How HIPAA works
Three-step view of how it operates in practice.
- Classify data. Identify where PHI (Protected Health Information) exists — EHR systems, email, storage, backups, third-party tools.
- Implement safeguards. Apply administrative, physical, and technical safeguards per the HIPAA Security Rule: access controls, encryption, audit logs, risk analysis.
- Document & train. Policies, procedures, BAAs with vendors, annual workforce training, and incident response plans, all must be documented.
Why HIPAA matters
Healthcare consistently posts the highest breach costs of any industry in IBM's annual research, and for an independent practice the aftermath, regulatory investigation, corrective action plan, patient notification, and lost trust, lands all at once. The encouraging news is that the Security Rule maps closely to ordinary good IT practice, so a practice with solid managed IT is most of the way there and mainly needs the documentation to prove it.
The three HIPAA rules (plus enforcement)
- Privacy Rule. Governs who may see and share protected health information and for what purposes, the rule about people and permissions, covering paper as well as digital records.
- Security Rule. Requires administrative, physical, and technical safeguards for electronic PHI: risk analysis, access controls, encryption, audit logging. This is the rule your IT provider helps you satisfy.
- Breach Notification Rule. Sets the clock after an incident — affected individuals and HHS must be notified within defined windows, with larger breaches publicly reported.
- Enforcement Rule. Defines how investigations and penalties work, including the tiered fines that scale with negligence. It is why 'we didn't know' is not a defense.
Common HIPAA mistakes
- Skipping the risk analysis. A documented security risk analysis is explicitly required and is the finding regulators cite most often after a breach investigation. Do one, keep it current, and keep the paper trail.
- Missing Business Associate Agreements. Every vendor that touches PHI — IT provider, cloud host, billing service, even the shredding company, needs a signed BAA. Without one, their mistake becomes your liability.
- Assuming small practices fly under the radar. Enforcement actions regularly hit clinics and single-location providers, and state attorneys general can bring actions too. Size determines the fine, not whether you're a target.