What HIPAA requirements apply to independent medical practices?
All of them. Independent medical practices are covered entities subject to the full HIPAA Security Rule, Privacy Rule, and Breach Notification Rule — the same 45+ requirements that apply to hospital systems. Practice size does not reduce obligations.
How does Patient Protect handle lab integration compliance?
Patient Protect's risk assessment maps ePHI data flows across lab integrations, identifying gaps in BAA coverage, encryption, and access controls. The platform tracks BAAs with all lab vendors and monitors compliance status continuously — not annually.
Do we need a HIPAA compliance officer?
HIPAA requires a designated Security Officer and Privacy Officer (one person can fill both roles). Patient Protect doesn't replace the designation, but it automates 90% of what that role requires — risk assessments, policy management, training, BAA tracking, and audit documentation.
What does HIPAA compliance cost for a medical practice?
Compliance consultants charge $5,000–$15,000 per year for medical practices, depending on size and complexity. Patient Protect starts at $39/month ($468/year) for Basic and $99/month for Pro, with no contracts — covering every HIPAA requirement for independent practices.
Do primary care practices need patient authorization for hospital coordination?
No, generally. Section 164.506 permits PHI disclosure for treatment, payment, and healthcare operations without specific patient authorization. Hospital coordination, specialist referrals, and care-team communication fall under treatment purposes and are permitted disclosures. The practice must still provide the required Notice of Privacy Practices and maintain audit trails of disclosures under §164.528.
How does HIPAA apply to patient portals?
Patient portals are PHI-handling systems and require the full HIPAA compliance framework: BAA with the portal vendor (most EHR vendors include the portal under their EHR BAA), access controls, audit logs, encryption in transit and at rest, and integration with the practice's broader breach response. Portal-specific compliance is sometimes overlooked because operators treat the portal as 'patient-facing' rather than 'clinical.'
Is faxing PHI still HIPAA-compliant in 2026?
Traditional analog faxing is permitted but disfavored — risks include misdirected faxes, unattended fax machines, and call-tracing exposure. Electronic fax services (e-fax) are generally compliant when the vendor signs a BAA, but the practice remains responsible for confirming the recipient's number and using cover sheets that limit incidental disclosure. OCR has enforced against practices for chronic fax-misdirection patterns.
Does an independent medical practice have to complete a HIPAA Security Risk Analysis?
Yes, across the whole environment rather than the EHR alone. Every covered practice must conduct and document an accurate, thorough assessment of the risks affecting all its ePHI. For an independent practice that means the complete system inventory: EHR access and administrative privileges, audit logging, integrations and APIs, the patient portal, laboratory and imaging interfaces, e-prescribing, claims and clearinghouse workflows, email, e-fax, telehealth, voicemail, every workstation and server, remote access, cloud storage and backup, and every outside organization touching PHI. Most practices discover during the inventory that they have more ePHI systems than they had counted.
Which of our medical practice vendors need Business Associate Agreements?
Any organization performing a function involving PHI on the practice's behalf: the EHR vendor, billing company, claims clearinghouse, patient portal and messaging vendors, transcription, cloud storage and backup, IT support, answering service, and any analytics or scheduling tool receiving identifiable data. Reference laboratories are the common misclassification — a lab performing and reporting a test is acting as a treating provider, and HHS gives that exact relationship as an example where no BAA is required. The interface, ordering, and results-routing vendors that sit between you and the lab generally do need agreements. Hospitals and specialists receiving referrals are treating providers, not business associates.
What do we actually owe a patient who asks for an accounting of disclosures?
Less than most practices assume, and more than most can produce. The accounting covers disclosures the practice made in the six years before the request, but it excludes the large categories that make up ordinary operations — disclosures for treatment, payment, and health care operations, disclosures made to the patient, and disclosures the patient authorized. What remains is the reportable set: certain public-health and law-enforcement reporting, disclosures required by law, judicial and administrative proceedings, and similar. The practical problem is that most EHRs log access rather than reportable disclosures, so a practice that has never separated the two cannot answer the request without reconstructing it by hand.
Is the government's Security Risk Assessment Tool mandatory?
No. The government's SRA Tool is one method designed to help small and medium-sized organizations perform the required analysis. HIPAA requires the underlying risk analysis — not the use of one particular tool. Patient Protect provides its own guided SRA and connects the findings directly to remediation, policies, tasks, and documentation.
Does our EHR make the practice HIPAA compliant?
No. An EHR may provide important safeguards for the records it maintains, but it does not conduct the practice's complete SRA, remediate every identified risk, train the workforce, manage all policies, identify every Business Associate, prepare the practice for incidents, or preserve the full body of compliance evidence.
How much does Patient Protect cost for an independent medical practice?
Patient Protect Basic costs $39 per office per month and includes up to 25 personnel. It includes the guided Security Risk Analysis, risk management, policies, workforce training, workforce and vendor management, BAA tracking, compliance scoring, and centralized documentation needed to operate the practice's core HIPAA compliance program.