Compliance

HIPAA Compliance Basics Every Medical Practice Gets Wrong

HIPAA fines average $50,000 per violation. Here are the five compliance gaps we find in nearly every small medical practice — and how to close them.

Jul 1, 20266 min read

HIPAA Isn't Optional, and It Isn't Just About Software

Every medical practice we audit believes they are HIPAA compliant. Most are not. HIPAA is a mix of technical, administrative, and physical safeguards — and the practices that get fined usually fail on the boring administrative pieces, not the technology.

The 5 Gaps We See Constantly

1. No Documented Risk Assessment

HIPAA requires an annual security risk assessment. Not a "we thought about it" — a documented, written assessment. This is the single most common finding in OCR audits and the fastest way to trigger a fine.

2. Business Associate Agreements Are Missing

Any vendor who touches PHI — your cloud backup provider, your IT company, even your shredding service — needs a signed BAA on file. Most practices have three or four vendors touching PHI without one.

3. Staff Training Is Stale

HIPAA training is required annually and after any material policy change. A dusty binder from 2021 is not compliance.

4. Email Isn't Actually Secure

Sending patient info through regular email is a violation. So is texting appointment reminders that include diagnosis or treatment info. You need encrypted email and a compliant patient communication platform.

5. Nobody Owns Off-boarding

When an employee leaves, their access to EHR, email, and shared drives should be revoked the same day. We routinely find active accounts for people who left 18 months ago.

What Compliance Actually Looks Like

Annual documented risk assessment
BAAs with every vendor touching PHI
Encrypted email + secure patient messaging
MFA on every clinical system
Written policies staff have actually read and signed
Quarterly access reviews
Incident response plan you've tested at least once

The Cost of Getting It Wrong

OCR fines range from $100 to $50,000 per violation, capped at $1.9M per year per category. A single stolen laptop with unencrypted PHI has cost practices over $1M. Compliance is dramatically cheaper than the alternative.

Book a HIPAA readiness review — we'll tell you exactly where you stand.

Related Articles

HIPAA, PCI, SOC 2: Which Compliance Framework Does Your Business Need?

9 min read

IT Services

Managed Services
Cloud Services
Cybersecurity
Data Backup
Web Development

Industries

Education
Financial Services
Government
Healthcare
Retail
Small Business
Legal
Manufacturing
Non-Profit
About Us
Careers
Contact
All Services
All Industries

Book a free consultation

Need a Clearer IT Strategy?

Tell us a bit about your business and pick a time that works. We'll respond within one business day to confirm your free 30-minute consultation — no obligation, no sales pressure.

  • Free 30-minute discovery call
  • Response within 1 business day
  • No obligation, no hard sell
  • Talk directly with a Sifo engineer
Choose a time