A Charlotte-area dental practice called us in the spring after a laptop got stolen out of a car. The laptop had one thing on it that mattered: a spreadsheet of patient names, dates of birth, and dental insurance details someone had exported the year before “just for a report.” No encryption. No password of any consequence. That's a HIPAA breach on Day 1.
What determined whether they were looking at a written warning or a six-figure resolution agreement wasn't the theft itself — it was whether they could show a paper trail of the seven Security Rule controls that OCR (the HHS Office for Civil Rights) actually checks. Everyone had heard of HIPAA. Almost no one had done these seven things.
Here they are, in plain English, for practices under about 50 employees.
Why these seven
The HIPAA Security Rule at 45 CFR Part 164, Subpart C has three families of safeguards — administrative, physical, and technical — and dozens of individual standards. In audits and post-breach investigations, OCR asks about the same handful over and over. You can see the pattern in HHS's published resolution agreements — the same missing controls show up in case after case.
These are the seven we treat as non-negotiable when we onboard a small healthcare client.
1. A current, written Security Risk Analysis
This is the single most common finding in OCR settlements. The Security Rule requires you to conduct an accurate, thorough assessment of the potential risks and vulnerabilities to ePHI (45 CFR § 164.308(a)(1)(ii)(A)).
Practical version: a document, ideally updated annually, that identifies every place ePHI lives (EHR, practice management, backups, staff phones, scan folders, email), the threats to each, the safeguards in place, and the gaps. Not a vendor checklist. Not “we passed a scan.” A real analysis with named systems, named risks, and dated findings.
If you have one thing done before an audit, make it this.
2. A written Risk Management plan tied to the analysis
The rule also requires you to actually reduce identified risks to a reasonable and appropriate level. That means every gap in your risk analysis needs an owner, a target date, and a status. When OCR shows up, they will match your risk analysis line-by-line against your risk management activity. Analyses without follow-through are worse than no analysis at all — they document that you knew about a risk and didn't act.
3. Encryption of ePHI on laptops, phones, and portable drives
Encryption of data at rest is technically “addressable” under the Security Rule, not “required” — but in practice, unencrypted device loss is the fastest path to a large settlement. HHS's own Breach Portal is dominated by unencrypted-laptop stories. Turn on BitLocker on every Windows device, FileVault on every Mac, and full-device encryption on every phone that touches practice email. Log the status. Auto-lock every screen after 10 minutes.
4. Unique user IDs and MFA on everything that touches ePHI
Shared logins are still shockingly common in small practices — especially at reception. Under 45 CFR § 164.312(a)(2)(i), every user must have a unique identifier. That is a hard requirement, not an addressable one. Then layer phishing-resistant MFA on:
- Your EHR / practice management system
- Microsoft 365 / Google Workspace (this is where PHI leaks the most in small practices)
- Any remote-access tool (RDP, VPN, ScreenConnect, TeamViewer)
- Backup consoles
SMS text codes are better than nothing, but push-based MFA with number matching or a FIDO2 hardware key is where you want the finance and clinical leadership.
5. A functional, tested backup with offline / immutable copies
The Security Rule requires a contingency plan and a data backup plan (45 CFR § 164.308(a)(7)). Practical version: at least one immutable, offline, or air-gapped copy of ePHI that ransomware can't reach, and a written test that shows you actually restored from it in the last 12 months. “We have Datto” is not a contingency plan; a signed test-restore report is.
6. Business Associate Agreements with every vendor that touches ePHI
Under 45 CFR § 164.502(e), you can't disclose ePHI to a business associate without a written BAA. Small practices routinely miss the less-obvious ones: your IT / MSP, your MSSP, your cloud backup, your EHR host, your transcription service, your billing service, your fax-to-email provider, your email host if PHI ever crosses it. Build a simple vendor list. For each vendor, know: do they touch PHI? Do we have a signed BAA? Where is it stored?
OCR asks for the list. Auditors ask for the list. Cyber insurance carriers ask for the list. If you can't produce it inside 15 minutes, you have a problem.
7. Workforce training documented per employee
Under 45 CFR § 164.308(a)(5), training is required for all workforce members, including management. The part that trips practices up is the documentation: OCR wants to see, per employee, the date they were trained, on what content, and their acknowledgment. A shared PDF nobody signed doesn't count. A tracked LMS with signed completions does.
Refresh training annually, and add a short micro-training when anything material changes (new EHR, ransomware incident in your specialty, new phishing pattern).
The North Carolina angle
North Carolina practices have a second layer to think about. A HIPAA breach involving unencrypted PHI of NC residents is also a security breach under N.C. Gen. Stat. § 75-65 and typically triggers notice to the N.C. Attorney General. HHS breach reporting and state breach reporting are separate obligations with separate timelines and different content requirements — you have to satisfy both. Get counsel involved on Day 1 of any suspected breach.
What WHT recommends
A 30-day path to being able to answer these seven questions truthfully:
- Week 1: Inventory. Every place PHI lives. Every workforce member. Every vendor that could touch PHI. Names on paper.
- Week 2: Risk Analysis. Sit down for 3 hours with your MSP/MSSP and walk each system: what threats apply, what safeguards exist, where the gaps are. Document.
- Week 3: Close the top 5 gaps. Almost always: turn on device encryption, kill shared logins, add MFA to the EHR and Microsoft 365, get missing BAAs signed, verify at least one immutable backup with a real restore test.
- Week 4: Documentation and training. Written Risk Management plan mapping gaps to owners and dates. Workforce training rolled out with signed completions. Incident-response and breach-notification playbook printed and on the shelf.
None of the seven controls above is expensive on its own. What's expensive is discovering you don't have them the week OCR sends a letter or the week a laptop walks off.
Want a small-practice HIPAA gap review?
We'll walk your practice through these seven controls in 60 minutes, tell you honestly where you stand, and hand you a prioritized 30-day punch list. No pitch, no upsell — just a straight readout you can act on.