Skip to content
MarketScale
‹ Back to IndustriesHealthcare

Is Your Practice HIPAA Compliant?

Is Your Practice HIPAA Compliant? With considerations and requirements that can be somewhat overwhelming, achieving HIPAA compliance can be quite challenging for medical practices. Even for those well acquainted with HIPAA provisions, there’s always the possibility of gaps and weaknesses. According to the Department of Health & Human Services (HHS), an average of 1,445 complaints…

This story was produced through MarketScale. See how Healthcare teams put it to work with Executive Thought Leadership.

Share

Get featured

Want to get featured in MarketScale Healthcare?

Create a free MarketScale workspace and get your company's expertise featured across our Healthcare coverage. No credit card, no demo required.

Start free

Is Your Practice HIPAA Compliant?

With considerations and requirements that can be somewhat overwhelming, achieving HIPAA compliance can be quite challenging for medical practices. Even for those well acquainted with HIPAA provisions, there’s always the possibility of gaps and weaknesses. According to the Department of Health & Human Services (HHS), an average of 1,445 complaints have been submitted each day during the calendar year 2018.[1] This staggering statistic means there is much cause for concern.

Often, the missteps in HIPAA compliance aren’t deliberate or due to lackadaisical procedures, but rather the result of insufficient documentation and/or inefficient tools. The first step in determining where your vulnerabilities lie is through a security Risk Analysis. However, a Risk Analysis is often considered the Achilles heel for practices, requiring substantial documentation on multiple processes and contingencies. While the many complex layers of a Risk Analysis present multiple opportunities for errors to occur, its importance in passing audits and being prepared is invaluable.

Security Risk Analysis 101

The Office of Civil Rights (OCR) has determined that the Risk Analysis, which is derived from the Security Rule, to be the foundation of a HIPAA-compliant program. The Risk Analysis and its significance in HIPAA compliance impacts every part of the healthcare ecosystem. There are no opt outs of HIPAA compliance, no matter the size of an organization or any other influencing factors. Every organization that transmits any Personal Health Information (PHI) in an electronic format or in data content in connection with a transaction for which HHS has adopted a standard, must be HIPAA-compliant. This includes providers such as doctors, clinics, psychologists, dentists, chiropractors, nursing homes, pharmacies, health insurance companies, HMOs, company health plans, government and military/veteran healthcare programs, healthcare clearinghouses, and/or MACRA/MIPS participants.

In straightforward terms, per the HHS site, the purpose of the Risk Analysis is to “conduct an accurate and thorough assessment of the potential risk and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information held by the [organization].” To ensure that information is protected and safeguarded to HIPAA standards, the Risk Assessment takes into account three separate organizational areas: physical, technical, and administrative. Each division must have its own plan for compliance, detailing both strengths and possible weaknesses. It’s also not a one and done type of exercise–plans must evolve throughout a healthcare organization’s lifespan.

Risk Analysis and Meaningful Use

In today’s medical profession, failing a Meaningful Use (MU) audit isn’t as uncommon as one would hope. In fact, the Morning eHealth section of Politico magazine reported that according to Centers for Medicare & Medicaid Services (CMS) data, 209,000 doctors and providers were penalized for failure to meet MU standards in 2014, which is approximately two in five physicians practicing in the U.S.[2] Failing a Meaningful Use audit often comes down to the same weak link—either the lack of, or the insufficiency of, a practice’s Risk Analysis. And further reports on 2016 HIPAA audits by HHS.gov have found that organizations did not have an adequate Risk Analysis 83% of the time. As the foundation for HIPAA compliance, it’s simple to see that Risk Analysis deficiencies can impact many other components of the compliance bionetwork as well.

Risk Analysis: The Center Piece of a Much Bigger Compliance Puzzle

Risk Analysis sets the tone for HIPAA compliance, and having a sound plan that details strategies in all three areas is essential. However, many other pieces must fit together to complete the puzzle. Remaining compliant is an ongoing act of vigilance. Policies and procedures must be drafted that define processes to safeguard PHI, and should include Disaster Recovery and Business Continuity Plans—compliance must continue even when the worst scenario occurs. In addition, every day operating initiatives must be supported, such as password protocols and staff training. In fact, staff should be trained in PHI security within 90 days of hire, with continued education scheduled on an annual basis.

Furthermore, organizations should set in place routine procedures to ensure patients sign required HIPAA-related notices and forms, during both new patient onboarding, and on an annual basis going forward. It is also essential to regularly verify that vendors and other providers that interact with a patient’s PHI are not only HIPAA-compliant, but have executed Business Associate Agreements to offset any liability in the case of a breach. Lastly, retaining HIPAA documentation in both hard copy and digital means practices have information readily accessible to confirm compliance.

Ensure Compliance: Join ChartLogic’s Webinar “Are You HIPAA-Compliant?”

In today’s modern electronic healthcare world, HIPAA compliance is mandatory, crossing all sectors of the healthcare industry. To avoid costly penalties, data violations, and breaches in doctor-patient trust, small practices and large organizations alike must keep current with the HIPAA landscape and ensure that weaknesses in their systems are turned to strengths.

Join a free webinar hosted by Abyde & ChartLogic to learn more about Security Risk Analysis and other related HIPAA requirements. In this complimentary educational HIPAA compliance webinar, other topics covered will include:

  • HIPAA Privacy & Security Rules simplified
  • MACRA/MIPS & Meaningful Use HIPAA Compliance requirements explained
  • Statistics from the most recent HIPAA audits
  • Passing an audit
  • Software solutions for HIPAA compliance

Read more at chartlogic.com

Your experts belong here

Every story in MarketScale Healthcare starts with a company putting its clinicians, service-line leaders, and field engineers on the record. Buyers are already reading this topic. The only question is whose experts they find.

Service-line buyers vet vendors quietly, and your clinicians become the proof they find while doing it.

Get your team featuredSee how it works15 minutes, straight to a calendar.

Follow Healthcare Insights

Get new expert content in your inbox.

Healthcare: are you visible to AI?

Before they reach out, Healthcare buyers ask AI engines which vendors to trust. Explore how your experts, customers, and partners can become useful content for buyers and AI search.

Free plan

You just read one Healthcare expert. Your company is full of them.

This article was produced through MarketScale. The same platform turns your clinicians, service-line leaders, and field engineers into the articles, video, and social content Healthcare buyers are searching for. Create a free workspace and see it with your own people. No credit card, no demo required.

NPS +73 · 1,000+ creators · 38+ countries

What you get, free

Your own MarketScale workspace, up to 10 people
One professional video edit a month for qualifying companies
Media requests to your crowd, remote recording, AI writing tools
$0, no credit card, nothing that expires

More Healthcare Insights

July partnerships show hospitals aligning without ownership change

July partnerships show hospitals aligning without ownership change

A July McDermott Will & Schulte analysis and four July partnership announcements tracked by Becker’s Hospital Review point to affiliation models that stop short of mergers. St. Christopher’s signed a nonbinding letter of intent with Nemours, Jefferson and Temple; Palomar UC San Diego Health began operating July 1 under a joint powers authority. Several announcements explicitly rule out ownership change, shifting the work to contracts covering governance and other terms.

  • 01In an alliance, the contract does the integrating that an org chart does in a merger: McDermott Will & Schulte says governance design, exclusivity, antitrust review, community commitments and exit rights all have to be settled before signing.
  • 02Purchasing is now explicitly on the table in at least one no-ownership deal, the St. Peter's Health and Billings Clinic-Logan Health talks in Montana, which means shared supply contracts can arrive without a change of control.

Sep 19, 2026

Eye telemedicine hits limits without home retinal imaging

Eye telemedicine hits limits without home retinal imaging

An Ophthalmology Times commentary by T.Y. Alvin Liu, Ferdinand Hui and Phillip Phan sorts eye patients into three telemedicine tiers by clinical need. Patients needing regular OCT scans benefit less unless a home device can send the image. Video tools already sit inside Epic and Cerner; the deciding purchase for retina clinics is the imaging device in the patient's living room.

  • 01The dividing line for eye telemedicine is imaging, not video: patients who need regular OCT scans benefit less from remote visits unless a device at home can send the scan, so a video license alone shifts few of those encounters.
  • 02The provider-side requirement, a HIPAA-compliant secured video platform, was already built into Epic and Cerner by 2020; the patient-side requirements (1.5 MB up and down bandwidth, a quiet private room, comfort with the technology) sit outside the health system's control and are the ones worth screening for at scheduling.
  • 03Self-administered home color fundus photography for tracking non-proliferative diabetic retinopathy was named as the nearer route into retina telemedicine; home OCT for wet AMD is the harder gate and the device to watch.

Sep 19, 2026

Value-based care reaches a quarter of revenue at 30% of surveyed health organizations

Value-based care reaches a quarter of revenue at 30% of surveyed health organizations

Wolters Kluwer Health argues value-based care software is judged on whether customers hit incentive thresholds and avoid penalties. A Fierce Healthcare-reported survey it cites puts value-based care at a quarter or more of revenue for 30% of organizations. The analysis is a vendor publication that ends by pitching its own UpToDate Connect API.

  • 01The sharper question for any population health or care coordination platform is whether it changes what a clinician does at the moment of decision, or only reports afterward what happened. Wolters Kluwer's reading of the evidence is that many platforms still struggle with the first.
  • 02Vendors selling into value-based contracts now face a build-or-license decision on clinical content, because Wolters Kluwer names current, trusted content, consistent clinician adoption across sites, and a traceable link from guidance to quality metrics as the three hard problems.

Sep 18, 2026

Explore More Healthcare Insights

Read more expert perspectives from across Healthcare.

Browse Healthcare Hub

For B2B teams

Your experts could be publishing here

Stories like this one run on content MarketScale captures from real practitioners. See how your team's expertise becomes coverage in Healthcare and beyond.

Book a 15-minute demo

Or call us. No forms required. We pick up. 214-945-2512