In December 2024, HHS proposed the first major update to the HIPAA Security Rule since 2013. The proposal would make several practices explicitly mandatory, including vulnerability scanning at least every six months, penetration testing at least every 12 months, encryption of ePHI, MFA and a written asset inventory. As of this page’s last review, a final rule had not been published. Most of the proposed controls are already expected practice, and we implement them now so the final rule is a formality.
Who HIPAA applies to
- Covered entities: medical, dental, chiropractic, physical therapy, behavioral health, med-spa and other providers that bill electronically
- Health plans and clearinghouses
- Business associates: vendors that create, receive, maintain or transmit ePHI for a covered entity, including IT providers, billing companies and many software vendors
What HIPAA means for a small business
The HIPAA Security Rule (45 CFR Part 164, Subpart C) does not prescribe specific products. It requires you to assess your own risks and implement “reasonable and appropriate” safeguards, then document what you did and why. In practice, OCR investigations most often cite the same failure: no accurate, current risk analysis.
That makes the risk analysis the foundation. Everything else, from encryption and MFA to training and backups, flows from it and should be traceable back to it.
HIPAA requirements and how we meet them
| Requirement | How Vail Valley IT handles it |
|---|---|
| Security risk analysis and risk management§164.308(a)(1) | Documented risk analysis of every system touching ePHI, a prioritized remediation plan, and an annual review. Cybersecurity Risk Assessment |
| Security awareness and training§164.308(a)(5) | Onboarding and recurring training with phishing simulations and completion records for every workforce member. Security Awareness Training |
| Access control and unique user IDs§164.312(a) | Individual accounts, MFA, least-privilege access and same-day offboarding. Managed IT Services |
| Audit controls§164.312(b) | Sign-in and activity logging in Microsoft 365 and endpoints, retained and reviewed. Compliance & Cybersecurity |
| Transmission and device security§164.312(e), §164.310(d) | Encrypted email options, full-disk encryption on laptops and phones, and secure disposal of old devices. Hardware Upgrades |
| Contingency plan and backups§164.308(a)(7) | Immutable, tested backups and a written disaster recovery and emergency mode plan. IT & Data Protection |
| Evaluation and technical testing§164.308(a)(8) | Vulnerability scanning and penetration testing to verify safeguards work as intended. Penetration Testing & Vulnerability Scanning |
| Business associate agreements§164.308(b) | We sign a BAA and help you track BAAs with other vendors that touch ePHI. |
Common HIPAA gaps we find in valley businesses
- A risk analysis that is years old, a generic template, or missing entirely
- Staff sharing logins to the EHR or front-desk computer
- Laptops and phones with patient data that are not encrypted
- No MFA on email, which is where most patient data leaks start
- Backups that have never been test-restored
- No record that staff completed security training
Evidence to keep on file
- Current security risk analysis and remediation plan
- Written policies and procedures
- Training completion records
- Vulnerability scan and penetration test reports
- Backup and restore test logs
- Signed business associate agreements
- Incident response plan and breach log
How we get you there
Gap assessment
We compare your current setup to HIPAA and list what is missing.
Remediation plan
Prioritized fixes with a flat price, in plain language.
Implement & train
Controls, policies and staff training put in place.
Test & document
Scans, pen tests and an evidence file you can hand to an auditor.
Frequently asked questions
Does a small medical or dental practice need to comply with HIPAA?
Yes. HIPAA applies to covered entities of every size, including solo and small practices. The Security Rule scales its expectations to your size and resources, but the risk analysis, safeguards and documentation are still required.
Is penetration testing required for HIPAA?
The current rule requires a risk analysis and periodic technical evaluation but does not name penetration testing explicitly. HHS’s proposed update would require penetration testing at least every 12 months and vulnerability scanning at least every six months. Many practices adopt both now because they are the clearest evidence that safeguards work.
Is HIPAA security training required every year?
HIPAA requires a security awareness and training program for the workforce but does not set a specific frequency in the current rule. Annual training plus periodic reminders and phishing tests is the common standard, and it is what auditors and insurers expect to see documented.
What happens if a small practice has a HIPAA breach?
Breaches of unsecured PHI must be reported to affected individuals, to HHS, and in larger cases to the media, within set deadlines. OCR may investigate, and penalties depend on the level of negligence. Encryption can change whether an incident is a reportable breach at all.
brand