A small medical or dental office can expose patient information through an ordinary email, a misplaced laptop, or a vendor’s access to its records. HIPAA does not exempt a practice because it has only a few employees. This HIPAA small practice guide explains who must comply, which safeguards deserve attention, and how California privacy law affects your obligations.
When HIPAA applies to a small practice
The Health Insurance Portability and Accountability Act applies to covered entities and their business associates. A healthcare provider generally becomes a covered entity when it transmits health information electronically in connection with a transaction covered by federal standards, such as certain insurance claims or eligibility inquiries. Using email alone does not establish covered-entity status.
A medical or dental practice that submits covered electronic transactions through a billing service may still be a covered entity. A cash-only practice requires a closer assessment rather than an automatic assumption that HIPAA applies or does not apply. The relevant definitions appear in 45 C.F.R. § 160.103.
California businesses providing healthcare also need to consider the Confidentiality of Medical Information Act, Cal. Civ. Code § 56 et seq. A practice outside HIPAA may still have California confidentiality duties. HIPAA generally does not displace more protective state privacy requirements. Reviewing both systems is part of effective regulatory compliance planning.
Build a practical HIPAA small practice program
The HIPAA Privacy Rule protects individually identifiable health information held or transmitted by covered entities and business associates in electronic, paper, and oral form, subject to the rule’s exclusions. The Security Rule addresses electronic protected health information, commonly called ePHI. Small offices may tailor their safeguards and policies to their size, complexity, capabilities, and circumstances, but covered entities must perform and document the required risk analysis and implement safeguards and policies required by the applicable HIPAA rules.
Start with these core tasks:
- Assign responsibility: Designate a privacy official and a security official. One person may fill both roles in a small office.
- Assess risks: Conduct an accurate and thorough assessment of potential risks and vulnerabilities to ePHI, then implement measures to reduce them.
- Document procedures: Address access, disclosures, patient requests, security incidents, complaints, and workforce sanctions.
- Train staff: Provide appropriate privacy training and a security awareness program, including instruction suited to each employee’s duties.
- Maintain required documentation: HIPAA generally requires documentation required by the Privacy and Security Rules to be retained for six years after the later of its creation or last effective date; this is not a universal medical-record retention deadline.
The Security Rule’s risk-analysis requirement appears in 45 C.F.R. § 164.308(a)(1). A checklist or vendor certificate is not a substitute for assessing how your office actually stores, uses, and transmits patient information.
Protect records and support patient rights
Map where patient information lives: electronic health records, imaging systems, email, paper charts, phones, backups, and billing platforms. Restrict access according to job responsibilities. Use individual accounts, promptly remove access when employees leave, and evaluate safeguards such as encryption, multifactor authentication, and secure backups.
HIPAA’s “minimum necessary” standard generally limits certain uses, disclosures, and requests to the information needed for their purpose. Important exceptions include disclosures to, or requests by, healthcare providers for treatment. Do not apply the rule in a way that unnecessarily obstructs appropriate patient care.
Privacy obligations also include patient-facing procedures:
- Provide a compliant Notice of Privacy Practices and follow applicable acknowledgment requirements.
- Establish a process for access to records, amendment requests, and confidential communications.
- Use appropriate authorizations when a disclosure requires one.
- Review marketing, patient photographs, testimonials, and online responses before sharing identifiable information.
Under 45 C.F.R. § 164.524, a covered entity generally must act on an access request within 30 calendar days. It may take one additional 30-calendar-day period only if it provides the individual, within the initial 30 calendar days, a written explanation of the delay and the date by which it will complete the request. California Health and Safety Code § 123110 generally requires inspection within five working days after receipt of a written request and transmission of requested copies within 15 days after receipt of a written request, subject to applicable statutory conditions and exceptions. Confirm the applicable deadline rather than treating the federal period as permission to delay.
Review vendors and business associate agreements
A vendor may be a business associate if it creates, receives, maintains, or transmits protected health information on the practice’s behalf. Common examples include billing companies, certain cloud services, IT providers with qualifying access, and records-storage companies. Classification depends on the service and information involved, not the vendor’s label.
Where required, obtain a written business associate agreement before providing access. The agreement must address permitted uses, safeguards, reporting, subcontractors, and other required terms. Relevant requirements appear in 45 C.F.R. §§ 164.502(e) and 164.504(e).
Ask who can access the data, where it is stored, how incidents are reported, and what happens when the relationship ends. A business associate agreement does not replace vendor review. Conversely, not every recipient needs one: disclosures between healthcare providers for treatment generally do not create a business associate relationship merely because information is exchanged.
Prepare for incidents before they happen
A lost device or misdirected message requires prompt investigation, but not every incident triggers breach notification. Under 45 C.F.R. § 164.402, an impermissible use or disclosure is generally presumed to be a breach unless an exception applies or a documented assessment establishes a low probability that the information was compromised.
Your response plan should identify who will contain the incident, preserve evidence, assess exposure, coordinate with vendors, and evaluate notices. For reportable breaches of unsecured protected health information, individual HIPAA notices generally must be sent without unreasonable delay and no later than 60 calendar days after discovery under 45 C.F.R. § 164.404. California’s separate breach-notification requirements may impose earlier deadlines. Civil Code § 1798.82 generally requires notice to affected California residents in the most expedient time possible and without unreasonable delay, no later than 30 calendar days after discovery or notification of the breach, subject to statutory exceptions. Certain healthcare facilities also have reporting and patient-notification duties under Health and Safety Code § 1280.15, generally within 15 business days after detection, subject to applicable exceptions. Additional federal and California obligations may apply.
Do not assume that deleting an email or retrieving a device resolves the legal analysis. Keep a written record of the facts, protective steps, assessment, and notification decisions.
Talk to a California business attorney
A free consultation with Itkin Law can help you identify questions about your practice’s HIPAA obligations, California privacy requirements, and vendor agreements. Schedule a free consultation or call (424) 603-8888.
This article is attorney advertising and provides general information only. It is not legal advice and does not create an attorney–client relationship. The law changes, and this article reflects the law as of its publication date. Every situation is different — contact us to discuss how the law applies to your exact circumstances. See our full disclaimer.

