HIPAA violations don't always look like a major data breach. Sometimes it's a staff member leaving too much information on a voicemail. A former employee still has access to an account. A patient requests a copy of their medical record and the practice doesn't respond properly. A vendor has access to PHI, but nobody can find the Business Associate Agreement. These situations can seem small. From a compliance standpoint, they may not be. The HHS Office for Civil Rights (OCR) says the most frequently alleged HIPAA issues include impermissible uses or disclosures of PHI, inadequate safeguards, failures involving patient access to PHI, inadequate administrative safeguards for ePHI, and disclosures involving more than the minimum necessary information — and private practices and physicians are among the organizations most frequently involved in HIPAA complaints. For a small practice, the problem is often not that people don't care about HIPAA. It's that HIPAA compliance is being managed informally. Here are some of the common problem areas worth looking at.
1. Discussing patient information where others can hear
A busy front desk can create privacy problems quickly. A staff member might call a patient by name and mention the reason for their visit while other patients are standing nearby. A nurse might discuss a patient's condition in a hallway. Someone may leave a voicemail containing more medical information than necessary. OCR has addressed cases involving inappropriate disclosures in conversations and telephone messages — in one example, a hospital employee left detailed information about a patient's condition and treatment plan in a message for the patient's daughter, and OCR required changes to procedures and staff training. The lesson isn't that employees can never discuss patient information. It's that practices need reasonable safeguards and should limit disclosures to what is appropriate. Ask yourself: are our employees trained on what they can say, where they can say it, and how much information they should disclose?
2. Giving out more PHI than necessary
HIPAA's minimum necessary principle is easy to overlook. A practice may have a legitimate reason to disclose information but still provide more than necessary for that purpose — think telephone messages, fax transmissions, emails, referrals, insurance communications, medical records sent to another provider, and conversations with family members. "Can we disclose this?" and "do we need to disclose all of this?" are not always the same question. OCR lists use or disclosure of more than the minimum necessary PHI among the most frequently alleged HIPAA compliance issues.
3. Not protecting paper records
HIPAA isn't only about cybersecurity. Paper records still contain PHI. A medical record left on a counter, a patient schedule visible to visitors, or documents thrown into an ordinary trash bin can create a privacy problem. OCR has even taken enforcement action involving a small, single-location pharmacy after unsecured documents containing PHI for 1,610 individuals were found in an unlocked container — the organization agreed to pay $125,000 and implement a corrective action plan. Small practice doesn't mean small responsibility.
4. Employees keeping access after they leave
This is one of the easiest things to overlook. Someone leaves the practice. Their email account remains active. Their EHR credentials remain active. Their access to cloud storage remains active. Nobody remembers to remove it. HIPAA's Security Rule requires appropriate workforce security and access management — practices should have procedures for authorizing access and managing access based on a person's role. A good offboarding process should include disabling accounts, removing EHR and remote access, recovering devices, reviewing shared accounts, removing access to cloud systems, and documenting the termination of access.
5. Not conducting a proper risk analysis
This is a big one. A practice cannot simply say "we have antivirus, firewalls, and an EHR, so we're covered." HIPAA requires a covered entity to conduct an accurate and thorough assessment of potential risks and vulnerabilities to ePHI and then manage those risks appropriately. Your risk analysis should consider the actual environment in which your practice operates — EHR systems, computers, mobile devices, email, cloud applications, vendors, backups, remote access, physical security, workforce practices, and potential threats and vulnerabilities. And the risk assessment shouldn't sit untouched in a folder for five years. It should inform what you actually do next.
6. Having policies that nobody follows
Having a HIPAA policy sitting in a folder doesn't automatically mean the practice has an effective compliance program. Imagine your practice has a written policy requiring employees to report security incidents. Then an employee accidentally sends PHI to the wrong person. Nobody knows who to tell. The policy exists. The process doesn't. OCR's enforcement work has repeatedly involved corrective actions requiring organizations to revise policies, implement procedures, and train their workforce. The goal isn't to have the biggest policy manual — it's to have policies that reflect how your practice actually operates.
7. Missing Business Associate Agreements
Your practice probably depends on outside companies — your EHR provider, billing company, IT provider, cloud storage provider, backup provider, transcription service, shredding company, and practice management software may all involve business associate relationships depending on the services provided and their access to PHI. The mistake is assuming "they're a reputable company, so we're fine." You need to understand the relationship and determine whether a BAA is required, and you need to know where the agreement is. A spreadsheet saying "BAA = Yes" is much less useful than having the actual agreement organized and readily accessible.
8. Not responding properly to patient record requests
Patients have rights under HIPAA, including rights concerning access to their protected health information. This is another area where small practices can get into trouble simply because staff don't understand the process — OCR has resolved multiple cases involving private practices that failed to provide patients with appropriate access to their records. Your practice should have a clear process for receiving requests, verifying the request, tracking it, determining what must be provided, meeting applicable deadlines, and documenting the response. Don't leave this to memory.
9. Ignoring employee training
You can have excellent policies and still have a weak HIPAA program if your employees don't understand what they're supposed to do. Employees should understand practical issues such as phishing, password security, patient conversations, email, mobile devices, incident reporting, social media, physical records, secure disposal, and access to patient information. And your practice should keep evidence that training occurred. If someone asks, "how do you know your workforce was trained?" you should be able to answer with documentation.
10. Not documenting what you do
This may be the biggest difference between a practice that says it is compliant and one that can actually demonstrate its compliance program. Think about it this way: you conducted a risk assessment — where is it? You trained your employees — where are the records? You reviewed your vendors — where is the evidence? You reviewed user access — where is the documentation? You responded to an incident — where is the incident record? This is why HIPAA compliance isn't just about doing the right things. It's about being able to demonstrate what you did.
The real problem for small practices
Most small practices don't have a Chief Compliance Officer sitting in an office reviewing HIPAA documentation all day. The practice manager may be doing it. Or the office manager. Or the physician. Sometimes it's simply whoever has time. That's understandable. But it creates another problem: compliance becomes scattered. One document is in email. Another is on someone's desktop. Training records are in a spreadsheet. BAAs are buried in a folder. The risk assessment hasn't been updated. Nobody remembers when the last vendor review happened. And then something happens. That's when everyone starts looking for the paperwork.
How Truvidence helps small medical practices
This is one of the reasons we built Truvidence. It's designed as a HIPAA compliance operating system for small healthcare practices — not simply another place to store policies. It brings the important parts of the compliance program together:
- Assess your practice and identify areas that need attention
- Create and organize HIPAA-related policies and documentation
- Keep your compliance evidence organized and accessible in one vault
- Track vendors, risk levels, agreements, reviews, and important dates
- Track workforce training and maintain documentation
- Keep recurring compliance activities and deadlines from disappearing into someone's calendar
- See your compliance posture in one place instead of piecing it together from spreadsheets
- Build a documented trail of the work your practice is doing so you're better prepared when documentation is requested
Don't wait until something goes wrong
HIPAA compliance shouldn't begin after a breach. It shouldn't begin after an OCR letter. And it shouldn't depend on whether the office manager remembers where the BAA folder is. The better approach is to build a compliance program that is organized, documented, and maintained throughout the year. Because the question isn't simply "are we HIPAA compliant?" The better question is "can we prove what we're doing to protect patient information?"
Want to see where your practice stands?
Take the free Truvidence HIPAA Risk Assessment. It can give your practice a practical starting point for identifying areas that may need attention. Truvidence — Assess. Document. Monitor. Prove. Maintain. This publication is for educational purposes only and is not legal advice, an OCR audit, or a guarantee of HIPAA compliance.