HIPAA Compliance for Small Practices A Minimum Viable Program That Works
- MLJ CONSULTANCY LLC

- 12 hours ago
- 15 min read
A small practice can be caring, trusted, and well run, yet still be one lost laptop, misdirected email, or missing policy away from a serious compliance problem.
The Health Insurance Portability and Accountability Act, better known as HIPAA, sets national rules for protecting certain health information. The U.S. Department of Health and Human Services enforces these rules through its Office for Civil Rights. For small practices, the hard part is rarely the goal. Everyone understands that patient information deserves care. The hard part is building a system that works without turning the practice into a paperwork machine.
That is where a minimum viable compliance program helps.
Minimum viable does not mean doing the least possible or cutting corners. It means building the smallest complete program that meets core requirements, reduces real risk, and can be maintained by a small team. It is practical, documented, and repeatable. It also grows over time.
This article is informational only and is not legal advice. For questions about specific legal duties, speak with qualified counsel or a compliance professional.

What a minimum viable compliance program really means
A minimum viable compliance program is the working foundation of HIPAA compliance for small practices. It covers the essential pieces that regulators, patients, and staff expect to see:
A current risk assessment
Written policies and procedures
Staff training
Access controls for patient information
A plan for handling incidents
Documentation that shows what the practice did and when
This program should fit the size and risk level of the practice. A two-provider therapy office does not need the same internal structure as a large hospital system. The HIPAA Security Rule recognizes this by allowing covered entities to consider factors such as size, complexity, technical setup, cost, and the likelihood of risk when choosing safeguards.
That flexibility matters. It means a small practice can build a real program without copying a hospital policy binder.
A useful minimum viable program answers four basic questions:
Where is patient information stored, used, and shared?
What could go wrong?
What safeguards are in place now?
What will the practice do next to reduce risk?
If the practice can answer those questions with current documents, assigned responsibility, and evidence of follow-through, it has moved from guessing to managing.
The HIPAA basics every small practice should understand
HIPAA has several parts, but small practices should pay close attention to three major areas.
The Privacy Rule controls how patient information is used and shared
The Privacy Rule covers protected health information. That means individually identifiable health information, such as a patient’s name with a diagnosis, test result, medication list, billing record, or appointment detail.
The Privacy Rule gives patients rights, including the right to access their records, request corrections, and receive a notice that explains how their information may be used. It also sets limits on when a practice may use or disclose patient information.
For example, a practice may generally use patient information for treatment, payment, and health care operations. But sharing information with a family member, employer, attorney, or outside party may require closer review.
The Security Rule protects electronic patient information
The Security Rule applies to electronic protected health information. That means patient information stored or sent electronically, such as in an electronic health record, billing system, email, cloud storage account, scanned document, or backup drive.
The Security Rule requires administrative, physical, and technical safeguards. In plain language, that means a practice needs rules, physical protections, and technology settings that reduce the chance of improper access or loss.
Examples include:
Unique user accounts
Strong passwords
Limits on who can see records
Secure backup practices
Device protection
Staff training
Review of system activity when appropriate
The Breach Notification Rule explains what to do after certain incidents
A breach is an impermissible use or disclosure of protected health information that compromises its privacy or security. Not every mistake is automatically a reportable breach, but every incident should be reviewed.
A small practice should have a written incident response process before something happens. The Office for Civil Rights provides guidance on breach notification, including notice to affected individuals, the federal government, and in some cases the media. Timing and content matter, so prompt review is important.
Start with a risk assessment that is small but serious
The risk assessment is the backbone of a minimum viable program. The HIPAA Security Rule requires covered entities to conduct an accurate and thorough assessment of potential risks and vulnerabilities to electronic patient information.
That can sound intimidating. It does not need to be.
A small-practice risk assessment can begin with a simple inventory and a structured review. The point is to identify where patient information lives, how it moves, who can access it, and where it could be exposed.
Build a simple information map
Start by listing every place patient information is created, received, stored, or sent.
Common locations include:
Electronic health record systems
Billing platforms
Email accounts
Patient intake forms
Scanned records
Fax machines
Voicemail systems
Text messages, if used
Laptops, tablets, and phones
External drives
Paper charts
Cloud storage
Backup systems
Vendor portals
Then list who has access. Include employees, contractors, billing services, technology support, answering services, and any other outside service that may handle patient information.
A small practice often finds risk in ordinary places. A shared login. A laptop with no screen lock. Old paper records in an unlocked storage room. Appointment details left on voicemail without a clear practice policy. These are fixable, but only after someone sees them.
Rate risks in plain language
A simple risk rating can work well. Use three levels:
Risk level | What it means | Example |
High | Likely to happen or could create serious harm | Staff share one login to a record system |
Medium | Possible and could cause moderate harm | Paper records are stored in a room with limited control |
Low | Less likely or smaller impact | A rarely used form needs updated wording |
This helps the practice decide what to fix first. High-risk items should move to the top of the list.
Turn findings into a work plan
A risk assessment should not end as a document no one reads. It should create a short work plan with owners and dates.
For example:
Replace shared logins with individual accounts by March 15
Add automatic screen locks to clinic devices this week
Update the patient record request process by April 1
Review vendor agreements this month
Add breach response training to the next staff meeting
The Office for Civil Rights has repeatedly stated through guidance and enforcement materials that risk analysis and risk management are central to HIPAA Security Rule compliance. For a small practice, that means the assessment should be practical, dated, and reviewed at least once a year, or sooner after major changes.

Build the core program around three essential pillars
A minimum viable program works best when it focuses on a few strong pillars. For most small practices, those pillars are risk assessment, training, and documentation.
Risk assessment keeps the program honest
The risk assessment tells the practice what needs attention. Without it, compliance becomes a stack of generic policies that may not match real workflows.
For example, a practice that never uses text messaging has different risk than a practice that sends appointment details by text. A practice with remote staff has different risk than one that works only from a clinic. A practice that stores old paper charts has different risk than one that has fully moved to electronic records.
The assessment should reflect how the practice actually operates.
Employee training makes privacy part of daily work
HIPAA training should happen when a staff member starts and on a regular basis after that. It should also happen when policies change or when an incident shows a knowledge gap.
Training does not need to be long to be useful. A focused 30-minute session on real practice tasks may work better than a long lecture.
Useful training topics include:
How to verify a patient’s identity before sharing information
What to do when someone requests records
How to handle calls from family members
How to protect screens, papers, and devices
How to report a suspected privacy or security incident
What information can and cannot be sent by email or text
How to recognize suspicious messages
Why shared passwords are not allowed
Use examples that match the practice.
A front desk employee may need examples about waiting room conversations, phone calls, and appointment reminders. A clinician may need examples about notes, consultations, and patient portal messages. A billing employee may need examples about payer requests and claim details.
Training should also create a clear rule: report problems quickly, even if the staff member is unsure. Many small incidents become harder to manage because people wait too long to speak up.
Documentation proves the work happened
Documentation is the part many small practices put off. It can feel tedious, but it protects the practice. It shows that compliance is not just an intention.
Good documentation includes:
Risk assessments
Training records
Signed workforce confidentiality acknowledgments
Policies and procedures
Incident reports and investigation notes
Vendor agreements when required
Patient requests for records and responses
Sanction records for policy violations
Access review notes
Meeting notes when compliance decisions are made
HIPAA requires certain documentation to be retained for six years from the date of creation or the date when it last was in effect, whichever is later. That rule makes organized recordkeeping more than a preference.
A simple folder system can be enough. The key is consistency. Store compliance records in a secure place, limit access, and use clear file names with dates.
Create policies that people can actually follow
Policies should tell staff what to do in common situations. They should not read like copied legal text.
A small practice can start with a compact policy set. Each policy should be short, plain, and tied to a real workflow.
The first policies to write or update
Start with these:
Notice of privacy practices
Patient access to records
Uses and disclosures of patient information
Minimum necessary use of information
Staff confidentiality
Passwords and user access
Device and workstation security
Email, texting, and voicemail
Paper record handling
Incident reporting
Breach review and notification
Vendor and business associate review
Record retention
Staff discipline for policy violations
The “minimum necessary” standard deserves special attention. In many situations, HIPAA expects covered entities to use or disclose only the information needed for the purpose. For example, a billing employee may need insurance and diagnosis information for a claim, but not the full psychotherapy note or unrelated clinical details.
Match policies to real-life decisions
A policy should answer common staff questions.
Can a parent get records for an adult child? What should staff do if a patient asks for records by email? Can appointment reminders include the provider’s specialty? Can lab results be left on voicemail? What happens if a fax goes to the wrong number?
If a policy does not help with real decisions, staff will improvise. Improvisation is where risk grows.
Review policies on a schedule
Set a yearly review date. Also review policies when something changes, such as:
New record system
New location
New remote work process
New vendor
New communication method
New type of service
Privacy incident
A review does not always require major edits. Sometimes the result is “reviewed, no changes needed.” Document that too.

Handle vendors before they become a weak spot
Many small practices rely on outside services. Billing companies, record storage services, shredding services, technology support, answering services, transcription services, and cloud-based tools may all touch patient information.
Under HIPAA, some vendors are “business associates.” A business associate is a person or organization that performs certain services for a covered entity and needs access to protected health information to do that work. When a vendor is a business associate, the practice generally needs a written business associate agreement.
That agreement should describe how the vendor will protect patient information and what must happen if there is an incident.
A practical vendor review can use these questions:
Does the vendor create, receive, maintain, or send patient information for the practice?
Is there a signed business associate agreement if one is needed?
Who owns the relationship with the vendor inside the practice?
What type of patient information does the vendor access?
How would the practice contact the vendor during an incident?
When was the agreement last reviewed?
Do not assume a vendor is safe because it is common in health care. The practice still needs to understand the relationship and keep records.
Reduce risk with practical safeguards that do not require a large budget
A small practice can reduce a lot of risk with basic safeguards. Many of these are low-cost and based on habits, settings, and clear responsibility.
Control access to patient information
Use individual logins. Do not allow shared accounts. Each person should have access based on their role.
A front desk employee may need scheduling and demographic information. A clinician needs clinical records for patients they treat. A billing employee needs billing-related information. Not everyone needs access to everything.
Remove access quickly when someone leaves the practice. This includes record systems, email, voicemail, billing tools, building access, and any shared storage.
Use strong sign-in practices
Use strong passwords and change them when there is a reason, such as suspected compromise or staff departure. If available, use multi-factor authentication. That means a user needs more than a password to sign in, such as a code or app prompt.
This is one of the clearest ways to reduce account takeover risk.
Protect devices
Every device that can access patient information should have basic protections.
That includes:
Screen lock after a short period of inactivity
Password or passcode protection
Security updates installed
Remote wipe if the device is lost, when available
Encrypted storage, when available
No shared devices without clear rules
Lost and stolen devices have long been a common source of health data incidents. Device protection is not optional housekeeping. It is part of the compliance program.
Be careful with email, texting, and voicemail
Communication tools create daily risk because they are easy to use quickly.
Set rules for:
What can be sent by email
What can be sent by text
Whether staff may include diagnoses or test details
How to verify recipient addresses and numbers
What may be left on voicemail
How patients can request a less private communication method
HIPAA allows some flexibility for patient communication, but the practice needs a clear process. Patients may prefer convenience, yet the practice still needs to explain risks when appropriate and document choices.
Keep paper records under control
Paper still matters. Intake forms, printed schedules, referral notes, lab reports, and old charts can all expose patient information.
Use simple rules:
Do not leave records where other patients can see them
Turn papers face down when not in use
Lock records when unattended
Use secure disposal for documents
Confirm fax numbers before sending
Pick up printed documents right away
A clean counter can be a privacy safeguard.
Train the team with short sessions and real scenarios
Training should not feel like a yearly punishment. It should help staff handle situations they face every week.
A minimum viable training plan can include:
New hire training before system access
Annual refresher training
Short updates after policy changes
Incident-based refreshers when mistakes happen
Role-specific examples for different tasks
Here are sample scenarios that work well in small practices.
A family member asks for test results
A patient’s sibling calls and asks for lab results. The staff member knows the sibling by name.
The safe response is to verify whether the patient has authorized the disclosure or whether another rule allows it. Familiarity is not enough.
A patient asks for records by email
The patient wants records sent to a personal email account.
Staff should follow the practice’s patient access policy. In many cases, patients have a right to receive records in the form and format they request if readily producible. The practice should explain security risks when needed and document the request and response.
A laptop goes missing
A staff member reports that a laptop used for practice work is missing.
The practice should follow its incident plan right away. It should identify what information was on the device, whether it was protected, who may be affected, and whether breach notification is required.
A staff member sees a neighbor’s chart
A team member notices that a neighbor is a patient and opens the chart out of curiosity.
That is not a treatment or work reason. The practice should treat it as a policy violation, review what was accessed, document the response, and apply sanctions based on its policy.
Real examples help staff understand that privacy is not abstract. It is a daily duty.
Keep documentation light but complete
A small practice does not need a complex system to document compliance. It needs reliable habits.
Create one secure compliance folder with sections such as:
Risk assessment
Policies
Training
Incidents
Vendors
Patient rights requests
Access reviews
Compliance work plan
Each section should have dated records. If the practice holds a training session, save the agenda, date, attendees, and topics. If the practice reviews access, save the date, reviewer, systems checked, and changes made. If an incident occurs, save the report, review notes, decision, and any follow-up steps.
Documentation should show a clear path:
The practice identified a risk.
The practice made a decision.
The practice took action.
The practice checked or updated the item later.
That pattern matters because compliance is judged not only by whether an incident occurred, but by whether the practice had reasonable safeguards and responded properly.
Common challenges and practical solutions
Small practices often face the same barriers. None of them mean compliance is out of reach.
Challenge | Why it happens | Practical solution |
No dedicated compliance officer | The team is small and people cover many roles | Assign one privacy lead and one backup, even if compliance is only part of their job |
Policies are too generic | Templates were copied without review | Rewrite policies around actual workflows and common questions |
Training gets delayed | Patient care and billing feel more urgent | Schedule short training blocks quarterly instead of one long session |
Risk assessment feels too large | The practice does not know where to start | Begin with an inventory of systems, devices, paper records, and vendors |
Staff fear reporting mistakes | People worry they will be blamed | Create a clear rule that fast reporting helps protect patients and the practice |
Vendor files are incomplete | Agreements were signed at different times | Build a vendor list and review a few each week until current |
Documentation is scattered | Records live in email, paper folders, and local files | Create one secure compliance folder with dated subfolders |
Technology settings are unclear | Outside support manages systems | Ask for a written summary of user access, backups, security updates, and device protections |
The common thread is consistency. HIPAA Compliance becomes easier when the practice uses repeatable routines instead of last-minute fixes.
A 30-day plan for a minimum viable program
A small practice can make meaningful progress in one month. The goal is not perfection. The goal is a complete starting point.
Week 1 starts with ownership and inventory
Assign a privacy lead and a backup. They do not need to be lawyers or technology experts. They need authority to organize the work and ask questions.
Create the first inventory:
Systems that store patient information
Devices used for patient information
Paper record locations
Communication methods
Vendors
Staff roles with access
Save the inventory in the compliance folder and date it.
Week 2 focuses on risk and quick fixes
Use the inventory to identify high-risk items.
Look for:
Shared logins
Former staff with active access
Devices without screen locks
Unlocked paper records
Missing vendor agreements
Staff uncertainty around record requests
No written incident process
Fix what can be fixed quickly. For larger items, add them to the work plan with dates.
Week 3 builds policies and training
Draft or update the core policies. Keep them plain. Focus on the decisions staff actually make.
Hold a short staff training session. Cover:
Patient privacy basics
Proper access
Record requests
Communication rules
Incident reporting
Device and paper safeguards
Document the date, attendees, and topics.
Week 4 completes documentation and review
Create or update the compliance folder. Add:
Risk assessment
Work plan
Policies
Training record
Vendor list
Incident response process
Access review notes
Then schedule the next review. Put it on the calendar now. A program that is not reviewed will fade under daily pressure.
What good looks like after the first month
After 30 days, a small practice should be able to show:
A named privacy lead and backup
A current list of systems, devices, records, and vendors
A basic risk assessment
A prioritized work plan
Staff training records
Core policies
A process for incidents
A secure place for compliance documentation
Evidence that high-risk items are being addressed
This is the heart of a minimum viable program. It is not everything a practice will ever need, but it is enough to create order, reduce risk, and support better decisions.
When to get outside help
Some situations call for help from a qualified professional.
Get support when:
The practice has had a privacy or security incident
A patient information request is complex or disputed
The practice is unsure whether breach notification is required
Vendor relationships are unclear
The practice uses remote staff or multiple locations
Policies have not been reviewed in years
The practice has never completed a risk assessment
State law may add extra requirements
Federal HIPAA rules are only part of the picture. State privacy, medical record, and data breach laws may also apply. A small practice does not need to solve every question alone.
For guided support with building a practical compliance foundation, review the available HIPAA compliance support plans.
Frequently asked questions
Does a small practice really need a HIPAA risk assessment?
Yes. The HIPAA Security Rule requires a risk analysis for electronic protected health information. A small practice can scale the process to its size, but it should still identify systems, risks, safeguards, and next steps.
How often should HIPAA training happen?
Training should happen for new staff and on a regular basis after that. Many practices use annual training plus shorter updates when policies, systems, or risks change.
What is the most common mistake small practices make?
One common mistake is relying on informal habits instead of written processes. Staff may be careful, but without policies, training, and documentation, the practice has less proof that it manages privacy and security in a consistent way.
Do all vendors need a business associate agreement?
No. The need depends on what the vendor does and whether the vendor creates, receives, maintains, or sends protected health information for the practice. Vendors that perform covered services involving patient information often need one.
Is HIPAA compliance a one-time project?
No. A practice should review risks, policies, training, vendors, and incidents over time. The first program creates the foundation. Ongoing review keeps it useful.

Build the program you can maintain
HIPAA does not require small practices to act like large hospital systems. It does require reasonable safeguards, thoughtful policies, trained staff, and records that show the work was done.
A minimum viable compliance program gives the practice a realistic path. Start with the patient information you handle every day. Identify the biggest risks. Train the team on real situations. Keep clear documentation. Review the program on a schedule.
That foundation will not remove every risk. It will make the practice better prepared, more consistent, and less likely to be surprised by preventable problems.





Comments