HIPAA for small practices & clinics
OCR doesn't grade on a curve — small practices face the same rules. Here's the lean path that actually works.
Your reality
10–30 staff, one or two locations, an EHR, email, and a handful of vendors touching PHI. No compliance officer, no security team. The good news: a small, well-documented ePHI footprint makes you the cheapest kind of assessment — if you keep it tight.
The lean playbook
- Inventory ePHI first. List every system, vendor, and data flow touching PHI. This one document controls your entire assessment cost.
- Sign every BAA. EHR host, billing, email, shredding, IT support — no BAA, no PHI sharing. This is free to fix.
- Encrypt everything portable. Laptops, USB drives, backups, email with PHI. Encryption is cheap; unencrypted breaches are not.
- Train and document. Annual workforce training with completion records — the easiest audit evidence you'll ever produce.
- Hire a HIPAA specialist for the risk analysis. Firms like BlueOrange Compliance, Securance Consulting, and TraceSecurity are built for organizations your size.
What it costs (planning)
Small-practice first-year all-in: roughly $30K–$75K (risk analysis $10K–$20K + policies/training/remediation). Run your numbers in the estimator.
What not to buy
Enterprise GRC platforms, "HIPAA certification" badges (they don't exist), and Big-Firm generalist engagements priced for health systems. Match the spend to your footprint.
Get quotes sized for small practices
Matched assessors that work with small practices — scoped quotes, free, 2 minutes.
How it works: tell us once (4 questions, 2 min) → we match HIPAA assessors to your size, setting, and timeline → they send scoped quotes directly. Free, no obligation.