HIPAA Compliance for Small Medical Practices: A Plain-English Checklist

The JenPulse team · 5 October 2026 · 4 min read

A red padlock resting on a black computer keyboard
Photo: FlyD on Unsplash

HIPAA has a reputation for being complicated, and the full regulations are long. But for a small practice, the day-to-day obligations come down to a handful of habits. This guide explains what the law expects in plain English, and ends with a checklist you can work through with your team.

It is a practical overview, not legal advice. For decisions specific to your practice, talk to a healthcare attorney or compliance consultant, and check guidance from the HHS Office for Civil Rights (OCR), which enforces HIPAA.

Does HIPAA apply to your practice?

HIPAA applies to "covered entities": health plans, healthcare clearinghouses, and healthcare providers who transmit health information electronically in connection with standard transactions, such as billing insurance. In practice, almost every practice that bills insurance is covered.

It also applies to your business associates: vendors that create, receive, store or transmit protected health information (PHI) on your behalf. Your EHR vendor, billing company, cloud backup provider and IT support firm are typical examples.

The three rules that matter most

The Privacy Rule: who can see and use PHI

The Privacy Rule sets limits on how PHI is used and shared. Key points for a small practice:

  • Use and share PHI for treatment, payment and healthcare operations; most other uses need the patient's written authorization
  • Apply the minimum necessary standard: staff should only access what they need for their job
  • Give patients your Notice of Privacy Practices and make a good-faith effort to get acknowledgment
  • Respect patient rights, especially the right of access: patients can request copies of their records, and you generally must respond within 30 days (with one possible 30-day extension)

Right of access is an area OCR has actively enforced, including against small practices. Don't make patients wait months for their records.

The Security Rule: protecting electronic PHI

The Security Rule requires administrative, physical and technical safeguards for electronic PHI. The single most important requirement is a risk analysis: a documented review of where PHI lives in your practice, what could go wrong, and what you are doing about it. Many enforcement cases start with a practice that never did one.

Other core safeguards:

  • Unique logins for every user, never shared passwords
  • Role-based access, so receptionists, billers and clinicians see what they need
  • Audit logs that record who accessed or changed records
  • Encryption for laptops, phones and backups
  • Automatic logoff on unattended workstations
  • Regular, tested backups and a plan for outages
  • Security training for every staff member, repeated regularly

HHS has proposed updates to the Security Rule in recent years that would make some safeguards more explicit. Keep an eye on the final version, but the safeguards above are good practice regardless.

The Breach Notification Rule: when something goes wrong

If unsecured PHI is breached, you must notify affected patients without unreasonable delay, and no later than 60 days after discovery. Breaches affecting 500 or more people must also be reported to HHS within 60 days, and to prominent media outlets if 500 or more residents of a state are affected. Smaller breaches can be logged and reported to HHS annually.

Encryption matters here: properly encrypted data that is lost or stolen is generally not considered "unsecured" PHI.

Business associate agreements (BAAs)

Before any vendor handles PHI for you, you need a signed business associate agreement. It obliges the vendor to protect the data and to tell you about breaches. Ask every vendor that touches patient data, and keep the signed agreements on file. "We're HIPAA-compliant" on a website is not a substitute for a BAA.

Mistakes that get small practices into trouble

  • No risk analysis, or one done years ago and never updated
  • Shared logins at the front desk
  • Texting or emailing PHI from personal phones and accounts
  • Unencrypted laptops that get lost or stolen
  • Replying to online reviews in a way that confirms someone is a patient or discusses their care
  • Slow responses to patients asking for their records
  • No BAA with a billing service, IT contractor or cloud provider

Your HIPAA checklist

  1. Name a privacy officer and a security officer (in a small practice, one person can do both)
  2. Complete and document a risk analysis, and review it at least once a year
  3. Write simple policies for access, passwords, devices, email and texting
  4. Give every staff member their own login and set role-based access
  5. Turn on audit logs and review them periodically
  6. Encrypt laptops, phones and backups
  7. Get signed BAAs from every vendor that handles PHI
  8. Train staff when they join and at least yearly, and keep records
  9. Post and hand out your Notice of Privacy Practices
  10. Write a one-page breach response plan: who does what in the first 24 hours
  11. Set a process to answer records requests well within 30 days

Where software helps

Good practice software makes several of these safeguards automatic: separate logins, role-based access down to individual fields, and an audit trail of sign-ins and changes. JenPulse includes all three, which you can explore in the live demo. Whatever system you use, including ours, make sure a signed BAA is in place before you store any patient information in it.