

Running a small or midsize healthcare practice means balancing patient care, staffing, billing, and the day-to-day demands of keeping the business running. Whether you manage a primary care office, a behavioral health practice, or a specialty group, cybersecurity needs an owner and a practical plan that fits your resources.
A useful starting question is simple: has your practice completed a documented HIPAA security risk analysis, and does it still reflect how you operate? For a practice covered by HIPAA, that analysis is already required. It should identify risks to electronic protected health information, or ePHI, across the practice.
This post covers what recent OCR enforcement cases can teach you, where gaps in your systems and workflows can arise, and how to prepare for a conversation with your cyber insurance broker. The goal is to help you protect patient information and keep your practice operating with fewer avoidable disruptions.
Your practice depends on reliable access to patient records, scheduling, billing, and communications. A security incident can interrupt those activities, even when the practice itself is small.
Consider the information your practice may hold: patient names, dates of birth, insurance information, treatment histories, clinical notes, imaging, and payment details. Protecting that information is part of protecting the care your patients rely on and the trust they place in your team.
An internal IT team or a managed service provider may handle your systems, but responsibility for security decisions, HIPAA documentation, and follow-through still needs to be clear. Ask who owns each part of the work and whether it is included in your current support arrangement.
Your review should also cover the vendors that store, process, or transmit patient information for your practice. Map where that information goes and clarify who handles access, backups, and incident response. Outsourcing a service does not remove the need to understand the risks associated with it.
The Office for Civil Rights, or OCR, enforces HIPAA across covered healthcare organizations. Two 2025 cases involving imaging providers show why a risk analysis needs to cover every system that actually holds patient information, not just the main electronic health record.
These two cases do not establish a trend for every type of practice. They illustrate a practical lesson: include all systems that hold ePHI in your risk analysis, including systems outside your main electronic health record platform. A small settlement amount, as in the Vision Upright MRI case, does not mean the underlying finding was minor. The same missing risk analysis produced a $350,000 penalty in the other case.
Patient access to records is a separate responsibility. HIPAA generally gives patients the right to access information in their designated record set, subject to specified exceptions. Your practice should have a clear process for receiving, tracking, and responding to those requests.
A risk analysis does not replace that records-request process, and a written report alone does not complete your security program. You also need to address the risks it identifies, assign responsibility, and review your safeguards as your practice changes.
Software can support HIPAA compliance, but buying a platform does not establish that your practice meets its obligations.
Your electronic health record (EHR), practice management, billing, and patient communication systems all need attention. Review the security features available, how your team actually uses them, and which responsibilities belong to your practice versus the vendor. Vendors that qualify as business associates have their own HIPAA obligations; your practice retains its responsibilities as a covered entity.
Configuration and process gaps to check for include:
These gaps can involve software limitations, configuration choices, or day-to-day workflows. Work with your IT team and vendors to understand the cause, agree on the fix, and document who will follow through.
The proposed HIPAA Security Rule, published in the Federal Register on January 6, 2025, would eliminate the distinction between "addressable" and "required" implementation specifications, with specific, limited exceptions. Under the current rule, "addressable" does not mean optional: practices must evaluate whether a safeguard is reasonable and appropriate and document that decision, including an equivalent alternative where one is reasonable and appropriate (Federal Register).
HHS continues to describe these changes as proposed. The existing Security Rule remains in effect, and a projected rulemaking date is not a compliance deadline.
Selected proposed changes relevant to practices covered by HIPAA:
| Proposed change | What it would mean for your practice |
|---|---|
| Encryption of ePHI at rest and in transit | Encrypt ePHI, subject to limited exceptions. |
| Multi-factor authentication | Use MFA for covered access, subject to limited exceptions. |
| Risk analysis at least every 12 months | Update the analysis on an ongoing basis, at least annually and when relevant changes occur. |
| Penetration testing at least every 12 months | Test relevant systems at least annually, or more often as the risk analysis requires. |
| Technology asset inventory and network map | Document relevant technology assets and ePHI flows; review at least annually and after relevant changes. |
| Restoration procedures with a 72-hour timeframe | Establish procedures to restore certain systems and data within 72 hours. This concerns recovery, not breach reporting. |
A proposed rule is not a reason to postpone current obligations. Risk analysis and risk management are already required, and your practice still needs appropriate safeguards today. Use these proposals to inform planning, while keeping your immediate focus on the requirements that already apply (HHS fact sheet).
The proposed 72-hour restoration provision concerns recovery, not breach notification. For a reportable breach of unsecured PHI, individual notice is generally due without unreasonable delay and no later than 60 calendar days after discovery. HHS must also be notified within that timeframe for breaches affecting 500 or more people; smaller breaches may be reported annually, within 60 days after the end of the year in which they were discovered. Breaches affecting more than 500 residents of a state or jurisdiction also require media notice (HHS, Breach Notification Rule).
Cyber insurance renewal is a useful time to review your safeguards and the evidence supporting your application. Ask your broker for the current questionnaire early enough to address gaps before your renewal date.
Requirements vary by insurer, policy, and the risks being insured. Be prepared to discuss and document:
If a control is missing or only partly implemented, explain that accurately. Ask your broker how it may affect eligibility, pricing, or coverage terms. The outcome depends on the insurer and the policy; a gap does not automatically mean coverage will be denied.
Starting early gives your practice time to make improvements and provide accurate documentation. Avoid answering yes to an application question until you have verified the control is in place for the scope the insurer asks about.
The decision depends on your practice's complexity, risks, and existing resources. If you need experienced security leadership but cannot justify a full-time Chief Information Security Officer, a fractional or virtual CISO can help you set priorities and coordinate the work.
A vCISO can work with your practice manager, IT team, and service providers to:
At Cybersecurity Advisory Group, that work can begin with a HIPAA risk assessment and a prioritized plan. Ongoing advisory support through a vCISO retainer helps your practice address the findings, coordinate with IT, and keep the security program current as you grow.
If you manage a healthcare practice and you are not sure where your security posture stands, here is where to start.
Step 1: Review your Business Associate Agreements. List the vendors that handle patient information, including your EHR, billing, cloud backup, and patient communication providers. Determine which qualify as business associates and confirm the required agreements are in place. Not every vendor relationship requires a BAA; the determination depends on the services and information involved.
Step 2: Audit your user accounts. How many people have login access to your EHR, practice management software, email, and billing systems? When did you last remove a former employee's access? Do any accounts share a password? Review permissions by job role and make access removal part of your employee departure process.
Step 3: Review MFA with your IT provider. Check whether multi-factor authentication is enabled for email, remote access, and systems that handle patient information. If a system does not support it, ask your provider about available protections and document the gap. Confirm your insurer's specific requirements rather than assuming all policies are the same.
Step 4: Verify your backups. When were your patient records last backed up? Where are those backups stored? Have you tested whether you can restore from them? Ask your IT provider to verify that backups are protected and that your recovery process works. Backups support recovery, but they do not prevent stolen information from being exposed.
Step 5: Schedule or update your HIPAA risk assessment. Include the systems and workflows that create, receive, maintain, or transmit ePHI. Use the findings to set priorities, assign owners, and track corrective actions. Revisit the assessment when changes in your practice or its risks call for an update.
No. The platform may support compliance, but your practice must still meet its own obligations. Review your configuration, staff access, workflows, and the responsibilities shared with the vendor.
It depends on the services in your agreement. Some providers offer security and compliance support; others focus on keeping systems running. Confirm who handles the risk assessment, policies, vendor oversight, and follow-up work, and ask for the documentation.
Costs depend on your locations, systems, vendors, and the scope of the assessment. Cybersecurity Advisory Group provides HIPAA risk assessments for small and midsize healthcare practices, with recommendations that reflect how the practice operates.
Ask your broker about the specific gap and available options. The insurer may request improvements or offer different pricing or terms. Eligibility and coverage depend on the application, underwriting decision, and policy wording.
Whether you run a primary care office, a behavioral health practice, or a specialty group, start by understanding where patient information lives and who is responsible for protecting it.
A documented risk assessment gives you a basis for deciding what to address first. Pair it with an action plan, appropriate safeguards, staff training, and follow-up that fits your practice's resources.
Cybersecurity Advisory Group provides healthcare cybersecurity consulting without the Fortune 500 price tag. Whether you are updating an overdue risk analysis, closing EHR configuration gaps, or preparing for a cyber insurance renewal, a HIPAA Risk Assessment & Compliance Program or a vCISO Retainer is the place to start. Cybersecurity Advisory Group also works with dental offices and behavioral health practices on the same fundamentals.
Book a free 30-minute Security Clarity Session. We'll go through where your practice's security posture actually stands today and what a realistic first year looks like. No pressure, no jargon, and no homework before we talk.
Book Your Free 30-Minute Security Clarity Session →
Melissa Thornton is the founder of Cybersecurity Advisory Group, providing virtual CISO and fractional cybersecurity leadership to healthcare organizations, startups, and SMBs. Based in White Plains, NY, serving clients remotely nationwide. sales@cyberadvisor.tech · +1 914-517-0022
This article is provided for general informational purposes and does not constitute legal advice.
Connect with Melissa Thornton on LinkedIn