service // hipaa
HIPAA
Practical HIPAA safeguards for small practices
HIPAA sounds like a monster, but for most small practices it's about a handful of practical safeguards: access controls, encryption, staff training, business associate agreements, and a plan for what happens if something goes wrong. I make it simple and keep it proportionate to your practice.
What's included
- Gap assessment: where you stand today, in plain English
- Access controls and MFA that fit a small team
- Encryption at rest and in transit — set and forget
- Staff training that doesn’t put people to sleep
- Business Associate Agreement (BAA) review
- Breach notification plan that’s actually usable
Common questions
Does HIPAA apply to my small practice?
HIPAA applies to any organization that handles protected health information (PHI) — including small practices, dental offices, therapy practices, and their business associates. If you store, transmit, or process health data, HIPAA likely applies to you.
What are the most common HIPAA gaps in small practices?
The most common gaps are: no written security policies, shared or weak passwords, unencrypted devices and email, no staff training records, and no Business Associate Agreements with vendors who touch PHI. All of these are fixable without a compliance department.
Is HIPAA compliance a one-time project?
No — HIPAA is ongoing. But once the safeguards are in place, ongoing compliance is mostly routine: periodic reviews, training refreshers, and keeping documentation current. Think of it like a car: the initial setup matters, but so does the maintenance schedule.
What happens if we have a breach?
You need to know who to notify and when. Covered entities must notify affected individuals without unreasonable delay and in most cases within 60 days, and HHS must be notified for larger breaches. A written incident plan means you don’t figure this out under pressure.
Talk it through
A free 30-minute call to see whether HIPAA applies to you and what the first step looks like.
book the call