Who I Help · Small Healthcare Practices

Cybersecurity and HIPAA compliance for small healthcare practices.

A behavioral health group with six locations and ninety employees called me because of a form. Not a breach. A form.

Page two of their cyber insurance renewal questionnaire asked for the date of their most recent security risk analysis. What came back was a certificate from 2019, generated by an online portal after someone worked through a set of multiple choice modules. It had a seal on it. It was framed, in the billing office.

Eleven weeks
How long the real risk analysis took, and how long it took to find four gaps nobody had anticipated.
Exhibit A · What the certificate was hiding

Six years of change, none of it assessed.

In the six years since that certificate was issued, the group had added telehealth across all six sites, an AI scribe, two changes of revenue cycle management vendor, and a scheduling platform nobody could confirm had a signed business associate agreement. Multi-factor authentication was on the EHR. It was not on email.

The part that makes them typical, not negligent

Everyone involved believed they were compliant. They had a certificate. They had policies in a binder. They had passed something.

The real risk analysis took eleven weeks. It surfaced four gaps nobody had anticipated, including an AI tool retaining transcripts considerably longer than anyone in the practice believed. The group answered their insurance questionnaire honestly, which they had not been able to do before, and their Recognized Security Practices clock started running in March.

That is the shape of most of this work. Not a crisis. A form, a question nobody can answer cleanly, and eleven weeks later a practice that knows what it has.

Exhibit B · Why the tools did not catch it

The technology problem is mostly solved. The leadership problem is not.

Encryption, MFA, endpoint detection, backup. All of it is available, affordable, and largely commoditized. No product addresses what is actually missing.

01
Deciding what you fund

No tool decides which risks a practice accepts and which it pays to close.

02
Writing policy that matches reality

No tool writes a policy that reflects how your front desk actually works.

03
Reading the BAAs

No tool confirms your scheduling vendor signed a business associate agreement, or reads it when they did.

04
Answering the underwriter

No tool answers a carrier's question in language a carrier accepts.

05
Sitting with the owners

No tool explains to your board what you chose not to do, and why.

06
Leaving a record

No tool produces the dated record that makes any of those choices defensible later.

Exhibit C · The mechanism almost nobody uses

Recognized Security Practices, and why the clock matters more than the controls.

Public Law 116-321 requires OCR to consider whether an organization had recognized security practices in place for the twelve months preceding an incident when it decides on penalties, audits and remedies (Public Law 116-321).

It is not a safe harbor. It creates no immunity, and its absence cannot be used to increase a penalty. It is the only mechanism in the statute that converts security investment into regulatory downside protection, and it runs on a rolling twelve-month look-back. The clock only starts when the practices actually start, which means standing up controls the week after an incident is worth nothing under this provision.

The published answer key

The companion piece is the HHS Cybersecurity Performance Goals: ten Essential and ten Enhanced, published free by the regulator (HHS). They are voluntary, and they map closely onto what the proposed Security Rule would make mandatory. That is not a coincidence, and it is the closest thing to a published answer key a practice is going to get.

Exhibit D · Where to start

Four things you can check this week.

01

Find the date of your last risk analysis

If it came from a portal and a quiz, it is not one. A security risk analysis examines your actual systems, data flows and vendors and produces findings specific to your practice.

02

List every vendor that touches patient data

Practice management software, billing company, cloud backup, email, telehealth, patient communication. Each one needs a current signed BAA. If you cannot find it, it may not exist.

03

Check whether MFA covers email

Not only the EHR. Email is where the attack starts, and it is the control most often left off when MFA was rolled out on the clinical system alone.

04

Establish what changed since the last assessment

Telehealth, AI tools and vendor swaps are the usual answers. None of them appear in an assessment conducted before they existed.

Exhibit E · Questions practices ask

Frequently asked questions

We completed an online HIPAA course and got a certificate. Is that a risk analysis?

No. A security risk analysis examines your actual systems, data flows and vendors and produces findings specific to your practice. A course certificate records that someone answered questions correctly. OCR's Risk Analysis Initiative settlements consistently cite the failure to conduct an accurate and thorough risk analysis, and a certificate does not satisfy it.

How long does a risk analysis take?

For a multi-site practice, plan on eight to twelve weeks. The behavioral health group described above took eleven. Most of that time is spent establishing what is actually running, not writing the report.

Does our EHR vendor handle HIPAA compliance for us?

No. Your vendor is responsible for its own obligations as a business associate. How you configure the system, who has access, how it connects to other systems and whether your other vendors are papered is the practice's responsibility.

We have a local IT company. Does that cover our HIPAA requirements?

IT support and HIPAA security compliance are different jobs. Your IT company keeps your systems running. Compliance requires a documented risk assessment, written policies, BAA management and ongoing governance, none of which fall within a standard IT support contract.

What does this cost?

Assessment work is scoped as a fixed-fee engagement based on the number of locations and systems. Ongoing fractional CISO retainers start at $5,000 per month.

Not sure what your last assessment actually was?

That is the most common place this starts, and it is a thirty-minute conversation rather than a project.

Book a Free Security Clarity Session
Melissa Thornton, CISSP, C|CISO · Founder, Cybersecurity Advisory Group · White Plains, New YorkLast reviewed September 2026