HIPAA compliance
What HIPAA compliance actually means for a small practice or health tech company, what it consists of, and what it is not.
HIPAA compliance at a glance
HIPAA compliance means a covered entity or business associate meets the HIPAA Privacy, Security and Breach Notification Rules: it limits how protected health information is used and shared, honors patients' rights, protects electronic health information with a documented risk analysis and safeguards, has business associate agreements with vendors, trains its workforce, and can respond to breaches. It is an ongoing program, not a certificate — no government body certifies HIPAA compliance.
| Who needs it | Covered entities and business associates |
|---|---|
| Core pieces | Risk analysis, policies, safeguards, BAAs, training, breach response, patient rights |
| Official certification | None — compliance is shown through documentation |
| Most-missed item | A documented security risk analysis |
| Keep records | Six years |
HIPAA compliance is not a status you buy or a certificate on the wall. It is the state of actually meeting the rules — and being able to show it.
What it consists of
| Area | What it means in practice | Rule |
|---|---|---|
| Scope | Know whether you’re a covered entity or business associate, and where PHI lives | Who must comply |
| Risk analysis | A written assessment of risks to ePHI and a plan to reduce them | Security risk analysis |
| Safeguards | Access control, strong authentication (MFA where appropriate based on risk), encryption, audit logs, device security | Security Rule |
| Policies | Written policies and procedures, kept six years | 45 CFR 164.316 |
| Vendors | A BAA with every vendor that is a business associate | BAAs |
| People | Workforce training and sanctions | Training requirements |
| Patients | Notice of Privacy Practices, access to records, valid authorizations | Privacy Rule |
| Incidents | A breach response process and the 60-day notification clock | Breach Notification Rule |
What it is not
- Not a certification. No agency certifies HIPAA compliance — see HIPAA compliance certification.
- Not a product feature. A vendor “being HIPAA compliant” doesn’t make your use of it compliant; what matters is the BAA and your configuration.
- Not one-and-done. The Security Rule requires periodic evaluation (164.308(a)(8)) and updates when things change.
Where to start
Use the HIPAA compliance checklist as a working list. If you are a small practice, the therapists scenario shows what to prioritize.
Next steps
- HIPAA for therapists in private practice →Scenario
- Security risk analysis →Requirement
- Business associate agreements (BAAs) →Requirement
- HIPAA training requirements →Requirement
- Notice of Privacy Practices →Requirement
- Notifying patients of a breach →Requirement
Frequently asked questions
How do I become HIPAA compliant?
Confirm HIPAA applies to you, complete a security risk analysis, put policies and safeguards in place, sign BAAs with vendors, train your staff, set up a breach response process, and keep documentation. Our checklist walks through each step.
Can software make me HIPAA compliant?
No. Compliance software can organize policies, risk assessments and training, but compliance depends on what your organization actually does.
Is HIPAA compliance a one-time project?
No. The risk analysis, policies, vendor list and training must be kept current as your systems and staff change.