Starting Point

What to Do First When Your Clinic Has No HIPAA Risk Assessment or Written Policies

A Step-by-Step HIPAA Compliance Starting Point for Small Practices

If your clinic has never completed a Security Risk Assessment or does not have written HIPAA policies, you are not alone. Most small practices start exactly here. This page tells you what to do first, in what order, and why each step matters.

What HHS Actually Requires

HHS says the Security Rule requires organizations to implement policies and procedures to prevent, detect, contain, and correct security violations. That is not optional guidance. It is a regulatory obligation under 45 CFR Section 164.306(a).

The short version: Start with a HIPAA Security Risk Assessment, then write and adopt the basic policies and procedures you are missing, assign ownership, train staff, and document the fixes. That sequence covers the foundations HHS expects to see if they ever investigate your practice.

The two most commonly cited deficiencies in OCR enforcement actions are (1) no documented Security Risk Assessment and (2) no written policies and procedures. If your clinic has neither, those are the first two things to fix.

Exactly What to Do First

1

Complete a Security Risk Assessment

This is where you start. Every covered entity and business associate must conduct a Security Risk Assessment regardless of size, as required by 45 CFR Section 164.308(a)(1)(ii)(A). There are no size-based exemptions.

The SRA identifies where electronic Protected Health Information (ePHI) lives in your practice - every system, device, and workflow that stores, transmits, or accesses patient data. You document the threats and vulnerabilities to each, rate the risk level, and create a plan to address the highest-risk items first.

If OCR investigates your practice, the SRA is the first document they ask for. Not having one is the single most common HIPAA violation found during audits and breach investigations.

Security Risk Assessment requirements and process

2

Write and Adopt Your Missing Policies

45 CFR Section 164.316(a) requires written policies and procedures that comply with the Security Rule. Generic templates you downloaded and never customized do not satisfy this requirement.

At minimum, a small practice needs these ten foundational policies:

  • Privacy Policy (Notice of Privacy Practices)
  • Security Management Process
  • Access Control and Authorization
  • Workforce Training
  • Device and Media Controls
  • Incident Response and Breach Notification
  • Business Associate Agreement Policy
  • Facility Access Controls
  • Contingency and Disaster Recovery
  • Sanctions Policy

These policies must reflect how your practice actually operates - not how a generic template assumes you operate. Not sure which ones you need? See the complete list of required HIPAA written policies.

HIPAA policy templates for small practices

3

Assign Ownership

HIPAA requires a designated Privacy Officer and Security Officer. In a small practice, one person can hold both roles. This person is responsible for maintaining your compliance program, responding to incidents, and serving as the point of contact for HIPAA-related questions from staff, patients, and - if it comes to it - OCR.

Without clear ownership, policies sit in a drawer, training does not happen, and vendor agreements go unsigned. Assigning a responsible person turns your compliance program from a stack of documents into an active, maintained system.

4

Train Your Staff

Every workforce member who handles PHI must receive HIPAA training before accessing patient information, as required by 45 CFR Section 164.308(a)(5)(i). Annual refresher training is the industry standard.

Training must cover the Privacy Rule, Security Rule, breach reporting procedures, phishing awareness, and your practice-specific policies. Completion must be documented with signed attestations - OCR does not accept "we trained them verbally."

HIPAA training requirements and program details

5

Document Everything

HIPAA requires you to retain all compliance documentation for at least six years under 45 CFR Section 164.530(j). This includes your completed SRA, written policies, training records with sign-off dates, your BAA inventory, and any incident reports.

If OCR investigates your practice, your documentation is your evidence that you took compliance seriously. A well-documented program - even an imperfect one - is treated far more favorably than no documentation at all.

The Cost of Waiting

The longer you operate without an SRA and written policies, the greater your exposure if a breach or patient complaint triggers an OCR investigation. Penalties for HIPAA violations range from $141 per violation for unknowing violations up to $2,134,831 per violation category per year for willful neglect.

Most small practice investigations start with one of two things: a reported breach or a patient complaint. In either case, the first thing OCR asks for is your Security Risk Assessment and your written policies. If you do not have them, the investigation gets worse from there.

Getting these five steps in place is the single highest-impact thing you can do to protect your practice.

Need Help Getting Started?

One Guy Consulting works directly with small practices to build HIPAA compliance programs from scratch. No platform to figure out on your own - a Certified HIPAA Professional walks you through every step.

Book Your Free HIPAA Compliance Review

Learn More About HIPAA Compliance