Skip to main content
The Practice
Practice growthAugust 24, 2026

HIPAA Compliance for a Small Practice: The Seven Artifacts That Prove It

HIPAA compliance for a therapy practice with no compliance officer: the two roles you must designate, the seven artifacts an investigator asks to see — risk analysis, business associate agreements, written policies, training records, and an incident path with deadlines — and the once-a-year rhythm that keeps them current.

Callie Editorial 18 min read
The compliance issue
Seven artifacts

4 notes left

Close-the-day system

Capture

Objective data at point of care

Interpret

One clinical decision

Close

Sign, route, and clear exceptions

A finish line for every clinical day

At a glance

What you’ll leave with

  • There is no HIPAA certification — HHS says so explicitly. Compliance is demonstrated with documents: a current risk analysis, signed BAAs, written policies, dated training records, and an incident path, each retained for six years.
  • Every covered practice, however small, must designate a privacy official and a security official in writing. They can be the same person, and in a solo practice that person is you. The rule requires the designation, not a hire.
  • Breach deadlines are unforgiving: affected individuals within 60 days of discovery, HHS within 60 days for breaches affecting 500 or more people, and an annual report for smaller ones. Decide the path before the day you need it.

HIPAA compliance in a small therapy practice has a marketing problem: everything sold under that name — seminars, seals, subscription binders — implies compliance is a thing you buy once and frame on the wall. Federal regulators see it differently. When the Office for Civil Rights investigates a complaint or a breach, it does not ask for a certificate, because none exists; it asks the practice to produce specific documents. A current security risk analysis. Signed business associate agreements. Written policies. Dated training records. Evidence of how an incident was handled. A practice with no compliance officer, no IT department, and no lawyer on retainer can hold every one of those artifacts — and the rules were explicitly written to scale down to a practice that size. This article is the list: the two roles you must put in writing, the seven artifacts that answer an investigator’s questions, and the once-a-year rhythm that keeps them from going stale.

The reframe

Compliance is a folder you can produce, not a feeling

Start by discarding the certification myth. HHS answers the question directly in its Security Rule FAQ: no standard or implementation specification requires a covered entity to “certify” compliance, and HHS does not endorse or certify any private compliance program, seminar, or product. What the Security Rule requires instead — at 45 CFR 164.308(a)(8) — is a periodic technical and non-technical evaluation of how well your safeguards meet the rule. In other words, the government replaced the certificate with a habit: look at your own setup on a regular basis, and write down what you found.

The second thing to know is that the rule was built to fit you. The Security Rule’s own flexibility provision directs each organization to adopt security measures that are reasonable and appropriate for its size, complexity, technical infrastructure, and resources — HHS’s risk analysis guidance says plainly that appropriate measures for a small covered entity may differ from those for a large one. A two-clinician practice is not held to a hospital’s playbook. What it is held to is the paper trail: HIPAA requires that policies, designations, and other required documentation be retained for six years from creation or from the date they were last in effect, whichever is later. Every artifact in this article inherits that clock.

Step zero

Put two names in writing before anything else

The phrase “we don’t have a compliance officer” misreads what HIPAA asks for. The Privacy Rule, at 45 CFR 164.530(a), requires every covered entity to designate a privacy official responsible for its privacy policies and procedures. The Security Rule, at 45 CFR 164.308(a)(2), requires it to identify a security official responsible for developing and implementing its security policies. Neither rule says these must be different people, be full-time, or hold a credential — in a small practice they are usually the same person, and in a solo practice that person is you. What the rules do require is that the designation be documented. One page in your policy folder — “Jordan Reyes, owner, serves as privacy official and security official, effective March 1” — satisfies step zero, gives every later artifact an owner, and tells an investigator exactly who answers for the practice. Undocumented is the only wrong answer.

Artifact 1

A written security risk analysis

The risk analysis is the artifact everything else hangs from, and it is the one OCR guidance calls the first step of Security Rule compliance. The requirement, at 45 CFR 164.308(a)(1)(ii)(A), is an “accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability” of the electronic protected health information you hold. Strip the regulatory language and the work is concrete: list every place ePHI lives or moves — the EHR, the billing portal, email, the practice laptop, therapists’ phones, any AI scribe or telehealth platform, paper charts in transit — then, for each, write down what could realistically go wrong, how likely and how damaging that would be, and what you currently do about it. The gaps you find become your to-do list; the document itself becomes your proof that the to-do list came from analysis rather than guesswork.

HHS’s guidance is explicit that there is no one-size-fits-all blueprint and that the analysis is not a one-time event: it should be revisited as the practice changes — a new EHR, a new location, a first hire, a new AI tool. It also does not need to be outsourced. ONC and OCR publish a free Security Risk Assessment (SRA) Tool built specifically for small and medium practices; it walks through the assessment as a questionnaire, stores everything locally on your own computer, and produces the documentation. An afternoon with that tool puts a small practice ahead of the many organizations OCR has cited for having no risk analysis at all.

Artifact 2

A signed BAA for every vendor that touches PHI

A business associate is any outside company or person that creates, receives, maintains, or transmits protected health information to do something on your behalf — and before any PHI flows to one, HIPAA requires a written business associate agreement that pins down what the vendor may do with the data and obligates it to safeguard the information. You do not have to draft one from scratch: HHS publishes sample provisions, and established health-tech vendors bring their own. Your artifact is simpler: one folder holding the signed BAA for every vendor on the list, so the answer to “where is your agreement with your EHR?” takes thirty seconds. The harder question for a small practice is which vendors belong on the list, and HHS has answered most of the common cases directly.

Who needs a BAA — the common small-practice cases

Vendor or relationshipBAA?Why, per HHS guidance
EHR or practice management vendorYesCreates, receives, and maintains ePHI on your behalf — the definitional business associate
Billing service or clearinghouseYesClaims processing and billing are named business associate activities in HHS guidance
Cloud storage, AI scribe, or any platform holding session dataYesA cloud provider maintaining ePHI is a business associate even if it stores only encrypted data it cannot read (HHS FAQ 2076)
Health plans you billNoProvider and payer each act as covered entities in their own right; a payment disclosure needs no BAA
Another treating provider you refer toNoDisclosures for treatment between providers do not create a business associate relationship
Janitorial service, landlord, electricianNoTheir work does not involve using PHI; any exposure is incidental (HHS FAQ 243)
Mail couriers and internet service providersNoPure conduits that only transport data without storing or accessing it fall outside the BAA requirement

Two edges of that table deserve emphasis, because they are the ones small practices get wrong. First, the cloud row is broader than it looks: HHS treats a vendor that merely stores ePHI as a business associate even when the data is encrypted and the vendor holds no key — “we can’t see your data” does not exempt anyone from a BAA. Second, absence from the folder is the failure mode, not weak contract language. If a transcription app, a form builder, or an email tool is holding client information and no BAA exists, that is the finding an investigator writes down. When a consumer-grade tool will not sign a BAA, the tool — not the rule — is what has to change.

Artifact 3

Access and device rules written for your actual office

The Security Rule’s administrative, physical, and technical safeguards all funnel into one artifact a small practice can actually maintain: a short set of written policies describing who may touch what information, on which devices, under which rules. Resist the urge to buy a 200-page template — the rule requires policies that reflect your practice, and a policy nobody has read protects no one. For a small clinic, a handful of pages covers the ground that matters: every user has their own login and nobody shares credentials; access matches role, so the front desk sees scheduling and billing but not clinical notes it has no need for; access ends the day employment does; and the device rules say which machines may hold ePHI, that they lock when idle, what happens when one leaves the building, and what is allowed on a personal phone. If your risk analysis flagged it, a policy should answer it — that correspondence between the two documents is exactly what a reviewer looks for.

Artifact 4

A training log with names and dates on it

Training is required twice over: the Privacy Rule requires training every workforce member on your policies and procedures, as necessary and appropriate to their role, and the Security Rule separately requires a security awareness and training program for the whole workforce — management explicitly included. In a three-person practice, the program does not need a learning platform. It needs to actually happen and to leave a record: a session when someone is hired, a refresher when a policy materially changes, and a log line each time — date, names, topics covered. The log is the artifact. Training that happened but was never documented is, for compliance purposes, indistinguishable from training that never happened. Pair it with the sanction policy the rules also expect: a short written statement that violating the practice’s privacy and security policies has consequences, applied consistently.

Artifact 5

An incident path with the deadlines already attached

The Security Rule requires policies for identifying and responding to security incidents, mitigating what can be mitigated, and documenting each incident and its outcome. The Breach Notification Rule then attaches deadlines that are brutal to discover for the first time mid-crisis. Write the path down while nothing is wrong: who a therapist tells the moment a laptop disappears or an email goes to the wrong family; who assesses whether the incident is a reportable breach of unsecured PHI; and who owns the clock if it is. The clock is the part small practices underestimate — an impermissible use or disclosure is presumed to be a breach unless your documented risk assessment shows a low probability the information was compromised, and once a breach is discovered, the notification deadlines below apply no matter how small the practice or the incident.

60 days

Outer limit for notifying affected individuals

Notice must go out without unreasonable delay, and never later than 60 days after the breach is discovered.

500

The threshold that changes the reporting path

At 500 or more affected individuals, HHS must be notified within the same 60 days — and prominent media too when 500 or more live in one state.

60 days after year end

Annual report for smaller breaches

Breaches affecting fewer than 500 people are logged and reported to HHS within 60 days of the end of the calendar year of discovery.

The centerpiece

The small-practice HIPAA artifact checklist

This is the whole article as a folder audit. Every line names something you can physically produce — print the list, walk your practice against it, and treat any unchecked line as the next compliance task. A small practice that can check every line holds a stronger position than most large organizations OCR writes about, because the artifacts exist, are current, and have an owner.

Field checklist

14 items

The HIPAA artifacts a small practice must be able to produce

  • A dated, signed designation naming the practice’s privacy official and security official — the same person is fine, and the designation is on paper, not just understood.
  • A written security risk analysis that lists every system and device holding ePHI, what could go wrong with each, and what the practice does about it.
  • Evidence the risk analysis is alive: a review note added after the last major change — new EHR, new hire, new location, new AI tool.
  • A signed business associate agreement on file for the EHR, the billing service or clearinghouse, and every cloud tool that stores or processes client information.
  • A vendor inventory that was swept against the BAA folder, so no tool holding PHI is missing its agreement.
  • Written access rules: individual logins for every user, permissions matched to role, and a same-day access shutoff step for departures.
  • Written device rules: which machines may hold ePHI, screen-lock expectations, what happens when a device leaves the office or a personal phone touches work.
  • A training log with dates, names, and topics — one entry per new hire, plus refreshers when policies change.
  • A short written sanction policy stating that privacy and security violations carry consequences.
  • A one-page incident path: who is told immediately, who runs the breach risk assessment, and who owns the notification deadlines.
  • The federal breach deadlines and your state’s breach-law requirements written into that incident document — looked up now, not during a crisis.
  • A Notice of Privacy Practices given to clients and posted as the Privacy Rule requires, matching what the practice actually does.
  • A backup and contingency answer: where ePHI backups live, and how the practice would keep operating and reach records if the primary system failed.
  • Six years of the above retained — policies, designations, training records, risk analyses, and incident documentation, kept from creation or last effective date.

Keeping it alive

The once-a-year rhythm that keeps the folder current

The Security Rule’s evaluation standard expects periodic review, and stale artifacts fail quietly: the risk analysis that predates your EHR switch, the BAA folder missing the AI scribe you adopted in March. The fix is a standing appointment with yourself — one afternoon, once a year, plus a lightweight check whenever something material changes. Put it on the calendar like a recertification deadline, because functionally it is one.

  1. 01

    Re-walk the risk analysis

    Open last year’s document and update it against reality: systems added or retired, new staff, new devices, new tools. Note what changed and date the review — the delta note is what proves the analysis is ongoing rather than archaeological.

  2. 02

    Sweep the vendor list against the BAA folder

    List every tool that touched client information this year, including anything a clinician adopted informally. Anything on the list without a signed BAA either gets one or gets replaced.

  3. 03

    Run the training refresher and log it

    Cover what changed this year — new tools, new policies, anything an incident taught you — and add the dated entry to the log while the room is still together.

  4. 04

    Read the policies against the actual office

    Where practice has drifted from policy, change one of them. A policy that says something nobody does is worse than no policy, because it documents that you knew.

  5. 05

    Test the contingency answer once

    Confirm the backup exists and restores, and rehearse the EHR-down morning for ten minutes. The Security Rule asks for contingency planning; a test is what makes the plan an artifact instead of an intention.

  6. 06

    Write the evaluation note

    Close with one page: what was reviewed, what changed, what remains open, signed and dated by the security official. That page is the periodic evaluation the rule asks for — and next year’s starting point.

Does a small therapy practice really need a HIPAA compliance officer?

Not an officer — a designation. Every covered practice must name a privacy official (45 CFR 164.530(a)) and a security official (45 CFR 164.308(a)(2)) in writing, but nothing requires a dedicated hire, a credential, or separate people. In most small practices the owner holds both roles. What fails an investigation is not the missing job title; it is the missing document naming who is responsible.

Is there an official HIPAA certification a practice can get?

No. HHS states directly that no HIPAA standard requires certifying compliance and that it does not endorse or certify any private compliance program, seminar, or seal. Vendors selling “HIPAA certified” status are selling their own assessment, which carries no federal standing. What the Security Rule requires instead is a periodic evaluation of your own safeguards — documented, dated, and kept.

How often does the security risk analysis need to be redone?

The rule sets no fixed interval; HHS guidance describes risk analysis as an ongoing process rather than a one-time event. The workable rhythm for a small practice is a documented review once a year plus an update whenever something material changes — a new EHR, a new location, a first hire, a new AI tool. A risk analysis that predates your current systems no longer describes your practice, and a reviewer will notice the dates.

Do I need a business associate agreement with my EHR and my AI scribe?

Yes to both. Any vendor that creates, receives, maintains, or transmits protected health information on your behalf is a business associate, and a written BAA is required before PHI flows — HHS guidance names EHR vendors and billing services explicitly, and its cloud-computing guidance extends the same rule to any platform storing client data, even encrypted data the vendor cannot read. If a tool holding session information will not sign a BAA, it cannot hold that information.

A note went to the wrong family. Is that really a reportable breach?

Treat it as one until your documented assessment says otherwise. Under the Breach Notification Rule, an impermissible disclosure is presumed to be a breach unless a risk assessment shows a low probability the information was compromised. If it qualifies as a breach, the affected individual must be notified within 60 days of discovery, and the incident joins the annual log reported to HHS after year end for breaches affecting fewer than 500 people. Either way, the assessment itself gets written down and kept — and your state’s breach law may add its own requirements.

What does HIPAA compliance cost a practice with no budget for it?

The federal toolkit is free: the ONC/OCR Security Risk Assessment Tool structures the risk analysis, HHS publishes sample business associate agreement provisions, and the policies and logs in this article are documents you write once and maintain. The real costs are time — roughly an afternoon a year once the folder exists — and choosing vendors that will sign BAAs. That is deliberate: the rules scale their expectations to the size and resources of the practice.

Primary sources

Bibliography / 13
  1. 01Summary of the HIPAA Security RuleU.S. Department of Health and Human Services
  2. 02Guidance on Risk AnalysisU.S. Department of Health and Human Services, Office for Civil Rights
  3. 0345 CFR § 164.308 — Administrative safeguardsElectronic Code of Federal Regulations
  4. 0445 CFR § 164.530 — Administrative requirements (Privacy Rule)Electronic Code of Federal Regulations
  5. 0545 CFR § 164.520 — Notice of privacy practices for protected health informationElectronic Code of Federal Regulations
  6. 06Business Associates (HIPAA guidance)U.S. Department of Health and Human Services
  7. 07Business Associate Contracts: Sample ProvisionsU.S. Department of Health and Human Services
  8. 08Guidance on HIPAA & Cloud ComputingU.S. Department of Health and Human Services
  9. 09FAQ 2076: If a CSP stores only encrypted ePHI and does not have a decryption key, is it a business associate?U.S. Department of Health and Human Services
  10. 10FAQ 243: Is a business associate contract required for inadvertent contact with PHI, such as janitorial services?U.S. Department of Health and Human Services
  11. 11FAQ 2003: Are we required to “certify” our organization’s compliance with the Security Rule?U.S. Department of Health and Human Services
  12. 12Breach Notification RuleU.S. Department of Health and Human Services
  13. 13Security Risk Assessment (SRA) ToolHealthIT.gov (ASTP/ONC and OCR)

Written by Callie Editorial

Published August 24, 2026

Educational content, not legal, billing, or patient-specific clinical advice.