Why Compliance Feels Broken for Many Small Businesses

Published On
August 24, 2026
Share this post
https://www.emrynetworks.com/post/why-compliance-feels-broken-for-small-businesses

The binder is current. Policies were reviewed in March, the risk assessment is done, staff has signed off, and the compliance dashboard is all green. Then someone asks a simple question: who has admin access to the practice management system right now? Suddenly, no one knows.

That silence is the real problem. You did all the work and paid for it, but it doesn't help you answer the question.

Compliance isn't actually broken. The real issue is that most small businesses were sold a version that treats it as paperwork with a renewal date, separate from the systems it should protect. That gives you documents, not real security. Those are not the same thing.

The paperwork is real work that produces nothing you can use

People often say compliance is hard for small businesses because there isn't enough staff, money, or time. That's true, but the bigger question is what you actually get for all that effort.

A typical year goes like this. Someone updates the policy library, someone else chases signatures, another person fills out a risk assessment template by mostly copying last year's answers. Then evidence gets put in a folder right before the review. After the review, the folder sits in a drive no one opens, and the whole cycle starts again.

None of these steps actually change any settings. No accounts get closed, no firewall rules are updated, and no backups are tested. At the end of the year, your environment is the same as it was at the start, except for eleven months of unnoticed changes. The program checked for paperwork, not for real changes.

So when an owner says compliance feels like theater, they aren't just being negative. They're describing how the system really works.

An audit measures what it sampled, not what you have

This is where the false sense of security comes from, and it's worth being clear about how it works.

A SOC 2 Type 2 report is an attestation, not a certificate. Under the AICPA framework, an independent auditor gives an opinion on how controls were designed and whether they worked over a set period, usually three to twelve months. The auditor doesn't check every event in that time. They pull a sample. Passing means the sample looked good.

The same is true of a HIPAA review or a PCI DSS assessment. An assessor asks for evidence of a control, you produce it, and the finding closes. What neither party has established is whether that control held on the other 300-odd days nobody looked at.

A clean audit means the sample checked was fine. It's the minimum standard, not the final word.

This gap is why owners get frustrated. Some organizations pass a review and still get breached that same year. The audit did its job, but it only answered the specific question it was asked, which was more limited than the owner thought.

Where the money actually goes

Be careful with the breach-cost numbers you see, because they usually don't reflect your own situation.

IBM's Cost of a Data Breach Report 2026 put the global average at $4.99 million, a 12% rise on the prior year. In the United States, the average was $11.5 million. Healthcare came in highest at $6.64 million, the thirteenth consecutive year it has topped the industry table. IBM also found that roughly one in four malicious breaches were AI-enabled, and those cost about $6 million on average.

A small dental practice with twelve people isn't going to lose $11.5 million. Those numbers come from big companies with millions of records. If someone says those are your risks, they're trying to sell you something. What matters is the ratio, not the total.

The most useful framing here is still the widely cited 2017 Ponemon Institute and Globalscape study, which found the cost of non-compliance ran about 2.71 times the cost of maintaining compliance, an average of $14.8 million against $5.5 million across the organizations studied. The dollar figures are enterprise-scale and nearly a decade old. The multiple is the point. Non-compliance is not cheaper. It is deferred, it compounds, and it arrives all at once.

But this only works if your compliance spending actually lowers your risk. If you just pay for paperwork, you end up paying for both compliance and non-compliance at the same time. That's the worst place to be, and it's where many small businesses end up.

The gap usually surfaces in your insurance before your audit

Here's a consequence most owners haven't heard about.

A cyber insurance application is not a survey. It is a warranty, a set of legal statements about your production environment that you are signing as true. Insurers now ask direct, verifiable questions. Is multi-factor authentication enforced for all users, on all remote access, on all administrative accounts, and on email? You answer yes, because MFA is on.

Then a claim is filed, the insurer investigates, and they find the service account that was left out so a scanner could keep sending emails to the front desk. Or the emergency admin login that was never set up right. Or the old VPN connection from before your current setup. You answered yes on your application, but your environment really says "mostly."

Carriers use that discrepancy to deny claims and, in some cases, to rescind the policy outright. Courts have frequently held that the carrier does not need to prove the misrepresentation caused the loss, only that the statement was inaccurate when made. The MFA exclusion did not have to be the way in. It only had to be untrue on the form.

The one document that is a legal promise

The insurance application is the only compliance document that is a legal promise about your real systems. Most owners fill it out from memory.

No one lied. The office manager filled out the renewal based on what the IT provider said two years ago. This isn't a personal failing. It's what happens when the compliance program isn't linked to the actual systems.

Regulators stopped grading the binder

If you work in healthcare, enforcement has already moved beyond checking paperwork, and the change is well documented.

On 23 April 2026, the HHS Office for Civil Rights announced settlements with four regulated entities following separate ransomware investigations. The incidents affected more than 427,000 individuals in total. The organizations paid $1,165,000 between them and entered corrective action plans under two years of OCR monitoring. OCR noted the announcement brought it to 19 completed ransomware investigations and 13 completed investigations under its Risk Analysis Initiative.

Read the four case summaries and you'll see the same problem in each one: the organization didn't do a thorough and accurate risk analysis of its own electronic protected health information. It wasn't that they had no policy or risk assessment on file. The analysis existed, but it didn't match the real environment.

OCR has also made clear that the initiative is expanding. It isn't just about confirming a risk analysis exists, but about what the organization actually did with the results. The focus is on risk management, not risk paperwork.

Practice size doesn't get you out of this. OCR has settled with solo and small practices, including a solo dental office and a small dermatology practice, with penalties from tens of thousands up to $150,000. The penalty limits also changed on 28 January 2026, when HHS adjusted for inflation: the minimum is now $145 per violation, and the yearly cap for all violations of the same rule is $2,190,294. Penalties are per violation with an annual cap, not per day. That detail is often misunderstood in vendor marketing.

One thing to be accurate about: the Security Rule update is still proposed

The Notice of Proposed Rulemaking that would overhaul the HIPAA Security Rule was published in the Federal Register on 6 January 2025, and the comment period closed on 7 March 2025. It is not law. HHS originally signaled a 2026 final rule; the federal unified agenda has since pushed final action to July 2027. The proposal could still be finalized as written, materially revised, delayed further, or withdrawn. If someone tells you that MFA and asset inventories are now legally required under HIPAA, they're mistaken about the details, even if they're right about the general direction. The proposal would require a written asset inventory, a network map, removal of the "addressable" label from implementation specifications, and controls like MFA and encryption. Each of these is about your real environment. The current rule already expects this level of discipline; the proposal would just make it clearer.

Attackers stopped needing your password

The 2026 Verizon Data Breach Investigations Report analyzed more than 22,000 confirmed breaches, the largest dataset in the report's history. For the first time in nineteen years, the leading way attackers gained initial access was not stolen credentials. It was exploitation of known software vulnerabilities, at roughly 31% of analyzed breaches. The human element still featured in 62%.

Think about the word "known." A patch was available. Someone had already created the fix. The breach happened in the time between the fix being released and it actually being applied to the system.

That gap isn't about policy. Your policy probably says you patch critical vulnerabilities within a set number of days. The real question is whether anyone checked the actual timing on the real machines, even the ones missing from your inventory. Every major framework (HIPAA, SOC 2, ISO 27001, NIST, PCI DSS, CMMC, HITRUST) expects this to happen. The paperwork version of compliance just assumes the policy is being followed.

What compliance looks like as an operating discipline

The fix is simple but not flashy: stop treating compliance as a set of documents with a deadline, and start treating it as ongoing checks with clear owners. Evidence should be something you already have, not something you scramble to assemble.

You don't need a huge budget or a full-time security expert for this. What you need is for compliance work and systems work to stop being two separate things handled by different people who only talk once a year. Side by side, the two versions of the same program look like this.

Two versions of the same program

DimensionCompliance as paperworkCompliance as operating discipline
The outputA binder, a report, and a renewal date.A validated environment and the records it generates while running.
CadenceAnnual, concentrated in the weeks before the review.Continuous, as a byproduct of normal operations.
Who owns itWhoever has capacity that quarter.A named owner per control, with an escalation path.
MFAEnabled, and reported as enabled.Enforced, with every exclusion named, approved, and given an expiry date.
BackupsThe nightly job reports success.The restore is tested, the recovery time is recorded.
Access reviewsDone when someone remembers, evidenced by an email.Run on a schedule against a written standard, logged.
A failure looks likeA finding in a report, months later.An alert, today, with a person assigned.
The insurance formFilled in from memory and old assumptions.Answered from current system state you can show.

Where this gets fixed

Emry Networks is a managed IT, cybersecurity, and IT compliance provider built around this specific gap. The distinction we draw is between standard IT, which measures itself on uptime and ticket response, and total defensibility, which measures whether a control is running where it is supposed to run and whether you can prove it. We've written about why working IT is not enough for regulated SMBs if you want the longer version of that argument.

The engagement starts with Regulatory Discovery, a deep scan of your live environment, cross-referenced against the frameworks that actually apply to you: HIPAA, SOC 2, ISO 27001, NIST, PCI DSS, CMMC, and HITRUST. The deliverable is a plain-English Risk Status Report that lists every gap between what your documentation claims and what your systems are doing. Security Hardening then deploys the managed stack, including managed detection and response, advanced endpoint protection, managed encryption, tested backups, and 24/7/365 monitoring, to move the business from at-risk to defensible. Continuous Management keeps it there with monitoring, staff phishing training, backup checks, and regular compliance drift checks. That last phase is what stops the eleven-month gap from reopening. The full breakdown is on our IT compliance service page.

What matters most is what happens after the findings. We fix the issues we find instead of handing you a report and a bill. A healthcare group with three clinics and over 75 staff came to us facing a surprise HIPAA audit. They hadn't done a formal risk assessment in two years and were sharing credentials in clinical systems. We found eighteen gaps, corrected the controls, and restructured the documentation, making them audit-ready in 90 days. On the security side, our managed stack helps make sure the patch window doesn't turn into a breach window.

If your policies are strong but you're not sure your real environment matches them, that doubt is a finding on its own. It's better and less costly to catch it yourself now than to have an insurer or a regulator point it out later.

Not sure your systems match your paperwork?

That doubt is worth a conversation. Talk to a security expert to see how we work and who would be handling your security.

Talk to a security expert

Frequently asked questions

Is compliance the same as being secure?

No. Compliance is a set of obligations you can demonstrate you've met; security is whether your environment actually resists attack. A compliance program confirms a control was implemented, which is not the same as confirming it is effective, enforced everywhere, and still enforced today. The overlap is real, since most frameworks require controls that genuinely reduce risk, but the measurement is different. Compliance measures documentation and sampled evidence. Security measures behavior in production. Programs that treat the two as identical tend to produce organizations that look protected on paper but aren't.

We passed our audit. Why is our IT provider saying we have gaps?

Because an audit and a control validation ask different questions. An auditor tests a defined scope against a defined framework over a defined period, and pulls a sample of evidence. A validation walks the live environment and asks whether each control is running as described right now: every account with privilege, every MFA exclusion, every system in scope for logging, every backup that has actually been restored. Passing the first does not answer the second. Both findings can be correct at the same time.

Does the size of my practice change how OCR enforces HIPAA?

Not in kind. OCR has settled with solo and very small practices, with resolution amounts running from a few tens of thousands of dollars upward, and its Risk Analysis Initiative has produced enforcement actions across organizations of every size. Penalty amounts scale with culpability and the number of violations, not headcount. What size does change is capacity. A small practice usually has nobody whose job is to notice drift between the risk analysis and the environment, which is precisely the finding OCR has cited most often.

Will the updated HIPAA Security Rule take effect in 2026?

No. The Notice of Proposed Rulemaking was published in the Federal Register on 6 January 2025 and the comment period closed on 7 March 2025. As of August 2026, no final rule has been issued, and the federal unified agenda has moved final action to July 2027. The proposal could still be finalized as drafted, revised in response to comments, delayed again, or withdrawn. The existing HIPAA Security Rule remains in force and is being actively enforced. Treat the proposal as a signal of direction, not a requirement.

Can a cyber insurance claim really be denied over a questionnaire answer?

Yes, and this is one of the most under-appreciated consequences of a paper-only compliance program. A cyber application functions as a warranty about your environment. If you attested that MFA is enforced on all remote access and administrative accounts, and a post-incident investigation finds accounts or paths where it was not, the carrier can deny the claim or rescind the policy. Courts have often held the carrier need not show the misstatement caused the loss. Before your next renewal, have someone confirm each answer against current system state rather than institutional memory.

What should a compliance assessment actually deliver?

Three things. First, an accurate inventory of what exists (systems, accounts, data locations, third-party connections), because you cannot validate a control on something you do not know about. Second, a control-by-control comparison of what your documentation claims against what the live environment is doing, with the gaps named in plain language. Third, an owner and a date for each gap. An assessment that ends at a scored report has given you a description of the problem, not a route out of it.

Sources

  • IBM, Cost of a Data Breach Report 2026 (published July 2026): global average $4.99M (+12% year over year); United States average $11.5M; healthcare $6.64M, highest for a thirteenth consecutive year; approximately one in four malicious breaches AI-enabled, averaging $6M.
  • Verizon, 2026 Data Breach Investigations Report: 22,000+ confirmed breaches analyzed; exploitation of known software vulnerabilities the leading initial-access vector at approximately 31%, the first time in nineteen editions; human element present in 62% of breaches.
  • HHS Office for Civil Rights, "HHS' Office for Civil Rights Settles Four HIPAA Security Rule Ransomware Investigations," press release, 23 April 2026: $1,165,000 total, 427,000+ individuals affected, two-year corrective action plans, 19 completed ransomware investigations and 13 completed Risk Analysis Initiative investigations.
  • HHS, annual civil monetary penalty inflation adjustment effective 28 January 2026 (Federal Register): Tier 1 minimum $145 per violation; calendar-year cap $2,190,294 per identical provision.
  • HHS Office for Civil Rights, HIPAA Security Rule Notice of Proposed Rulemaking: published in the Federal Register 6 January 2025; comment period closed 7 March 2025. Status as of August 2026: proposed, not final; final action listed in the federal unified agenda for July 2027.
  • AICPA, SOC 2 reporting and the Trust Services Criteria: Type 2 reports address suitability of design and operating effectiveness across a defined observation period; there is no SOC 2 certificate.
  • Ponemon Institute and Globalscape, The True Cost of Compliance with Data Protection Regulations (2017): non-compliance cost 2.71 times the cost of compliance; averages of $14.8M and $5.5M respectively. Widely cited; note the age and the enterprise sample.

Exact figures above are attributed to the named primary sources. Any other number in this article is presented as reasoning or as an explicit estimate and should not be read as a measured value.

Share this post
https://www.emrynetworks.com/post/why-compliance-feels-broken-for-small-businesses

Ready to strengthen your compliance?

Get hands-on assessment and guidance from our compliance experts.