HIPAA Isn't Optional, and It Isn't Just About Software
Every medical practice we audit believes they are HIPAA compliant. Most are not. HIPAA is a mix of technical, administrative, and physical safeguards — and the practices that get fined usually fail on the boring administrative pieces, not the technology.
The 5 Gaps We See Constantly
1. No Documented Risk Assessment
HIPAA requires an annual security risk assessment. Not a "we thought about it" — a documented, written assessment. This is the single most common finding in OCR audits and the fastest way to trigger a fine.
2. Business Associate Agreements Are Missing
Any vendor who touches PHI — your cloud backup provider, your IT company, even your shredding service — needs a signed BAA on file. Most practices have three or four vendors touching PHI without one.
3. Staff Training Is Stale
HIPAA training is required annually and after any material policy change. A dusty binder from 2021 is not compliance.
4. Email Isn't Actually Secure
Sending patient info through regular email is a violation. So is texting appointment reminders that include diagnosis or treatment info. You need encrypted email and a compliant patient communication platform.
5. Nobody Owns Off-boarding
When an employee leaves, their access to EHR, email, and shared drives should be revoked the same day. We routinely find active accounts for people who left 18 months ago.
What Compliance Actually Looks Like
The Cost of Getting It Wrong
OCR fines range from $100 to $50,000 per violation, capped at $1.9M per year per category. A single stolen laptop with unencrypted PHI has cost practices over $1M. Compliance is dramatically cheaper than the alternative.
Book a HIPAA readiness review — we'll tell you exactly where you stand.
Related Articles
9 min read