A counseling practice with five clinicians holds the same category of protected health information as a hospital system: diagnoses, session notes, insurance details, contact information for people who very much do not want it public. What it does not have is a security team.
What makes small practices attractive
- High-value records — health data sells for more and cannot be reissued like a credit card.
- Personal devices — clinicians reading notes on their own phones and home laptops.
- Shared logins — one front-desk account used by everyone on the schedule.
- No formal risk analysis — the single most common HIPAA finding in enforcement actions.
- Pressure to pay — a practice that cannot see its schedule tomorrow morning has very little leverage.
What HIPAA actually expects
The Security Rule does not require expensive tooling. It requires a documented risk analysis, a plan to address what you find, written policies your staff have actually read, workforce training, and agreements with the vendors who touch PHI. Practices get penalized far more often for having nothing written down than for having imperfect technology.
A realistic starting point
- Complete a written risk analysis and keep the evidence.
- Turn on multi-factor authentication for email and the EHR.
- Give every person their own login and remove access on the day someone leaves.
- Confirm a signed BAA for every vendor that can see PHI, including AI tools.
- Train the team once a year and keep the sign-in sheet.
For most small practices this is a few weeks of focused work, not a capital project.