by Jay Hodes, President – Colington Consulting
It came as no surprise to me when I reviewed a recent HIPAA survey conducted by NueMD, in conjunction with Porter Research and The Daniel Brown Law Group, which found that most healthcare providers and business associates that responded have a limited knowledge of compliance regulations. This was one of the most comprehensive surveys on HIPAA compliance that I have seen.
Part of the survey asked over 1,000 providers, administrators and medical office staff a number of questions regarding their knowledge and awareness of HIPAA compliance requirements. Let me share some of those practice findings:
- 68% of respondents were unaware that random HIPAA audits were going to be conducted.
- Only 35% of respondents said they conducted a HIPAA-required risk analysis.
- Only 24% of managers, owners and administrators reported that they evaluated all of their Business Associate Agreements.
Why does it not come as a surprise to me? Well, for a number of reasons. Smaller medical practices do not have the in-house resources to handle the complexities of meeting all of their compliance requirements. Most donโt realize what is involved. When I provide initial consultations with potential clients and explain all the areas that must be covered, I usually get the typical response that they did not think all the regulations applied to their practice or that their practice was too small and some of this compliance stuff was not necessary. Itโs not that they donโt want to be compliant; it is more that they do not know or understand what is entailed.
Reinforcing this perception, when looking at โpractices by size, (the survey) found that larger practices (particularly those with 10 or more providers) tended to do better when it came to compliance measures within the office – things like having a plan, training staff, appointing officers and conducting risk analyses. This wasn’t surprising, as larger organization usually have more resources to devote to regulatory compliance.โ
I feel part of the onus for so much confusion among smaller providers rests with my former agency, the U.S. Department of Health and Human Services. Although the Office for Civil Rights (OCR) has the primary responsibility to enforce HIPAA regulations, the Office of the National Coordinator for Health Information Technology (ONC) promotes the use of electronic exchanges of health information. ONC pushes out guidance on health information privacy, security and the implementation of electronic health records.
Then there is the Centers for Medicare & Medicaid Services (CMS) that administers the EHR Incentive Program. CMS has started to conduct meaningful use attestation audits. One of the core objectives that must be attested to is that a HIPAA Risk Assessment was conducted, the same risk assessment that OCR requires and would review during their own audit or compliance review.
A practice manager, already wearing so many hats, does not have the time to conduct the research, check the websites of three different agencies and find the necessary answers to what is reasonable and appropriate for that officeโs environment. This leads to another survey finding from medical practices in that only 38% of respondents said โthat someone at (the) business is actively ensuring (the) business’s compliance with HIPAA.โ
If you are unsure of where to start, have a HIPAA Risk Assessment conducted, especially if your practice or business has never done one. The assessment will identify vulnerabilities and threats to your current administrative, physical and technical safeguards for protected health information you maintain. A good assessment must provide an action plan or steps for remediation for all the vulnerabilities and threats that were detected. It provides a critical road map, based on the rated risk level, for what needs to be addressed immediately to meet compliance requirements.
What is clear is the need to make HIPAA compliance an important part of the everyday operations for any healthcare practice or business, not just when there is a threat of an audit. Because compliance requirements can be such a time consuming process, consider outsourcing this responsibility. I know there are quite a few practice managers who need assistance and would relish having a consultant provide this service. In the end, it may be a cost saving measure to outsource HIPAA compliance assistance, saving workforce time and a lot of frustrating hours.
Need Help with Your HIPAA Compliance Program?
At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.
- This article was updated on June 22, 2026 and reviewed By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert
- Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.