Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect

HIPAA Compliance for Medical Practices

The HIPAA compliance and security operating system for independent medical practices. Your EHR manages records; it does not run your compliance program. Patient Protect maps every system that touches ePHI — portals, labs, e-prescribing, claims, fax, remote access — then runs the risk analysis, policies, training, vendor agreements, and audit evidence from one place.

Medical practices that electronically submit claims, check eligibility, request authorization, or conduct another adopted transaction are HIPAA covered entities. That describes the overwhelming majority of modern medical practices. The duties below are required; an EHR does not perform them for the practice.

HIPAA compliance is not optional for a covered independent medical practice.

If your practice is a HIPAA covered entity, it is required to maintain an active, documented compliance program — and if it performs covered functions as a Business Associate, it must implement the Security Rule and every other duty attaching to that role. The responsibility does not transfer to your EHR, IT company, consultant, insurance carrier, or software provider. Those partners can support the work; your practice remains responsible for completing it.

Watching one training video is not a compliance program. Downloading a policy template is not a compliance program. Signing one BAA is not a compliance program. HIPAA requires your practice to implement, maintain, and document the complete operating system behind each of those activities.

Your practice is required to do all of the following

  1. 01Conduct and document a Security Risk Analysis

    Identify every place electronic protected health information enters, moves through, or leaves the practice. Assess the systems, devices, people, vendors, locations, workflows, threats, and vulnerabilities that could compromise that information.

    45 CFR §164.308(a)(1)(ii)(A)

  2. 02Manage the risks the analysis uncovers

    Turn identified risks into a documented remediation plan. Assign responsibility, prioritize the work, implement safeguards, and preserve evidence showing how the practice responded.

    45 CFR §164.308(a)(1)(ii)(B)

  3. 03Designate Privacy and Security Officials

    Assign and document who is responsible for developing, maintaining, and enforcing the practice's privacy and security program. In a small practice, one person may perform both roles — but the responsibilities must still be assigned and documented.

    45 CFR §164.530(a) · §164.308(a)(2)

  4. 04Maintain written policies and procedures

    Document how the practice protects patient information, controls access, handles permitted disclosures, responds to incidents, enforces workforce accountability, and maintains required privacy and security safeguards.

    45 CFR §164.316(a) · §164.530(i)

  5. 05Train the entire workforce

    Train workforce members on the privacy policies relevant to their roles and maintain an ongoing security-awareness program. Preserve records showing who was trained, what the training covered, and when it was completed.

    45 CFR §164.530(b) · §164.308(a)(5)

  6. 06Identify and govern every Business Associate

    Determine which vendors and service providers create, receive, maintain, or transmit protected health information on the practice's behalf. Execute the required Business Associate Agreement before protected information flows and maintain the agreement as part of the practice's compliance record.

    45 CFR §164.502(e) · §164.308(b) · §164.504(e)

  7. 07Implement administrative, physical, and technical safeguards

    Control who can access patient information, secure the systems and locations where it is maintained, review activity, authenticate users, protect data integrity, and safeguard electronic transmission.

    45 CFR §164.308 · §164.310 · §164.312

  8. 08Protect patient privacy rights

    Maintain the required notices, authorization processes, complaint procedures, and workflows for responding to patient requests involving access, amendments, confidential communications, restrictions, and applicable disclosure accounting.

    45 CFR §164.520 · §164.524 · §164.526 · §164.522 · §164.528

  9. 09Prepare for incidents, outages, and breaches

    Maintain security-incident procedures, data backup, disaster recovery, emergency operations, mitigation, and breach-notification processes before an event occurs.

    45 CFR §164.308(a)(6) · §164.308(a)(7) · Subpart D

  10. 10Preserve proof that the work was completed

    Retain the assessments, risk decisions, policies, training records, official designations, BAAs, acknowledgments, incident records, and other documentation needed to demonstrate what the practice actually did.

    45 CFR §164.316(b) · §164.530(j)

The Security Risk Analysis is where the work begins.

The Security Rule requires an accurate, thorough assessment of the risks and vulnerabilities affecting every form of electronic protected health information your practice creates, receives, maintains, or transmits. This is commonly called a Security Risk Analysis, or SRA.

The federal government publishes its own Security Risk Assessment Tool for small and medium-sized practices. You are not required to use that particular tool. You are required to perform and document the underlying analysis.

Patient Protect provides its own guided SRA. It walks the practice through the assessment in plain language, identifies what is missing, and carries those findings into risk management, remediation, policies, tasks, and documentation — so the assessment ends with the problem assigned and resolved, not merely named.

A five-minute readiness quiz is not an SRA. Reviewing only your EHR is not an SRA. Reusing an old checklist that no longer reflects your systems, vendors, workforce, or workflows is not an SRA.

That includes our own free tool. The Patient Protect Score is a free exposure scan and a starting point. It is not your completed Security Risk Analysis, and we will not tell you it is.

What an independent medical practice’s Security Risk Analysis must cover

Independent medical practices often have the broadest technology and data surface: EHRs, portals, laboratories, e-prescribing, imaging, claims, referrals, fax, remote access, and dozens of vendors. The SRA must cover the whole environment — not merely the primary EHR.

  • The complete inventory of systems that create, receive, maintain, or transmit ePHI
  • EHR access, administrative privileges, audit logging, integrations, APIs, and patient-portal connections
  • Laboratory, imaging, e-prescribing, pharmacy, hospital, specialist, and referral data flows
  • Claims, eligibility, prior authorization, clearinghouse, billing, and payment workflows
  • Email, text, e-fax, forms, telehealth, call recording, voicemail, and patient messaging
  • Workstations, servers, laptops, tablets, phones, network equipment, remote access, cloud storage, and backup
  • Workforce access by role, location, employment status, and job responsibility
  • Every external organization that handles PHI on the practice's behalf

What the medical-practice compliance program must also address

  • Role-based access and unique user identification across clinical and administrative functions
  • Business Associate identification, agreement execution, oversight, and offboarding
  • Patient access, amendment, confidential-communication, restriction, and applicable disclosure-accounting workflows
  • Written sanction, complaint, mitigation, incident-response, contingency, and breach-notification procedures
  • Training grounded in the disclosure, communication, device, and workflow decisions the workforce actually encounters

An EHR manages medical records. It does not operate the practice's complete HIPAA compliance program.

What HIPAA actually looks like for medical practices.

The regulatory framework, the enforcement patterns OCR has historically cited, the non-HIPAA standards that apply, the gaps audits routinely surface, and the record-retention overlay — HIPAA’s six-year rule for compliance documentation, and the separate state law that governs how long clinical records must be kept.

Regulatory framework

Medical practices operate under HIPAA as covered entities through the full set of standard electronic transactions — 837 claims submission, 270/271 eligibility verification, 276/277 claim status, 278 referral certification and prior authorization, 835 remittance advice, 820 premium payment, and 834 enrollment. E-prescribing under NCPDP SCRIPT is a standard practices use but is not itself an adopted covered transaction. Medicare and Medicaid impose additional documentation requirements for reimbursement and quality reporting (MIPS, ACO programs, value-based-care frameworks). State medical practice acts govern record-keeping. The ONC HITECH meaningful-use legacy continues to shape EHR vendor compliance behavior even after the program transitioned to MIPS.

OCR enforcement patterns

OCR's enforcement record against medical practices is the most extensive of any healthcare segment, including lost or stolen unencrypted laptops and backup tapes, unauthorized employee access to patient records, business associate breaches that cascade to the covered entity, ransomware incidents, improper disposal of paper records, missing breach notification, accounting-of-disclosures failures, and right-of-access denials. The Optum/UnitedHealth Change Healthcare incident in 2024 is the largest healthcare breach on record and continues to reshape OCR's expectations for business associate oversight.

Standards beyond HIPAA

NCPDP SCRIPT for e-prescribing. HL7 v2 and FHIR R4 for clinical interfaces. Section 164.528 accounting-of-disclosures requirements (operationally complex; rarely fully implemented). MIPS quality-measure reporting. ONC certification for EHR vendors creates downstream compliance obligations for practices using certified products. State-specific telemedicine licensure compacts (IMLC for medical, PSYPACT for psychology) where the practice conducts cross-state telemedicine.

Common compliance gaps

The medical-practice compliance gap inventory is large and well-documented: lab partner BAAs missing across the long tail (Quest and LabCorp are signed but specialty labs are not), patient portal access controls and audit logs not integrated with the broader breach response, faxing patterns that produce chronic misdirected-fax exposure, accounting-of-disclosures rarely operationally implemented despite being a §164.528 requirement, business associate oversight that ends at BAA signing rather than continuing through the relationship, and inadequate workforce training on the disclosure scenarios staff actually encounter.

Compliance documentation, then state record law.

HIPAA's six-year rule governs compliance documentation, not clinical records (§164.530(j)). State medical practice acts govern patient record retention — typically seven to ten years for adult patients post-last-encounter, with longer timelines for minors (until age of majority plus statute-of-limitations period). Medicare requires retention of certain document categories beyond the state minimum. Malpractice insurance carriers commonly impose retention requirements as a condition of coverage. Imaging records and pathology specimens are often subject to separate retention rules. Federal research contracts (NIH, AHRQ) may require longer retention for research-related records.

Reference summary, not legal advice. This page summarizes how HIPAA and adjacent regulatory frameworks apply to medical practices based on Patient Protect’s reading of the relevant CFR provisions, OCR enforcement record, and state statutes. Operators with specific compliance questions should consult a qualified HIPAA attorney. Patient Protect is a HIPAA compliance platform; we are not a law firm and do not provide legal advice.

HIPAA training for medical practices.

A 19-module HIPAA Foundations series with the workforce roles, PHI workflows, disclosure scenarios, and vendor risks that actually apply to medical practices— not a generic healthcare course.

Where medical practices are most exposed.

Lab integrations create ePHI data flows you don't monitor

Lab orders, results, and specimen tracking data move between your EHR, reference labs, and patient portals. Each integration is a data flow that requires a BAA, encryption, and documented access controls. Most practices have never mapped these flows.

E-prescribing adds EPCS and DEA compliance layers

Electronic prescribing for controlled substances (EPCS) requires identity proofing, two-factor authentication, and specific audit trail capabilities. These requirements layer on top of standard HIPAA — make sure your compliance program explicitly addresses EPCS controls.

Patient portals expand your attack surface

Patient portals give patients access to lab results, appointment scheduling, and messaging — but they also create new entry points for attackers. Credential stuffing, session hijacking, and unauthorized access attempts target healthcare portals daily.

Multi-provider practices need per-provider access controls

When multiple physicians, NPs, and PAs share a practice, each provider needs role-appropriate access to patient records. Shared logins, over-permissioned accounts, and missing audit trails are the most common findings in OCR audits of medical practices.

Built for medical practices, not hospital systems.

ePHI data flow mapping

The risk assessment covers lab integrations, e-prescribing, patient portals, and every other system touching patient data. See your complete ePHI surface — not just what your EHR vendor tells you.

Multi-vendor BAA management

Track BAAs with labs, pharmacies, EHR vendors, billing services, patient portal providers, and every other business associate. Alerts before any agreement expires.

Secure clinical communication

BAA-gated messaging replaces unsecured email and personal texts between providers, staff, and referring practices. Referral tracking from send to acceptance.

Practice-wide compliance dashboard

See compliance standing across all providers and departments. Identify which workflows have the most exposure. Prioritize based on risk score, not guesswork.

Lab interface compliance for Quest, LabCorp, and regional partners

Most primary care practices order labs through one or more of Quest, LabCorp, regional reference labs, plus specialty labs for specific test categories. A reference lab that performs and reports a test is acting as a treating provider — HHS gives that exact relationship as an example where no BAA is required. The vendors sitting between the practice and the lab, including interface and results-routing services, generally are business associates. Patient Protect's vendor tracking makes you classify each relationship instead of assuming it, and surfaces the long-tail vendors that get missed.

Hospital coordination and referral compliance

Care coordination with hospitals, specialists, and external providers involves continuous PHI exchange — admission notifications, discharge summaries, specialist consult notes. The platform handles the coordination workflow under §164.506 (treatment-purpose exception) while maintaining audit trails for the §164.528 accounting-of-disclosures requirement.

HIPAA already requires the work. Patient Protect starts at $39 a month.

For a covered practice, HIPAA does not ask whether the organization has the budget, internal expertise, or spare time to build a compliance program. The obligation already exists. The only real question is whether you run it through spreadsheets, generic templates, disconnected training and scattered agreements — or keep the whole program in one place.

  • Guided Security Risk Analysis
  • Risk-management and remediation workflows
  • 48 customizable policies and procedures
  • HIPAA Foundations workforce training
  • Completion tracking and verifiable training certificates
  • Workforce and vendor management
  • Business Associate Agreement tracking and documentation
  • Compliance scoring and centralized audit evidence
Start your 14-day free trial

$39 per office per month · Up to 25 personnel · No long-term contract

State-specific HIPAA rules for medical practices.

HIPAA is federal — but your state layers additional breach notification deadlines, AG reporting requirements, and privacy laws on top. Select your state to see what applies to your practice.

What happens after the paperwork is done.

Every major compliance platform covers risk assessments and policy templates. This is the part that differs.

What to ask

Patient Protect

01

Risk assessment that satisfies §164.308(a)(1)

A readiness quiz is not a risk analysis.

Full SRA wizard mapped to NIST CSF with live scoring

02

Auto-generated policies with workforce acknowledgment

HIPAA requires documented proof your staff reviewed them.

48 policies from your risk profile, versioned acknowledgment

03

Staff training with delivery tracking

§164.308(a)(5) — sending a PDF is not sufficient.

HIPAA Foundations — 19 modules, 95 assessment questions, verifiable certificates

04

Full BAA lifecycle management

Expired BAAs are a top enforcement target.

E-signature, renewal alerts, Vendor Risk Scanner

Yes on all 10. Now run the checklist on the rest.

From $39/mo · No long-term contracts.

Enterprise-grade compliance. Independent-practice pricing.

No contracts · No setup fees · Cancel anytime

Basic

$39/mo

Risk assessments, policies, BAA management, training, and compliance scoring.

Recommended

Pro

$99/mo

Everything in Basic plus secure messaging, breach intelligence, live diagnostics, and AI compliance assistant.

See full feature comparison →

Common questions about HIPAA compliance for medical practices.

What HIPAA requirements apply to independent medical practices?

All of them. Independent medical practices are covered entities subject to the full HIPAA Security Rule, Privacy Rule, and Breach Notification Rule — the same 45+ requirements that apply to hospital systems. Practice size does not reduce obligations.

How does Patient Protect handle lab integration compliance?

Patient Protect's risk assessment maps ePHI data flows across lab integrations, identifying gaps in BAA coverage, encryption, and access controls. The platform tracks BAAs with all lab vendors and monitors compliance status continuously — not annually.

Do we need a HIPAA compliance officer?

HIPAA requires a designated Security Officer and Privacy Officer (one person can fill both roles). Patient Protect doesn't replace the designation, but it automates 90% of what that role requires — risk assessments, policy management, training, BAA tracking, and audit documentation.

What does HIPAA compliance cost for a medical practice?

Compliance consultants charge $5,000–$15,000 per year for medical practices, depending on size and complexity. Patient Protect starts at $39/month ($468/year) for Basic and $99/month for Pro, with no contracts — covering every HIPAA requirement for independent practices.

Do primary care practices need patient authorization for hospital coordination?

No, generally. Section 164.506 permits PHI disclosure for treatment, payment, and healthcare operations without specific patient authorization. Hospital coordination, specialist referrals, and care-team communication fall under treatment purposes and are permitted disclosures. The practice must still provide the required Notice of Privacy Practices and maintain audit trails of disclosures under §164.528.

How does HIPAA apply to patient portals?

Patient portals are PHI-handling systems and require the full HIPAA compliance framework: BAA with the portal vendor (most EHR vendors include the portal under their EHR BAA), access controls, audit logs, encryption in transit and at rest, and integration with the practice's broader breach response. Portal-specific compliance is sometimes overlooked because operators treat the portal as 'patient-facing' rather than 'clinical.'

Is faxing PHI still HIPAA-compliant in 2026?

Traditional analog faxing is permitted but disfavored — risks include misdirected faxes, unattended fax machines, and call-tracing exposure. Electronic fax services (e-fax) are generally compliant when the vendor signs a BAA, but the practice remains responsible for confirming the recipient's number and using cover sheets that limit incidental disclosure. OCR has enforced against practices for chronic fax-misdirection patterns.

Does an independent medical practice have to complete a HIPAA Security Risk Analysis?

Yes, across the whole environment rather than the EHR alone. Every covered practice must conduct and document an accurate, thorough assessment of the risks affecting all its ePHI. For an independent practice that means the complete system inventory: EHR access and administrative privileges, audit logging, integrations and APIs, the patient portal, laboratory and imaging interfaces, e-prescribing, claims and clearinghouse workflows, email, e-fax, telehealth, voicemail, every workstation and server, remote access, cloud storage and backup, and every outside organization touching PHI. Most practices discover during the inventory that they have more ePHI systems than they had counted.

Which of our medical practice vendors need Business Associate Agreements?

Any organization performing a function involving PHI on the practice's behalf: the EHR vendor, billing company, claims clearinghouse, patient portal and messaging vendors, transcription, cloud storage and backup, IT support, answering service, and any analytics or scheduling tool receiving identifiable data. Reference laboratories are the common misclassification — a lab performing and reporting a test is acting as a treating provider, and HHS gives that exact relationship as an example where no BAA is required. The interface, ordering, and results-routing vendors that sit between you and the lab generally do need agreements. Hospitals and specialists receiving referrals are treating providers, not business associates.

What do we actually owe a patient who asks for an accounting of disclosures?

Less than most practices assume, and more than most can produce. The accounting covers disclosures the practice made in the six years before the request, but it excludes the large categories that make up ordinary operations — disclosures for treatment, payment, and health care operations, disclosures made to the patient, and disclosures the patient authorized. What remains is the reportable set: certain public-health and law-enforcement reporting, disclosures required by law, judicial and administrative proceedings, and similar. The practical problem is that most EHRs log access rather than reportable disclosures, so a practice that has never separated the two cannot answer the request without reconstructing it by hand.

Is the government's Security Risk Assessment Tool mandatory?

No. The government's SRA Tool is one method designed to help small and medium-sized organizations perform the required analysis. HIPAA requires the underlying risk analysis — not the use of one particular tool. Patient Protect provides its own guided SRA and connects the findings directly to remediation, policies, tasks, and documentation.

Does our EHR make the practice HIPAA compliant?

No. An EHR may provide important safeguards for the records it maintains, but it does not conduct the practice's complete SRA, remediate every identified risk, train the workforce, manage all policies, identify every Business Associate, prepare the practice for incidents, or preserve the full body of compliance evidence.

How much does Patient Protect cost for an independent medical practice?

Patient Protect Basic costs $39 per office per month and includes up to 25 personnel. It includes the guided Security Risk Analysis, risk management, policies, workforce training, workforce and vendor management, BAA tracking, compliance scoring, and centralized documentation needed to operate the practice's core HIPAA compliance program.

Corrections & Updates

Healthcare security data changes as investigations progress, vendors update systems, and laws and guidance evolve. If you see something outdated, incomplete, or incorrect — or have newer source material — we’d appreciate hearing from you.

Submit a correction →

Patient Protect is intuitive, proactive, and affordable — exactly what small clinics like ours need to keep patient data safe and stay on the right side of HIPAA.
Dr. Thomas E Murray, D.D.S.Patient Protect Member Since 2017

Your medical practice has the broadest ePHI exposure in healthcare.

See your compliance gaps today. Free risk assessment — no login required.

Or explore the full HIPAA compliance software comparison or all HIPAA compliance solutions