HIPAA Compliance Consulting for Medical Practices

Medical practices are covered entities under HIPAA whenever they transmit health information electronically as part of a covered transaction (45 CFR §160.103). That includes filing insurance claims, checking patient eligibility, sending electronic referrals, and processing billing through a clearinghouse. There is no size exemption. Solo physicians, multi-provider groups, urgent care clinics, outpatient surgery centers, and specialty practices all face the same rules. For a detailed look at what this investment often involves, see our HIPAA compliance cost breakdown.

HIPAA Requirements for Medical Practices

HIPAA applies equally to solo practitioners and large healthcare systems. There is no exemption based on practice size, patient volume, or revenue.

Medical practices that are covered entities must follow three core HIPAA rules:

PHI in Medical Practices

Protected Health Information (PHI) in medical practices includes patient intake forms, medical histories, clinical notes, lab results, diagnostic imaging, prescription records, insurance claims, appointment schedules, and billing data. Any information that identifies a patient and relates to their health condition, treatment, or payment for care counts as PHI under 45 CFR §160.103. This also includes information patients share through a patient portal, over the phone, or via text message.

Electronic health records (EHR/EMR) are the central repository of ePHI for most practices. The EHR must be configured with unique user IDs for every staff member, automatic session timeouts, audit logging that tracks who viewed or modified each record, and encryption for data at rest and in transit. Shared logins are a common violation - they make audit logs useless and remove individual accountability. The EHR vendor must sign a Business Associate Agreement per §164.308(b)(1) before any PHI is stored in or transmitted through their system.

Patient portals that allow patients to view records, message providers, or schedule appointments must use encrypted transmission (TLS/SSL), strong authentication, and role-based access controls. The portal vendor needs a BAA, and the practice needs documented procedures for how staff assist patients with portal access and how portal-related security incidents are handled.

Connected medical devices - diagnostic equipment, remote monitoring tools, vital sign monitors, and any device integrated with the EHR - create, transmit, or store ePHI and fall under the Security Rule. These devices must be included in the practice's risk analysis, covered by facility access controls per §164.310(a), and their vendors must sign BAAs. Many practices overlook networked devices during their risk assessment, which creates undocumented gaps.

Required HIPAA Compliance Steps

These six steps apply to every medical practice that is a covered entity. Each ties to a specific CFR requirement and carries its own enforcement risk if left undone.

Common HIPAA Compliance Gaps in Medical Practices

The most common gap is the missing or incomplete Security Risk Analysis. Many practices either have never done one, or completed a checklist-style assessment years ago that does not meet the standard OCR expects. Other frequent findings include:

Multi-provider groups and practices with multiple locations face added challenges when building uniform policies across sites with different EHR systems, staffing levels, and physical layouts. A gap analysis at the organizational level is the right starting point before standardizing policies across locations.

HIPAA Regulatory Standards for Medical Practices

Key federal standards that define HIPAA duties for medical practices. Practices in states with additional health privacy laws should also review California HIPAA compliance requirements as an example of how state rules can layer on top of federal requirements.

StandardKey Requirements
45 CFR §164.308Administrative safeguards: risk analysis, workforce training, access management, contingency planning, and security incident procedures.
45 CFR §164.310Physical safeguards: facility access controls, workstation use and security, device and media controls for any hardware containing ePHI.
45 CFR §164.312Technical safeguards: unique user IDs, emergency access procedures, automatic logoff, audit controls, integrity controls, and transmission security.
Privacy Rule (Subpart E)Patient rights to access, amend, and receive an accounting of disclosures of their PHI. Requires a Notice of Privacy Practices and minimum necessary use standards.
Breach Notification (Subpart D)Notification to affected individuals within 60 days, HHS reporting, and media notification for breaches affecting 500+ people.
Business Associate ContractsWritten BAAs required with every vendor that creates, receives, maintains, or transmits PHI - including EHR, billing, IT, cloud, and shredding services.

Medical Practice HIPAA FAQ

How long does it take a medical practice to become audit-ready?
Most practices see meaningful progress in 30 to 60 days. The timeline depends on the size of the practice, the number of systems handling ePHI, and how many gaps the initial risk analysis turns up. Practices that complete the security risk analysis first and address high-priority findings right away often reach a defensible compliance posture within that window. The key is starting with the SRA, because it sets the remediation priority for everything else.

What EHR access controls does HIPAA require?
HIPAA's Technical Safeguard rules at 45 CFR §164.312 require unique user IDs for every person who accesses ePHI, automatic logoff after a period of inactivity, audit controls that log who accessed what and when, and encryption for data both in transit and at rest. Most EHR platforms support these controls out of the box, but they need to be configured correctly and reviewed on a regular basis. A common gap is shared login credentials among staff, which violates the unique user ID requirement and makes audit logs useless for tracking individual access.

How do we secure a patient portal for HIPAA?
Patient portals must use encrypted transmission (TLS/SSL), strong authentication such as multi-factor login, and role-based access controls. The portal vendor must sign a BAA before any PHI passes through their system. You also need documented procedures for how staff assist patients with portal access, how you handle portal-related complaints, and what happens if the portal experiences a security incident. If the portal stores messages, lab results, or appointment records, all of that data is ePHI and falls under the Security Rule.

Do connected medical devices create HIPAA duties?
Yes. Any device that creates, receives, transmits, or maintains ePHI is in scope for the HIPAA Security Rule. That includes connected diagnostic equipment, remote patient monitoring tools, wearables integrated with your EHR, and bedside devices that record vitals. Vendors providing those devices often need a BAA, and the devices themselves must be included in your facility access controls as required by 45 CFR §164.310(a). Many practices overlook networked devices during their risk analysis, which creates an undocumented gap that OCR can flag.

What is required when a staff member with PHI access leaves?
HIPAA requires that access to PHI be terminated promptly when employment ends, as part of the workforce clearance and termination procedures under 45 CFR §164.308(a)(3)(ii)(C). That means revoking EHR credentials, email access, VPN access, and any system where the employee could reach PHI. Physical items like keys, badges, and mobile devices with PHI access must also be recovered. Document every step taken and the date it was completed. Include access revocation in your standard offboarding and incident management procedures so nothing gets missed.

Does HIPAA apply to paper records in medical practices?
Yes. The Privacy Rule covers all PHI regardless of format, and the Security Rule's physical safeguard requirements under §164.310 apply to paper charts, printed lab results, prescription pads, and any physical media containing PHI. Practices must implement workstation use policies (§164.310(b)), device and media controls (§164.310(d)), and documented disposal procedures such as cross-cut shredding. Common gaps include printers in shared hallways, unlocked file cabinets, and sign-in sheets that expose patient names and appointment reasons in waiting areas.

How often must medical practice staff complete HIPAA training?
HIPAA requires training at hire and whenever policies or procedures change, per §164.308(a)(5)(i). Annual refresher training is not technically required by the rule, but it is considered best practice and is the standard OCR expects to see during investigations. Training records must include the date, topics covered, and each attendee's name, and must be retained for at least six years per §164.530(j). Missing training records is one of the most common findings in OCR investigations.

HIPAA Enforcement for Medical Practices

The Office for Civil Rights (OCR) enforces HIPAA for all covered entities, including medical practices of every size. Civil monetary penalties range from $145 to $2,190,294 per violation category per year under 45 CFR §160.404, with four penalty tiers based on the level of culpability. OCR has investigated medical practices for complaints involving unauthorized disclosures, missing risk assessments, failure to provide patients access to their records within 30 days per §164.524(b)(2), and insufficient safeguards on electronic systems. The most common trigger for an investigation is a patient complaint or a breach report, and the first document OCR often requests is the security risk analysis.

Chuck Weiselberg, Certified HIPAA Professional (C.H.P.). Zero client fines. Zero failed audits.
“One Guy Consulting is super easy to work with. I actually look forward to my implementation meetings for HIPAA.” — Samantha M.

Need HIPAA Support for Your Medical Practice?

One Guy Consulting works with solo physicians, multi-provider groups, urgent care clinics, outpatient surgery centers, and specialty practices. We are based in Queens, New York and work remotely with practices nationwide; see HIPAA compliance services near you.

Book Your Free 30 Minute HIPAA Compliance Review