You run a three-chair dental office, or a small counseling practice, or a one-doctor clinic. You hear “HIPAA” thrown around constantly, usually right before someone tries to sell you something. So the fair question is the one most owners actually ask us: does HIPAA really apply to a practice this small, and if it does, what’s my IT supposed to be doing about it?
The short answer is that size has nothing to do with it. A solo provider is held to the same Privacy and Security Rules as a hospital system. What changes is scale, not whether the rules apply. Let’s walk through who’s actually covered, what your IT has to handle, and where the lines really sit, without the fear-selling.
Who HIPAA actually covers
HIPAA applies to two groups: covered entities and business associates. A covered entity is a health plan, a healthcare clearinghouse, or a healthcare provider who transmits health information electronically in connection with certain transactions, things like billing a claim, checking eligibility, or sending a referral electronically. The U.S. Department of Health and Human Services keeps the plain definitions on its covered entities guidance page.
In practice, almost every modern provider who bills insurance electronically is a covered entity. If your front desk submits claims through a clearinghouse, you are in. The rare exception is a cash-only provider who never transmits any of the standard electronic transactions, and even that is narrower than people assume.
A business associate is anyone who handles protected health information on your behalf: your billing company, your EHR vendor, your cloud backup provider, and yes, your IT company. HHS explains the business associate relationship and the contract that has to back it up. We’ll come back to that, because it matters more than most owners realize.
So if you’re a provider who bills electronically, HIPAA applies. Now the real question.
What “protected health information” means for your systems
Protected health information, or PHI, is any individually identifiable health information you create, receive, store, or transmit. When it lives in or moves through computers, phones, servers, or the cloud, it is electronic PHI, or ePHI, and that is the slice your IT is responsible for protecting.
That is broader than the chart in your practice-management software. It includes the email your front desk sends to confirm an appointment, the scanned insurance card sitting in a shared folder, the imaging files on a workstation, the text thread a provider started with a patient, and the backup copy of all of it. If a patient’s name is attached to anything health-related, and it touches a device, your IT setup has to account for it.
What your IT actually has to do
The HIPAA Security Rule sets the requirements for ePHI. It is built around three kinds of safeguards: administrative, physical, and technical. HHS publishes the full Security Rule summary, and we suggest skimming it once so the vocabulary is yours and not just your vendor’s. Here is the honest version of what those safeguards mean for a small practice.
A risk analysis comes first. This is the requirement people skip, and it is the one auditors ask about first. You have to identify where ePHI lives, what could go wrong, and how likely each risk is. Everything else, every control you put in place, should trace back to something the risk analysis found. A good IT partner does this with you, in writing, and revisits it when something changes.
Access controls. Each staff member gets a unique login, not a shared one. People should only reach the information their job requires. When someone leaves, their access ends that day, not next month.
Encryption. ePHI should be encrypted on devices (so a stolen laptop is a lost laptop, not a breach) and in transit (so email and remote connections are not readable on the wire). Encryption is technically “addressable” rather than flatly required, which trips people up. It does not mean optional. It means you either implement it or document a reasonable alternative, and for a small practice, implementing it is almost always the cheaper, defensible choice.
Audit logging. Your systems should record who accessed what and when, and someone should actually be able to review those logs if a question comes up.
Backup and recovery. You need backups of ePHI that you can restore, plus a plan for keeping the practice running if a system goes down. Tested backups are part of the Security Rule’s contingency planning, not a nice-to-have.
Multi-factor authentication and patching. Not named word-for-word in the 2003 rule text, but these are how you actually satisfy the access and integrity requirements against today’s threats, and they are what cyber insurers and OCR investigators now expect to see.
None of this requires a hospital budget. It requires the right configuration and someone keeping it current, which is exactly the kind of layered, practical work we describe in our People+ Framework.
Where your IT company fits, and where it does not
Here is the part worth being clear-eyed about. Because your IT company handles ePHI, it’s your business associate, and you must have a signed Business Associate Agreement with it. If your current IT provider has never signed one with you, that’s a gap to close this week. Any provider who balks at signing a BAA is telling you something important.
But a BAA doesn’t move responsibility off your shoulders. HIPAA compliance stays with you as the covered entity. Your IT partner secures the systems and produces evidence that the controls are working; you own the policies, the training, the decisions, and the breach response. We dig into exactly where that line sits in whether an MSP can make you compliant, because the answer is more nuanced than most sales pitches admit. For dental offices specifically, we also break down what a HIPAA-compliant IT setup actually includes.
If you want a structured way to see where you stand, our HIPAA IT Compliance Checklist for small practices walks through the technical safeguards in the order we tackle them, so you can spot your own gaps before anyone else does.
Where to start
If you’ve been wondering whether HIPAA applies, you almost certainly already have your answer, and the more useful work is figuring out where your current setup is strong and where it’s exposed. That starts with a real risk analysis and an honest look at your access, encryption, and backups. You can read more on our compliance hub, or sit down with us for a straightforward conversation about your practice. We’re local, we work with healthcare providers across Alaska and Hawaii, and we’ll tell you plainly what needs attention and what doesn’t.