Short answer: A HIPAA-compliant small practice needs eight core items on file: a written risk assessment, a Security Rule policies and procedures manual, a designated Security Officer, Business Associate Agreements with every vendor touching PHI, employee training records, a written incident response and breach notification plan, an access control and audit log policy, and a documented sanctions policy for staff violations. If any of these are missing, that's a specific, identifiable gap rather than a vague sense of "we should probably have that."
Why "we're careful with patient data" isn't documentation
Plenty of small practices genuinely handle patient information carefully in day-to-day practice, but that's not the same as having documented evidence of a compliance program. If OCR ever audits your practice, or a patient files a complaint, "we're careful" isn't something you can hand over. These eight items are.
The 8 items, explained
1. A written risk assessment. Identifies where PHI lives across your systems (EHR, billing, email, physical files) and what threatens it. Needs a date, and that date needs to be current.
2. A Security Rule policies and procedures manual. The written document describing how your practice implements the Security Rule's required and addressable safeguards — access controls, encryption practices, workstation security, and so on.
3. A designated Security Officer. A specific person, by name, responsible for your practice's security program. This mirrors the "Qualified Individual" concept in other compliance frameworks — someone accountable, not a general statement that "the practice" handles it.
4. Business Associate Agreements (BAAs). Signed agreements with every vendor that creates, receives, maintains, or transmits PHI on your behalf — your EHR vendor, billing service, cloud storage provider, and any IT support with system access.
5. Employee training records. Dates, content covered, and proof each staff member with PHI access actually completed training — not just a policy stating training happens.
6. A written incident response and breach notification plan. A specific plan for what happens if PHI is exposed, including your process for meeting the Breach Notification Rule's timelines.
7. Access control and audit log policy. Documentation of who can access what patient information, and how you monitor and log that access.
8. A documented sanctions policy. What happens internally if a staff member violates your security policies — this needs to be written down, not just understood informally.
Where small practices typically fall short
Most small practices have some of these — usually a risk assessment or a basic policy document — but rarely all eight, and even less often with everything current and consistent with each other. BAAs are a particularly common gap: practices often have one with their EHR vendor but miss smaller vendors like a billing service or a cloud backup provider that also touch PHI.
Getting all eight into one place
Reconstructing this list under audit pressure, or after a patient complaint, is a much harder position than having it ready in advance. Truvidence generates and maintains all eight of these documents in one dashboard, tied to your actual risk assessment, so producing proof of compliance becomes a quick request instead of a scramble.