HIPAA has a reputation as a wall of legal text only hospitals can afford to climb. In practice, what the rules ask of a solo or small practice is finite and mostly common sense. Here is the working checklist — the handful of items that cover the real obligations and the real risks.
1. Do a risk assessment — and write it down
The Security Rule's foundation is a security risk assessment: where does patient information live, who can touch it, and what could go wrong. For a small practice this is an afternoon, not a consulting engagement — HHS publishes a free Security Risk Assessment Tool built for exactly this. The writing-it-down part matters: a documented assessment is the first thing asked for after any incident.
2. Sign a BAA with every vendor that touches PHI
Your EHR, your email provider if patient information crosses it, your billing service, your cloud storage — each needs a signed Business Associate Agreement. A vendor that won't sign one cannot hold patient data for you, full stop. This is the quiet disqualifier for consumer tools — personal Gmail, standard Dropbox, most booking apps.
3. Control who can see what
- Unique logins for every person. Shared accounts make audit trails meaningless.
- Strong passwords and two-factor authentication wherever offered.
- Access matched to role — the front desk doesn't need every clinical note.
- Auto-lock on every device, and no PHI on personal phones outside secure apps.
4. Encrypt — or better, don't store locally at all
Laptops with patient spreadsheets are how small practices end up on the HHS breach portal. A cloud EHR that encrypts data in transit and at rest (see how Branzino handles security) removes the biggest category of small-practice breach: the lost or stolen device with a local copy of your charts.
5. Train the team — even a team of two
One short session, repeated annually and documented: what PHI is, what phishing looks like, no charts discussed where others can hear, no PHI in regular text messages. Most reportable incidents are human error, and most human error is preventable with a single afternoon a year.
6. Have a breach plan before you need one
Know the first three moves: contain it (revoke access, remote-wipe the device), assess what was exposed, and notify — affected patients and HHS within the required windows, per the Breach Notification Rule. Deciding this in advance turns a crisis into a procedure.
7. Honor patient access requests
Patients have a right to copies of their records, generally within 30 days and at no more than a reasonable cost. An EHR with real export makes this a button instead of a project — and it's the same export freedom that protects you from lock-in, as we argue in the buyer's guide.
The bottom line
Risk assessment, BAAs, access controls, encryption, training, a breach plan, and patient access. Do those seven consistently and a solo practice is in genuinely defensible shape — no binder required. And note how many items your software either solves or fails for you: HIPAA is one more reason the EHR choice matters beyond the price tag.

