HIPAA for Small Healthcare Practices: Where IT Usually Breaks Down
In small practices, HIPAA problems usually aren't about missing policies. They come from things like an unpatched computer, a shared login, or a vendor no one is monitoring.
Most small dental or medical practices have their paperwork in order. Someone bought a HIPAA compliance kit a few years back, the policies are signed, the training certificates are filed, and the Notice of Privacy Practices is on the wall at the front desk.
Meanwhile, the computer attached to the panoramic X-ray machine is still running Windows 10, which stopped getting security updates on 14 October 2025.
No one made a bad decision here. That machine was never really seen as a computer. It came with the imaging equipment, it does one job, and replacing it would cost more than three years of the practice's IT budget. But about ten months ago it quietly became a risk, and it stores patient images.
This is what most HIPAA gaps look like in small practices. Not a missing policy, but a piece of equipment that gets overlooked because it doesn't feel like IT.
There is no small-practice exemption, and the enforcement record shows it
HIPAA scales how you comply with your size, not whether you have to. The Security Rule expects a solo practitioner to take steps reasonable for their situation; it doesn't mean they can ignore it. Plenty of people misread this and assume regulators only care about hospitals.
The enforcement a small practice usually faces isn't a big ransomware case. It's often a patient who couldn't get their records.
OCR's Right of Access Initiative had passed 50 enforcement actions as of January 2026, and Director Paula M. Stannard confirmed it continues through 2026 with an added focus on parents seeking access to their minor children's records. The settlements scale with the organization: a solo dental practice settled at $3,500, a hospital system at $240,000. The dollar figure isn't the story. The story is that a one-dentist practice ended up in a federal enforcement action over a records request, and that the initiative has run long enough to produce more than fifty of them.
Breaches are worth a look too. OCR's public breach portal recorded 189 large healthcare breaches in the first half of 2026, affecting over 19 million people. Most were hacking or IT incidents, not lost laptops or misdirected mail.
But the portal only shows breaches affecting 500 or more people. For a practice with 2,000 patients, a breach that size would involve most of the practice. Smaller incidents are reported to HHS once a year and don't appear on the public portal. So the data people cite leaves out most small practices. If you don't see small practices listed, that's the reporting rule, not proof they're safer.
"Addressable" is the most expensive word in the Security Rule
Ask ten practice managers what "addressable" means and most will say optional. That's wrong, and correcting it is one of the easiest HIPAA gaps to close.
HHS is clear. For an addressable requirement, you can do one of three things: implement it, use another method that achieves the same goal, or choose not to do it. All three are allowed. Here's the part most people miss: your choice has to be written down, including the reasoning and the results of your risk assessment.
So the rule lets you decide not to encrypt data at rest on a certain system, but you can't just skip it silently. The difference that protects you in an audit is the written decision.
The most expensive word in the rule
"Addressable" means you can choose not to do something, but you have to be able to explain why. Most practices only do the first part.
In reality, no one actually makes the decision. Encryption at rest on the imaging server is usually not considered, not rejected, and not documented. Doing nothing becomes the default because nobody decided otherwise, and it leaves you with nothing to show an investigator.
You can fix this in a morning. Review the addressable requirements, write down what you decided for each and why, and include your risk-assessment reasoning. You don't need to buy anything. Most practices just were never told the writing is part of the rule.
Where the IT actually breaks down
Six failure points keep turning up in small healthcare and dental offices. None of them is exotic or complicated.
1. The workstation attached to a machine
Windows 10 stopped getting support on 14 October 2025. Unless the practice paid for Extended Security Updates, which start at $61 per device for the first year and double each year for up to three years ending in October 2028, those computers haven't had security patches for about ten months.
The machines that last longest aren't the front-desk PCs. They're the ones wired to equipment: imaging units, intraoral scanners, sterilizer loggers, the old server in the closet running your practice-management database. They get overlooked because people think of them as equipment, not IT. And practice-management vendors are now dropping Windows 10 support too, which tightens the squeeze.
The real HIPAA question isn't whether the machine is old. It's whether you've listed it in your asset inventory, included it in your risk analysis, and documented your decisions about it. Assess an unsupported workstation, put it on its own network segment, and write it all down, and it's a managed risk. Leave it out of your paperwork and it's a problem waiting to be found.
2. Vendor access that nobody owns
Count how many outside parties can reach your practice network: the practice-management vendor for support, the imaging vendor, the billing or claims company, the IT provider, sometimes a separate phone or scheduling system. Five access points is common. Five people responsible for them is not.
Each of those relationships almost certainly makes the vendor a business associate under HIPAA, because they can reach systems holding protected health information. That means a current agreement describing the data movement that actually happens, not a template signed at onboarding. If those vendors use subcontractors who can also reach the data, the obligations extend to them too.
The practical question is easier than the legal one: when did someone last check who still has access, and whether the person who set it up three years ago is even still around?
3. The shared login at the front desk
Everyone understands why this happens. Four people work the front desk across two shifts, the schedule's on one screen, and separate logins felt like friction. So one account gets used by everyone.
Unique user identification is not an addressable specification. It is required, under 45 CFR §164.312(a)(2)(i). There's no documented-alternative route for this one.
The real problem is operational, not only compliance. Your practice-management system records who accessed what, but after an incident or a complaint you can only show that the account opened the chart, not which of the four people was at the keyboard. The audit trail exists and doesn't help, which can be worse than no logs at all, because you thought you had control.
4. Backups that have never been restored
A finished backup job only shows that the backup ran. It doesn't prove you can recover the data or tell you how long the practice would be closed if you had to. Those are different facts, and only the job status shows up on the dashboard.
This matters more in healthcare than most sectors, because ransomware crews now steal data before encrypting it, so a clean restore ends the outage without ending the breach. That's the argument we made in double extortion ransomware and why SMB backups aren't enough. Ask for the date of the last restore test and the recorded recovery time. If neither exists, there hasn't been a test.
5. Protected health information moving through channels nobody mapped
The risk analysis asks where ePHI is created, received, maintained, and transmitted. Most small-practice risk analyses answer "the practice-management system" and stop there, which is where they stop being accurate.
Picture an ordinary Tuesday. A referral is emailed to a specialist. Appointment reminders go out by text. A hygienist takes a photo on a personal phone to show the dentist. The back-office scanner emails documents to a shared front-desk inbox. Insurance paperwork is uploaded to a portal nobody has reviewed since setup. Each of these moves patient information, and most exist because they make someone's day easier. That's why banning them doesn't work, but mapping them does.
6. The 60-day clock nobody has rehearsed
Breach-notification timing is one of the more misunderstood parts of the rule in small practices, usually as a belief that a small breach doesn't need reporting.
Affected individuals must be notified without unreasonable delay and no later than 60 days after you discover a breach, no matter how many people are involved. Breaches affecting 500 or more must also be reported to HHS and the media within that same 60 days. Breaches affecting fewer than 500 are logged and sent to HHS within 60 days after the end of the year. That's a different reporting schedule, not an exemption, and the notification deadline for individuals is always the same.
The problem usually isn't a lack of knowledge. It's that nobody has ever walked through who decides when a breach is discovered, who writes the notification, and who decides whether an incident is a breach at all. That call tends to get made in a rush by whoever happens to be there.
What a HIPAA readiness review should actually examine
If you're arranging a review, whether with your IT provider or someone else, this is what it should cover. Notice how little of it is about documents.
What a real readiness review examines
| Area | What gets checked | What "done" looks like |
|---|---|---|
| Asset inventory | Every device and system that touches patient data, including equipment-attached workstations and anything in the closet. | A current list nobody has to reconstruct, with operating system and support status per device. |
| Identity and access | Unique logins per person, administrative accounts, MFA coverage, accounts belonging to departed staff, vendor accounts. | No shared logins, a named owner per privileged account, and a review date. |
| ePHI data flows | Where patient information is created, received, stored and sent, including email, text, scanners, portals and personal devices. | A map that matches a normal working day rather than the org chart. |
| Vendors and agreements | Who can reach the network, what they can reach, and whether agreements reflect actual data movement. | A register of access paths with current agreements, including subcontractors. |
| Encryption | At rest and in transit, across servers, workstations, portable media and backups. | Implemented, or an alternative implemented, or a written decision explaining why neither. |
| Addressable decisions | Every addressable specification and what the practice decided about it. | A documented decision file with the reasoning and the risk assessment behind it. |
| Logging | Which systems log, how long records are kept, and who reviews them. | Twelve months producible on request for systems holding patient data. |
| Backup and recovery | Not whether jobs complete, but whether a restore has been performed. | A dated restore test with a recorded recovery time. |
| Incident response | Who determines a breach occurred, who notifies, and against what clock. | A named decision-maker and a rehearsed 60-day path. |
A review run this way doesn't need you to close the practice for a day. We cover how in our piece on preparing for a compliance audit without disrupting daily operations.
How this looks when someone runs it properly
Emry Networks works with regulated small businesses, especially healthcare and dental practices. Our IT compliance service starts with Regulatory Discovery: scanning your live environment and comparing it against the rules that apply. You get a plain-English Risk Status Report showing the gaps between your paperwork and what your systems actually do. Security Hardening then stands up the managed stack, and Continuous Management keeps things on track with monitoring, staff phishing training, backup checks, and periodic compliance reviews.
A group of three clinics with over 75 staff came to us facing a surprise HIPAA audit. Their issues matched the list above: no formal risk assessment in two years, shared credentials in clinical systems, no documented incident response plan, and incomplete business associate documentation. We found eighteen gaps, enforced role-based access, enabled MFA, and reorganized their evidence. They were audit-ready in 90 days. Every engagement starts from where you are; if a provider gives you a timeline before seeing your systems, they're selling, not assessing.
This is why these issues are handled by an IT provider rather than a compliance consultant: most of the problems are operational. A consultant can point out that a shared front-desk login is a problem, but fixing it means setting up new accounts, reconfiguring the practice-management system, and retraining four people without slowing a busy morning. That's managed IT work, done with compliance in mind.
If your policies are in place but you're not sure your environment matches them, that uncertainty is a finding on its own. Better to catch it yourself, before an auditor, an insurer, or a patient complaint does.
Find the gaps before an auditor does
Start a HIPAA readiness review. We assess the live environment, not the binder, and hand you every gap between your paperwork and your systems.
Start HIPAA readiness reviewFrequently asked questions
Does HIPAA apply differently to a small practice?
The obligations are the same; the expected implementation scales. The Security Rule asks for safeguards that are reasonable and appropriate given the size, complexity, and resources of the organization, which means a two-dentist practice isn't expected to build what a hospital builds. It is expected to conduct an accurate risk analysis, act on what it finds, document its decisions, and maintain the required specifications. There is no headcount below which the rule stops applying, and OCR enforcement actions include solo practitioners.
Does "addressable" mean a HIPAA requirement is optional?
No. For an addressable implementation specification, HHS permits three routes: implement it, implement an equivalent alternative that accomplishes the same purpose, or implement neither. The choice must be documented in writing, including the factors considered and the risk assessment the decision rested on. So a practice may lawfully decide not to encrypt a particular system, but only as a recorded decision with reasoning. Skipping both the control and the documentation is the one outcome the rule doesn't allow, and it's the most common one in small practices.
Our imaging workstation runs an old version of Windows. Is that automatically a HIPAA violation?
Not automatically. HIPAA doesn't name operating systems. It requires a risk analysis that reflects your actual environment and risk management that acts on what the analysis finds. An unsupported workstation that appears in your asset inventory, has been assessed, has compensating controls such as network segmentation and restricted access, and has a documented decision behind it is a managed risk. The same machine absent from your inventory and unmentioned in your analysis is a gap, and after an incident it's the kind of gap investigators cite, because it shows the analysis wasn't accurate.
Is our IT provider a business associate?
If they create, receive, maintain, or transmit protected health information on your behalf, which includes having remote access to systems that hold it, then yes, and a business associate agreement is required. The agreement should describe the data movement that actually occurs rather than repeat generic language. If your provider engages subcontractors who can reach that data, those subcontractors are business associates too and need agreements of their own. OCR can pursue business associates directly, but the practice remains the covered entity and carries its own obligation to show the arrangement was governed.
Do we have to report a breach that affected only a few patients?
Yes, on a different schedule. Affected individuals must be notified without unreasonable delay and no later than 60 days after discovery, no matter how many people were involved. Breaches affecting 500 or more individuals are reported to HHS and notified to the media within that same 60-day window. Breaches affecting fewer than 500 are logged and submitted to HHS within 60 days after the end of the calendar year. Small breaches are a different reporting cadence, not an exemption, and it's worth rehearsing before you need it, since the individual notification clock starts at discovery.
Where should a small practice start if the last risk analysis was years ago?
With an asset inventory, because every other control depends on it and you cannot assess a system you have not listed. Walk the practice and record every device that touches patient information, including the ones attached to equipment. Then map where patient data actually travels on a normal day: email, text, scanners, portals, personal phones. Those two artifacts turn a risk analysis from a template exercise into a description of your environment, which is the standard OCR applies when it uses the phrase 'accurate and thorough.'
Sources
- HHS Office for Civil Rights, FAQ: 'What is the difference between addressable and required implementation specifications in the Security Rule?': the three permitted routes for an addressable specification and the written documentation obligation, including factors considered and risk assessment results.
- HIPAA Security Rule, 45 CFR §164.312(a)(2)(i): unique user identification is a required implementation specification.
- HIPAA Breach Notification Rule, 45 CFR §164.404 and §164.408: individual notification without unreasonable delay and within 60 days of discovery; breaches affecting 500 or more reported to HHS and media within 60 days; breaches affecting fewer than 500 submitted to HHS within 60 days after the end of the calendar year.
- HHS Office for Civil Rights, Right of Access Initiative: more than 50 enforcement actions as of January 2026; settlements ranging from $3,500 for a solo dental practice to $240,000 for a hospital system; Director Paula M. Stannard confirmed continuation through 2026 with added focus on parental access to minors' records.
- HHS Office for Civil Rights breach portal: 189 reported breaches affecting 500 or more individuals in the first half of 2026, covering more than 19 million individuals, predominantly classified as hacking or IT incidents. The portal lists only breaches affecting 500 or more.
- Microsoft: Windows 10 end of support 14 October 2025; commercial Extended Security Updates available through volume licensing at $61 per device for year one, doubling each subsequent year, to a maximum of three years ending October 2028.
Exact figures above are attributed to the named primary sources. Any other number in this article is presented as reasoning or as an explicit estimate and should not be read as a measured value.
Read more from our team
Explore insights on compliance and security.
Ready to strengthen your compliance?
Get hands-on assessment and guidance from our compliance experts.