Free tools Windows power users keep installed
One-click scans. No signup required.
iTechGuides is reader-supported. When you buy through links on our site, we may earn an affiliate commission. As an Amazon Associate I earn from qualifying purchases. Learn more
Small and mid-size medical practices covered by HIPAA must protect electronic protected health information (ePHI); there is no small-practice exemption from the Security Rule. The practical starting point is an accurate, thorough risk analysis, followed by safeguards suited to the practice and regular review. A cybersecurity rule HHS listed on January 6, 2025 is proposed, not a requirement to treat as final law based on that listing.
Which HIPAA security duties apply to a small practice?
The HIPAA Security Rule applies to covered entities and business associates within its scope. It protects ePHI created, received, used, or maintained by those organizations, and calls for appropriate administrative, physical, and technical safeguards to protect its confidentiality, integrity, and availability. HHS describes the rule as “a national set of security standards to protect certain health information that is maintained or transmitted in electronic form.”
HHS’s summary identifies several core responsibilities:
- Conduct an accurate and thorough assessment of potential risks and vulnerabilities to ePHI.
- Implement security measures that reduce identified risks to a reasonable and appropriate level.
- Designate a security official.
- Set workforce and information-access controls.
- Regularly review records to detect security incidents, periodically evaluate security measures, and reevaluate risks.
These duties make compliance operational work, not a one-time policy exercise. The assessment should cover the places the practice creates, receives, maintains, or transmits ePHI, including its systems, vendors, and work practices. HHS explains the requirements in its Security Rule overview and Summary of the HIPAA Security Rule.
#1 Best Overall
Is the cybersecurity rule announced in 2025 already in effect?
HHS’s Security Rule page lists “HIPAA Security Rule to Strengthen the Cybersecurity of Electronic Protected Health Information,” published January 6, 2025, as a proposed rule. A proposal should not be presented as a binding final requirement. Check HHS’s current rulemaking page for any later status update before relying on a claim about the proposal.
How should a practice prioritize its compliance work?
- Map where ePHI is handled. Identify the systems, devices, people, workflows, and vendors that create, receive, maintain, or transmit it.
- Perform and document the risk analysis. Assess potential risks and vulnerabilities rather than treating an EHR checklist as the whole exercise. Use the findings to select reasonable and appropriate risk-management measures for the practice.
- Assign ownership and control access. Designate a security official and document workforce authorization and information-access processes.
- Review and update. Periodically evaluate safeguards, review records for incidents, and revisit risks as systems, vendors, work practices, or circumstances change.
HHS and the Office of the National Coordinator for Health Information Technology offer a free Security Risk Assessment Tool aimed at small and medium providers. The ONC page lists version 3.7 and was last updated September 18, 2026. HHS says the tool may not be appropriate for larger organizations; it is an aid, not a certification or automatic finding of compliance. NIST standards referenced in the tool are informational and are not themselves requirements of the Security Rule.
Rank #2
A practice may also choose professional help, particularly if its systems, vendors, or workflows are difficult to assess internally. The relevant question is whether the work covers the practice’s actual ePHI environment, produces useful documentation, and supports follow-up—not whether a checklist, software purchase, or consultant can promise compliance. HHS’s risk analysis guidance explains the assessment obligation.
What should a practice require from vendors?
When a covered entity engages a business associate to help carry out health-care activities or functions, it must have a written contract or other arrangement describing the work and requiring protection of PHI. Business associates are directly liable for some HIPAA provisions. HHS provides details in its business associate contract provisions guidance.
For a cloud service provider that handles ePHI, HHS says the customer must obtain satisfactory assurances through a business associate agreement. HHS does not expressly require the provider to supply security documentation or permit customer audits. A practice may seek additional assurances based on its risk analysis and compliance needs, but should not confuse those prudent requests with an express Security Rule requirement.
Outsourcing destruction does not remove the practice’s responsibility to safeguard PHI. A disposal contractor handling PHI may be a business associate, so the practice should have an agreement requiring the contractor to protect it.
Rank #4
How can medical offices dispose of paper records and electronic media?
HIPAA requires reasonable safeguards, but HHS does not mandate one destruction method or a particular device. The appropriate approach depends on the circumstances and the form, type, and amount of information. HHS describes shredding, burning, pulping, or pulverizing paper until it is essentially unreadable, indecipherable, and unreconstructable. Records awaiting pickup should be stored securely.
- Paper: Choose a method that makes the information essentially unreadable, indecipherable, and unreconstructable. A cross-cut paper shredder is one optional way to shred; HHS does not require that cut type or certify a product.
- Electronic media: HHS describes clearing, purging, or destroying the media, and requires policies and procedures for final disposition of ePHI and reuse of electronic media.
- Public trash: HHS says publicly accessible trash is generally not appropriate for PHI unless the information has first been rendered essentially unreadable, indecipherable, and unreconstructable. Its dumpster FAQ was content-reviewed August 12, 2026.
- Disposal vendor: Secure PHI while it awaits pickup, and use a business associate agreement when the vendor handles PHI.
See HHS’s guidance on disposal of PHI and its FAQ on PHI in dumpsters. State medical-record retention and disposal rules may also apply; these federal sources do not resolve state-specific requirements.
Best Value
What does enforcement show—and what does it not show?
On April 25, 2025, the HHS Office for Civil Rights announced a settlement with Comprehensive Neurology, PC, described as a small New York neurology practice, after investigating a ransomware attack. OCR called it its 12th ransomware enforcement action and the eighth action in its Risk Analysis Initiative at that time, emphasizing the Security Rule’s risk-analysis provision. This dated case illustrates enforcement attention to risk analysis; it does not establish that every small practice faces the same circumstances or outcome. Read the OCR announcement.
These sources establish ongoing federal obligations and a proposed rule, but do not quantify a trend showing that compliance has become harder over time. HHS also does not certify products or endorse private compliance systems, so a purchased tool or device alone cannot establish that a practice complies.
Quick Recap
Product prices and availability are accurate as of the date/time indicated and are subject to change. Any price and availability information displayed on Amazon at the time of purchase will apply.
Do these 3 things before closing this tab:
1Fix the driver behind crashes, sound loss and screen glitches2Repair Windows errors before they cause bigger problems3Scan for outdated or missing drivers - takes under a minute

