Small Practice Owners Guide to HIPAA Compliance Programs

Article Contents

If you own a small practice, here is what to focus on when it comes to HIPAA:

Small Practice Owner’s Legal Responsibility for HIPAA Compliance

A small practice owner carries legal responsibility for HIPAA compliance regardless of who performs the day-to-day compliance tasks. That means confirming the practice has completed a recent risk analysis, written policies actually reflect what HIPAA requires, staff training stays documented, and HIPAA agreements are in place with every vendor handling patient data. Ownership of a HIPAA-covered practice creates direct financial and legal exposure to fines, corrective action plans, and civil litigation.

Why Ownership Carries the Responsibility

The Office for Civil Rights holds the business liable for a HIPAA violation, not any individuals who may be “at fault” except in extreme circumstances. Many of these practices operate under the owner’s own name and because a reportable breach or settlement becomes part of the public record, a HIPAA issue can attach to an owner’s name well beyond the incident itself. This is not true for every practice, but the underlying accountability works the same way regardless: the owner is the ultimate level where accountability lives.

Many practice owners decide to delegate responsibilities like HIPAA compliance, which is perfectly reasonable, but maintaining oversight is advised considering what is ultimately at stake. At a minimum, that means checking in with whoever manages the details to ask for the date of the last risk analysis, the status of staff training, and any open items from a prior review.

What Noncompliance Actually Costs

Penalties for HIPAA violations scale with the nature of the violation and the practice’s compliance history. Regulators also look at a practice’s financial position when setting the amount: the fine is not designed to bankrupt a practice, but it is designed to hurt, and a small practice’s thin margins and limited cash reserves make that pain land harder than it would for a larger system facing the same underlying violation.

The fine, though, is usually the smallest piece of what an actual breach costs. Figuring out what happened and how far it spread often means bringing in forensic help. Then comes recovery, patient notification, and the reputational fallout of lost patients and the revenue that goes with them. A larger breach can also draw attention from law firms that monitor the public breach records and file class action lawsuits, adding even more costs.

None of this is fully avoidable. A strong program lowers the risk of a breach, but nothing eliminates that risk entirely. What a practice has the most control over is the fine itself. A practice that can show a documented, good-faith compliance effort is positioned to avoid at least that piece of the cost.

Understanding What the Practice Is Actually Obligated to Do

A HIPAA compliance program exists because a practice handles patient information, and federal law sets specific expectations for how that information gets protected, used, and disclosed. Those expectations come from three related rules: the HIPAA Privacy Rule, the HIPAA Security Rule, and the HIPAA Breach Notification Rule. Together they cover who can access patient information, how it needs to be secured, and what happens if it is exposed.

The underlying requirements do not shrink for a smaller practice. A solo practitioner and a ten-provider group face the same rules, but applying them gets more complex as a practice grows, with more systems, more staff, and more vendors to account for. Size affects capacity and complexity. It does not affect what is actually required.

Where the Program Starts

Every compliance program starts with an honest look at where patient data actually exists in the practice and what protects it today. HIPAA has a name for that ongoing process: a Security Risk Analysis. It is documented work, not a one-time form to fill out, that establishes the practice’s baseline risk and tracks progress reducing it over time. An owner should be able to confirm when it was last done, who did it, and what remediation items came out of it. An analysis older than a year, or one that has never accounted for a new system the practice adopted, is an open gap worth asking about directly.

Confirming Policies and Training Are in Place

There are several other critical elements to a compliance program beyond the risk analysis. A policy library, built in part from what the risk analysis reveals, spells out how the practice actually operates and what staff are expected to do in specific situations. A training program then uses those same policies, along with everyday security topics, to reinforce that expected behavior. Together, these are what prevent the kind of human-error breach that is the most common type a practice faces. Most owners delegate or outsource training, and often policy development as well, but the policies still need to reflect how the practice actually operates and not a one-size-fits-all template.

While training gives staff the instruction to follow proper procedure, a sanctions policy is what backs that up. This is a documented statement of what happens when someone does not follow policy, with consequences ranging from a warning to termination depending on the severity of the violation. Having this in writing, and applying it consistently, gives an owner clear grounds to act when someone falls short, and it also shows an investigator that the practice’s rules were actually being enforced.

An Easy Gap to Miss: Vendor Agreements

A practice’s list of vendors tends to grow quietly over time, often without a matching update to its agreements with them. Billing services, scheduling platforms, cloud storage providers, and IT support contractors typically all need a signed HIPAA Business Associate Agreement (BAA) before they can access patient data. This is an area of compliance that rarely comes up in daily operations, so an owner who has not personally checked the vendor list against the practice’s signed BAAs can easily be unaware of a gap that has existed for years, sometimes until an incident forces the review.

This makes vendor oversight one of the larger risk areas for a small practice, for two reasons. First, it is easy to overlook. The practice is usually focused on internal measures and fails to think about these vendors at all. Secondly, these vendors often handle data for many practices at once, which makes them a more likely source of a breach than the practice’s own systems. When a breach does trace back to a vendor, without a BAA the practice still faces serious judgement with the Office for Civil Rights, regardless of where the actual fault lay.

Preparing for an Investigation or Breach

When a breach occurs or a patient files a complaint, documentation, not intention, determines how the investigation resolves. An owner who has maintained oversight of a current, documented program enters that process with evidence the practice acted in good faith. An owner who cannot produce basic documentation faces a much harder path through the same investigation, regardless of how well the practice actually operated day to day.

During an active investigation, the owner typically serves as the practice’s primary point of contact and decision-maker, even when a Privacy Officer or outside counsel manages the technical response. An owner already familiar with the practice’s own compliance documentation responds to the process more effectively than one encountering it for the first time, and avoids the delay of scrambling to locate records that should have been maintained all along.

Staying Current with Regulatory Change

HIPAA requirements change through new rules, updated guidance, and shifting enforcement priorities from the Office for Civil Rights. An owner does not need to track every development personally, but they do need to confirm that whoever manages the practice’s compliance program has a process for identifying relevant changes and applying them, since a policy that reflects an outdated version of a rule is a gap that can sit unnoticed until it matters.

State law adds another layer, and in some ways a harder one to track. There are more states to watch than there are federal agencies, state regulators and courts tend to move faster than federal rulemaking, and many state requirements are stricter than HIPAA’s baseline. Every practice is expected to stay current with both.

Choosing How to Run the Program

A small practice owner generally chooses among three approaches: handling compliance internally with existing staff and generic templates, engaging an outside consultant for periodic review, or adopting dedicated software built specifically to generate and maintain the program. Each carries real tradeoffs in cost, staff time, and how current the program stays between reviews, and the right fit depends heavily on the practice’s specific situation.

The post Small Practice Owners Guide to HIPAA Compliance Programs appeared first on The HIPAA Journal.

North Los Angeles County Regional Center Notifies Individuals About November 2024 Ransomware Attack

North Los Angeles County Regional Center has started mailing notification letters to individuals affected by a November 2024 ransomware attack, and Midland Care Connection in Kansas has announced a March 2026 hacking incident.

North Los Angeles County Regional Center

North Los Angeles County Regional Center has started notifying individuals about a cybersecurity incident and data breach that was first identified 17 months ago on November 28, 2024. Suspicious activity was identified within its computer network, and the forensic investigation confirmed unauthorized access from November 20, 2024, to December 1, 2024.

North Los Angeles County Regional Center determined that sensitive data was exfiltrated from its systems before ransomware was used to encrypt files. The files exfiltrated from its systems included names, addresses, dates of birth, telephone numbers, Social Security numbers, passport numbers, driver’s license or other state-issued ID numbers, U.S. federal issued ID numbers, email addresses, usernames/passwords, financial account information, payment card information, health plan information, CI and patient ID numbers, medical record numbers, lab results, medications, physical and/or mental conditions, diagnosis and/or treatment information, prescription or medication information, treatment cost information, disability codes, certificate/license numbers, and certain other medical and health insurance-related information.

North Los Angeles County Regional Center said it first announced the incident on its website on January 6, 2025, to allow individuals to take steps to protect themselves against data misuse; however, it has taken time to review the affected data to allow notification letters to be issued. North Los Angeles County Regional Center said it implemented additional technical security measures shortly after the attack and is continuing to work with data security experts to further enhance the security of its systems. The Medusa ransomware group claimed responsibility for the attack, in which more than 600 gigabytes of data was allegedly stolen.

The incident is shown on the HHS’ Office for Civil Rights website as affecting 500 individuals. That is a placeholder figure, as the breach was reported to OCR on January 6, 2025, well before the investigation had concluded.  The total should be updated in the coming days, now that the data review has concluded.

Midland Care Connection

Midland Care Connection Inc., a Topeka, Kansas-based non-profit provider of patient care, hospice, and community health support services, has experienced a cybersecurity incident that may have resulted in the theft of sensitive data. Suspicious network activity was identified on March 31, 2026, and legal counsel and third-party digital forensics experts were engaged to investigate the activity. They confirmed network access by an unauthorized third party starting on March 30, 2026, and initiated a data review to determine the individuals affected and the types of information. The data review was completed on June 12, 2026.

The affected information varied from individual to individual and may have included names, birth dates, medical treatment information, medical health information, health insurance information, financial account information, and, for certain individuals, Social Security numbers. Data privacy and security policies have been reviewed and enhanced to reduce the risk of similar incidents in the future, and the affected individuals have been notified by mail and offered 12 months of complimentary single-bureau credit monitoring and identity theft protection services. The incident is not yet shown on the HHS’ Office for Civil Rights breach portal, so it is currently unclear how many individuals have been affected.

The post North Los Angeles County Regional Center Notifies Individuals About November 2024 Ransomware Attack appeared first on The HIPAA Journal.

AI Agent Conducts First Fully Autonomous Ransomware Attack

Researchers have identified what they believe to be the first agentic ransomware attack. An autonomous large language model (LLM) agent conducted an entire attack without human involvement, including vulnerability exploitation, credential theft, lateral movement and file encryption.

The attack was identified by researchers at the cloud security company Sysdig, who linked the attack to the JadePuffer ransomware operation. JadePuffer used a fully autonomous AI agent to conduct reconnaissance on the targeted company, exploit a vulnerability (CVE-2025-3248), steal credentials, move laterally within the victim’s network, establish persistence, escalate privileges, encrypt data, and drop a ransom note, adapting to failures on the fly without human intervention.

The vulnerability exploited for initial access was an unauthenticated remote code execution vulnerability in the Langflow open source framework. The researchers explained that this is an attractive entry point as Langflow servers are AI-adjacent, often hold provider API keys and cloud credentials, and are commonly stood up quickly without network controls. While a patch had been issued to fix the vulnerability on April 1, 2025, and the flaw was known to be actively exploited, the vulnerability had not been patched.

The AI agent was able to adjust its approach in a similar way to a human attacker. For instance, when an API request returned XML instead of JSON, the next payload adjusted its parsing logic accordingly, and when certain steps failed, the AI agent retried those steps using refined parameters. “In one sequence, it went from a failed login to a working fix in 31 seconds,” explained the researchers.

The AI agent gained access to a production MySQL server running Alibaba Nacos by exploiting a 2021 authentication bypass vulnerability, then encrypted all 1,342 Nacos service configuration items and deleted the originals. The AES encryption key was not transmitted to the attacker’s infrastructure, so even if the ransom was paid, recovery would not have been possible.

According to a recent statement from the Five Eyes cybersecurity agencies,  advances in artificial intelligence have accelerated the speed, scale, and sophistication of cyber threats. The agencies warned that “frontier AI models are anticipated to exceed current industry expectations, fundamentally transforming both offensive and defensive cyber capabilities. The timeline is not years; it is months.” The Sysdig researchers say the age of agentic threat actors has arrived.

While the attack was fully automated, it did not involve the exploitation of any zero-day vulnerabilities or novel techniques, therefore defending against automated attacks is no different to defending against hands-on- keyboard attacks. As recommended by the Five Eyes agencies, organizations should take steps now to combat threats by reducing their attack surface, accelerating patching processes, addressing legacy systems, reviewing and strengthening identity and access controls, and ensuring they develop and test incident response plans, which should be focused on fast containment and recovery.

The post AI Agent Conducts First Fully Autonomous Ransomware Attack appeared first on The HIPAA Journal.

Almost 30,000 Texas Residents Affected by Data Breach at The Texas Hearing Institute

The Texas Hearing Institute has notified the Texas Attorney General about a data breach impacting more than 29, 000 state residents. Data breaches have also been announced by Family Health Centers of Southern Indiana, the Wisconsin Department of Health Services, and Stephen W. Brown & Radiology Associates of Augusta.

Texas Hearing Institute

The Texas Hearing Institute, a pediatric hearing center in Houston, Texas, has started notifying at least 29,498 individuals about a March 2026 cyberattack that resulted in unauthorized access to its network and the exposure of patients’ personal and health data.

Unauthorized network access was identified on March 20, 2026, and immediate steps were taken to contain the incident and secure its systems. Assisted by third-party digital forensics experts, the Texas Hearing Institute determined on April 22, 2026, that there had been unauthorized access to personal information on its systems. The data review confirmed that names, Social Security numbers, financial information, and medical records were compromised in the incident.

The affected individuals have been offered 24 months of complimentary credit monitoring and identity theft protection services. While the notification letters do not provide further information about the nature of the attack, this appears to have been a ransomware incident. The interlock ransomware group added the Texas Hearing Institute to its dark web data leak site in early April, claiming to have stolen 540 gigabytes of data. As such, the affected individuals should ensure that they take advantage of the free identity theft protection services being offered. The Texas Attorney General was informed that 29,498 Texas residents were affected. It is currently unclear how many individuals were affected in total.

Family Health Centers of Southern Indiana

Family Health Centers of Southern Indiana, a network of health centers in Jeffersonville, New Albany, Corydon, and Clarksville in Indiana, announced a data security incident on June 22, 2026, that may have resulted in unauthorized access to patient data.

Unauthorized network activity was identified on or around January 16, 2026. Its incident response plan was immediately initiated, and an investigation was launched to determine the nature and scope of the activity. The investigation confirmed that an unauthorized third party had access to parts of its network containing patient data, including names, dates of birth, contact information, demographic information, Social Security numbers, medical information, and health insurance information.

Family Health Centers of Southern Indiana has implemented additional technical safeguards, enhanced security measures, and updated its procedures related to data privacy and security. Complimentary credit monitoring and identity theft protection services have been offered to individuals whose Social Security numbers were involved.

The data breach is not yet shown on the HHS’ Office for Civil Rights website; however, the Indiana Attorney General was informed that the protected health information of 7,037 Indiana residents was compromised in the incident. The Termine threat group took responsibility for the incident and added Family Health Centers of Southern Indiana to its dark web data leak site, including samples of the stolen data. The group claims to have exfiltrated around 250 gigabytes of data.

Stephen W. Brown & Radiology Associates of Augusta

Stephen W. Brown & Radiology Associates of Augusta have been affected by a data breach at their third-party billing vendor, MCBS, LLC. MCBS was provided with patient information as part of its contracted duties, and discovered on or around September 26, 2025, that an unauthorized third party had gained access to systems containing that information.

After an extensive forensic analysis, MCBS determined that its systems were accessed by an unauthorized third party between September 22 and September 26, 2025. Individuals affected by the incident may have had some or all of the following data stolen in the incident: name, address, date of birth, Social Security number, diagnosis, treatment information, mental or physical condition, medical history, health plan beneficiary number, health insurance policy number/subscriber identification number, and other health insurance information.

MCBS said it is unaware of any misuse of the affected data; however, as a precaution, the affected individuals have been offered complimentary credit monitoring and identity theft protection services for 12 months. It is currently unclear how many patients of Stephen W. Brown & Radiology Associates of Augusta have been affected, or how many individuals were affected in total.

Wisconsin Department of Health Services

The Wisconsin Department of Health Services has recently reported a HIPAA breach to the HHS’ Office for Civil Rights that involved unauthorized access to the protected health information of 8,157 individuals. The affected individuals were Medicaid recipients who received benefits from the Wisconsin Supplementary Security Income program.

Letters were mailed to those individuals that contained personal and private information regarding an increase in their benefits. Some of those letters were inadvertently sent to outdated addresses. The error was identified on April 30, 2026, and further mailings to the incorrect addresses have been prevented. Up to 8,157 individuals were affected and have now been notified that their information may have been accessed by unauthorized individuals as a result of the error. Complimentary credit monitoring services have been offered to those individuals for 12 months.

The post Almost 30,000 Texas Residents Affected by Data Breach at The Texas Hearing Institute appeared first on The HIPAA Journal.