HIPAA compliance for a solo practice: a program one owner can run
A solo practice needs the same HIPAA program as a large group, at a size one owner can run. That means a written risk analysis, named privacy and security officials (often you), short policies, trained staff, signed business associate agreements and a plan for breaches. Most of it can be set up in a few working days and kept current with a few hours each quarter.
- First check whether you are a covered entity: a provider is covered if it transmits health information electronically in a standard transaction, such as billing insurance.
- The core file: risk analysis, officer designations, policies, Notice of Privacy Practices, training records, BAAs and a breach log, kept for six years.
- Most solo-practice risk sits in personal phones, shared passwords, unencrypted laptops and marketing tools added without a BAA.
- Encrypting devices properly can mean a lost laptop is not a reportable breach.
- When you open a second office, revisit everything: see the multi-location guide.
- Every practice welcome — retainers from $499/mo, Goals-Driven engagements, Performance-Linked Payout Models available.
- Dallas, Texas LLC
- 10-person US client team · Central Time (CST)
- 25+ US healthcare clients
- BAA signed with every client
- HIPAA compliance training across client and delivery teams
- Contracts and invoices in USD
-
Primary Care · North Dallas, TXCase study →
-
MedSpa · North Dallas, TX
-
Skin Care · Beverly Hills, CA
-
Dental · Christiansburg, VACase study →
-
Pediatrics · Blacksburg, VACase study →
-
Pediatric Dentistry · Blacksburg, VACase study →
-
Dental · Roanoke, VACase study →
-
Functional Medicine · Telehealth · USACase study →
“They were able to get all my ideas and work with me over a period of three to four months and create this amazing website. It's super customized, very modern, and it incorporates all the elements that I had wanted — the patient portal, nice pictures, a very interactive website, patient reviews. I would highly recommend their company to anyone who wants to make an excellent website.”
Step one: confirm you are a covered entity
Short answer: if your practice bills insurance electronically, or checks eligibility or claim status electronically, you are a covered entity and HIPAA applies in full.
Under 45 CFR 160.103, a health care provider is a covered entity when it "transmits any health information in electronic form in connection with a transaction" covered by HIPAA. Claims, eligibility checks, referral authorizations and remittance are the common ones. Using a billing company to send them for you still counts.
A cash-only practice that never conducts those transactions, such as some med spas, concierge practices and wellness clinics, may not be a covered entity. That does not leave patient data unregulated. Texas, for example, defines "covered entity" in Health and Safety Code Chapter 181 to include anyone who comes into possession of PHI, Washington’s My Health My Data Act covers consumer health data outside HIPAA, and the FTC polices deceptive privacy promises. Most cash practices follow HIPAA-level practices anyway, because patients and partners expect it.
The HIPAA file every solo practice should have
Short answer: eight documents, kept current and kept for six years after they were last in effect.
| Document | What it needs to cover | Rule |
|---|---|---|
| Risk analysis | Where electronic PHI lives (EHR, phones, laptops, email, cloud tools), the threats to it and how likely and damaging each is | 164.308(a)(1)(ii)(A) |
| Risk management plan | What you will do about each risk, by when and who owns it; update as items are closed | 164.308(a)(1)(ii)(B) |
| Officer designations | Who is the privacy official, who is the security official, who takes complaints | 164.308(a)(2), 164.530(a) |
| Policies and procedures | Short and specific to your office: access, passwords, devices, email and texting, records requests, disposal, incidents, sanctions | 164.316, 164.530(i) |
| Notice of Privacy Practices | Given at the first visit with a good-faith effort to get acknowledgment, posted in the office and posted prominently on your website | 164.520 |
| Training records | Who was trained, when and on what; at hire and after material policy changes | 164.530(b), 164.308(a)(5) |
| Business associate agreements | One for every vendor that handles PHI for you | 164.308(b), 164.504(e) |
| Incident and breach log | Every incident, the risk assessment you did and whether you notified; small breaches reported to HHS within 60 days after year end | 164.402 to 164.408 |
HHS and the Office of the National Coordinator offer a free Security Risk Assessment Tool built for small and medium practices. It is a reasonable way to produce your first written risk analysis. Whatever tool you use, the analysis has to reflect your actual systems, not a template.
Where solo practices actually get into trouble
Short answer: devices and shortcuts. In a small office, the convenient way to do something is often the risky way.
- Personal phones. Patient photos, texts and voicemails on an owner’s or staff member’s own phone. Use practice-managed apps that sign BAAs and keep PHI off personal camera rolls.
- Shared logins. One front-desk password for the EHR means you cannot tell who looked at what. HIPAA expects unique user identification (164.312(a)(2)(i)).
- Unencrypted laptops and backups. Under HHS guidance on unsecured PHI, data encrypted to the NIST-based standard is not "unsecured", so losing an encrypted laptop is generally not a reportable breach. Losing an unencrypted one usually is.
- Personal email accounts. Free email accounts used for referrals, lab results or scheduling sit outside any BAA.
- Paper. Sign-in sheets that show reasons for visit, charts on the front counter and records thrown in the regular trash.
- Former staff. Accounts that stay active after someone leaves. Remove access the same day.
Your vendor and BAA list
Short answer: write down every vendor that can see patient data, get a BAA from each, and stop sending PHI to any that refuse.
A typical solo practice list: EHR and practice management, clearinghouse or billing service, IT support, cloud backup, phone system and voicemail, online scheduling, intake forms, patient texting, email, payment processing for anything beyond the payment itself, review request tool, answering service, shredding and the marketing agency. Ask each one three questions: will you sign our BAA (or show us yours), which of your subcontractors will handle our data, and how do we get our data back when we leave?
Be careful with tools picked for convenience. An all-in-one marketing platform, a free form builder or a chat widget can collect PHI the moment a patient types a symptom into it. Some offer a BAA only on certain plans or only for some features. Our comparison of agencies and all-in-one automation platforms covers what to check.
Patient requests, email and texting
- Right of access. Patients can ask for copies of their records. You must act within 30 days, with one 30-day extension if you tell the patient why in writing (164.524), and any fee must be reasonable and cost-based.
- Confidential communications. Patients can ask to be contacted a certain way, such as on a mobile number but not at home, and you must accommodate reasonable requests (164.522(b)).
- Email and texts. HHS guidance allows unencrypted email or text to patients who have been told the risks and still prefer it. Record that preference. For anything else, use a secure messaging tool under a BAA.
- Marketing texts. Appointment reminders and promotional texts are treated differently under the TCPA. Get written consent before promotional texts. See the healthcare SMS compliance guide.
Marketing a solo practice without leaking PHI
Short answer: keep patient data out of ad platforms and analytics, get BAAs from the tools that do touch it, and never confirm a patient relationship in public.
- Website tracking. Keep ad pixels off booking pages, intake forms and patient portals. Our HIPAA-safe website tracking guide shows a setup that still measures bookings.
- Reviews. Thank reviewers without confirming they are patients or discussing care. See how to respond to negative reviews under HIPAA.
- Testimonials and photos. Using a patient’s story, photo or before-and-after image in marketing needs a signed HIPAA authorization (164.508), plus compliance with FTC endorsement rules.
- Patient lists. Emailing your own patients about your own services is generally allowed. Selling or sharing lists with another business for its marketing requires authorization.
- Ads. Target by location and broad interests, not by health condition, and keep ad copy from implying you know the viewer’s condition. Google Ads healthcare policy has the detail.
A quarterly routine that keeps the program alive
- Each quarter: review who has access to each system, remove anyone who has left, check backups restore, and look at the incident log.
- Each year: review the risk analysis and policies, retrain staff, confirm every vendor still has a current BAA, and report any small breaches to HHS within 60 days after December 31.
- Whenever something changes: new software, a move, a new vendor, a new service line or a second location. Update the risk analysis before the change goes live.
If you plan to grow, read HIPAA compliance as you scale now. A few habits set up early, like unique logins and a written vendor list, save a great deal of work at the second and third office.
Ichelon Consulting US works with independent practices as well as groups. We sign a BAA with every US client, and our client-facing team holds HIPAA compliance training certificates. Read how we work, browse US guides or book a call.
Find the guide for your size and structure
HIPAA compliance as you scale
The pillar: what changes from one office to a private-equity-backed platform.
Multi-location practice
Several offices, shared systems, a central phone team and location managers.
MSO or management company
A management company serving affiliated practices, usually as a business associate.
Private-equity-backed platform
Acquisitions every quarter, inherited systems and diligence on every deal.
HIPAA compliance by role
What owners, practice managers, front desk and marketing staff each need to do.
Sources
- 45 CFR 160.103, definitions (covered entity, health care provider, business associate).
- 45 CFR 164.308, administrative safeguards; 164.312, technical safeguards.
- 45 CFR 164.530, administrative requirements; 164.520, notice of privacy practices.
- 45 CFR 164.524, access of individuals; 164.522, confidential communications; 164.508, authorizations.
- 45 CFR 164.408, notification to the Secretary.
- Guidance to render unsecured PHI unusable, unreadable or indecipherable (HHS).
- Security Risk Assessment Tool (HHS / ONC).
- Using email to communicate with patients (HHS FAQ).
- Texas Health and Safety Code 181.001, definitions.
- Chapter 19.373 RCW, Washington My Health My Data Act.
- HIPAA and Google Analytics (Google).
Not legal advice: this guide describes a typical HIPAA program for a small practice. It is not legal advice. Confirm your obligations, including state law, with healthcare counsel.
Related pages from the US team
HIPAA compliance as you scale
How the program changes from one office to a platform.
HIPAA compliance by role
What owners, front desk and marketing staff each need to do.
Responding to reviews under HIPAA
How to reply to Google reviews without confirming a patient relationship.
Choosing an agency for a small practice
What to ask before you hire.
Every practice welcome — Goals-Driven engagements from $499/mo
We benchmark your last 90 days, agree monthly goals with you, and track them live on Ichelon Agency OS with a report every Monday. Performance-Linked Payout Models are available. Our US leadership is based in Dallas, and strategy calls run in US business hours.
Common questions
Does HIPAA apply to a small or solo practice?
Yes, if the practice is a covered entity. A health care provider is covered when it transmits health information electronically in connection with a standard transaction, such as submitting insurance claims or checking eligibility. Size does not matter. A cash-only practice that never conducts those transactions may not be covered, but state privacy laws and the FTC Act can still apply.
Can the owner be the HIPAA privacy officer and security officer?
Yes. HIPAA requires a covered entity to designate a privacy official and a security official, and one person can hold both. Put the designation in writing and keep it with your policies.
How often does a solo practice need a HIPAA risk analysis?
HIPAA does not set a fixed interval, but the analysis must be accurate and current. Review it at least once a year and update it when you change systems, move offices or add a vendor that handles patient data. HHS offers a free Security Risk Assessment Tool designed for small practices.
Can I text patients from my own phone?
It is better not to. Patient texts on a personal phone sit outside your controls, mix with personal messages and leave with the device. Use a texting tool that signs a BAA, and get consent before any marketing texts under the TCPA.
Is a lost laptop a HIPAA breach?
It depends. If the device held unsecured PHI, it is presumed to be a breach unless a risk assessment shows a low probability of compromise. If the data was encrypted to the standard HHS describes, the information is not unsecured and breach notification is not required.
Which of my marketing vendors need a BAA?
Any vendor that creates, receives, maintains or transmits PHI for you: online scheduling, intake forms, call tracking and recording, texting, review request tools that use patient contact lists, and a marketing agency with access to any of that data. Tools that will not sign a BAA, such as Google Analytics, must be configured so PHI never reaches them.
A note on this guide: it explains marketing practice, not legal advice. Rules on privacy, advertising and insurance change and vary by state, so confirm anything compliance-related with your own counsel.
Running a one-office practice?
A 30-minute call with the US team. We will look at your website forms, phone setup and review requests and show you where patient data goes today.