Introduction: HIPAA Compliance Does Not End With Privacy
The Privacy Rule tells you who can see patient information and when. The Security Rule tells you how to protect it once it's stored electronically. Those are two separate problems, and a practice that's solid on one can still be exposed on the other.
Part 1 of this series covered the Privacy Rule: Patient rights, minimum necessary disclosures, who's responsible for policy. This post covers what comes after that. Limiting who's allowed to see a patient's record does nothing to stop that record from being accessed by someone who was never supposed to have it in the first place. This can mean a stolen laptop, a weak password, or a vendor system nobody thought to check.
The Security Rule exists to set standards for protecting electronic protected health information (ePHI) from unauthorized access, loss, theft, and breaches. For a small practice, that means specific, practical safeguards, not just a policy on paper.
What Is the HIPAA Security Rule?
Unlike the Privacy Rule, which applies to PHI in any form, the Security Rule only applies once that information touches a computer, a server, an EHR, or any electronic system. For most practices today, that's nearly everything. Paper charts are rare enough that the Security Rule ends up governing the bulk of daily operations, even if it doesn't feel that way. (HHS.gov, Security Rule Summary)
Physical Safeguards
Physical safeguards cover the tangible side of protecting ePHI: the building, the devices, and who can get near either one.
This includes limiting physical access to areas where ePHI is stored, keeping workstations secured, so screens aren't left exposed, and controlling what happens to hardware and media containing ePHI, from receiving new devices to disposing of old ones. Data must also be wiped from any device before it's reused.
Technical Safeguards
Access control means only authorized users reach ePHI, each with a unique login. Authentication checks that whoever is logging in is that person. Audit controls track who accessed what, and when. Integrity measures confirm data hasn't been altered or destroyed. Transmission security covers encryption while data moves across a network.
Access Management: Who Can Access Your EHR?
Every login should map to one person, doing one job, with access limited to that job. The front desk doesn't need clinical notes. Billing doesn't need full chart access.
The most common failure point here is stale access: logins that stay active after someone's role changes or their employment ends. A quick check: pull your user list and see if everyone still needs the access they have.
HIPAA Hosting, Vendors, and Business Associates
Protecting ePHI doesn't stop at your practice's own systems. Many practices rely on third-party vendors for EHR hosting, cloud storage, billing, IT support, backups, and communication tools, all of which may access or store patient information.
Under HIPAA, these vendors may be considered business associates if they handle ePHI on your behalf. Before allowing a vendor to access, practices should have a signed Business Associate Agreement (BAA) that defines how the data will be protected, what security responsibilities the vendor has, and how potential breaches will be handled.
A vendor claiming to be "HIPAA compliant" isn't enough by itself. Jeremy Shiner has pointed out that once PHI leaves the EHR, it can pass through centralized databases, vendors that aren't covered by entities, or technology partners with no BAA in place at all. This risk has grown with AI tools added as plug-ins or API connections outside the EHR, some of which rely on models accessed via API in ways that bypass BAA requirements entirely. His advice: ask for a full data flow diagram, identify every system that touches PHI, and confirm a BAA exists at each level, not just at the top.
Regular vendor reviews should be part of your practice security process. Questions that you should ask before:
Does this vendor still need access to ePHI?
Is there a current BAA in place?
What security measures does the vendor use to protect patient data?
Are access permissions limited to only what is necessary?
Common HIPAA Security Mistakes and Violations
Beyond shared logins and stale access, a few other mistakes show up often:
Not using multi-factor authentication (MFA). A password alone may not be enough. MFA adds a verification step and helps prevent unauthorized access if credentials are compromised.
Storing ePHI on unsecured devices. Laptops, phones, and tablets containing patient information need encryption, strong passwords, and remote-wipe capability where available.
Skipping regular risk assessments. HIPAA compliance isn't a one-time checklist. Practices need to regularly review where ePHI is stored, who can access it, and what new risks have appeared as technology and workflows change.
Ignoring software updates and security patches. Outdated systems can carry known vulnerabilities attackers already know how to exploit.
Failing to train staff properly. Employees are often the first line of defense. Without regular training, staff may unintentionally expose patient information through phishing emails, improper sharing, or weak security habits.
What to Do After a Potential PHI Breach
Even with strong safeguards, a practice may still face a potential breach. The key is responding quickly and following a documented process.
First, identify and contain the incident. This may include disabling compromised accounts, recovering lost devices, removing unauthorized access, or working with vendors to stop further exposure.
Next, document and investigate. Determine what information was involved, whose data may have been affected, when the incident occurred, and whether it's a reportable breach under HIPAA.
Involve the right people early: your Security Official, privacy officer, IT team, or legal counsel. If a breach is confirmed, HIPAA may require notifying affected individuals, HHS, and in some cases, the media.
Don't treat the incident as solved once it's handled. Use it to review what caused the breach and update policies, training, access controls, or security measures to prevent it from happening again.
The complete HIPAA Security Rule checklist
Administrative safeguards
Designate a Security Official responsible for HIPAA security policies
Complete regular risk assessments to identify potential threats to ePHI
Create policies for access management, incident response, and data recovery
Train employees on HIPAA security responsibilities
Maintain a process for reporting and responding to security incidents
Review business associates and confirm BAAs are in place where required
Maintain backups and recovery processes for critical systems
Physical safeguards
Limit physical access to areas where ePHI is stored
Secure workstations and prevent unauthorized screen access
Protect laptops, tablets, and other devices containing patient information
Have procedures for securely disposing of devices and electronic media
Ensure data is removed before equipment is reused or discarded
Technical safeguards
Give each user a unique login and avoid shared accounts
Use strong authentication methods, including multi-factor authentication where possible
Limit EHR access based on each employee’s role
Monitor system activity through audit controls
Protect ePHI during transmission with appropriate security measures
Vendor and access management
Review every vendor that stores, processes, or accesses ePHI
Confirm vendors have appropriate security practices in place
Remove access when employees or contractors no longer need it
Regularly review user permissions to ensure access remains appropriate
How to perform a HIPAA gap analysis
A HIPAA gap analysis helps practices understand where their current security practices stand, where they need improvement, and what steps are needed to strengthen compliance. It compares your existing policies, procedures, and safeguards against HIPAA requirements to identify areas of risk.
A HIPAA gap analysis can be completed in four steps:
1. Review your current operations
Start by understanding how your practice currently handles ePHI. Review your policies, procedures, systems, and workflows. Are your security policies up to date? Are employees following the procedures that are already in place?
2. Compare your practices against HIPAA requirements
Evaluate your current operations against the standards outlined in the HIPAA Privacy and Security Rules. Review areas such as access controls, employee training, risk assessments, vendor management, and technical safeguards to determine whether your current practices meet requirements.
3. Identify security gaps
Document where your HIPAA program falls short. This could include outdated policies, excessive user access, missing documentation, weak security controls, or vendors without proper agreements in place. Be specific so each issue can be addressed effectively.
4. Create and implement an improvement plan
Develop a clear action plan to close the identified gaps. Assign responsibilities, set realistic deadlines, and prioritize improvements based on risk. A successful gap analysis should result in measurable steps that strengthen your practice’s HIPAA compliance over time.
HIPAA Compliance Requirements for Ongoing Security
Maintaining HIPAA Security Rule compliance can feel complex, but the right systems and processes make it manageable. Regularly reviewing your safeguards and closing gaps as they show up reduces risk and builds real trust with patients.
Risk assessments, access logs, and training records all need to be tracked consistently, and that's a lot to manage by hand on top of running a practice. None of this has to run on manual tracking. Myriad Systems takes tracking off your plate, protecting patient data without the extra workload. Schedule a walkthrough to see how it works for your practice.
FAQ
What does NPP stand for in HIPAA
NPP stands for Notice of Privacy Practices. It explains how a healthcare provider may use and disclose a patient’s protected health information (PHI) and describes the patient’s privacy rights.
What is a HIPAA breach?
A HIPAA breach is an unauthorized access, use, disclosure, or acquisition of PHI that compromises the security or privacy of patient information.
What are examples of HIPAA violations?
Examples include accessing patient records without permission, sharing PHI with unauthorized individuals, using unsecured devices, failing to protect passwords, or not having proper agreements with business associates.
Is ChatGPT HIPAA compliant?
ChatGPT isn't automatically HIPAA compliant. Healthcare organizations should only use AI tools with appropriate safeguards in place, including a signed BAA, and should avoid entering PHI into tools not approved for HIPAA use. ( HHS.gov, Business Associates; HIPAA Journal, HIPAA, Healthcare Data, and Artificial Intelligence)
How long does HIPAA certification last?
HIPAA does not provide an official certification that expires. Organizations may complete HIPAA training or compliance programs, but maintaining compliance requires ongoing reviews, updates, and risk assessments.






