Category: HIPAA Regulations

  • Why HIPAA Is Still Confusing After Thirty Years, Especially for Small and Midsize Providers

    Why HIPAA Is Still Confusing After Thirty Years, Especially for Small and Midsize Providers

    Quick answer: HIPAA has been federal law since 1996, yet small and midsize providers still get tripped up by it, and the reason is rarely carelessness. Most owners and office managers never received formal HIPAA training; they inherited assumptions from a prior job, a vendor’s marketing page, or an online forum, and those assumptions are often wrong. The confusion tends to fall into two camps that look opposite but create the same exposure: providers who assume a tool or vendor already handles compliance for them, and providers who never learned the regulations well enough to tell a permitted disclosure from one that actually requires authorization. Both leave real gaps, and OCR, along with a growing number of state regulators, is actively finding them.

    Thirty Years Old, Still Misunderstood

    HIPAA is not a new law, and that is part of the problem. It has been amended, reinterpreted, and layered with guidance so many times since 1996 that the version most people learned, whether from a compliance seminar a decade ago or a coworker’s offhand explanation, is often out of date. Add in the fact that most clinicians and practice administrators never sat through a formal HIPAA course in school, and you get a compliance culture built on secondhand information rather than the actual rule text.

    That gap shows up constantly in small practice communities online, where one commenter insists a tool is safe, another insists it never can be, and a third says solo practices simply do not get looked at. None of them are working from the regulation itself; they are working from what they have heard. The confusion is understandable. It is also, according to compliance experts who work directly with small practices, a training problem rather than a character problem, and it is fixable once the actual myths are named and corrected.

    Myth One: “Our Software Already Makes Us HIPAA Compliant”

    This is the myth doing the most quiet damage right now. A recent survey of IT leaders and practice managers at organizations with fewer than 250 employees found that nearly all of them believed their email platform automatically encrypted messages containing patient information. In reality, common business tools like Microsoft 365 and Google Workspace do not guarantee that protection by default; encryption can drop entirely if the recipient’s mail server does not support current protocols, leaving protected health information exposed without anyone realizing it. Close to half of healthcare email breaches trace back to Microsoft 365 environments alone.

    The same false confidence shows up with EHR platforms. A vendor’s business associate agreement covers how that vendor handles data inside its own system; it does not cover how your staff handles PHI outside the EHR, and it does not satisfy your own obligation to conduct a Security Risk Analysis. An EHR is a clinical documentation tool. It is not a compliance program, no matter what the marketing page implies.

    Myth Two: “Regulators Only Care About Big Health Systems”

    Every headline breach involves a hospital system or a national health plan, so it is an easy leap to assume enforcement follows the same pattern. It does not. OCR has been explicit that practice size does not create an exemption, and enforcement data backs that up: small medical and dental practices accounted for the majority of OCR’s financial penalties in a recent reporting year. Investigations are frequently triggered by something small, a single patient complaint, a lost laptop, or a phishing email that catches one employee, not a headline grade breach.

    Risk analysis failures have been the single most cited deficiency in OCR enforcement actions for more than a decade, and that pattern holds regardless of organization size. A five provider practice and a five hundred provider hospital system are held to the same underlying standard; the hospital system just has more staff to absorb the work.

    Myth Three: “HIPAA Only Applies Once Someone Is Officially Our Patient”

    It is a natural assumption. In most professional relationships, obligations start once a formal engagement begins, so providers assume PHI protections kick in once someone signs an intake form or shows up for a first visit. HIPAA does not draw that line. Protected health information is defined as individually identifiable information related to a person’s past, present, or future healthcare, which means a phone call, an intake questionnaire, or even a scheduling message can already be covered before a formal patient relationship exists.

    Myth Four: “The Safest Move Is to Share Nothing With Anyone”

    Overcorrection is just as common as underprepared, and it carries its own cost. Some practices become convinced they cannot discuss a patient anywhere on the premises, or that every routine disclosure for treatment purposes needs a separate signed authorization. Compliance risk management professionals who work with small providers regularly see practices treat ordinary care coordination, like transferring records to a specialist for continued treatment, as though it required the same authorization process as a marketing disclosure. It does not. HIPAA already permits use and disclosure of PHI for treatment, payment, and healthcare operations without a separate authorization each time; practices that add friction here are not being safer, they are just slower, and staff eventually start looking for workarounds that create real risk.

    Myth Five: “A HIPAA Compliant Vendor Means We Are a HIPAA Compliant Practice”

    This one deserves its own heading because it is so common. Signing on with a vendor who advertises HIPAA compliant software, hosting, or messaging is a meaningful step, but it addresses one piece of a much larger program. Your practice still needs its own current Security Risk Analysis, its own written policies and procedures, its own workforce training, and its own documented incident response plan; none of that transfers from a vendor’s compliance posture to yours. Even organizations with no self funded health plan or complex vendor stack still need these four documented pieces, because they are what OCR asks for first in any investigation or audit.

    Why This Confusion Is Expensive, Not Just Awkward

    None of this would matter much if the stakes were low, but they are not. Healthcare has held the highest average breach cost of any industry sector for well over a decade running, and small practices absorb that cost with far less cushion than a large system. State regulators have also become more active alongside OCR, with several states bringing high profile settlements against small practices in the past year, which means a multi-state practice can no longer rely on federal HIPAA alone; state overlay requirements increasingly apply too.

    The pattern across almost every enforcement action tells the same story: it is rarely one dramatic mistake. It is a pile of ordinary, unremarkable decisions, a personal phone used for patient texts because it is faster, a new scheduling tool adopted without a signed business associate agreement, a risk analysis that was accurate three systems ago and never got updated, that nobody treated as a compliance decision when it was made.

    What Actually Clears Up the Confusion

    The fix is not memorizing the regulation. It is building a small number of documented habits that hold up regardless of which myth an employee picked up somewhere along the way.

    • Treat your Security Risk Analysis as a living document, not a one time project; update it whenever you change EHR systems, add a telehealth platform, or bring on new staff.
    • Confirm encryption in writing rather than assuming it; ask your email and EHR vendors directly whether encryption is guaranteed by default or dependent on the recipient’s system.
    • Map every point where PHI can leave your walls, phone, email, fax, text, patient portal, and confirm a business associate agreement or a documented safeguard covers each one.
    • Separate treatment, payment, and healthcare operations disclosures, which generally do not require a signed authorization, from marketing or research disclosures, which usually do.
    • Put workforce training on a real schedule, not a onboarding checkbox; most confusion traces back to staff repeating what they were told once, years ago, by someone who was also guessing.

    A Quick Self Check for Small and Midsize Practices

    โ˜  Do you have a Security Risk Analysis completed or updated within the last twelve months?

    โ˜  Have you confirmed, in writing, whether your email and messaging platforms encrypt PHI by default?

    โ˜  Do your written policies distinguish between disclosures that require patient authorization and those that do not?

    โ˜  Does every vendor touching PHI have a current, signed business associate agreement on file?

    โ˜  Has your team received HIPAA training in the last year, beyond a one time onboarding session?

    โ˜  If you offer a self funded employee health plan, has it been assessed as its own separate covered entity?

    Frequently Asked Questions

    Is a small medical or dental practice actually at risk of a HIPAA investigation?

    Yes. OCR has increasingly focused enforcement attention on smaller practices, and in a recent reporting year, small medical and dental practices accounted for the majority of OCR’s financial penalties. Investigations are often triggered by a single patient complaint or a routine incident, not a large scale breach.

    Does using a HIPAA compliant EHR mean our practice is fully compliant?

    No. An EHR vendor’s business associate agreement covers how that vendor handles data within its own system. It does not cover how your staff uses PHI outside the EHR, and it does not satisfy your practice’s own requirement to complete and maintain a Security Risk Analysis.

    Does HIPAA require a signed authorization before discussing a patient with another treating provider?

    Generally, no. HIPAA permits use and disclosure of PHI for treatment, payment, and healthcare operations without a separate authorization for each instance. Authorization requirements typically apply to disclosures outside those categories, such as marketing.

    When do HIPAA protections actually start applying to a person’s information?

    Protected health information is defined by an individual’s past, present, or future healthcare, not by whether a formal patient relationship has begun. Information shared during an intake call or scheduling message can already be covered.

    What is the single most common deficiency OCR cites in enforcement actions?

    Risk analysis failures. An incomplete, outdated, or missing Security Risk Analysis has been the most frequently cited deficiency in OCR enforcement for more than a decade, across organizations of every size.

    Not Sure Where Your Practice Actually Stands? Colington Consulting Can Help You Find Out

    Most of the small and midsize providers we work with are not careless; they are working from secondhand information that was never fully accurate to begin with. Colington Consulting works hands on with small practices, clinics, and specialty groups to replace assumptions with a documented, defensible compliance program built for organizations that do not have a dedicated compliance department.

    Get a free HIPAA Risk Review. We will walk through where your practice’s understanding of HIPAA may be out of date, identify the gaps that matter most, and show you exactly where to focus first.

    Schedule Your Free HIPAA Risk Review โ†’

    Sources

    Medical Economics, “Most small practices think they’re HIPAA compliant, a new report says they’re wrong,” reporting on Paubox survey data of IT leaders and practice managers at organizations under 250 employees.

    Patient Protect, “HIPAA Compliance for Independent Medical Practices: The Complete 2026 Guide.”

    Facet Technologies, “What the 2026 HIPAA Changes Actually Mean for Your Practice.”

    HIPAA Journal, “Editorial: HIPAA Compliance Challenges for Small Medical Practices” and “Why You Don’t Need to Understand HIPAA to Make Your Small Practice HIPAA Compliant.”

    Physicians Practice, “Four Common HIPAA Misconceptions.”

    U.S. Department of Health and Human Services, HIPAA Guidance Materials, hhs.gov.