A solo practitioner reads the Security Rule and finds a strange document. It keeps asking the practice to "identify the security official," "designate a privacy official," "train all members of its workforce," and "apply appropriate sanctions against workforce members." In a one-clinician office, every one of those sentences points at the same chair.
That is not a loophole. It is the assignment. HIPAA has no small-practice exemption, and OCR (the HHS Office for Civil Rights) has settled with practices of every size. Its list includes a settlement titled "Small Health Care Provider Fails to Implement Multiple HIPAA Security Rule Requirements" (July 23, 2020), a $10,000 ransomware settlement (January 15, 2025), a $70,000 civil money penalty against Gums Dental Care for failure to provide timely access to patient records (October 17, 2024), and a $15,000 right of access settlement (May 8, 2023). None of those numbers would trouble a hospital. Each one would ruin a solo practice's year.
This guide covers the covered-entity test, where P.H.I. (Protected Health Information) lives in a one-person practice, the violations that recur at this size, how to build a program that fits, which vendors need a B.A.A. (Business Associate Agreement), and what the proposed Security Rule update would add.
HIPAA Compliance for Solo Practitioners: Why the Rules Apply, and How They Scale
45 CFR 160.103 defines a covered entity to include "a health care provider who transmits any health information in electronic form in connection with a transaction covered by this subchapter." Submitting a claim electronically, checking a patient's eligibility online, or receiving an electronic remittance advice is enough. The definition does not mention size, revenue, or headcount. A solo therapist, dentist, chiropractor, or physician who bills insurance electronically is a covered entity in exactly the same sense as a health system. The covered entity guide covers the test and the cash-only exception.
What the rule does offer is scale. 164.306(b)(2) requires a covered entity, "in deciding which security measures to use," to take into account "the size, complexity, and capabilities of the covered entity," its "technical infrastructure, hardware, and software security capabilities," "the costs of security measures," and "the probability and criticality of potential risks." That is the flexibility clause. It lets a solo practice choose measures proportionate to a solo practice. It does not let the practice skip a standard. Every standard applies; the implementation is what shrinks.
Where PHI Lives in a One-Person Practice
- The EHR, and the laptop it runs on. Usually one machine, usually carried between the office and home.
- The practitioner's phone. Patient texts, voicemails, photos taken during visits, and the EHR app. That device is a workstation under 164.310(b) whether or not anyone has ever called it one.
- Personal email that became practice email. Referral letters, records requests, and lab results in a mailbox that also holds the family vacation photos.
- Paper. Intake forms, superbills, signed consents, and the notepad in the coat pocket.
- The billing trail. The clearinghouse portal, the payer portals, and the bookkeeping file that names patients on invoices.
- Helpers who are not employees. The spouse who does the billing on Sundays, the part-time virtual assistant, the student intern. 160.103 defines workforce to include "employees, volunteers, trainees, and other persons whose conduct, in the performance of work for a covered entity or business associate, is under the direct control of such covered entity or business associate, whether or not they are paid." They are workforce, and they need training and access rules.
Common HIPAA Violations in Solo Practices
No risk analysis, ever. 164.308(a)(1)(ii)(A) makes the risk analysis Required, and it is the first document OCR asks for after a breach report. A solo practice's analysis can be four pages: the systems, the threats, the likelihood, the fixes. The problem is not that it is hard. The problem is that it was never done.
Records requests that slip. 164.524(b)(2) requires action on a patient's access request within 30 days, with one extension of up to 30 days if the patient is told in writing. The right of access cases on OCR's list are heavy with small providers, because in a small practice a request sits in one inbox with nobody watching the calendar. The right of access guide covers the deadline, fees, and the narrow denial grounds.
The unencrypted laptop. Encryption is Addressable under 164.312(a)(2)(iv), which under 164.306(d)(3) means implement it if reasonable and appropriate, or document why not and do something equivalent. For a laptop that leaves the building, no honest document says encryption is unreasonable; full-disk encryption is a checkbox on every modern operating system. The lost device guide explains why encrypted-and-lost is a bad day and unencrypted-and-lost is a reportable breach.
Texting patients from a personal number. A convenience that becomes an unsecured PHI archive on a device with no policy behind it. The texting rules article in Related Reading covers the compliant versions.
No BAA with the one vendor that matters. The EHR, the billing service, the cloud backup, the transcription app. OCR's list includes a settlement titled "No Business Associate Agreement? $31K Mistake" (April 20, 2017).
Closing without a plan. OCR's list also includes an item titled "Consequences for HIPAA violations don't stop when a business closes" (February 13, 2018). A solo practice that retires, sells, or is forced to close by illness still owes patients their records and still owes six years of documentation retention under 164.316(b)(2)(i) and 164.530(j)(2).
Building the Program: One Person, Every Role
Everything below is required. Each item is also small at this size.
| Requirement | Section | What it looks like in a solo practice |
|---|---|---|
| Privacy official and complaint contact | 164.530(a)(1) | One signed page naming the practitioner as both |
| Security official | 164.308(a)(2) | Same page, same name |
| Risk analysis and risk management | 164.308(a)(1)(ii)(A) and (B) | A few pages listing systems, risks, and dated fixes; redone when anything changes |
| Sanction policy | 164.308(a)(1)(ii)(C), 164.530(e) | A paragraph stating what happens to any workforce member, helpers included, who violates the policies |
| Written policies and procedures | 164.316(a), 164.530(i) | Short, and matching what the practice actually does |
| Workforce training | 164.530(b), 164.308(a)(5) | The practitioner trains and documents it for everyone, including the practitioner; 164.308(a)(5)(i) says "including management" |
| Notice of Privacy Practices | 164.520 | Given at first visit, posted in the office and on the website, acknowledgment attempted and documented |
| Contingency plan | 164.308(a)(7) | A backup that has been test-restored, and a written answer to "who gets patients their records if the practitioner is out for two months" |
| Unique user IDs, audit controls | 164.312(a)(2)(i), 164.312(b) | Separate logins for the practitioner and every helper; the EHR's audit log turned on |
| Business associate agreements | 164.502(e), 164.308(b) | Signed with every vendor that touches PHI, kept in one folder |
| Documentation retention | 164.316(b)(2)(i), 164.530(j)(2) | Six years, from creation or last effective date, whichever is later |
The contingency item deserves a second look. A one-clinician practice has a single point of failure, and it is a person. 164.308(a)(7)(ii)(C) requires an emergency mode operation plan; for a solo practice the emergency that matters most is the practitioner being unavailable. A sealed instruction sheet held by a trusted colleague, naming where the records are and how patients get them, is the solo version of that requirement. The contingency plan guide covers the rest.
Vendor BAA Checklist for Solo Practices
160.103 defines a business associate as a person who "creates, receives, maintains, or transmits protected health information" on the covered entity's behalf, outside its workforce. The list for a solo practice is short, which is the good news. The bad news is that the list is usually missing one.
- EHR and practice management software: yes.
- Billing service or clearinghouse: yes; billing is named in the definition.
- Cloud storage, email, and backup that hold PHI: yes, and generally only the business tiers of the large providers will sign. The Google Workspace and Microsoft 365 articles in Related Reading cover which plans.
- Telehealth platform: yes.
- Answering service and virtual assistant company: yes.
- Transcription or AI note-taking app: yes, if PHI goes in.
- IT support with access to the laptop: yes.
- Shredding service: yes.
- Accountant: yes if invoices or ledgers name patients and diagnoses; 160.103 lists "accounting" among the services that create business associate status when PHI is disclosed.
- Landlord, cleaning crew, courier: no, as long as PHI is locked away; they are not working with it on the practice's behalf.
The BAA guide lists the terms 164.504(e)(2) requires the contract to contain.
The Proposed Security Rule Update
HHS published a proposed Security Rule overhaul in January 2025. It has not been finalized and nothing in it is required today. As proposed, it would make encryption and multifactor authentication required rather than Addressable, require a written asset inventory and network map, and require vulnerability scanning at least every six months and penetration testing at least every 12 months. For a solo practice, the encryption and MFA pieces are already the reasonable-and-appropriate answer under the current rule, so turning them on now changes nothing later. The asset inventory for a one-laptop practice fits on an index card. The Security Rule delay article tracks the timeline.
---
FAQ
Does HIPAA apply to a solo practice with no employees?
Yes, if the practice transmits any health information electronically in connection with a standard transaction such as a claim or an eligibility check. 45 CFR 160.103 sets that test with no size threshold. Training and policy requirements still apply, and the practitioner is the workforce.
Can one person be both the privacy official and the security official?
Yes. 164.530(a)(1) requires a designated privacy official and 164.308(a)(2) a designated security official; nothing prevents the same person from holding both. Put the designation in writing and keep it with the policies.
Does a solo practitioner need a sanction policy with no staff?
Yes. 164.308(a)(1)(ii)(C) makes the sanction policy Required and 164.530(e) requires one for the Privacy Rule. It covers every workforce member, including unpaid helpers, volunteers, and trainees, and it can be a single paragraph.
Is a solo practice exempt from the risk analysis?
No. 164.308(a)(1)(ii)(A) makes the risk analysis Required for every covered entity. The flexibility clause in 164.306(b)(2) lets a small practice scale the analysis to its size; it does not remove the requirement.
What happens to HIPAA obligations when a solo practice closes?
They continue. Patients keep their right of access, and the practice must retain its policies and compliance documentation for six years from creation or last effective date under 164.316(b)(2)(i) and 164.530(j)(2). State law sets how long the medical records themselves must be kept and who is responsible for them; consult counsel before closing.
Conclusion
A solo practice does not need a compliance department. It needs a short set of policies that match how the practice actually runs, a risk analysis that took an afternoon, and a place to keep the proof. One Guy Consulting's Full-Scope plan was built for practices this size: the risk analysis, the policies, the vendor and B.A.A. register, training, and consulting time from someone who has done this for one-clinician offices since 2015. Start with a free 30-minute compliance review. No obligation, no pressure.
Sources
- 45 CFR 160.103 (definitions: covered entity, business associate, workforce)
- 45 CFR 164.306 (security standards: general rules, flexibility of approach)
- 45 CFR 164.308 (administrative safeguards)
- 45 CFR 164.312 (technical safeguards)
- 45 CFR 164.316 (policies, procedures, and documentation)
- 45 CFR 164.524 (right of access)
- 45 CFR 164.530 (administrative requirements)
- HHS OCR resolution agreements and civil money penalties
- HIPAA Security Rule NPRM, 90 FR 898 (January 6, 2025)
Related Reading