHI hides.

Square publishes a HIPAA BAA that applies by use rather than signature. Its scope clause names Appointments and Invoices, and expressly excludes Square Buyer Services.

Business associate agreements are one of the most commonly violated HIPAA requirements. This checklist covers what a BAA must include, which vendors need one, and how to manage the entire lifecycle.

The HIPAA risk analysis is the single most-cited gap in OCR enforcement. Most independent-practice risk analyses fail in one of seven predictable ways — all visible before any audit.

Apple's iCloud Terms of Service prohibit using it with PHI. iCloud, iMessage, FaceTime, and Apple Health are all off-limits for PHI.

Mailchimp cannot be used for healthcare email marketing involving PHI. No published BAA offering was found on any Mailchimp plan — Free, Essentials, Standard or Premium.

HIPAA compliance checklists run to hundreds of items. The eleven below are the ones independent practices most often skip — and the ones that surface most often in OCR enforcement actions.

OCR enforcement isn't random. Eight patterns recur across the public settlement record — and each one is a preview of the audit findings a similar practice can expect.

You don't need a law degree or an IT department to be HIPAA compliant. You need three things, one afternoon, and a plan that doesn't make your head spin.

HIPAA gives patients specific, enforceable rights over their health information. Most independent practices comply with some of them and overlook the rest.

Most practices think physical security means locking the server room. It actually means controlling every point where someone could see, touch, or walk away with patient data.

Every device that touches ePHI is a potential breach vector. This step covers encryption, mobile device management, BYOD, patching, and the endpoint controls that keep patient data off the dark market.

If everyone in your practice can access every patient record, you do not have access controls. You have a breach waiting for a trigger.

Before you can build a compliant practice, you need to know exactly what HIPAA requires of you — and that depends entirely on your entity classification.

A risk assessment is not a form you fill out once a year. It is a living map of every threat to the patient data your practice holds — and the foundation of every HIPAA safeguard you implement.

Policies without enforcement are just paper. This step covers how to designate HIPAA officers, build policies that reflect real operations, and train your workforce to follow them.

Most HIPAA checklists give you boxes to check. This one gives you a sequence to follow — from risk assessment through incident response — so your practice builds compliance that holds up under scrutiny.

If your marketing agency collects patient inquiries through web forms, they are handling PHI. Most practices have no BAA in place to cover this.

Having an EHR, a privacy policy, and annual training does not make you HIPAA compliant. Here is what OCR actually looks for — and why most practices fall short.

Patients are paying attention to how their data is handled. Practices that treat compliance as a trust-building tool — not just a legal requirement — outperform on retention, reputation, and referrals.
Related references
147+ provisions mapped to platform features
10-minute readiness scan, no login
How to compare HIPAA platforms
When HIPAA applies to direct primary care + 5-step compliance path
Telehealth-pharmacy stack, state consumer-health law overlay