Cybersecurity and HIPAA compliance for small healthcare practices.
A behavioral health group with six locations and ninety employees called me because of a form. Not a breach. A form.
Page two of their cyber insurance renewal questionnaire asked for the date of their most recent security risk analysis. What came back was a certificate from 2019, generated by an online portal after someone worked through a set of multiple choice modules. It had a seal on it. It was framed, in the billing office.
Six years of change, none of it assessed.
In the six years since that certificate was issued, the group had added telehealth across all six sites, an AI scribe, two changes of revenue cycle management vendor, and a scheduling platform nobody could confirm had a signed business associate agreement. Multi-factor authentication was on the EHR. It was not on email.
Everyone involved believed they were compliant. They had a certificate. They had policies in a binder. They had passed something.
The real risk analysis took eleven weeks. It surfaced four gaps nobody had anticipated, including an AI tool retaining transcripts considerably longer than anyone in the practice believed. The group answered their insurance questionnaire honestly, which they had not been able to do before, and their Recognized Security Practices clock started running in March.
That is the shape of most of this work. Not a crisis. A form, a question nobody can answer cleanly, and eleven weeks later a practice that knows what it has.
The technology problem is mostly solved. The leadership problem is not.
Encryption, MFA, endpoint detection, backup. All of it is available, affordable, and largely commoditized. No product addresses what is actually missing.
No tool decides which risks a practice accepts and which it pays to close.
No tool writes a policy that reflects how your front desk actually works.
No tool confirms your scheduling vendor signed a business associate agreement, or reads it when they did.
No tool answers a carrier's question in language a carrier accepts.
No tool explains to your board what you chose not to do, and why.
No tool produces the dated record that makes any of those choices defensible later.
Recognized Security Practices, and why the clock matters more than the controls.
Public Law 116-321 requires OCR to consider whether an organization had recognized security practices in place for the twelve months preceding an incident when it decides on penalties, audits and remedies (Public Law 116-321).
It is not a safe harbor. It creates no immunity, and its absence cannot be used to increase a penalty. It is the only mechanism in the statute that converts security investment into regulatory downside protection, and it runs on a rolling twelve-month look-back. The clock only starts when the practices actually start, which means standing up controls the week after an incident is worth nothing under this provision.
The published answer key
The companion piece is the HHS Cybersecurity Performance Goals: ten Essential and ten Enhanced, published free by the regulator (HHS). They are voluntary, and they map closely onto what the proposed Security Rule would make mandatory. That is not a coincidence, and it is the closest thing to a published answer key a practice is going to get.
Four things you can check this week.
Find the date of your last risk analysis
If it came from a portal and a quiz, it is not one. A security risk analysis examines your actual systems, data flows and vendors and produces findings specific to your practice.
List every vendor that touches patient data
Practice management software, billing company, cloud backup, email, telehealth, patient communication. Each one needs a current signed BAA. If you cannot find it, it may not exist.
Check whether MFA covers email
Not only the EHR. Email is where the attack starts, and it is the control most often left off when MFA was rolled out on the clinical system alone.
Establish what changed since the last assessment
Telehealth, AI tools and vendor swaps are the usual answers. None of them appear in an assessment conducted before they existed.
Frequently asked questions
We completed an online HIPAA course and got a certificate. Is that a risk analysis?
No. A security risk analysis examines your actual systems, data flows and vendors and produces findings specific to your practice. A course certificate records that someone answered questions correctly. OCR's Risk Analysis Initiative settlements consistently cite the failure to conduct an accurate and thorough risk analysis, and a certificate does not satisfy it.
How long does a risk analysis take?
For a multi-site practice, plan on eight to twelve weeks. The behavioral health group described above took eleven. Most of that time is spent establishing what is actually running, not writing the report.
Does our EHR vendor handle HIPAA compliance for us?
No. Your vendor is responsible for its own obligations as a business associate. How you configure the system, who has access, how it connects to other systems and whether your other vendors are papered is the practice's responsibility.
We have a local IT company. Does that cover our HIPAA requirements?
IT support and HIPAA security compliance are different jobs. Your IT company keeps your systems running. Compliance requires a documented risk assessment, written policies, BAA management and ongoing governance, none of which fall within a standard IT support contract.
What does this cost?
Assessment work is scoped as a fixed-fee engagement based on the number of locations and systems. Ongoing fractional CISO retainers start at $5,000 per month.
Not sure what your last assessment actually was?
That is the most common place this starts, and it is a thirty-minute conversation rather than a project.
