Skip to Content

HIPAA Technology Requirements for Small Medical Practices

The owner's account is usually the least protected one in the building. That is backwards, and it is the most common thing we find.
September 3, 2026 by
HIPAA Technology Requirements for Small Medical Practices
Casey Quinn
A client of ours clicked one phishing email. Not a doctor, not an owner, just a normal staff account on a normal Tuesday.

That one account was used to send the next email. Which compromised a second account. Which sent the next one. By the time it stopped, three accounts across multiple buildings were in someone else's hands.

Here is what the practice learned over the following two weeks, roughly in order. They were legally required to report it. Their insurance carrier had to be involved, and so did the carrier's legal team. The incident response engagement alone came to just shy of $10,000, with remediation costs stacking on top of that. Insurance covered the majority of that engagement. Staff could not send email for several days.

And then the part nobody expects. When the insurer and the IR team came back with the controls they wanted implemented, the practice's environment could not support them. We had to rebuild how their email and SaaS applications were connected before we could begin to strengthen their security controls. The fix required a fix first.

That last part is the whole reason this article exists. Most practices are not one purchase away from being secure. They are one architecture decision away from being able to be secure, and they find that out at the worst possible moment.

The account everybody gets backwards

When we take over a practice, we look at who has what. Almost every time, the owner and the practice administrator have the most relaxed security settings in the organization. No forced re-authentication. Exempted from the multifactor rollout because it was slowing them down. Sometimes a shared password with a spouse who helps with billing.


The logic is understandable. They are the boss. The controls are annoying. Somebody made an exception once and it stuck.


But an attacker does not care about the org chart the way you do. They care about which account can approve a wire, sign into the EHR with the widest permissions, email every employee without raising an eyebrow, and reset other people's passwords. That is the owner. That is the administrator. Those two accounts should carry the strictest controls in the building, not the loosest.


We say this out loud to owners and it does not always land well. Nobody enjoys being told their own convenience is the vulnerability. But the accounts with the most authority carry the most risk, and the person who holds them sets the security culture for everyone else. If staff see the owner skipping the login prompt, the policy is already dead.

What we find when we walk into a practice for the first time


We support roughly 17 medical practices across dental, primary care, specialty, behavioral health, and PT ranging from 5 to 65 users. The same five things come up over and over:

1. Reused and insecure passwords. 

The same password across the EHR, the email, and the imaging portal. Often written somewhere at the front desk. 

2. No network segmentation.

The scheduling machine, the imaging equipment, the guest Wi-Fi, and the server all live in the same flat network. Anything that gets in can reach everything. 

3. No clear owner for any responsibility.

Not just who administers the server. Who is accountable for the processes that keep running after the person who invented them leaves.

4. Generic shared accounts with no audit trail.

A "frontdesk" login that four people use. When something happens, there is no way to answer the only question that matters, which is who did this.

5. Every workstation managed individually.

No domain controller, no Intune, no MDM. Each machine is its own island with its own settings and its own local admin.

That third one is worth unpacking, because it is not really about hardware. Three examples of what we mean. Your practice management software adds an AI assistant this quarter, so who is responsible for updating the acceptable use policy to make sure nobody is feeding patient data into a public language model? Sherry kept the onboarding and offboarding checklist current for six years and then took another job, so who owns that process now? A cyberattack hits on a Saturday morning, so who is the point of contact, is that documented anywhere, and does your front desk know where to look when they cannot remember?

If the answer to any of those is a person's name rather than a documented role, that is the gap. Names leave. Roles do not.

The last item on that list deserves more than a bullet. You cannot secure an organization one computer at a time. If a new patch needs to go out, or a policy needs to change, or a departing employee needs to lose access on eleven machines, somebody has to physically touch every device. In practice that means it does not happen, or it happens to nine of the eleven. Centralized management is not a luxury purchase. It is the thing that makes every other control enforceable.

There is also a labor argument, and it is usually the one that lands with a practice administrator. Pushing a single piece of software to a practice with no central management means touching every machine by hand. That runs hours depending on device count, and it interrupts staff while it happens. The same deployment through Active Directory, Intune, or an MDM platform takes under 15 minutes and nobody notices it happened. Now multiply that difference by every patch, every configuration change, and every new hire.

Your EHR vendor is not your compliance department

The most common misunderstanding we run into is the belief that signing a Business Associate Agreement is the end of the conversation. Sign it, file it, move on.


A BAA is a contract, not a control. It establishes who is responsible for what. It does not tell you whether your vendor is actually doing any of it.


These are the questions worth asking your EHR vendor, your billing service,

and anyone else touching patient data:




Where is our data physically stored, and who else has access to that environment?


How is it protected at rest and in transit?


If you get hit with an incident, what is your recovery process and how long does it take?



Do you adhere to a recognized security framework? Are you SOC 2 certified?


What kind of multifactor authentication do you support? Is it app based or hardware based, or is it SMS and email codes?​



Does your login enforce inactivity timeouts? If not, why not?

That fifth question matters more than it sounds. A vendor can truthfully say they offer two factor authentication while only offering codes sent by text message or email, which is well behind current practice and is defeated routinely. The vendor is not lying to you. They are answering a checkbox question with a checkbox answer.

None of this is because EHR companies are careless. They build clinical software. They are experts in medical workflow, not in modern identity security, and they generally will not raise these issues on their own. Somebody on your side of the table has to ask.

The two most valuable fixes cost nothing

Write down your policies.

No license, no hardware, no software. A notepad file will do. Pen and paper will do. What happens when someone reports a suspicious email. Who gets called first when the server is encrypted. What the offboarding steps are when an employee leaves. Which systems hold patient data and who owns each one.

This is boring and it is the single highest value thing a small practice can do, for two reasons. During an incident you already have a plan instead of inventing one at 6am. And documented policies are precisely what a regulator asks for when they come looking.

They are also not optional in the way most practices assume. Written policies are a standard requirement on cyber insurance applications, they sit inside HIPAA's administrative safeguards, and they appear in every major security framework, including NIST, ISO 27001, and CIS. Exactly which policies are required varies a little between them. Disaster recovery and business continuity plans show up on nearly all of them at minimum.

Turn on multifactor authentication everywhere.

Still overlooked, still free on most platforms, still worth doing on day one.

Now the honest caveat, because you deserve one. MFA is no longer the wall it was five years ago. Attackers steal session tokens, run device code phishing, and walk around it in ways that did not exist when it became the standard recommendation. 


Any consultant who tells you MFA alone makes you safe is selling you something. What it still does reliably is stop the enormous volume of automated credential stuffing and bot driven brute force attempts, which is most of what is thrown at a small practice. It is a floor, not a ceiling. Build the floor.

What conditional access actually stops.


Once the free work is done, conditional access is the next meaningful step, and it is becoming the standard we would expect most practices to reach. On Microsoft 365 that means Business Premium or higher. You can also get there with an Entra ID P1 add on license, but if the practice is already running Word, Excel, and Outlook, Business Premium usually covers all of it in one place.

Conditional access sets rules about the circumstances under which a login is allowed, rather than just checking the password and the code. Sign in attempt from a country you do not operate in, on a device nobody has ever registered, at three in the morning. Blocked, or challenged, without anyone having to notice.

It closes the specific gaps that make MFA insufficient on its own. It defeats stolen session token reuse. It shuts down device code exploitation. And it guarantees MFA coverage across every account, which solves the quiet problem where someone was missed during rollout and nobody realized for eight months.

The number a practice administrator will actually want is the difference. Business Premium runs roughly $7 more per user per month than Business Standard, the tier below it. For a twelve-person practice, that is about $84 a month to close the gap that MFA alone leaves open.


What OCR is actually penalizing practices for.


If you read the enforcement actions, one failure appears again and again, and it is not a firewall or an antivirus product.

It is the risk analysis.

In April 2025, OCR settled with Comprehensive Neurology, PC, a small New York neurology practice, over a ransomware attack that encrypted their network and affected 6,800 individuals. The finding was that the practice had failed to conduct an accurate and thorough risk analysis. They paid $25,000 and agreed to two years of monitored corrective action.

In July 2025, OCR settled with Syracuse ASC, a single facility ambulatory surgery center in Liverpool, New York, over a ransomware breach affecting 24,891 people. Same core finding, never conducted a thorough risk analysis, plus a failure to notify affected individuals in time. That one cost $250,000 and two years of monitoring.

Neither is a hospital system. Both are the size of practices we work with every week.

The pattern holds across OCR's Risk Analysis Initiative, which the agency created specifically to focus investigations on this one requirement. OCR has said it is expanding that initiative in 2026 to cover risk management as well, meaning not just whether you identified your risks but whether you did anything about them.

For scale, the current civil monetary penalty tiers run from a $145 minimum per violation where an entity genuinely did not know, up to $2,190,294 for willful neglect left uncorrected, following the inflation adjustment effective January 28, 2026.


A risk analysis is not a scan, and it is not a certificate you buy. It is a documented assessment of where electronic patient data lives, how it moves through your systems, what could go wrong at each point, and what you are doing about each of those risks. It has to be accurate, thorough, and kept current. If you cannot produce yours right now, that is the first thing to fix.

The Security Rule overhaul, and why July 2027 is not a real deadline


In January 2025, HHS published a proposed rule that would be the first significant rewrite of the HIPAA Security Rule since 2013. If it goes through as written, the practical effect is that a long list of things practices currently document as an accepted risk become mandatory.

The proposal includes required multifactor authentication for systems accessing electronic patient data, encryption at rest and in transit, annual penetration testing and vulnerability scans twice a year, written disaster recovery and incident response policies, a risk analysis reviewed and updated every twelve months, an asset inventory with network maps showing how patient data flows, internal incident flagging within 72 hours, and backups tested to prove recovery within 72 hours. It would also require covered entities to obtain written verification from their business associates every twelve months confirming the safeguards are actually deployed, which ends the era of the signed BAA sitting in a drawer.

Here is the part most articles will not tell you. The timeline has already slipped once, from May 2026 to July 2027, and HHS moved the rulemaking to its long term actions list, which generally signals no final rule within a year. OCR received nearly 5,000 public comments, many of them from provider organizations arguing the requirements are too expensive and the timelines unworkable. HHS's own analysis projected roughly $9 billion in first year compliance costs across the industry. Some observers expect it to slip again.

So we are not going to tell you a deadline is coming. What we will tell you is that every requirement in that proposal is something a well-run practice should already be doing, and OCR is enforcing the existing rule right now without waiting for the new one. Treating July 2027 as a due date is how you end up doing the same work later, under pressure, with less room to plan it.


One Virginia thing practices get wrong


Virginia has a medical information breach notification law, § 32.1-127.1:05, that requires reporting to the Office of the Attorney General and the Commissioner of Health. Practices hear about it and assume it applies to them.

For most private practices, it does not. Subsection F explicitly excludes any person or entity that is a covered entity or business associate under HIPAA and subject to federal breach notification requirements. The statute's definition of "entity" points at public bodies and organizations supported wholly or principally by public funds. Virginia's general breach law, § 18.2-186.6, carries a comparable carve out for medical information.

What that means in practice is that your obligations run through the federal HIPAA Breach Notification Rule, not the Virginia statutes. Notify affected individuals without unreasonable delay and no later than 60 days from discovery. If the breach affects 500 or more people, notify HHS and prominent media in the state within that same 60 days. Under 500, log it and report to HHS within 60 days after the end of the calendar year.

The nuance worth knowing is that patient data is not the only sensitive data you hold. Employee records, payroll, and tax identification numbers sit outside HIPAA, and a breach touching those can trigger Virginia's general notification law even when the patient side is handled federally. If your practice also does contract work with a state entity, separate reporting obligations may attach through that relationship.


We are an IT company, not a law firm. If you are working through an actual incident, your attorney and your insurance carrier drive the notification decisions. This is context so you know which questions to ask them.

If you only do Four Things

1

Tighten the owner and administrator accounts.

 Whatever the strictest policy in your practice is, those accounts get it. No exceptions, starting with the person who signs the checks.

2

Produce a current risk analysis.

 If you cannot hand one to a regulator today, this is your largest exposure, and the one OCR is most actively enforcing.

3

Write the policies down.

Incident response, offboarding, acceptable use, backup and recovery. Free, boring, and the thing you will be judged on.

4

Get every workstation under central management.

Until that exists, every other control is applied by hand and will drift. 

And one question to take to your next renewal meeting: do you carry cyber insurance, and have you read what your carrier requires you to have in place? In the incident we opened with, insurance covered the majority of an incident response engagement that came to just shy of $10,000, before any remediation work. Carriers are also increasingly specific about the controls they expect, and finding out at claim time that you did not meet them is a bad afternoon.

Not sure where your practice stands?

Top Notch Computers has supported Virginia businesses since 1999, with offices in Charlottesville, Richmond, and Falls Church. We currently support around 16 medical practices across the Commonwealth. Start with a conversation, not a contract.




Top Notch Computers Proactive IT Support

Frequently asked questions

Here are some common questions about this topic and from medical practices like yours.

The current Security Rule does not name multifactor authentication as a required control. It requires reasonable and appropriate safeguards, and MFA is what a reasonable safeguard looks like in 2026, which is why it shows up in nearly every OCR corrective action plan. The proposed Security Rule update would make it explicitly mandatory for systems accessing electronic patient data, though that rule is not final and is currently projected for July 2027 at the earliest.

No. A compliant EHR covers the EHR. Your practice is still responsible for the workstations, the network, the email system, the accounts, the physical access, the training, the documented policies, and the risk analysis covering all of it. Vendor compliance is one input, not the answer.

It depends heavily on size, insurance, and how long the intrusion went undetected. For a concrete floor, one of our clients faced an incident response engagement just shy of $10,000 from a single compromised email account, before remediation costs, with insurance covering the majority of it. On the regulatory side, recent OCR settlements with practices comparable to a typical Virginia office have ranged from $25,000 to $250,000, alongside two years of monitored corrective action.

Generally no, if you are a HIPAA covered entity. Virginia Code § 32.1-127.1:05 expressly exempts covered entities and business associates subject to federal breach notification requirements, so a private practice reports under the federal HIPAA Breach Notification Rule instead. Breaches involving employee or payroll data rather than patient data can fall under Virginia's general notification statute, so confirm the scope of any incident with your attorney.

Yes, and not because anyone picked you specifically. Most of what reaches a small practice is automated and indiscriminate, looking for reused credentials and unpatched systems. Both of the OCR settlements referenced above involved single site practices. Being small is not cover.

Sources

HHS Office for Civil Rights, settlement with Comprehensive Neurology, PC, April 25, 2025 · HHS Office for Civil Rights, settlement with Syracuse ASC, LLC, July 23, 2025 · HHS Office for Civil Rights, Notice of Proposed Rulemaking on the HIPAA Security Rule, published January 6, 2025 · OMB Unified Agenda, RIN 0945-AA22, final action projected July 2027 · HHS civil monetary penalty inflation adjustment, effective January 28, 2026 · Code of Virginia § 32.1-127.1:05 and § 18.2-186.6



Share this post