HIPAA Security Rule Basics for Small Practices

By J. Mesa

A two-dentist office and a 500-bed hospital answer to the same HIPAA Security Rule. The rule scales to your size, but it does not excuse you for being small. Regulators have fined solo practitioners and small clinics, and the most common finding in those cases is the same: nobody performed a risk analysis. A new year is a good time to check where your practice stands.

What is the HIPAA Security Rule?

The HIPAA Security Rule is a federal regulation that sets standards for protecting electronic protected health information, or ePHI. It requires you to keep that information confidential, accurate, and available. The Office for Civil Rights at the Department of Health and Human Services enforces it.

The Privacy Rule governs who may use and disclose patient information in any form. The Security Rule covers how you protect the electronic version.

Who has to comply?

Two groups.

  • Covered entities. Health plans, clearinghouses, and health care providers who send information electronically for standard transactions, such as billing insurance. That includes medical and dental practices, chiropractors, optometrists, therapists, pharmacies, and clinics.
  • Business associates. Companies that handle ePHI on behalf of a covered entity: billing services, IT providers, cloud hosting and backup vendors, transcription services, shredding companies, and consultants.

What is ePHI?

ePHI is health information that identifies a patient and that you create, store, or send in electronic form. Examples:

  • Electronic health records and practice management data
  • Digital X-rays and images
  • Appointment schedules that list names and reasons for visits
  • Billing and insurance records
  • Emails and text messages about patients
  • Voicemail recordings stored on a phone system
  • Scanned intake forms on a copier’s hard drive

What does the Security Rule require?

The rule groups its requirements into three sets of safeguards.

Administrative safeguards cover how you manage security:

  • Perform a risk analysis and manage the risks you find
  • Name a security official
  • Control who gets access to ePHI and remove access when people leave
  • Train the workforce
  • Plan for incidents and report them
  • Keep a contingency plan: backups, disaster recovery, and emergency operations
  • Sign business associate agreements

Physical safeguards cover buildings and equipment:

  • Limit physical access to servers and workstations
  • Position screens away from public view and lock unattended computers
  • Track, wipe, and dispose of devices and media that hold ePHI

Technical safeguards cover the technology:

  • Give each user a unique login
  • Log off idle sessions
  • Encrypt ePHI where reasonable
  • Record and review system activity
  • Protect data from improper changes
  • Verify the identity of users
  • Protect data sent over networks

What is a HIPAA risk analysis?

A risk analysis is a documented review of where your ePHI lives, what could go wrong with it, how likely each problem is, and how much damage it would cause. Follow these steps:

  1. List every system, device, and vendor that stores or touches ePHI.
  2. Identify the threats to each: theft, ransomware, employee error, fire, flood, vendor failure.
  3. Record the protections you already have.
  4. Rate the likelihood and the impact of each threat.
  5. Rank the risks.
  6. Write a plan to reduce the high ones, with owners and dates.

Update the analysis each year and after major changes, such as a new records system, a move, or a new office. The Department of Health and Human Services offers a free Security Risk Assessment Tool for small practices.

A vulnerability scan is not a risk analysis. A checklist from your records vendor is not a risk analysis. Regulators ask for the document described above, and they ask for it first.

What do “required” and “addressable” mean?

The rule labels each specification as required or addressable. Required means you must implement it. Addressable does not mean optional. For an addressable item, you assess whether it is reasonable for your practice. Then you implement it, implement an equivalent alternative, or document why neither is reasonable.

Encryption is addressable. In practice, a laptop with unencrypted patient data is a reportable breach the moment it gets stolen. Encrypt the laptops, the phones, and the backups.

Do I need a business associate agreement?

Yes, with each vendor that creates, receives, stores, or transmits ePHI for you. The agreement binds the vendor to protect the data and to report breaches to you. Common vendors that need one:

  • Your IT company
  • Cloud backup and file storage providers
  • Email and messaging providers
  • Billing and collections services
  • Your records software vendor
  • Answering services and appointment reminder services

A free email account or a consumer file-sharing plan comes with no agreement. Use the business versions that offer one, and sign it before you send patient data.

What training does HIPAA require?

You must train every workforce member on security, including owners, clinicians, front desk staff, and part-time employees. Train new hires at the start, repeat the training each year, and send reminders between sessions. Cover phishing, passwords, device handling, and how to report an incident. Keep attendance records. Our cybersecurity training covers these topics for health care teams.

What are the most common HIPAA security mistakes in small practices?

  • No risk analysis, or one from years ago
  • Shared logins at the front desk
  • No multi-factor authentication on email and remote access
  • Unencrypted laptops and phones
  • Texting patient details from personal phones
  • No signed business associate agreements
  • Former employees with active accounts
  • Unsupported operating systems on imaging and front desk computers
  • Backups that nobody tested
  • No written policies, or policies downloaded once and never read
  • Old computers and copiers discarded with patient data on the drives

What happens after a breach?

The Breach Notification Rule sets the duties.

  • Notify each affected patient without unreasonable delay, and no later than 60 days after you discover the breach.
  • For a breach affecting 500 or more people, notify the Department of Health and Human Services within the same 60 days. When the breach affects more than 500 residents of one state, notify prominent media outlets in that state as well.
  • For a breach affecting fewer than 500 people, log it and report it to the Department within 60 days after the end of the calendar year.

A ransomware attack on systems that hold ePHI counts as a breach unless you can show a low probability that the data was compromised. State laws may add shorter deadlines. Follow your incident response plan and call an attorney early.

What are the penalties?

Civil penalties rise with the level of fault, from cases in which the practice did not know about a violation up to willful neglect left uncorrected. The amounts range from about a hundred dollars to tens of thousands of dollars per violation, with annual caps that adjust for inflation. Settlements usually add a corrective action plan with years of government monitoring. State attorneys general can bring their own cases.

The Office for Civil Rights runs an enforcement initiative focused on risk analysis, and it has settled with small practices under that initiative.

How do I get started?

  1. Name your security official in writing.
  2. Complete a risk analysis.
  3. Fix the highest risks first: multi-factor authentication, encryption, backups, and patching.
  4. Write or update your policies and procedures.
  5. Collect signed business associate agreements.
  6. Train the staff and record it.
  7. Write an incident response and breach notification procedure.
  8. Keep all documentation for six years.
  9. Review the program each year.

Your next step

Find your last risk analysis and read the date on it. If it is more than a year old, or you can’t find one, start there. Cerberus Cybersecurity performs HIPAA risk assessments, writes the required policies, and trains health care staff. See our services or contact us.