HIPAA's IT requirements come from the HIPAA Security Rule (45 CFR Part 164, Subpart C), which requires every covered medical practice — regardless of size — to protect electronic protected health information (ePHI) with three categories of safeguards: administrative safeguards (risk analysis, workforce training, contingency planning), physical safeguards (facility, workstation, and device security), and technical safeguards (access control, audit logging, authentication, and transmission security). The rule's general requirement is to “ensure the confidentiality, integrity, and availability” of all ePHI a practice “creates, receives, maintains, or transmits.” There is no small-practice exemption — a two-provider clinic in Lake Charles is held to the same standards as a hospital system, though the rule explicitly allows smaller organizations to meet them with measures that fit their size, infrastructure, and budget.
3
Safeguard Categories
18
Security Standards Across Them
0
Small-Practice Exemptions
Who Actually Has to Comply
The Security Rule applies to covered entities — health care providers that transmit health information electronically (which includes essentially any practice that bills insurance), health plans, and clearinghouses — and to their business associates: vendors that create, receive, maintain, or transmit ePHI on the practice's behalf. That sweeps in medical, dental, chiropractic, optometry, and behavioral health practices alike, from a solo dentist to a multi-location clinic.
What the rule does offer smaller organizations is a flexibility of approach. Under 45 CFR 164.306(b), a practice may choose security measures appropriate to its size, complexity, and capabilities; its technical infrastructure; the cost of the measures; and the probability and criticality of the risks to its ePHI. In other words: the standards scale, but they never skip. A four-person family practice in Lake Charles doesn't need a hospital's security program — it needs a right-sized version of the same safeguards, documented. We cover the technology side of this in more depth on our healthcare industry page.
The Three Safeguard Categories, in Plain English
Every requirement in the Security Rule falls into one of three buckets. Here is what each one covers, straight from the regulation:
Administrative Safeguards (45 CFR 164.308)
The paperwork-and-people layer: a documented risk analysis (required), risk management, a named security official, workforce training, security incident procedures, and a contingency plan — including a data backup plan and disaster recovery plan, both explicitly required. Business associate agreements live here too.
Physical Safeguards (45 CFR 164.310)
Controls on the building and the hardware: facility access controls, workstation use and security policies, and device and media controls. Note that secure disposal and media re-use procedures are required — which matters because copiers and multifunction printers store document images on internal drives. Our guide to office equipment for law firms, medical practices, and schools covers that trap in detail.
Technical Safeguards (45 CFR 164.312)
The IT layer: access control (unique user identification is required), audit controls that record and examine system activity, integrity protections, person-or-entity authentication, and transmission security for ePHI moving across networks — with encryption as the standard answer.
“Addressable” does not mean optional
Some specifications, like encryption, are labeled addressable rather than required. Under 164.306(d), a practice must assess whether an addressable measure is reasonable and appropriate for its environment — and either implement it, or document why not and implement an equivalent alternative. For a modern practice, skipping encryption is very hard to justify on paper.
From Rule Text to Real Controls
The regulation describes outcomes, not products. Here is how the four controls auditors and insurers ask about most map back to the rule — and what each typically looks like inside a small practice:
Where Small Practices Usually Fall Short
In our experience working with small medical and dental offices around Lake Charles, the gaps are rarely exotic. They are the same handful, over and over:
- No documented risk analysis. The practice may be doing many things right, but nothing is written down — and under the Security Rule, an undocumented safeguard might as well not exist.
- Shared logins. One front-desk username defeats both the unique-user-ID requirement and any hope of a meaningful audit trail.
- Backups that have never been restore-tested. A backup you have never restored is a hope, not a plan.
- Unencrypted laptops. A stolen laptop with an encrypted drive is an inconvenience; an unencrypted one can be a reportable breach.
- Missing business associate agreements with the IT vendor, the cloud backup service, or the email host.
- Copiers returned off-lease with the hard drive intact — a physical-safeguard failure hiding in the supply closet.
If that list feels familiar, start with our small business cybersecurity checklist — most of its items double as Security Rule technical safeguards.
A word about “HIPAA-compliant IT”
No vendor can make your practice HIPAA compliant — compliance includes policies, training, sanctions, and documentation that only the practice itself owns. What an IT partner like AOP does is implement and maintain the technical safeguards — access control, encryption, audit logging, tested backups — and hand you the documentation that feeds your risk analysis. Our breakdown of what managed IT services include shows where those safeguards fit in a monthly service.
Frequently Asked Questions
Do I need a business associate agreement with my IT provider?
Yes. Any vendor that creates, receives, maintains, or transmits ePHI on your behalf is a business associate, and the rule requires a written agreement before they touch patient data — that includes your IT provider, EHR vendor, cloud backup service, billing company, and email host. A reputable provider will bring a BAA to the table without being asked.
Does HIPAA require encrypted email?
Transmission encryption is an addressable specification — you must assess it and either implement it or document a reasonable equivalent. For staff and provider email that carries PHI, encryption is the defensible answer in nearly every environment. HHS guidance does allow a practice to honor a patient's own request to receive regular, unencrypted email after warning them of the risk.
How often do we need a HIPAA risk assessment?
The Security Rule does not set a fixed calendar interval. Risk analysis is a required, ongoing process, and the rule separately requires a periodic evaluation and re-review whenever your environment changes. In practice, most guidance points to at least an annual review, plus a fresh look after any major change — a new EHR, a new location, a merger, or a security incident.
Our EHR vendor says their software is HIPAA compliant. Doesn't that cover us?
No. A well-secured EHR covers one system; the Security Rule covers all ePHI everywhere it lives — email, workstations, phones, copiers, backups, and file shares. Your risk analysis has to account for every one of those, not just the chart.
Does HIPAA really get enforced against small practices?
The rule applies to every covered entity, and the HHS Office for Civil Rights investigates complaints and reported breaches at organizations of every size. Breach notification duties apply to a two-person clinic the same as a hospital — and for a small practice, the reputational cost of notifying patients often outweighs the regulatory one.
Getting the Technical Safeguards Handled
The administrative work — policies, training, the risk analysis itself — belongs to your practice. The technical safeguards are where a local IT partner earns its keep. AOP implements and maintains access control, encryption, audit logging, and tested backups for small medical and dental practices across Lake Charles and Southwest Louisiana, with the documentation to show for it.
If you would like a straightforward look at where your practice stands, start with our cybersecurity services, send us a note, or call (337) 477-3700 — we are happy to talk through the safeguards before you commit to anything.