🇮🇳 India 🇺🇸 US
Healthcare SEO AI search (AIO) Local SEO & Google Business Profile Content marketing Performance marketing Google Ads Meta Ads Email & SMS marketing Reputation management Website design Branding YouTube & video Marketing consulting
Dental practices Pediatric practices Primary care Med spas Dermatology IVF & fertility Dallas (HQ) Houston New York All US cities and specialties
US healthcare marketing statistics Med spa consumer behavior report Dental patient experience report Google benchmarks: 9 specialties Free tools All US research US case studies
Software
Healthcare practices Pharma Medical devices
About Ichelon Consulting US How we work Santosh Reddy, Director Ravi Kumarraju, Partner & Director
Book a call with the US team Call +1 (724) 612-3694
We Do It Right. The right diagnosis. The right strategy. The right systems. Giving healthcare leaders the confidence to make better decisions, build stronger operations, and achieve sustainable growth. — Team Ichelon
Ichelon Consulting US · HIPAA by practice size

HIPAA compliance for a solo practice: a program one owner can run

A solo practice needs the same HIPAA program as a large group, at a size one owner can run. That means a written risk analysis, named privacy and security officials (often you), short policies, trained staff, signed business associate agreements and a plan for breaches. Most of it can be set up in a few working days and kept current with a few hours each quarter.

Guide for US practice owners · Published October 4, 2026

TL;DR
  • First check whether you are a covered entity: a provider is covered if it transmits health information electronically in a standard transaction, such as billing insurance.
  • The core file: risk analysis, officer designations, policies, Notice of Privacy Practices, training records, BAAs and a breach log, kept for six years.
  • Most solo-practice risk sits in personal phones, shared passwords, unencrypted laptops and marketing tools added without a BAA.
  • Encrypting devices properly can mean a lost laptop is not a reportable breach.
  • When you open a second office, revisit everything: see the multi-location guide.
  • Every practice welcome — retainers from $499/mo, Goals-Driven engagements, Performance-Linked Payout Models available.
Ichelon Consulting US
  • Dallas, Texas LLC
  • 10-person US client team · Central Time (CST)
  • 25+ US healthcare clients
  • BAA signed with every client
  • HIPAA compliance training across client and delivery teams
  • Contracts and invoices in USD
How we work with US practices →
Trusted by US practices · case studies → 25+ US clients · 8 shown · TX · CA · VA · nationwide telehealth
Dr. Rajan Kohli
Owner, Lakewood Primary Care & Wellness · North Dallas, TX
Client video · Practice website build
“They were able to get all my ideas and work with me over a period of three to four months and create this amazing website. It's super customized, very modern, and it incorporates all the elements that I had wanted — the patient portal, nice pictures, a very interactive website, patient reviews. I would highly recommend their company to anyone who wants to make an excellent website.”
Dr. Rajan Kohli Owner, Lakewood Primary Care & Wellness · North Dallas, TX
Are you covered?

Step one: confirm you are a covered entity

Short answer: if your practice bills insurance electronically, or checks eligibility or claim status electronically, you are a covered entity and HIPAA applies in full.

Under 45 CFR 160.103, a health care provider is a covered entity when it "transmits any health information in electronic form in connection with a transaction" covered by HIPAA. Claims, eligibility checks, referral authorizations and remittance are the common ones. Using a billing company to send them for you still counts.

A cash-only practice that never conducts those transactions, such as some med spas, concierge practices and wellness clinics, may not be a covered entity. That does not leave patient data unregulated. Texas, for example, defines "covered entity" in Health and Safety Code Chapter 181 to include anyone who comes into possession of PHI, Washington’s My Health My Data Act covers consumer health data outside HIPAA, and the FTC polices deceptive privacy promises. Most cash practices follow HIPAA-level practices anyway, because patients and partners expect it.

The core file

The HIPAA file every solo practice should have

Short answer: eight documents, kept current and kept for six years after they were last in effect.

DocumentWhat it needs to coverRule
Risk analysisWhere electronic PHI lives (EHR, phones, laptops, email, cloud tools), the threats to it and how likely and damaging each is164.308(a)(1)(ii)(A)
Risk management planWhat you will do about each risk, by when and who owns it; update as items are closed164.308(a)(1)(ii)(B)
Officer designationsWho is the privacy official, who is the security official, who takes complaints164.308(a)(2), 164.530(a)
Policies and proceduresShort and specific to your office: access, passwords, devices, email and texting, records requests, disposal, incidents, sanctions164.316, 164.530(i)
Notice of Privacy PracticesGiven at the first visit with a good-faith effort to get acknowledgment, posted in the office and posted prominently on your website164.520
Training recordsWho was trained, when and on what; at hire and after material policy changes164.530(b), 164.308(a)(5)
Business associate agreementsOne for every vendor that handles PHI for you164.308(b), 164.504(e)
Incident and breach logEvery incident, the risk assessment you did and whether you notified; small breaches reported to HHS within 60 days after year end164.402 to 164.408

HHS and the Office of the National Coordinator offer a free Security Risk Assessment Tool built for small and medium practices. It is a reasonable way to produce your first written risk analysis. Whatever tool you use, the analysis has to reflect your actual systems, not a template.

Where the risk is

Where solo practices actually get into trouble

Short answer: devices and shortcuts. In a small office, the convenient way to do something is often the risky way.

  • Personal phones. Patient photos, texts and voicemails on an owner’s or staff member’s own phone. Use practice-managed apps that sign BAAs and keep PHI off personal camera rolls.
  • Shared logins. One front-desk password for the EHR means you cannot tell who looked at what. HIPAA expects unique user identification (164.312(a)(2)(i)).
  • Unencrypted laptops and backups. Under HHS guidance on unsecured PHI, data encrypted to the NIST-based standard is not "unsecured", so losing an encrypted laptop is generally not a reportable breach. Losing an unencrypted one usually is.
  • Personal email accounts. Free email accounts used for referrals, lab results or scheduling sit outside any BAA.
  • Paper. Sign-in sheets that show reasons for visit, charts on the front counter and records thrown in the regular trash.
  • Former staff. Accounts that stay active after someone leaves. Remove access the same day.
Vendors

Your vendor and BAA list

Short answer: write down every vendor that can see patient data, get a BAA from each, and stop sending PHI to any that refuse.

A typical solo practice list: EHR and practice management, clearinghouse or billing service, IT support, cloud backup, phone system and voicemail, online scheduling, intake forms, patient texting, email, payment processing for anything beyond the payment itself, review request tool, answering service, shredding and the marketing agency. Ask each one three questions: will you sign our BAA (or show us yours), which of your subcontractors will handle our data, and how do we get our data back when we leave?

Be careful with tools picked for convenience. An all-in-one marketing platform, a free form builder or a chat widget can collect PHI the moment a patient types a symptom into it. Some offer a BAA only on certain plans or only for some features. Our comparison of agencies and all-in-one automation platforms covers what to check.

Patients

Patient requests, email and texting

  • Right of access. Patients can ask for copies of their records. You must act within 30 days, with one 30-day extension if you tell the patient why in writing (164.524), and any fee must be reasonable and cost-based.
  • Confidential communications. Patients can ask to be contacted a certain way, such as on a mobile number but not at home, and you must accommodate reasonable requests (164.522(b)).
  • Email and texts. HHS guidance allows unencrypted email or text to patients who have been told the risks and still prefer it. Record that preference. For anything else, use a secure messaging tool under a BAA.
  • Marketing texts. Appointment reminders and promotional texts are treated differently under the TCPA. Get written consent before promotional texts. See the healthcare SMS compliance guide.
Marketing

Marketing a solo practice without leaking PHI

Short answer: keep patient data out of ad platforms and analytics, get BAAs from the tools that do touch it, and never confirm a patient relationship in public.

  • Website tracking. Keep ad pixels off booking pages, intake forms and patient portals. Our HIPAA-safe website tracking guide shows a setup that still measures bookings.
  • Reviews. Thank reviewers without confirming they are patients or discussing care. See how to respond to negative reviews under HIPAA.
  • Testimonials and photos. Using a patient’s story, photo or before-and-after image in marketing needs a signed HIPAA authorization (164.508), plus compliance with FTC endorsement rules.
  • Patient lists. Emailing your own patients about your own services is generally allowed. Selling or sharing lists with another business for its marketing requires authorization.
  • Ads. Target by location and broad interests, not by health condition, and keep ad copy from implying you know the viewer’s condition. Google Ads healthcare policy has the detail.
Keeping it current

A quarterly routine that keeps the program alive

  1. Each quarter: review who has access to each system, remove anyone who has left, check backups restore, and look at the incident log.
  2. Each year: review the risk analysis and policies, retrain staff, confirm every vendor still has a current BAA, and report any small breaches to HHS within 60 days after December 31.
  3. Whenever something changes: new software, a move, a new vendor, a new service line or a second location. Update the risk analysis before the change goes live.

If you plan to grow, read HIPAA compliance as you scale now. A few habits set up early, like unique logins and a written vendor list, save a great deal of work at the second and third office.

Ichelon Consulting US works with independent practices as well as groups. We sign a BAA with every US client, and our client-facing team holds HIPAA compliance training certificates. Read how we work, browse US guides or book a call.

HIPAA by practice size

Find the guide for your size and structure

HIPAA compliance as you scale

The pillar: what changes from one office to a private-equity-backed platform.

Multi-location practice

Several offices, shared systems, a central phone team and location managers.

MSO or management company

A management company serving affiliated practices, usually as a business associate.

Private-equity-backed platform

Acquisitions every quarter, inherited systems and diligence on every deal.

HIPAA compliance by role

What owners, practice managers, front desk and marketing staff each need to do.

Keep reading

Related pages from the US team

HIPAA compliance as you scale

How the program changes from one office to a platform.

HIPAA compliance by role

What owners, front desk and marketing staff each need to do.

Responding to reviews under HIPAA

How to reply to Google reviews without confirming a patient relationship.

Choosing an agency for a small practice

What to ask before you hire.

How we work

Every practice welcome — Goals-Driven engagements from $499/mo

We benchmark your last 90 days, agree monthly goals with you, and track them live on Ichelon Agency OS with a report every Monday. Performance-Linked Payout Models are available. Our US leadership is based in Dallas, and strategy calls run in US business hours.

Read the full engagement model →

FAQ

Common questions

Does HIPAA apply to a small or solo practice?

Yes, if the practice is a covered entity. A health care provider is covered when it transmits health information electronically in connection with a standard transaction, such as submitting insurance claims or checking eligibility. Size does not matter. A cash-only practice that never conducts those transactions may not be covered, but state privacy laws and the FTC Act can still apply.

Can the owner be the HIPAA privacy officer and security officer?

Yes. HIPAA requires a covered entity to designate a privacy official and a security official, and one person can hold both. Put the designation in writing and keep it with your policies.

How often does a solo practice need a HIPAA risk analysis?

HIPAA does not set a fixed interval, but the analysis must be accurate and current. Review it at least once a year and update it when you change systems, move offices or add a vendor that handles patient data. HHS offers a free Security Risk Assessment Tool designed for small practices.

Can I text patients from my own phone?

It is better not to. Patient texts on a personal phone sit outside your controls, mix with personal messages and leave with the device. Use a texting tool that signs a BAA, and get consent before any marketing texts under the TCPA.

Is a lost laptop a HIPAA breach?

It depends. If the device held unsecured PHI, it is presumed to be a breach unless a risk assessment shows a low probability of compromise. If the data was encrypted to the standard HHS describes, the information is not unsecured and breach notification is not required.

Which of my marketing vendors need a BAA?

Any vendor that creates, receives, maintains or transmits PHI for you: online scheduling, intake forms, call tracking and recording, texting, review request tools that use patient contact lists, and a marketing agency with access to any of that data. Tools that will not sign a BAA, such as Google Analytics, must be configured so PHI never reaches them.

A note on this guide: it explains marketing practice, not legal advice. Rules on privacy, advertising and insurance change and vary by state, so confirm anything compliance-related with your own counsel.

Running a one-office practice?

A 30-minute call with the US team. We will look at your website forms, phone setup and review requests and show you where patient data goes today.

Chat with Sr. Leadership
🎯 Goals-Driven engagements · Performance-Linked Payout Models
Chat with Sr. Leadership