What HHS Actually Requires
HHS says the Security Rule requires organizations to implement policies and procedures to prevent, detect, contain, and correct security violations. That is not optional guidance. It is a regulatory obligation under 45 CFR Section 164.306(a).
The short version: Start with a HIPAA Security Risk Assessment, then write and adopt the basic policies and procedures you are missing, assign ownership, train staff, and document the fixes. That sequence covers the foundations HHS expects to see if they ever investigate your practice.
The two most commonly cited deficiencies in OCR enforcement actions are (1) no documented Security Risk Assessment and (2) no written policies and procedures. If your clinic has neither, those are the first two things to fix.
Exactly What to Do First
Complete a Security Risk Assessment
This is where you start. Every covered entity and business associate must conduct a Security Risk Assessment regardless of size, as required by 45 CFR Section 164.308(a)(1)(ii)(A). There are no size-based exemptions.
The SRA identifies where electronic Protected Health Information (ePHI) lives in your practice - every system, device, and workflow that stores, transmits, or accesses patient data. You document the threats and vulnerabilities to each, rate the risk level, and create a plan to address the highest-risk items first.
If OCR investigates your practice, the SRA is the first document they ask for. Not having one is the single most common HIPAA violation found during audits and breach investigations.
Write and Adopt Your Missing Policies
45 CFR Section 164.316(a) requires written policies and procedures that comply with the Security Rule. Generic templates you downloaded and never customized do not satisfy this requirement.
At minimum, a small practice needs these ten foundational policies:
- Privacy Policy (Notice of Privacy Practices)
- Security Management Process
- Access Control and Authorization
- Workforce Training
- Device and Media Controls
- Incident Response and Breach Notification
- Business Associate Agreement Policy
- Facility Access Controls
- Contingency and Disaster Recovery
- Sanctions Policy
These policies must reflect how your practice actually operates - not how a generic template assumes you operate. Not sure which ones you need? See the complete list of required HIPAA written policies.
Assign Ownership
HIPAA requires a designated Privacy Officer and Security Officer. In a small practice, one person can hold both roles. This person is responsible for maintaining your compliance program, responding to incidents, and serving as the point of contact for HIPAA-related questions from staff, patients, and - if it comes to it - OCR.
Without clear ownership, policies sit in a drawer, training does not happen, and vendor agreements go unsigned. Assigning a responsible person turns your compliance program from a stack of documents into an active, maintained system.
Train Your Staff
Every workforce member who handles PHI must receive HIPAA training before accessing patient information, as required by 45 CFR Section 164.308(a)(5)(i). Annual refresher training is the industry standard.
Training must cover the Privacy Rule, Security Rule, breach reporting procedures, phishing awareness, and your practice-specific policies. Completion must be documented with signed attestations - OCR does not accept "we trained them verbally."
Document Everything
HIPAA requires you to retain all compliance documentation for at least six years under 45 CFR Section 164.530(j). This includes your completed SRA, written policies, training records with sign-off dates, your BAA inventory, and any incident reports.
If OCR investigates your practice, your documentation is your evidence that you took compliance seriously. A well-documented program - even an imperfect one - is treated far more favorably than no documentation at all.
The Cost of Waiting
The longer you operate without an SRA and written policies, the greater your exposure if a breach or patient complaint triggers an OCR investigation. Penalties for HIPAA violations range from $141 per violation for unknowing violations up to $2,134,831 per violation category per year for willful neglect.
Most small practice investigations start with one of two things: a reported breach or a patient complaint. In either case, the first thing OCR asks for is your Security Risk Assessment and your written policies. If you do not have them, the investigation gets worse from there.
Getting these five steps in place is the single highest-impact thing you can do to protect your practice.
Need Help Getting Started?
One Guy Consulting works directly with small practices to build HIPAA compliance programs from scratch. No platform to figure out on your own - a Certified HIPAA Professional walks you through every step.
Book Your Free HIPAA Compliance Review