Vertical guide

HIPAA for small practices & clinics

OCR doesn't grade on a curve — small practices face the same rules. Here's the lean path that actually works.

Your reality

10–30 staff, one or two locations, an EHR, email, and a handful of vendors touching PHI. No compliance officer, no security team. The good news: a small, well-documented ePHI footprint makes you the cheapest kind of assessment — if you keep it tight.

The lean playbook

  1. Inventory ePHI first. List every system, vendor, and data flow touching PHI. This one document controls your entire assessment cost.
  2. Sign every BAA. EHR host, billing, email, shredding, IT support — no BAA, no PHI sharing. This is free to fix.
  3. Encrypt everything portable. Laptops, USB drives, backups, email with PHI. Encryption is cheap; unencrypted breaches are not.
  4. Train and document. Annual workforce training with completion records — the easiest audit evidence you'll ever produce.
  5. Hire a HIPAA specialist for the risk analysis. Firms like BlueOrange Compliance, Securance Consulting, and TraceSecurity are built for organizations your size.

What it costs (planning)

Small-practice first-year all-in: roughly $30K–$75K (risk analysis $10K–$20K + policies/training/remediation). Run your numbers in the estimator.

What not to buy

Enterprise GRC platforms, "HIPAA certification" badges (they don't exist), and Big-Firm generalist engagements priced for health systems. Match the spend to your footprint.

Get quotes sized for small practices

Matched assessors that work with small practices — scoped quotes, free, 2 minutes.

Get a free quote