Category: HIPAA Compliance

  • Does Having an MSP Mean Your Practice Is HIPAA Compliant? Not on Its Own

    Does Having an MSP Mean Your Practice Is HIPAA Compliant? Not on Its Own

    Quick answer: No, and this is one of the most common and most understandable misconceptions in healthcare compliance. A skilled managed service provider, or MSP, can lock down your network, patch your systems, and manage backups better than most practices could on their own; if that MSP handles protected health information, it is likely a business associate with its own direct HIPAA obligations. None of that, on its own, satisfies your practice’s obligations. The Security Rule requires every covered entity to maintain its own compliance program; a practice still needs its own risk analysis, policies, workforce training, and a signed business associate agreement with every vendor that touches patient data, including its IT partner.

    Where the False Sense of Security Comes From

    It is an easy assumption to make. A practice hires a capable IT company; that company installs firewalls, manages antivirus tools, sets up secure backups, and generally keeps the network running well. From the practice’s point of view, the technical side of compliance feels handled. The trouble is that HIPAA compliance is not only a technical question. It also requires a documented risk analysis, written policies and procedures, a designated privacy and security officer, workforce training records, and an incident response plan tied specifically to protected health information. A great MSP can support several of these pieces; it cannot generate them on its own, and it certainly cannot sign them on the practice’s behalf.

    What a Good MSP Actually Covers, and What It Doesn’t

    Most reputable MSPs are genuinely strong at the technical safeguards: encryption, access controls, patch management, monitoring, and secure backups. Where the gap tends to show up is on the administrative side, since a Security Risk Analysis, HIPAA-specific workforce training, and a program for managing business associate agreements across every vendor a practice uses are compliance program tasks, not network tasks; they belong to the covered entity, even when an MSP is excellent at its own job.

    Why Not Every MSP Understands HIPAA Either

    This is the part that deserves equal attention. In our experience, most MSPs are genuinely good at IT; general cybersecurity, network uptime, and help desk support are their bread and butter. HIPAA, though, is a specific regulatory framework with its own definitions, documentation requirements, and enforcement history, and general IT training does not automatically cover it. A provider that assumes any IT company can double as a HIPAA partner is often building its compliance program on an assumption nobody actually verified. This is not a knock on MSPs; it is simply a reminder that HIPAA knowledge and IT skill are two different areas of expertise, and a practice should confirm, in writing, that its MSP genuinely understands the requirements rather than assuming it by default. Because of this, Colington Consulting works only with MSP referral partners who demonstrably understand HIPAA’s administrative, physical, and technical safeguard requirements, not just general network security.

    The Data Behind the Confidence Gap

    A recent survey of 214 IT leaders and practice managers at healthcare organizations with fewer than 250 employees found that 98 percent believed their email platforms encrypted messages by default, and more than 80 percent expressed overall confidence in their HIPAA compliance posture; in reality, tools like Microsoft 365 and Google Workspace do not guarantee that protection, and encryption can silently fail if a recipient’s server does not support current protocols. The same survey found that 83 percent believed a patient’s consent to email removed the legal requirement for safeguards, which is incorrect. As the Director of the HHS Office for Civil Rights has said, risk assessments are not optional; they are foundational, and that obligation applies to the covered entity’s own program, even when a capable vendor manages the network.

    What This Means for Your Practice

    • A signed business associate agreement with your MSP covers how it protects data, not whether your practice as a whole is HIPAA compliant.
    • Your practice still needs its own current Security Risk Analysis, documented policies, and workforce training records; none of that transfers from a vendor.
    • Ask your MSP directly how it stays current on HIPAA-specific requirements, not just general cybersecurity best practices.
    • A strong MSP and a strong compliance program work together; one does not substitute for the other.

    Frequently Asked Questions

    If our IT company signs a business associate agreement, are we HIPAA compliant?

    No. A business associate agreement establishes how your MSP is expected to protect data it can access; it does not satisfy your practice’s own obligation to complete a Security Risk Analysis, maintain policies, or train your workforce.

    Does a HIPAA-compliant MSP mean we do not need our own compliance program?

    No. Even organizations with excellent technical safeguards still need their own documented risk analysis, policies, and training; these are the covered entity’s own administrative requirements, and they hold regardless of how compliant your MSP is with its own separate obligations.

    How do we know if our MSP actually understands HIPAA?

    Ask specific questions, such as how they support your Security Risk Analysis, how they handle breach notification timelines, and whether they can speak to the difference between HIPAA and general cybersecurity best practices; a partner who cannot answer clearly is a signal worth taking seriously.

    Not Sure If Your IT Setup Actually Covers Your Compliance Obligations? Colington Consulting Can Help You Find Out

    A capable MSP is a valuable part of a compliance program; it was never meant to be the whole program. Colington Consulting works directly with small and midsize providers to build the documented, defensible pieces that sit outside of IT, and we only refer clients to MSP partners who genuinely understand HIPAA’s requirements.

    Get a free HIPAA Risk Review. We’ll help you see exactly where your IT setup ends and your compliance obligations begin, and show you what still needs to be built.

    Schedule Your Free HIPAA Risk Review โ†’

    Sources

    U.S. Department of Health and Human Services, Office for Civil Rights, statement on HIPAA Security Rule risk assessment obligations.

    Paubox, survey of 214 IT leaders and practice managers at healthcare organizations under 250 employees, reported in Medical Economics, “Most small practices think they’re HIPAA compliant, a new report says they’re wrong.”

  • Why HIPAA Is Still Confusing After Thirty Years, Especially for Small and Midsize Providers

    Why HIPAA Is Still Confusing After Thirty Years, Especially for Small and Midsize Providers

    Quick answer: HIPAA has been federal law since 1996, yet small and midsize providers still get tripped up by it, and the reason is rarely carelessness. Most owners and office managers never received formal HIPAA training; they inherited assumptions from a prior job, a vendor’s marketing page, or an online forum, and those assumptions are often wrong. The confusion tends to fall into two camps that look opposite but create the same exposure: providers who assume a tool or vendor already handles compliance for them, and providers who never learned the regulations well enough to tell a permitted disclosure from one that actually requires authorization. Both leave real gaps, and OCR, along with a growing number of state regulators, is actively finding them.

    Thirty Years Old, Still Misunderstood

    HIPAA is not a new law, and that is part of the problem. It has been amended, reinterpreted, and layered with guidance so many times since 1996 that the version most people learned, whether from a compliance seminar a decade ago or a coworker’s offhand explanation, is often out of date. Add in the fact that most clinicians and practice administrators never sat through a formal HIPAA course in school, and you get a compliance culture built on secondhand information rather than the actual rule text.

    That gap shows up constantly in small practice communities online, where one commenter insists a tool is safe, another insists it never can be, and a third says solo practices simply do not get looked at. None of them are working from the regulation itself; they are working from what they have heard. The confusion is understandable. It is also, according to compliance experts who work directly with small practices, a training problem rather than a character problem, and it is fixable once the actual myths are named and corrected.

    Myth One: “Our Software Already Makes Us HIPAA Compliant”

    This is the myth doing the most quiet damage right now. A recent survey of IT leaders and practice managers at organizations with fewer than 250 employees found that nearly all of them believed their email platform automatically encrypted messages containing patient information. In reality, common business tools like Microsoft 365 and Google Workspace do not guarantee that protection by default; encryption can drop entirely if the recipient’s mail server does not support current protocols, leaving protected health information exposed without anyone realizing it. Close to half of healthcare email breaches trace back to Microsoft 365 environments alone.

    The same false confidence shows up with EHR platforms. A vendor’s business associate agreement covers how that vendor handles data inside its own system; it does not cover how your staff handles PHI outside the EHR, and it does not satisfy your own obligation to conduct a Security Risk Analysis. An EHR is a clinical documentation tool. It is not a compliance program, no matter what the marketing page implies.

    Myth Two: “Regulators Only Care About Big Health Systems”

    Every headline breach involves a hospital system or a national health plan, so it is an easy leap to assume enforcement follows the same pattern. It does not. OCR has been explicit that practice size does not create an exemption, and enforcement data backs that up: small medical and dental practices accounted for the majority of OCR’s financial penalties in a recent reporting year. Investigations are frequently triggered by something small, a single patient complaint, a lost laptop, or a phishing email that catches one employee, not a headline grade breach.

    Risk analysis failures have been the single most cited deficiency in OCR enforcement actions for more than a decade, and that pattern holds regardless of organization size. A five provider practice and a five hundred provider hospital system are held to the same underlying standard; the hospital system just has more staff to absorb the work.

    Myth Three: “HIPAA Only Applies Once Someone Is Officially Our Patient”

    It is a natural assumption. In most professional relationships, obligations start once a formal engagement begins, so providers assume PHI protections kick in once someone signs an intake form or shows up for a first visit. HIPAA does not draw that line. Protected health information is defined as individually identifiable information related to a person’s past, present, or future healthcare, which means a phone call, an intake questionnaire, or even a scheduling message can already be covered before a formal patient relationship exists.

    Myth Four: “The Safest Move Is to Share Nothing With Anyone”

    Overcorrection is just as common as underprepared, and it carries its own cost. Some practices become convinced they cannot discuss a patient anywhere on the premises, or that every routine disclosure for treatment purposes needs a separate signed authorization. Compliance risk management professionals who work with small providers regularly see practices treat ordinary care coordination, like transferring records to a specialist for continued treatment, as though it required the same authorization process as a marketing disclosure. It does not. HIPAA already permits use and disclosure of PHI for treatment, payment, and healthcare operations without a separate authorization each time; practices that add friction here are not being safer, they are just slower, and staff eventually start looking for workarounds that create real risk.

    Myth Five: “A HIPAA Compliant Vendor Means We Are a HIPAA Compliant Practice”

    This one deserves its own heading because it is so common. Signing on with a vendor who advertises HIPAA compliant software, hosting, or messaging is a meaningful step, but it addresses one piece of a much larger program. Your practice still needs its own current Security Risk Analysis, its own written policies and procedures, its own workforce training, and its own documented incident response plan; none of that transfers from a vendor’s compliance posture to yours. Even organizations with no self funded health plan or complex vendor stack still need these four documented pieces, because they are what OCR asks for first in any investigation or audit.

    Why This Confusion Is Expensive, Not Just Awkward

    None of this would matter much if the stakes were low, but they are not. Healthcare has held the highest average breach cost of any industry sector for well over a decade running, and small practices absorb that cost with far less cushion than a large system. State regulators have also become more active alongside OCR, with several states bringing high profile settlements against small practices in the past year, which means a multi-state practice can no longer rely on federal HIPAA alone; state overlay requirements increasingly apply too.

    The pattern across almost every enforcement action tells the same story: it is rarely one dramatic mistake. It is a pile of ordinary, unremarkable decisions, a personal phone used for patient texts because it is faster, a new scheduling tool adopted without a signed business associate agreement, a risk analysis that was accurate three systems ago and never got updated, that nobody treated as a compliance decision when it was made.

    What Actually Clears Up the Confusion

    The fix is not memorizing the regulation. It is building a small number of documented habits that hold up regardless of which myth an employee picked up somewhere along the way.

    • Treat your Security Risk Analysis as a living document, not a one time project; update it whenever you change EHR systems, add a telehealth platform, or bring on new staff.
    • Confirm encryption in writing rather than assuming it; ask your email and EHR vendors directly whether encryption is guaranteed by default or dependent on the recipient’s system.
    • Map every point where PHI can leave your walls, phone, email, fax, text, patient portal, and confirm a business associate agreement or a documented safeguard covers each one.
    • Separate treatment, payment, and healthcare operations disclosures, which generally do not require a signed authorization, from marketing or research disclosures, which usually do.
    • Put workforce training on a real schedule, not a onboarding checkbox; most confusion traces back to staff repeating what they were told once, years ago, by someone who was also guessing.

    A Quick Self Check for Small and Midsize Practices

    โ˜  Do you have a Security Risk Analysis completed or updated within the last twelve months?

    โ˜  Have you confirmed, in writing, whether your email and messaging platforms encrypt PHI by default?

    โ˜  Do your written policies distinguish between disclosures that require patient authorization and those that do not?

    โ˜  Does every vendor touching PHI have a current, signed business associate agreement on file?

    โ˜  Has your team received HIPAA training in the last year, beyond a one time onboarding session?

    โ˜  If you offer a self funded employee health plan, has it been assessed as its own separate covered entity?

    Frequently Asked Questions

    Is a small medical or dental practice actually at risk of a HIPAA investigation?

    Yes. OCR has increasingly focused enforcement attention on smaller practices, and in a recent reporting year, small medical and dental practices accounted for the majority of OCR’s financial penalties. Investigations are often triggered by a single patient complaint or a routine incident, not a large scale breach.

    Does using a HIPAA compliant EHR mean our practice is fully compliant?

    No. An EHR vendor’s business associate agreement covers how that vendor handles data within its own system. It does not cover how your staff uses PHI outside the EHR, and it does not satisfy your practice’s own requirement to complete and maintain a Security Risk Analysis.

    Does HIPAA require a signed authorization before discussing a patient with another treating provider?

    Generally, no. HIPAA permits use and disclosure of PHI for treatment, payment, and healthcare operations without a separate authorization for each instance. Authorization requirements typically apply to disclosures outside those categories, such as marketing.

    When do HIPAA protections actually start applying to a person’s information?

    Protected health information is defined by an individual’s past, present, or future healthcare, not by whether a formal patient relationship has begun. Information shared during an intake call or scheduling message can already be covered.

    What is the single most common deficiency OCR cites in enforcement actions?

    Risk analysis failures. An incomplete, outdated, or missing Security Risk Analysis has been the most frequently cited deficiency in OCR enforcement for more than a decade, across organizations of every size.

    Not Sure Where Your Practice Actually Stands? Colington Consulting Can Help You Find Out

    Most of the small and midsize providers we work with are not careless; they are working from secondhand information that was never fully accurate to begin with. Colington Consulting works hands on with small practices, clinics, and specialty groups to replace assumptions with a documented, defensible compliance program built for organizations that do not have a dedicated compliance department.

    Get a free HIPAA Risk Review. We will walk through where your practice’s understanding of HIPAA may be out of date, identify the gaps that matter most, and show you exactly where to focus first.

    Schedule Your Free HIPAA Risk Review โ†’

    Sources

    Medical Economics, “Most small practices think they’re HIPAA compliant, a new report says they’re wrong,” reporting on Paubox survey data of IT leaders and practice managers at organizations under 250 employees.

    Patient Protect, “HIPAA Compliance for Independent Medical Practices: The Complete 2026 Guide.”

    Facet Technologies, “What the 2026 HIPAA Changes Actually Mean for Your Practice.”

    HIPAA Journal, “Editorial: HIPAA Compliance Challenges for Small Medical Practices” and “Why You Don’t Need to Understand HIPAA to Make Your Small Practice HIPAA Compliant.”

    Physicians Practice, “Four Common HIPAA Misconceptions.”

    U.S. Department of Health and Human Services, HIPAA Guidance Materials, hhs.gov.

  • 5 HIPAA Compliance Gaps That Put Healthcare Organizations at Risk

    Why Small Gaps Create Big Exposure

    HIPAA compliance failures rarely begin with a single dramatic mistake. More often, they stem from overlooked documentation, inconsistent staff practices, incomplete risk reviews, or security controls that have not kept pace with operational change. For healthcare providers and business associates, these gaps can increase exposure during audits, investigations, and breach response.

    Colington Consulting helps organizations build defensible HIPAA compliance programs that are practical, documented, and aligned with real-world regulatory expectations. Below are five common compliance gaps that deserve immediate attention.

    1. Incomplete Risk Assessments

    A HIPAA risk assessment should do more than satisfy a checkbox. It should identify where protected health information is created, stored, transmitted, and exposed across systems, vendors, workflows, and physical environments. When assessments are outdated, too narrow, or unsupported by evidence, organizations may struggle to demonstrate a reasonable compliance posture.

    A defensible risk assessment creates the foundation for stronger decisions, better documentation, and more credible compliance efforts.

    2. Weak Risk Management Follow-Through

    Finding risks is only the beginning. A common problem is the absence of a documented risk management plan that prioritizes issues, assigns responsibility, and tracks remediation over time. Without follow-through, known weaknesses remain unresolved and can become harder to explain after an incident.

    3. Staff Training That Lacks Depth

    HIPAA training should reflect actual job responsibilities and current threats, not just generic annual reminders. Workforce members need clear guidance on privacy expectations, security practices, phishing awareness, device use, reporting procedures, and how to handle protected health information in day-to-day operations.

    • Role-based training improves relevance
    • Recurring refreshers reinforce accountability
    • Documented completion records support compliance readiness

    4. Outdated Policies and Documentation

    Policies that do not match current systems, vendors, or workflows can create significant compliance risk. Organizations should regularly review privacy and security documentation, business associate oversight practices, facility safeguards, and incident response procedures to ensure written materials reflect operational reality.

    5. Limited Access to Expert Guidance

    Many organizations do not need a large internal compliance department, but they do need reliable expertise when important decisions arise. Virtual HIPAA compliance officer support and hourly consulting can help leadership evaluate risks, respond to questions, and strengthen documentation before issues escalate.

    What a Stronger Program Looks Like

    A stronger HIPAA compliance program is not built on assumptions. It is built on documented assessments, practical risk management, informed staff, current policies, and access to experienced consulting support. When these elements work together, organizations are better positioned to reduce risk exposure and respond confidently to regulatory scrutiny.

    How Colington Consulting Helps

    Colington Consulting supports healthcare providers and business associates with HIPAA risk assessments, risk management plans, staff training, policy reviews, privacy and security rule documentation, facility security planning, and ongoing consulting guidance. The goal is to help organizations create compliance programs that are practical, defensible, and ready for real-world challenges.

    If your organization is unsure whether its current HIPAA program would hold up under an audit, investigation, or breach review, now is the right time to evaluate the gaps and strengthen the foundation.

    Schedule a Free HIPAA Risk Review

    No Obligation. No Committment

  • HIPAA Security Rule Delay: Why You’re Not Off the Hook

    Quick answer: HHS has pushed its target for finalizing the HIPAA Security Rule update from May 2026 to July 2027. But the delay only applies to the proposed new requirementsโ€” the current HIPAA Security Rule is still fully in effect, still enforced by OCR, and still carries the same penalties for noncompliance. Organizations that treat this as a compliance holiday are misreading what actually changed.

    What Actually Happened

    In January 2025, HHS’s Office for Civil Rights (OCR) published a Notice of Proposed Rulemaking (NPRM) proposing the most significant overhaul of the HIPAA Security Rule since 2013. The proposal would replace many of today’s flexible, “addressable” safeguards with hard requirements, including:

    • Mandatory encryption of ePHI at rest and in transit (no more “addressable” workaround)
    • Mandatory multi-factor authentication on all systems touching ePHI
    • 72-hour incident reporting timelines
    • Annual penetration testing
    • Tighter oversight and contractual obligations for business associates

    More than 100 hospital systems and provider associations โ€” including Cleveland Clinic, Yale New Haven Health, Advocate Health, and the American Medical Association โ€” formally asked HHS to withdraw or scale back the proposal, citing cost and implementation timelines.

    HHS didn’t withdraw it. Instead, the agency moved final action from its near-term regulatory agenda to its Long-Term Actions agenda, now targeting July 2027 for a final rule. That’s a one-year-plus slip from the original May 2026 estimate โ€” and Unified Agenda dates are planning estimates, not binding deadlines, so this could move again.

    What the Delay Does Not Change

    This is the part that gets lost in the headlines:

    1. The current Security Rule is still active and enforceable. Every requirement already on the books โ€” risk analysis, access controls, audit controls, transmission security, business associate agreements โ€” remains fully in force. OCR investigations, audits, and civil monetary penalties for violations of the existing rule continue exactly as before.
    2. OCR enforcement priorities haven’t slowed down.Ransomware, ePHI breaches, and risk-analysis failures remain top enforcement targets, and settlements under the current rule continue to be announced regularly.
    3. State law and contractual obligations don’t pause. Many states have their own health data security and breach-notification laws that meet or exceed HIPAA. Cyber insurance underwriters, hospital system contracts, and business associate agreements increasingly bake in MFA, encryption, and incident-response expectations regardless of what the federal rule says.
    4. The direction of travel hasn’t changed, only the timing. Encryption, MFA, and faster breach reporting aren’t going away as regulatory priorities โ€” they’re simply arriving later. Organizations that wait until the rule is finalized to start will be doing a rushed 240-day sprint (60 days to effective date + 180 days to compliance, under the current proposal) instead of a planned multi-year rollout.

    “We Have More Time” Is the Wrong Read

    The delay gives organizations breathing room to prepare well, not permission to deprioritize security. Three reasons this matters:

    • Rulemaking timelines are not compliance timelines.Nothing in HIPAA law says organizations must wait for a final rule before improving encryption or access controls. Most of what’s proposed is already considered best practice and is often expected by cyber insurers and auditors today.
    • A pushed date is not a canceled rule. HHS has reaffirmed the rulemaking is still active; it’s simply been reclassified as a longer-term project. Treating this like the Security Rule update “went away” sets organizations up for a scramble later.
    • Breaches don’t wait for regulations. Ransomware and phishing attacks against healthcare targets have continued to rise. The safeguards in the proposed rule exist because current threat activity outpaced the 2013-era requirements โ€” that risk doesn’t disappear because the paperwork is delayed.

    What Compliance Teams Should Do With the Extra Time

    Run or refresh your risk analysis now, mapping current safeguards against the proposed rule’s requirements to identify gaps early.

    1. Move encryption and MFA from “addressable” to “implemented,” even ahead of any mandate โ€” these are the two changes most likely to survive the rulemaking process largely intact.
    2. Review business associate agreements and vendor oversight, since expanded BA accountability is one of the more consistent themes across the NPRM comments and industry response.
    3. Stress-test your incident response plan against a 72-hour reporting window, even though the current rule doesn’t require it yet โ€” this is the kind of internal capability that takes real time to build.
    4. Document everything. If the rule is finalized on a compressed timeline later, organizations with a documented head start will have an easier path to demonstrating good-faith compliance.

    Frequently Asked Questions

    Is the HIPAA Security Rule update dead?

    No. HHS moved the target for final action to July 2027 on its Long-Term Actions agenda; it did not withdraw the proposal.

    Do I still have to comply with HIPAA Security Rule requirements right now?

    Yes. The current HIPAA Security Rule remains fully in effect and enforceable regardless of the delay to the proposed update.

    When will the new HIPAA Security Rule requirements take effect?

    HHS currently targets July 2027 for final action, but this is an estimate, not a legal deadline, and could shift again. If finalized as proposed, the rule would take effect 60 days after publication, with a 180-day compliance window after that.

    What should healthcare organizations do now?

    Use the additional time to close gaps against the proposed requirements โ€” especially encryption, MFA, business associate oversight, and incident response โ€” rather than waiting for a final rule to start preparing.

    Not Sure Where Your Gaps Are? Find Out Before the Rule Forces You To

    The safest move during this delay isn’t waiting โ€” it’s finding out now where your organization stands against encryption, MFA, business associate oversight, and incident response expectations, so you’re not scrambling later.

    Get a free HIPAA Risk Review. We’ll help you identify gaps in your current Security Rule compliance and show you exactly where to focus before the final rule lands.

    Schedule Your Free HIPAA Risk Review โ†’

    Source

    U.S. Office of Information and Regulatory Affairs, Unified Agenda of Federal Regulatory and Deregulatory Actions โ€” RIN 0945-AA22 (HIPAA Security Rule), reginfo.gov.

  • Is Your HIPAA Compliance Program on Summer Vacation?

    Summer is here โ€” and while your staff rotates through PTO, cyber criminals are not. Ransomware gangs, phishing campaigns, and hacking groups operate 365 days a year, and the data confirms they are not taking July off. If your HIPAA compliance program has quietly gone on summer vacation, this is your wake-up call.

    Hackers Don’t Take Time Off โ€” The Numbers Prove It

    At a recent HIPAA conference, the OCR Director stated that 74% of all data breached in 2025 was cybersecurity related. These weren’t sophisticated, novel attacks limited to big health systems. They included ransomware infections on individual workstations, phishing attacks on small practices, and server misconfigurations left undetected for months.

    The most visible example of what’s at stake: the Change Healthcare cyberattack, which OCR confirmed affected approximately 130 million individuals โ€” making it one of the largest breaches of protected health information (PHI) in U.S. history. As OCR noted in its investigation guidance, the incident had an unprecedented impact on patient care and privacy across the entire health care sector.

    What OCR’s Own Investigations Keep Finding

    OCR doesn’t just count breaches โ€” it investigates the compliance failures that allowed them to happen. Across its 2024 breach investigations, OCR consistently identified the same deficiencies: failures in risk analysis, risk management, information system activity review, audit controls, and user authentication. These aren’t exotic compliance requirements. They are foundational Security Rule obligations that covered entities and business associates are required to maintain โ€” not just once, but on an ongoing basis.

    That’s the critical point. HIPAA cybersecurity compliance isn’t a project you complete and then set aside. It’s an active, continuous program. Reduced staffing and distracted workflows during summer months create exactly the gaps that threat actors are trained to exploit.

    OCR Is Actively Auditing Right Now

    OCR launched its 2024โ€“2025 HIPAA Audit Program, targeting 50 covered entities and business associates with a focused review of Security Rule provisions most directly tied to hacking and ransomware attacks. OCR has been explicit about why: substantial increases in large breaches involving hacking and ransomware โ€” and the scale of harm to patients โ€” have made Security Rule compliance a top enforcement priority.

    If your organization hasn’t updated its risk analysis recently, can’t demonstrate ongoing monitoring of your systems, or hasn’t tested its incident response plan, you are not audit-ready โ€” regardless of the season.

    What You Should Be Doing Right Now

    OCR provides guidance your organization can use today:

    โ€ข Conduct a Security Risk Assessment โ€” HIPAA requires covered entities to perform an accurate and thorough risk analysis as an ongoing process. You can attempt this internally using the HHS Security Risk Assessment (SRA) Tool, designed to help small and medium-sized organizations get started. However, a HIPAA compliance consultant with extensive experience can conduct this assessment more efficiently, identify vulnerabilities you may overlook, and ensure your documentation will hold up under OCR scrutiny.

    โ€ข OCR Ransomware and HIPAA Factsheet โ€” outlines what constitutes a ransomware breach under HIPAA and what your response obligations are.

    โ€ข OCR Breach Portal โ€” publicly available at HHS.gov, showing active breach reports and giving compliance officers a real-time view of what’s happening across the sector.

    The bottom line: summer is not a compliance pause. It may actually be your highest-risk window โ€” reduced oversight, skeleton crews covering critical systems, and delayed incident detection. The organizations that stay vigilant year-round are the ones that don’t end up on OCR’s breach portal.

    Frequently Asked Questions

    Does HIPAA require ongoing risk analysis, or is a one-time assessment enough?

    HIPAA requires covered entities to conduct risk analysis as an ongoing process, not a one-time event. OCR’s breach investigations consistently cite failure to maintain current risk analysis as a leading compliance gap.

    What is the most common cause of large HIPAA breaches?

    According to the OCR Director, 74% of all data breached in 2025 was cybersecurity related โ€” making hacking and IT incidents the dominant threat to protected health information.

    Is OCR actively auditing organizations right now?

    Yes. OCR’s 2024โ€“2025 audit program is currently underway, focusing on Security Rule compliance areas tied to hacking and ransomware.

    Where can I report a HIPAA breach to HHS?

    Breach reports are submitted through the OCR Breach Reporting Portal at HHS.gov.

    Need Help with Your HIPAA Compliance Program?

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

    Reviewed By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert

    Regulatory Sources:

    Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.

  • Is the New HIPAA Security Rule Final Yet?

    Is the New HIPAA Security Rule Final Yet? What Covered Entities Need to Know Right Now

    Quick answer: No. As of mid-2026, the proposed HIPAA Security Rule overhaul is still just that โ€” proposed. OCR has not issued a final rule, its informal May 2026 target came and went with nothing published, and a coalition of more than 100 hospital and provider groups has formally asked HHS to withdraw the rule altogether. That said, organizations shouldn’t treat “not final” as “not urgentโ€ as HIPAA’s civil penalty tiers already increased this year under current law, and history shows compliance windows shrink fast once a final rule does land.

    What the Proposed Rule Would Actually Change

    The HIPAA Security Rule hasn’t seen a substantive update since 2013. The Notice of Proposed Rulemaking published in January 2025 would be the most significant rewrite in the rule’s history, and the headline change is structural: it eliminates the long-standing distinction between “addressable” and “required” safeguards. Today, organizations can implement reasonable alternatives to certain controls and document why. Under the proposal, that flexibility disappears โ€” nearly every safeguard becomes mandatory.

    In practice, that means encryption of electronic PHI at rest and in transit with no documented-alternative exception, multi-factor authentication required for any system that touches ePHI, network segmentation written explicitly into the technical safeguards, and a shift from occasional testing to recurring, scheduled technical assessments such as penetration testing. Business associates would also face tighter, faster incident-reporting obligations to the covered entities they serve.

    Where Things Actually Stand

    OCR’s own regulatory agenda pointed to a May 2026 finalization, but that window has passed without action. Pushback has been significant: HHS’s own regulatory impact analysis estimated roughly $9 billion in first-year industry compliance costs, climbing toward $34 billion over five years, and that price tag is a big part of why provider groups are lobbying for withdrawal rather than finalization. There’s no confirmed new timeline. If and when a final rule does publish, the expected compliance runway is short โ€” roughly 60 days until the rule takes effect, then another 180 days to come into full compliance.

    The Part That’s Already Real: Penalties Went Up

    Separately from the Security Rule fight, OCR’s civil monetary penalty tiers received their routine annual inflation adjustment effective January 28, 2026. The top tier โ€” willful neglect that goes uncorrected โ€” now caps at $2,190,294 per calendar-year violation category, with the other tiers adjusted upward as well. This is current law today, independent of whatever happens with the proposed overhaul.

    What to Do Now, Regardless of the Final Rule’s Fate

    The organizations best positioned aren’t waiting for a final rule to start the clock. Encrypting ePHI everywhere, rolling out MFA, segmenting networks, and testing on a schedule are good security practice today and lower your real exposure under the penalty structure that already exists. A practical starting point: refresh your documented risk analysis, confirm your business associate agreements already require prompt breach notification language, and budget for these controls now rather than scrambling on a 240-day deadline later.

    Frequently Asked Questions

    Has the HIPAA Security Rule update been finalized? No. As of mid-2026 it remains a proposed rule with no confirmed finalization date.

    Will MFA become mandatory under HIPAA? Under the proposed rule, yes โ€” for any system accessing ePHI. It isn’t legally required yet, though many auditors already treat it as a baseline expectation.

    How long would organizations get to comply once it’s final? Industry estimates point to about 240 days total: roughly 60 days until the rule takes effect, then 180 more days to reach full compliance.

    Did HIPAA penalties increase in 2026? Yes. The annual inflation adjustment took effect January 28, 2026, raising the maximum penalty tier.

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

    Reviewed on June 18, 2026, By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert

    Sources:

    • U.S. Department of Health and Human Services, Office for Civil Rights. “HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information,” Notice of Proposed Rulemaking, 90 Fed. Reg. 898 (Jan. 6, 2025). federalregister.gov
    • HHS.gov, “HIPAA Security Rule NPRM” overview page. hhs.gov
    • HHS.gov, Fact Sheet on the HIPAA Security Rule NPRM. hhs.gov
    • U.S Department of Health and Human Services, “Annual Civil Monetary Penalties Inflation Adjustment,” Fed. Reg. (Jan. 28, 2026). federalregister.gov
    • HHS.gov, “Summary of the HIPAA Security Rule” (current rule in effect). hhs.gov

    Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.

  • When Are NEMT Organizations HIPAA Business Associates?

    Non-Emergency Medical Transportation (NEMT) providers serve a critical role in helping patients access healthcare services. However, one of the most common compliance questions in the industry is straightforward: When is a NEMT organization considered a HIPAA Business Associate?

    For most providers, the answer is simpler than expectedโ€”yet often misunderstood.

    Understanding the Business Associate Role

    HIPAA Business Associate (BA) is any organization that creates, receives, maintains, or transmits Protected Health Information (PHI) on behalf of a covered entity, such as a healthcare provider, health plan, or managed care organization.

    PHI includes identifiable information connected to healthcare services. In the NEMT context, that often looks like patient names tied to medical appointments, transportation arranged for treatment, Medicaid identifiers, or trip data linked to healthcare delivery.

    If your operations involve this type of information, even at a basic level, HIPAA likely applies.

    How NEMT Providers Become Business Associates

    In most healthcare transportation models, NEMT organizations are functioning as an extension of the healthcare system. This is particularly true in Medicaid and broker-driven environments, where transportation is a defined benefit tied to care.

    When trip requests are received from a broker, hospital, dialysis center, or health plan, they almost always include information that connects an individual to medical services. That connection is what transforms routine transportation data into PHI.

    Dispatch teams, drivers, and administrative staff all interact with this information in some formโ€”whether scheduling rides, confirming appointments, or maintaining trip records. Even if the data seems limited, the healthcare context is what matters.

    The role of the NEMT provider in these scenarios is not just logistical. It supports treatment access, continuity of care, and patient outcomes. From a regulatory standpoint, that places the organization squarely within the definition of a Business Associate.

    The Role of Data Storage and Technology

    Many NEMT providers assume HIPAA only applies when they actively use patient information. In reality, simply maintaining or storing PHI is enough to trigger Business Associate status.

    Trip manifests, dispatch software, billing platforms, and ride history logs often contain patient identifiers linked to healthcare services. These systemsโ€”whether cloud-based or localโ€”must be evaluated through a HIPAA compliance lens.

    Communication tools are another important factor. Dispatch-to-driver coordination frequently involves mobile apps, texting, or call systems. If these channels include PHI, they must be secured appropriately. Standard consumer tools without safeguards can create immediate compliance risks.

    What HIPAA Requires from NEMT Business Associates

    Once classified as a Business Associate, an NEMT organization takes on defined responsibilities under HIPAA.

    This includes executing Business Associate Agreements (BAAs) with covered entities, implementing safeguards to protect PHI, and training workforce members on privacy and security expectations. Organizations are also responsible for identifying risks, monitoring their environment, and responding to potential breaches.

    Importantly, these obligations apply across the organizationโ€”not just in the back office. Drivers, dispatchers, and management all play a role in protecting patient information.

    Common Misunderstandings in the NEMT Industry

    A frequent misconception is that NEMT providers are โ€œjust transportationโ€ and therefore outside the scope of healthcare regulation. In reality, the moment transportation is linked to medical care and involves patient-specific information, the regulatory landscape changes.

    This misunderstanding often leads to gaps such as missing BAAs, unsecured devices, or untrained staff. Over time, these issues increase exposure to audits, penalties, and contract challenges with healthcare partners.

    Key Takeaways

    Most NEMT organizations working within healthcare networks should assume they are operating as Business Associates. The combination of receiving, storing, and using patient information tied to medical services establishes that role in the majority of cases.

    Compliance is not just a contractual requirementโ€”it is a foundational part of operating responsibly within the healthcare ecosystem.

    Final Thoughts

    For NEMT providers, the question is rarely whether HIPAA applies, but rather whether compliance practices fully reflect that reality. Organizations that take a proactive approachโ€”aligning their policies, technology, and workforceโ€”are better positioned to reduce risk and strengthen partnerships.

    Next Steps for NEMT Providers

    At Colington Consulting, we specialize in helping NEMT providers operating as HIPAA Business Associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current compliance posture as an NEMT organization.

    • Reviewed on June 16, 2026 by:ย Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert
    • Regulatory Sources: ย 45 CFR 164.502(e), 164.504(e), 164.532(d) and (e) ย 
    • Disclaimer:ย The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.

  • What Are HIPAA Workforce Training Requirements?

    Under federal regulation 45 C.F.R. ยง 164.530(b)(1), all HIPAA Covered Entities and Business Associates are legally required to provide security and privacy training to every member of their workforce. Training must be delivered to new employees within a reasonable period after hiring and updated whenever a significant change occurs in company policies, software, or federal regulations. Failing to properly train employees is one of the most common triggers for Office for Civil Rights (OCR) investigations and costly financial settlements. A single employee clicking on a phishing link or mishandling Protected Health Information (PHI) can breach data security, transforming workforce training from a legal chore into your strongest line of defense.

    A common misconception is that HIPAA training is only for doctors, nurses, and medical staff. Under the law, workforce members is broadly defined to include full-time and part-time employees, volunteers, interns, contractors, and temporary staff. Administrative personnel in billing, human resources, IT, and reception roles must also be trained if they have any potential to encounter protected data. Essentially, if someone works under your direct control and could come into contact with PHI, they require formal compliance training.

    Timing is critical for maintaining a defensible position during an OCR audit. New workforce members must receive training within a reasonable period after joining the organization, which best practice dictates should occur within the first 30 to 90 days of employment. This onboarding training should ideally conclude before individuals are granted unsupervised access to systems containing Electronic Protected Health Information (ePHI). Additionally, if your organization updates its internal privacy policies, implements new Electronic Health Record (EHR) software, or if federal regulations change, affected workforce members must receive immediate retraining on those specific updates. While the law does not explicitly mandate annual training, the HIPAA Security Rule requires an ongoing security awareness training program, meaning compliance experts strongly recommend annual refresher courses alongside monthly phishing simulations.

    To satisfy both the Privacy and Security Rules, an effective training curriculum must address broad data handling principles alongside specific technological safeguards. Your training program must cover core privacy fundamentals, including what constitutes PHI, the minimum necessary standard, proper disclosure rules, and patient rights. On the technical side, employees need guidance on password management best practices, log-in monitoring protocols, and recognizing malware or phishing attempts. Finally, the training must cover organizational policies like mobile device management for personal devices, data backup protocols, physical data destruction, and clear instructions on your internal sanction policies for reporting a suspected data breach.

    If an auditor or investigator requests proof of compliance, simply stating that you train your staff is not enough. You must maintain audit-ready documentation, which means keeping signed acknowledgments or digital logs proving each employee completed their assigned modules. You must also log the exact dates training was completed and keep a record of the specific curriculum, slides, or videos used.

    Need help evaluating your organization’s current training protocols or overall compliance posture? You can schedule a HIPAA risk review with Colington Consulting to identify structural gaps before they lead to an enforcement action.

    • Reviewed on June 13, 2026, By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert
    • Regulatory Source: The formal regulatory source for HIPAA workforce training requirements is 45 C.F.R. ยง 164.530(b)(1). This specific section falls under the administrative requirements of the HIPAA Privacy Rule, which dictates that a Covered Entity or Business Associate must train all members of its workforce on the policies and procedures regarding Protected Health Information (PHI) as necessary and appropriate for them to carry out their functions within the organization.
    • Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.
  • HIPAA and Social Media: What are the Rules?

    by Jay Hodes, Presidentย – Colington Consultingย 

    The use of social media in todayโ€™s society continues to grow as more Americans interact through one or more social media platforms. Whether writing a blog article, posting on Facebook or tweeting on Twitter, many users see social media as a primary means to communicate. According the Pew Research Center, as many as 46% of users โ€œdiscussed a news issue or eventโ€ on a social media platform.

    As more healthcare providers use or consider using social media for business purposes, HIPAA plays a more significant role in what can be said in a Facebook post, a tweet or a blog article. There are some clear challenges when it comes to meeting the requirements of the HIPAA Privacy Rule. But those challenges do not need to be obstacles, as long as there is proper guidance on what can or cannot be posted.ย 

    My advice when it comes to the use of social media in a healthcare organization is to have a comprehensive, written policy and procedure. The less discretion the better, meaning there is always structured guidance to follow with little to no wiggle room.

    In formulating your organizationโ€™s social media policy, start with the 3 Wโ€™s: Who, What and Where. ย 

    • Who โ€“ Determine who is permitted to post material on social media on behalf of the organization. Designate a specific person as the organizationโ€™s official social media administrator.
    • What โ€“ Determine what can be posted. The policy should include how to handle an individual that posts a medical question on a social media platform. As an example, if a patient can ask specific questions about a medical condition on your Facebook page, how does your organization address it? I caution from a possible liability standpoint that it may be inappropriate to respond with advice. A better response would be to ask the individual to contact the office to discuss the specific concern.
    • Where โ€“ Determine where and on what platforms posting will occur. The policy must clearly state which social media sites the organization will use. ย 

    Guidelines issued by the AMA on social media say, โ€œBe cognizant of standards of patient privacy and confidentiality. Don’t post sensitive patient information online or transmit it without appropriate protection.โ€ The guidelines also say to โ€œmaintain the appropriate boundaries of the patient-physician relationship, just as in any other context.โ€ This means following all the applicable standards of the HIPAA Privacy Rule.

    Another area of concern is the use of patient testimonials. This is a somewhat newer trend in the healthcare provider marketing strategy. Any patient testimonials used by a healthcare organization must comply with the HIPAA Privacy Rule. A healthcare provider, as a covered entity, must obtain the written authorization of the patient prior to any use or disclosure of the individualโ€™s protected health information for marketing purposes.

    In an enforcement case, a California physical therapy practice paid a settlement of $25,000 to the HHS Office for Civil Rights for a HIPAA privacy violation. There were allegations that the practice posted patient testimonials to its website without legal, HIPAA-compliant authorization. This is not a situation you want to find yourself in.

    If your organization embraces social media as a method to market or provide information, have robust policies and procedures in place and follow them. You can be social, but be safe.

    Schedule a 30-Minute HIPAA Risk Review and find out if your organization’s social media policy stands up to the HIPAA Privacy Rule

  • HIPAA Security Rule Policies And Procedures: Complete Guide

    Most organizations know they need HIPAA Security Rule policies and procedures. Fewer know what that actually means in practice. The Security Rule requires covered entities and business associates to document how they protect electronic protected health information (ePHI), not in vague terms, but through specific, implementable policies that address administrative, physical, and technical safeguards. Getting this wrong isn’t a minor oversight. It’s the single most common finding in OCR enforcement actions.

    The challenge is that the Security Rule is deliberately flexible. It tells you what to address but leaves how largely up to you. That flexibility is a feature for organizations that understand their risk environment, and a trap for those that don’t. Without clear guidance, many healthcare organizations either over-engineer policies they can’t maintain or adopt generic templates that fall apart under scrutiny. Neither approach produces a defensible compliance program.

    At Colington Consulting, we’ve helped hundreds of organizations build HIPAA compliance programs that hold up when it matters, during audits, breach investigations, and enforcement actions. This guide breaks down what the Security Rule actually requires for your policies and procedures, how to structure them, and what separates documentation that checks a box from documentation that protects your organization. Whether you’re building from scratch or overhauling an outdated program, you’ll walk away with a clear framework for implementation.

    Why HIPAA security rule policies and procedures matter

    When the Office for Civil Rights (OCR) investigates a breach or complaint, documented policies and procedures are among the first things auditors request. Your organization needs to show not just that a policy existed, but that it was in place before the incident, that workforce members received training on it, and that your team actually followed it. Without that paper trail, organizations with otherwise solid security controls still face significant penalties. The Security Rule exists to make ePHI protection systematic and verifiable, and your policies are the mechanism that proves you’ve done the work.

    Documentation is what OCR actually audits

    OCR’s enforcement investigations rely heavily on written documentation review. When auditors arrive, they request your policies, your risk analysis, your training records, and your sanction logs. If those documents don’t exist, or if they don’t reflect what your staff actually does day-to-day, that gap becomes a formal finding. Organizations frequently lose enforcement cases not because their security controls were technically inadequate, but because they couldn’t demonstrate those controls existed in writing. Your policies aren’t just internal guidance; they function as legal evidence of your compliance posture at any given point in time.

    OCR has cited missing or inadequate security policies as a contributing factor in enforcement actions even in cases where no breach actually exposed patient data.

    The financial stakes are concrete and growing

    OCR has collected over $150 million in HIPAA settlements and civil monetary penalties since enforcement began. Fines vary by violation tier, reaching up to $73,111(inflation adjusted) per violation for willful neglect that goes uncorrected. But your financial exposure doesn’t stop with OCR. Cyber insurers now routinely require documented HIPAA security policies as a condition of coverage, and many carriers deny claims when your documentation fails to demonstrate that reasonable safeguards were in place before a breach. A missing or outdated policy can cost your organization both the regulatory penalty and the insurance payout simultaneously.

    Beyond insurance, business associate agreements and contract requirements from health systems and payers increasingly include HIPAA compliance documentation as a contractual obligation. If you can’t produce current policies during a vendor audit, you risk losing those contracts entirely.

    Policies create a clear, consistent standard for your workforce

    Your staff cannot follow rules they don’t know exist. HIPAA security rule policies and procedures translate abstract regulatory language into specific, actionable instructions for the people who handle ePHI every day. A workstation use policy tells employees exactly what they can and cannot do on devices that access patient records. An access management policy tells your IT team precisely how to provision and revoke user credentials when roles change or employees leave. Without written standards, every person makes independent judgment calls, and your security posture depends entirely on individual behavior rather than organizational control.

    Written policies also reduce liability for your leadership team. When a workforce member follows a documented procedure and an incident still occurs, your organization can demonstrate reasonable diligence to regulators and insurers. When no procedure exists, both the organization and individual executives face significantly greater personal exposure. Sound documentation protects your staff and your leadership, not just your patients.

    Who must follow the HIPAA Security Rule

    The Security Rule applies to two broad categories of organizations under HIPAA: covered entities and business associates or referred to as regulated entities. If your organization falls into either group and handles electronic protected health information in any form, you are legally required to have HIPAA Security Rule policies and procedures in place. There is no minimum size threshold. A solo medical practice carries the same core compliance obligations as a large hospital system.

    Covered entities

    Covered entities are healthcare providers, health plans, and healthcare clearinghouses that transmit health information electronically in connection with standard transactions. This includes physicians, dentists, hospitals, outpatient clinics, health insurers, and Medicare/Medicaid programs. If your organization sends electronic claims, checks eligibility, or transmits any other standard healthcare transaction, you qualify as a covered entity regardless of how small your practice is.

    Many small practices mistakenly assume they fall below the regulatory threshold. OCR has enforced HIPAA against solo practitioners and small group practices in numerous documented cases.

    Size and patient volume do not affect your status as a covered entity. A two-physician practice that submits electronic claims to a single insurer has the same obligation to maintain written security policies as a 500-bed hospital. The Security Rule does allow smaller organizations to scale the complexity of their policies to match their risk environment, but it does not exempt them from having those policies at all.

    Business associates

    Business associates are vendors, contractors, and service providers that create, receive, maintain, or transmit ePHI on behalf of a covered entity. This category is broad and includes medical billing companies, IT managed service providers, cloud storage vendors, EHR software companies, and third-party transcription services. If your company touches patient data while performing a service for a healthcare organization, you are a business associate under HIPAA.

    Your business associate agreement (BAA) with a covered entity does not substitute for your own internal compliance program. You still need written security policies that meet the Security Rule’s requirements. If OCR investigates a breach that originates from your systems, your policies, not your BAA, will determine your exposure.

    What HIPAA requires for security policies and procedures

    The Security Rule organizes its requirements around three safeguard categories: administrative, physical, and technical. Within each category, individual standards contain specific implementation specifications. Your HIPAA Security Rule policies and procedures must address every applicable standard, but the rule gives you two types of specifications to work with, and understanding the difference directly affects how you write and structure your documentation.

    Required vs. addressable specifications

    Required specifications are non-negotiable. You must implement them as written, and your policies must reflect that you’ve done so. Addressable specifications carry more flexibility, but they are not optional. For each addressable specification, you must either implement it as described, implement an equivalent alternative, or document why it does not apply to your organization based on your risk analysis.

    Many organizations treat “addressable” as a synonym for “optional.” It is not. Failing to document your decision on an addressable specification is itself a compliance gap.

    Your policies need to capture the outcome of each of these decisions in writing. If you implemented multi-factor authentication as an alternative to a specification’s default control, your policy should state what you implemented and why that choice is appropriate for your risk environment.

    Documentation requirements

    Beyond the content of your policies, the Security Rule specifies how long you must retain your documentation. You are required to keep written policies, procedures, and related records for six years from the date of creation or the date they were last in effect, whichever is later. This means you cannot simply replace an outdated policy without retaining the prior version.

    Your documentation also needs to reflect changes in your organization over time. When you update a workflow, adopt a new system, or change workforce roles that affect ePHI access, your policies must be reviewed and revised accordingly. Static documentation that no longer matches how your organization actually operates creates significant risk during an OCR audit, because auditors compare your written procedures against your actual operational practices, and gaps between the two become formal findings.

    Administrative safeguard policies and procedures

    Administrative safeguards represent the largest and most foundational category of the HIPAA Security Rule. These are the management-level controls that govern how your organization identifies risk, trains staff, manages access, and responds when things go wrong. Your HIPAA Security Rule policies and procedures for administrative safeguards set the foundation that every other safeguard category builds on. Without them, your physical and technical controls have no governance structure supporting them.

    Security Management Process

    Your security management process policies need to document how your organization identifies, analyzes, and responds to risks to ePHI. This standard includes four required implementation specifications: risk analysis, risk management, sanction policy, and information system activity review. Each one requires a written policy explaining what your organization does, how often it does it, and who is responsible.

    Your risk analysis is not a one-time event. OCR expects documented evidence that you repeat this process when your environment changes, such as when you adopt new technology or experience a workforce restructuring.

    Your sanction policy is one of the most frequently overlooked elements in this category. It must specify the consequences your organization applies when workforce members violate your security policies. Without a written sanction policy, you cannot demonstrate to OCR that you hold your staff accountable, which becomes a significant problem during breach investigations.

    Workforce and Access Management

    Access management policies cover who gets access to ePHI, under what conditions, and how that access gets removed. Your authorization and supervision policies should define the process your organization uses to grant access based on job function, not individual preference. When employees change roles or leave the organization, your policies need to specify the exact steps for modifying or terminating their access and the timeframe in which those steps must be completed.

    Your workforce training policies fall under this category as well. These policies must describe how you deliver security awareness training, how you track completion, and how often you refresh that training. Training records tied directly to your written policies give you the documentation trail that OCR auditors look for when evaluating whether your administrative safeguards function as a real program rather than a set of documents stored in a drawer.

    Physical safeguard policies and procedures

    Physical safeguards govern how your organization controls access to the physical spaces and devices that store or process ePHI. Most organizations underestimate this category because it feels less technical than firewalls or encryption, but OCR takes physical access controls seriously. Your HIPAA Security Rule policies and procedures for this category need to address your facilities, your workstations, and every device that touches patient data, including laptops, mobile devices, and workstations in shared clinical areas.

    Facility Access and Control

    Your facility access policies must define who can enter areas where ePHI systems are housed and how your organization documents, monitors, and restricts that access. This includes server rooms, records storage areas, and any space where unattended workstations could give an unauthorized person access to patient data. Your policies should specify the physical controls you use, such as key cards, locks, or visitor logs, and assign clear accountability for maintaining and reviewing those controls.

    Physical access events that go undocumented create a compliance gap that OCR investigators can use to establish a pattern of insufficient safeguards, even when no breach occurred.

    Your contingency access procedures also belong in this category. When your normal access controls fail during an emergency, your staff needs a written protocol for maintaining facility security while still allowing appropriate personnel to reach critical systems. Document that protocol explicitly so it is available and tested before an incident requires it.

    Workstation and Device Controls

    Workstation use policies must define what employees are permitted to do on devices that access ePHI and what physical environment those workstations should be in. Screens that face public waiting areas, unlocked devices left unattended, and shared login credentials are all physical security failures that belong in your policy documentation. Your workstation security policy should describe the physical positioning, screen lock requirements, and access restrictions that apply to every ePHI-capable device in your environment.

    Device and media controls extend this to hardware that moves in and out of your organization. Your policies need to address how you track, transfer, and dispose of devices that store ePHI, including the steps required before any hardware leaves your control through reassignment, repair, or destruction.

    Technical safeguard policies and procedures

    Technical safeguards define the technology-based controls your organization uses to protect ePHI at rest and in transit. Your HIPAA Security Rule policies and procedures for this category need to cover how your systems restrict access, generate audit logs, protect data integrity, and secure transmissions. These policies must reflect the actual technology your organization uses, not generic descriptions of controls that don’t match your environment.

    Access Controls and Audit Controls

    Your access control policies must specify how your systems limit ePHI access to authorized users only and what technical mechanisms enforce those limits. This includes unique user identification requirements, emergency access procedures, automatic logoff settings, and encryption or decryption protocols. Each of these elements needs its own policy language that assigns responsibility and defines the technical standard your organization meets.

    A policy that simply states “we control access to ePHI” gives OCR auditors nothing to work with. Your documentation needs to name the specific controls in place and explain how they function within your environment.

    Your audit control policies address how your organization captures and reviews activity logs across systems that contain ePHI. You need written procedures that describe which systems generate logs, what those logs capture, how long you retain them, and who reviews them and at what frequency. Without a documented review process, your logs become a liability rather than an asset because you collect evidence of potential violations without any mechanism to detect or respond to them.

    Transmission Security and Integrity Controls

    Transmission security policies must define how your organization protects ePHI when it moves across networks, including email, patient portals, file transfers, and API connections. Your policies should identify the encryption standards your organization applies and specify which transmission types require those controls. Staff need clear written guidance on which channels are approved for sending ePHI and which are prohibited.

    Integrity controls belong alongside your transmission policies. These procedures describe how your organization detects whether ePHI has been altered or destroyed without authorization, both in storage and during transmission. Document the specific mechanisms your systems use and assign a responsible party for monitoring and responding to integrity alerts.

    Final takeaways

    HIPAA Security Rule policies and procedures are not a compliance checkbox. They are the documented foundation that determines whether your organization can defend itself when OCR comes knocking, when a breach triggers an investigation, or when a cyber insurer reviews your claim. Every administrative, physical, and technical safeguard your organization implements needs written policies that reflect how your systems actually operate, who owns each control, and what happens when something goes wrong.

    Generic templates and one-time documentation projects leave you exposed. Your policies need to evolve as your organization changes, and they need to be enforced through training, sanction procedures, and regular review. The gap between having a policy and having a defensible compliance program is exactly where most organizations fail.

    If you want to build a compliance program that holds up under scrutiny, work with a HIPAA compliance consulting firm that takes ownership of the process alongside you.

    Schedule a 30 minute HIPAA Risk Review