Skip to main content
Patient Protect circular logo mark in purple and white used for site navigationPatient Protect
Breach Intelligence

HIPAA for Independent Practices: Running It Lean

Same obligations as a hospital system, none of the staffing. EHR configuration gaps, vendor sprawl, offboarding, and what the proposed Security Rule amendments would change if finalized.

Patient ProtectPatient Protect Editorial Team·May 5, 2026·15 min read

Written and reviewed by the Patient Protect team — Joseph A. Perrin, CTO (federal infrastructure background, platform security architect), Angie Perrin, CSO (CHPC, 10+ years clinical practice), and Alexander Perrin, CEO (20 years enterprise SaaS, primary author of the Secure Care Research Institute research program). See editorial standards.

Share

When nobody's job title says compliance

Independent medical practices — solo physicians, small group practices, family medicine offices, specialty clinics — carry an obligation built for organizations with a compliance department, and meet it with an office manager who also does payroll. Healthcare has been the most expensive sector in IBM's breach-cost report for thirteen consecutive years. Small practices do appear throughout OCR's enforcement record, and the published resolution agreements skew toward larger organizations for the ordinary reason that larger incidents get investigated — so treat the absence of small-practice settlements as a limitation of the record rather than a measure of your exposure.

The reason is structural, not negligent. Independent practices carry the same HIPAA obligations as hospital systems — the same Security Rule requirements, the same Privacy Rule provisions, the same Breach Notification Rule timelines — while operating with a fraction of the administrative, legal, and IT resources that those systems dedicate to compliance.

One thing to be clear about before going further: being independent does not change a single HIPAA requirement. There is no small-practice exemption, no reduced standard and no different rule. What changes is the operating context — who does the work, how much of it fits in a week, and how much of it survives the person who was doing it leaving. That context is what this article is about, and it is why the same advice that works for a health system fails here.

This guide covers the complete HIPAA compliance picture for independent medical practices in 2026: what the law requires, where practices are most exposed, how EHR complexity creates hidden gaps, what the 2025 Security Rule amendments change, and the step-by-step path from wherever you are now to demonstrable, continuous compliance.


The Independent Practice Risk Profile

Independent medical practices face three compounding risk factors that differentiate their exposure from larger organizations.

Size is not a shield. There is no threshold below which OCR stops looking, and the Risk Analysis Initiative has produced actions against very small organizations. What the published record does not support is a ranking — whether small practices are OCR's primary target is not something the resolution agreements establish, and this page previously claimed it. The useful reading is narrower and still uncomfortable: being small has not prevented enforcement, and the deficiency cited most often is one a small practice is most likely to have skipped.

Their EHR creates compliance obligations they have not fully mapped. Most independent practices rely on one or more EHR systems — athenahealth, eClinicalWorks, Epic, Kareo, Modernizing Medicine, and others — for clinical documentation, scheduling, and billing. The EHR vendor signs a BAA. What the practice often does not realize is that the EHR generates ongoing ePHI flows to sub-processors, clearinghouses, labs, imaging centers, and patient portal providers — each of which requires its own BAA assessment. The EHR is not a compliance solution. It is a complex ePHI system that requires its own compliance framework.

The 2025 Security Rule amendments raised the technical standard. HHS proposed the most significant Security Rule update in twenty years in January 2025, with an effective date that brings independent practices into direct scope for encryption mandates, multi-factor authentication requirements, annual penetration testing, and explicit AI tool risk assessment obligations. The "addressable vs. required" distinction that previously gave small practices flexibility on certain technical safeguards has been significantly narrowed. For many independent practices, the 2025 amendments represent a compliance gap that did not exist two years ago.


What HIPAA Actually Requires for Independent Medical Practices

The Security Rule: Technical Baseline for 2026

The HIPAA Security Rule requires administrative, physical, and technical safeguards for all ePHI. For independent medical practices in 2026, the technical baseline has been raised by the proposed 2025 amendments:

Encryption — now effectively mandatory: The 2025 proposed rule eliminates the "addressable" classification for encryption in most contexts, making encryption of ePHI at rest and in transit effectively required for all covered entities. Independent practices that have relied on the addressable classification to defer encryption implementation are operating under a standard that is being elevated.

For independent practices specifically, encryption must cover: workstations and laptops containing or accessing ePHI, servers or cloud systems storing ePHI, backup media, mobile devices used for clinical documentation or EHR access, and all ePHI transmitted over networks (including lab result transmissions, imaging referrals, and insurance claims).

Multi-factor authentication — expected standard: The 2025 amendments make MFA an expected implementation for systems accessing ePHI. A username and password alone — for EHR access, email, cloud systems — no longer meets the standard that OCR will apply in enforcement contexts.

Annual penetration testing — new requirement: The 2025 proposed rule introduces an annual penetration testing requirement. For independent practices without IT departments, this means engaging an external security professional to test systems annually — a cost and process that most practices have never budgeted for.

AI tool risk assessment — explicit inclusion: The 2025 amendments explicitly require that AI tools touching patient data be included in the formal risk analysis. For practices where staff have adopted AI tools for documentation, scheduling, or clinical support, this creates an immediate compliance gap if those tools have not been assessed.

The Privacy Rule: Disclosure Management

The Privacy Rule governs how PHI is used and disclosed. For independent medical practices, the highest-risk provisions are:

Minimum necessary standard (§164.502(b)): Access to and disclosure of PHI must be limited to the minimum necessary for the purpose. In medical practices, this most commonly produces violations through: staff accessing records of patients who are not their assigned patients, sharing more information than necessary with insurers and other providers, and using PHI for practice marketing purposes without appropriate authorization.

Patient access rights (§164.524): Patients have the right to access their medical records within 30 days of request (extendable once to 60 days). A 2020 OCR enforcement push specifically targeted practices that were charging excessive fees for records access or delaying production beyond the deadline. The right extends to ePHI and to records held by Business Associates.

Notice of Privacy Practices: Independent practices must maintain a current NPP that accurately reflects their information practices, provide it to patients at first service, and post it visibly in the practice.


The EHR Compliance Gap

The most common misconception about HIPAA compliance in independent medical practices is that the EHR handles it. It does not.

An EHR is a clinical documentation and practice management system. When an EHR vendor signs a BAA, that BAA covers the vendor's handling of ePHI within their system — their servers, their sub-processors, their security practices. It does not:

  • Cover the independent practice's handling of ePHI outside the EHR
  • Satisfy the practice's Security Risk Analysis requirement
  • Constitute a workforce training program
  • Track BAAs with other vendors the practice uses
  • Monitor who at the practice is accessing which records
  • Generate the audit evidence OCR will request in an investigation

The EHR creates a structured environment for clinical documentation. It does not create a compliance program. Practices that treat their EHR subscription as their compliance solution are exposed on every dimension the EHR does not address — which is most of them.

EHR configuration gaps that create violations:

Most EHR systems have security configurations that must be actively set — they are not enabled by default. Audit logging may not be fully enabled. Role-based access controls may default to broad permissions rather than minimum necessary. Session timeout settings may be set to hours rather than minutes. Password strength requirements may be below current standards.

The practice is responsible for ensuring its EHR is configured to meet Security Rule requirements — not just purchased and deployed. The fact that a vendor provides a BAA does not mean the system, as configured at your practice, meets HIPAA's technical safeguard requirements.

The sub-processor ecosystem around your EHR:

Your EHR is connected to labs, imaging centers, pharmacies, clearinghouses, and patient portal services. Each connection creates an ePHI flow. Each receiving party is potentially a Business Associate. The BAA with your primary EHR vendor does not cover these downstream relationships.

Mapping the full ePHI ecosystem around your EHR — and ensuring BAAs are in place for every vendor that receives patient data through that ecosystem — is one of the most critical and most commonly incomplete compliance tasks for independent medical practices.


The Independent Medical Practice Vendor BAA Checklist

Every vendor on this list requires a signed, current BAA before any ePHI is shared:

Electronic Health Records

  • athenahealth
  • eClinicalWorks
  • Epic (independent practice deployments)
  • Kareo / Tebra
  • Modernizing Medicine
  • Allscripts / Veradigm
  • DrChrono
  • Practice Fusion
  • NextGen

Billing and Revenue Cycle

  • Third-party billing service
  • Primary insurance clearinghouse
  • Change Healthcare / Availity
  • Patient payment processing (if handling PHI)

Labs and Diagnostic Services

  • Reference laboratory (Quest, LabCorp, regional labs)
  • Any lab that transmits results back to the practice
  • Point-of-care testing vendors with connected software

Imaging and Radiology

  • Radiology centers receiving referrals with patient identifiers
  • PACS (Picture Archiving and Communication System) vendors
  • Teleradiology services

Patient Communication and Portal

  • Patient portal vendor (separate from EHR if applicable)
  • Appointment reminder services
  • Secure patient messaging platforms
  • Telehealth platform vendor (if applicable)

Pharmacy and E-Prescribing

  • E-prescribing network (Surescripts)
  • Medication management services

IT and Infrastructure

  • Managed IT provider
  • Cloud backup service
  • Email hosting provider (if ePHI is transmitted by email)
  • Remote access or VPN provider with EHR system access

AI and Documentation Tools

  • Any AI scribing or ambient documentation service
  • Voice recognition software that processes clinical content
  • Any AI-assisted diagnostic tool that accesses patient data

OCR Enforcement Patterns for Independent Medical Practices

The Risk Analysis Initiative

OCR publicly described the Risk Analysis Initiative during 2024 and announced its first enforcement action under it on 31 October 2024; roughly a dozen actions had followed by early 2026. The message is consistent: the risk analysis is not a one-time exercise, and completing the HHS tool without working the findings does not discharge it.

The pattern in these enforcement actions is consistent: the practice failed to conduct an adequate risk analysis, failed to implement a risk management plan addressing identified findings, or conducted an initial analysis and never updated it as the practice environment changed.

Enforcement case pattern — small medical practice: In multiple Risk Analysis Initiative cases, OCR has pursued practices that received prior OCR technical assistance — meaning they had been contacted by OCR about compliance deficiencies — and still failed to implement adequate controls. Prior contact matters because §160.404 keys the penalty tier to what the entity knew and whether it exercised reasonable diligence, and it is hard to argue you did not know about a deficiency OCR wrote to you about. The tier is OCR's determination on the facts, not an automatic escalation.

Patient Access Right Enforcement

OCR's Right of Access Initiative produced a long run of settlements with practices that missed the §164.524 timeline — 30 days, with one 30-day extension — or made the request process obstructive.

One correction worth making, because this page previously got it wrong and the error is everywhere. $6.50 is not a cap. It is an optional flat rate a covered entity may choose for electronic copies of ePHI maintained electronically, offered in OCR guidance so practices can avoid calculating actual costs. The regulation permits a reasonable, cost-based fee under §164.524(c)(4), and Ciox Health v. Azar (D.D.C. 2020) vacated the extension of the fee limitation to records sent to third parties at a patient's direction. Charging more than $6.50 is not a violation; charging more than your actual allowable costs is.

The practical implication for 2026: If your practice does not have a documented, compliant process for receiving and responding to patient records requests — including electronic records requests — this is an active compliance gap.

Breach Notification Failures

OCR has pursued enforcement against practices that experienced breaches and failed to notify affected patients within 60 days, failed to report to HHS on time, or failed to provide adequate notification content. The 60-day clock starts from discovery — not from completion of the investigation.


The Proposed Security Rule Amendments: What Would Change, If Finalized

HHS published a Notice of Proposed Rulemaking in January 2025 (RIN 0945-AA22) that would be the most significant update to HIPAA's technical standards since the Security Rule was written. It has not been finalized. Nothing below is currently required, and a practice should not be sold any of it as a present obligation. It is worth reading anyway, because the direction is unlikely to reverse and the work is useful regardless.

What the proposal would do:

Encryption would become required rather than addressable in most contexts, narrowing the §164.312 addressable/required distinction substantially. Until a final rule says so, encryption remains addressable — which is not the same as optional, and already obliges you to assess it and record the reasoning either way.

Multi-factor authentication would be required for systems accessing ePHI. Today it is not, though it is among the cheapest controls available and hard to justify omitting in a risk analysis.

Annual penetration testing and semi-annual vulnerability scanning would be required. For an independent practice this is the proposal with the largest cost implication, and it is the one worth watching most closely as comments are resolved.

Network segmentation would be required, separating clinical systems from the general office network — something most independent practices have not done.

AI tool inclusion in risk analysis: Any AI tool that processes or accesses patient data must be included in the formal security risk analysis. Shadow AI — staff using consumer AI tools for clinical work — must be inventoried and assessed.

Faster vendor notification. The proposal tightens what business associates owe covered entities, including 24-hour notice on certain triggers such as activation of a contingency plan. Read the specific trigger rather than the headline: this is not a blanket replacement of the §164.410 60-day outer bound with 24 hours.

One caution about how this gets sold. A proposed rule is not enforceable, and OCR cannot cite you for failing a standard that has not been finalized. If a vendor tells you otherwise, that is a sales technique. The honest reason to act early is that most of these controls would improve a risk analysis you already have to do.


Step-by-Step: How to Become HIPAA Compliant as an Independent Medical Practice

The requirement-by-requirement walkthrough, including the state-law pathway this article does not cover, lives on HIPAA compliance for medical practices. What follows is the same sequence with the independent-practice constraint applied at each step: who actually does it, and what happens when that person is on vacation.

Step 1: Designate Officers and Document the Chain of Accountability

Name a Security Officer and Privacy Officer by name, not title. Document the designation. In a solo practice, this is the physician. In a group practice, the designees should be named individuals who understand the role — not an administrative title that changes with staff turnover.

Step 2: Map Your Full ePHI Ecosystem

Before conducting the SRA, map every system that stores, processes, or transmits ePHI. This includes your EHR and every system connected to it — labs, imaging, pharmacy, clearinghouses, patient portal, backup. Use the ePHI Data Flow Mapper to build a complete inventory. This map is the foundation of your SRA and your BAA audit.

Step 3: Conduct a Current, Comprehensive Security Risk Analysis

The SRA must cover every system in your ePHI map. For each system: identify what ePHI it holds or processes, what threats and vulnerabilities exist, what controls are currently in place, what the residual risk level is, and what your plan is for addressing unacceptable risk.

Produce a documented Risk Management Plan with specific remediation steps, owners, and timelines. The SRA is not complete until the Risk Management Plan exists and implementation begins.

Step 4: Audit and Execute BAAs

Work through the vendor checklist above. For every vendor with ePHI access, verify that a signed, current BAA exists. Execute agreements for any vendor without one before sharing further ePHI. Review the sub-processor coverage in BAAs for high-volume relationships (clearinghouses, billing services, labs).

Step 5: Implement and Verify Technical Safeguards

  • Enable full audit logging in your EHR
  • Verify role-based access is configured to minimum necessary
  • Enable session timeout on all workstations
  • Encrypt workstations and backup media
  • Implement MFA on EHR, email, and cloud system access
  • Verify TLS encryption is active for all ePHI in transit

Document the configuration for each system. "We have the EHR" is not a technical safeguard record. "We have audit logging enabled, session timeout set to 15 minutes, role-based access configured per the attached access control matrix, and encryption verified on [date]" is.

Step 6: Inventory and Assess AI Tools

Identify every AI tool currently used in the practice — including tools staff are using without formal approval. For each tool that accesses or processes patient data, assess BAA status, encryption, and inclusion in the SRA.

Step 7: Train Your Workforce With Documentation

Every staff member — clinical and administrative — requires HIPAA training with individual completion records. Training must cover the basics of the Privacy Rule and Security Rule, your specific policies, how to handle patient records requests, and how to report a suspected breach.

Step 8: Implement a Patient Records Request Protocol

Establish a documented process for receiving, reviewing, and responding to patient records requests. Set a calendar reminder for the 30-day deadline. Document every request received and the date of fulfillment.

Step 9: Build Your Breach Response Procedure

Document your response process before you need it. Who assesses the breach? Who notifies affected patients? Who reports to HHS? What documentation is created? Practice the process with a tabletop exercise on a cadence the practice sets and can justify.

Step 10: Review and Update Continuously

Every new vendor, every new system, every staff departure, every significant operational change is a compliance event. Build review triggers into your operational processes — not a calendar reminder to "do compliance" once a year, but specific events that automatically generate specific compliance actions.


Why Independent Practices Are Better Positioned Than They Think

The compliance challenge for independent medical practices is real. The resource constraint is real. What is also real is that the tools available in 2026 make continuous, automated compliance accessible at a price and complexity level that was not available five years ago.

Patient Protect is built for independent practices rather than scaled down from hospital software. What that means concretely: the risk analysis is structured and retained rather than restarted each year, agreements carry a visible state so a lapse is something you can see, and the compliance score moves as your compliance state moves. What it does not mean is that the platform performs your safeguards for you — the analysis is your practice's, and so is the decision behind every control it records.

Basic starts at $39/month with no long-term contract. A consultant is not required and is also not the enemy; plenty of practices run this well with one, and we work with consultants directly.

Map your full ePHI data ecosystem →

See the platform built for independent practices →

Related: HIPAA violations in independent medical practices →


Reflects 45 CFR Parts 160 and 164 as of August 2026. The Security Rule amendments discussed are proposed (RIN 0945-AA22) and were not final at that date. Informational only; not legal advice.

Was this useful? Share it.

Share

Corrections & Updates

Healthcare security data changes as investigations progress, vendors update systems, and laws and guidance evolve. If you see something outdated, incomplete, or incorrect — or have newer source material — we’d appreciate hearing from you.

Submit a correction →

Next step

How exposed is your practice right now?

Take the free self-assessment — see your compliance gaps with prioritized next steps.

Stay informed

Subscribe to HIPAA Pulse.

Breach alerts, enforcement updates, and compliance intelligence — every two weeks.

© 2026 Patient Protect LLC. All rights reserved. Content may not be reproduced, scraped, or used to train AI models without written permission. Terms · DMCA