Your Healthcare Practice Has Never Had a HIPAA Risk Assessment. Here Is Where to Start.

September 28, 2026
September 28, 2026
By Melissa Thornton, CISSP | Cybersecurity Advisory Group | cyberadvisor.tech

‍

Running a small or midsize healthcare practice means balancing patient care, staffing, billing, and the day-to-day demands of keeping the business running. Whether you manage a primary care office, a behavioral health practice, or a specialty group, cybersecurity needs an owner and a practical plan that fits your resources.

A useful starting question is simple: has your practice completed a documented HIPAA security risk analysis, and does it still reflect how you operate? For a practice covered by HIPAA, that analysis is already required. It should identify risks to electronic protected health information, or ePHI, across the practice.

This post covers what recent OCR enforcement cases can teach you, where gaps in your systems and workflows can arise, and how to prepare for a conversation with your cyber insurance broker. The goal is to help you protect patient information and keep your practice operating with fewer avoidable disruptions.

Why Cybersecurity Matters for Small and Midsize Healthcare Practices

‍

Your practice depends on reliable access to patient records, scheduling, billing, and communications. A security incident can interrupt those activities, even when the practice itself is small.

Consider the information your practice may hold: patient names, dates of birth, insurance information, treatment histories, clinical notes, imaging, and payment details. Protecting that information is part of protecting the care your patients rely on and the trust they place in your team.

An internal IT team or a managed service provider may handle your systems, but responsibility for security decisions, HIPAA documentation, and follow-through still needs to be clear. Ask who owns each part of the work and whether it is included in your current support arrangement.

Your review should also cover the vendors that store, process, or transmit patient information for your practice. Map where that information goes and clarify who handles access, backups, and incident response. Outsourcing a service does not remove the need to understand the risks associated with it.

What Recent OCR Enforcement Cases Can Teach You

‍

The Office for Civil Rights, or OCR, enforces HIPAA across covered healthcare organizations. Two 2025 cases involving imaging providers show why a risk analysis needs to cover every system that actually holds patient information, not just the main electronic health record.

  • Northeast Radiology, which provides clinical services at imaging centers in New York and Connecticut, agreed to pay $350,000 in an April 2025 settlement. OCR found the practice had not conducted an accurate and thorough risk analysis. The investigation followed unauthorized access, between April 2019 and January 2020, to the picture archiving and communication system (PACS) used to store and manage radiology images, after security researchers had flagged vulnerabilities in that system in 2019 (HHS; HIPAA Journal).
  • Vision Upright MRI, a California imaging provider, settled with OCR in May 2025 for $5,000. OCR reported that the provider had never conducted a comprehensive and accurate risk analysis, and had failed to notify affected individuals within 60 days of discovering a breach that involved an unsecured PACS server accessed by an unauthorized third party (HHS; HIPAA Journal).

These two cases do not establish a trend for every type of practice. They illustrate a practical lesson: include all systems that hold ePHI in your risk analysis, including systems outside your main electronic health record platform. A small settlement amount, as in the Vision Upright MRI case, does not mean the underlying finding was minor. The same missing risk analysis produced a $350,000 penalty in the other case.

Patient access to records is a separate responsibility. HIPAA generally gives patients the right to access information in their designated record set, subject to specified exceptions. Your practice should have a clear process for receiving, tracking, and responding to those requests.

A risk analysis does not replace that records-request process, and a written report alone does not complete your security program. You also need to address the risks it identifies, assign responsibility, and review your safeguards as your practice changes.

Does Your EHR or Practice Management Software Make You HIPAA Compliant?

‍

Software can support HIPAA compliance, but buying a platform does not establish that your practice meets its obligations.

Your electronic health record (EHR), practice management, billing, and patient communication systems all need attention. Review the security features available, how your team actually uses them, and which responsibilities belong to your practice versus the vendor. Vendors that qualify as business associates have their own HIPAA obligations; your practice retains its responsibilities as a covered entity.

Configuration and process gaps to check for include:

  • No role-based access controls: every staff member, from the front desk to the clinical team, has access to the same patient data with the same permissions.
  • Automatic login or shared passwords: staff log in once and leave the system open all day, meaning anyone who walks up to that terminal can access patient records.
  • Unencrypted backups: patient data is backed up to an external hard drive or local server with no encryption, making it fully readable if stolen.
  • No audit logging reviewed: the software logs who accessed what records and when, but no one has ever looked at those logs.
  • Outdated software versions: updates that patch known security vulnerabilities are not applied because there is no clear owner or maintenance schedule.

These gaps can involve software limitations, configuration choices, or day-to-day workflows. Work with your IT team and vendors to understand the cause, agree on the fix, and document who will follow through.

What the Proposed HIPAA Security Rule Would Mean for Your Practice

‍

The proposed HIPAA Security Rule, published in the Federal Register on January 6, 2025, would eliminate the distinction between "addressable" and "required" implementation specifications, with specific, limited exceptions. Under the current rule, "addressable" does not mean optional: practices must evaluate whether a safeguard is reasonable and appropriate and document that decision, including an equivalent alternative where one is reasonable and appropriate (Federal Register).

HHS continues to describe these changes as proposed. The existing Security Rule remains in effect, and a projected rulemaking date is not a compliance deadline.

Selected proposed changes relevant to practices covered by HIPAA:

Proposed changeWhat it would mean for your practice
Encryption of ePHI at rest and in transitEncrypt ePHI, subject to limited exceptions.
Multi-factor authenticationUse MFA for covered access, subject to limited exceptions.
Risk analysis at least every 12 monthsUpdate the analysis on an ongoing basis, at least annually and when relevant changes occur.
Penetration testing at least every 12 monthsTest relevant systems at least annually, or more often as the risk analysis requires.
Technology asset inventory and network mapDocument relevant technology assets and ePHI flows; review at least annually and after relevant changes.
Restoration procedures with a 72-hour timeframeEstablish procedures to restore certain systems and data within 72 hours. This concerns recovery, not breach reporting.

A proposed rule is not a reason to postpone current obligations. Risk analysis and risk management are already required, and your practice still needs appropriate safeguards today. Use these proposals to inform planning, while keeping your immediate focus on the requirements that already apply (HHS fact sheet).

The proposed 72-hour restoration provision concerns recovery, not breach notification. For a reportable breach of unsecured PHI, individual notice is generally due without unreasonable delay and no later than 60 calendar days after discovery. HHS must also be notified within that timeframe for breaches affecting 500 or more people; smaller breaches may be reported annually, within 60 days after the end of the year in which they were discovered. Breaches affecting more than 500 residents of a state or jurisdiction also require media notice (HHS, Breach Notification Rule).

How Should Your Practice Prepare for Cyber Insurance Renewal?

‍

Cyber insurance renewal is a useful time to review your safeguards and the evidence supporting your application. Ask your broker for the current questionnaire early enough to address gaps before your renewal date.

Requirements vary by insurer, policy, and the risks being insured. Be prepared to discuss and document:

  • Where multi-factor authentication is enabled, including email and remote access
  • Whether endpoint detection and response (EDR) protects your practice computers
  • How backups are protected, separated from production systems, and tested
  • Your incident response plan and who is responsible for carrying it out
  • When your HIPAA risk assessment was last completed or updated, and how you are addressing its findings
  • Your staff security awareness training and the records showing it was completed

If a control is missing or only partly implemented, explain that accurately. Ask your broker how it may affect eligibility, pricing, or coverage terms. The outcome depends on the insurer and the policy; a gap does not automatically mean coverage will be denied.

Starting early gives your practice time to make improvements and provide accurate documentation. Avoid answering yes to an application question until you have verified the control is in place for the scope the insurer asks about.

When Does a Small or Midsize Healthcare Practice Need a vCISO?

‍

The decision depends on your practice's complexity, risks, and existing resources. If you need experienced security leadership but cannot justify a full-time Chief Information Security Officer, a fractional or virtual CISO can help you set priorities and coordinate the work.

A vCISO can work with your practice manager, IT team, and service providers to:

  • Complete a HIPAA risk assessment and produce documentation you can show to OCR or your insurer
  • Review your Business Associate Agreements with your practice management vendor, billing company, and any cloud services you use
  • Build written security policies that reflect how your office actually operates
  • Work with your IT team and software vendors to implement appropriate access controls and audit logging
  • Create a basic incident response plan so your staff knows exactly what to do if something goes wrong
  • Prepare you for cyber insurance renewal with the documentation your carrier requires

At Cybersecurity Advisory Group, that work can begin with a HIPAA risk assessment and a prioritized plan. Ongoing advisory support through a vCISO retainer helps your practice address the findings, coordinate with IT, and keep the security program current as you grow.

What Should a Healthcare Practice Do Right Now?

‍

If you manage a healthcare practice and you are not sure where your security posture stands, here is where to start.

Step 1: Review your Business Associate Agreements. List the vendors that handle patient information, including your EHR, billing, cloud backup, and patient communication providers. Determine which qualify as business associates and confirm the required agreements are in place. Not every vendor relationship requires a BAA; the determination depends on the services and information involved.

Step 2: Audit your user accounts. How many people have login access to your EHR, practice management software, email, and billing systems? When did you last remove a former employee's access? Do any accounts share a password? Review permissions by job role and make access removal part of your employee departure process.

Step 3: Review MFA with your IT provider. Check whether multi-factor authentication is enabled for email, remote access, and systems that handle patient information. If a system does not support it, ask your provider about available protections and document the gap. Confirm your insurer's specific requirements rather than assuming all policies are the same.

Step 4: Verify your backups. When were your patient records last backed up? Where are those backups stored? Have you tested whether you can restore from them? Ask your IT provider to verify that backups are protected and that your recovery process works. Backups support recovery, but they do not prevent stolen information from being exposed.

Step 5: Schedule or update your HIPAA risk assessment. Include the systems and workflows that create, receive, maintain, or transmit ePHI. Use the findings to set priorities, assign owners, and track corrective actions. Revisit the assessment when changes in your practice or its risks call for an update.

Frequently Asked Questions

‍

Does using an EHR advertised as HIPAA compliant make our practice compliant?

No. The platform may support compliance, but your practice must still meet its own obligations. Review your configuration, staff access, workflows, and the responsibilities shared with the vendor.

We have a local IT company. Doesn't that cover our HIPAA requirements?

It depends on the services in your agreement. Some providers offer security and compliance support; others focus on keeping systems running. Confirm who handles the risk assessment, policies, vendor oversight, and follow-up work, and ask for the documentation.

How much does a HIPAA risk assessment cost for a healthcare practice?

Costs depend on your locations, systems, vendors, and the scope of the assessment. Cybersecurity Advisory Group provides HIPAA risk assessments for small and midsize healthcare practices, with recommendations that reflect how the practice operates.

What happens if our practice does not meet a cyber insurer's requirements?

Ask your broker about the specific gap and available options. The insurer may request improvements or offer different pricing or terms. Eligibility and coverage depend on the application, underwriting decision, and policy wording.

A Practical Next Step for Your Practice

‍

Whether you run a primary care office, a behavioral health practice, or a specialty group, start by understanding where patient information lives and who is responsible for protecting it.

A documented risk assessment gives you a basis for deciding what to address first. Pair it with an action plan, appropriate safeguards, staff training, and follow-up that fits your practice's resources.

Start with 30 minutes

‍

Cybersecurity Advisory Group provides healthcare cybersecurity consulting without the Fortune 500 price tag. Whether you are updating an overdue risk analysis, closing EHR configuration gaps, or preparing for a cyber insurance renewal, a HIPAA Risk Assessment & Compliance Program or a vCISO Retainer is the place to start. Cybersecurity Advisory Group also works with dental offices and behavioral health practices on the same fundamentals.

Book a free 30-minute Security Clarity Session. We'll go through where your practice's security posture actually stands today and what a realistic first year looks like. No pressure, no jargon, and no homework before we talk.

Book Your Free 30-Minute Security Clarity Session →

‍

Melissa Thornton is the founder of Cybersecurity Advisory Group, providing virtual CISO and fractional cybersecurity leadership to healthcare organizations, startups, and SMBs. Based in White Plains, NY, serving clients remotely nationwide. sales@cyberadvisor.tech · +1 914-517-0022

This article is provided for general informational purposes and does not constitute legal advice.

Connect with Melissa Thornton on LinkedIn

Sources

‍

Related Blogs

Device inventory graphic illustrating the connected medical device landscape discussed in this article
September 26, 2026
September 26, 2026

When Security Meets Patient Care: How Health Tech Startups, Rural Hospitals, and PE Investors Can Secure Connected Medical Devices

Read More
September 2, 2026
September 2, 2026

$11.5 Million Is the Average. You're Not Average — And That's the Problem.

Read More
September 1, 2026
September 1, 2026

Nobody Told Them To

Read More