Who HIPAA Actually Applies To
Most people think HIPAA only applies to hospitals, doctor’s offices, and health insurance companies. That’s a partial truth that gets a lot of businesses in trouble.
Covered Entities are the organizations most people think of:
- Healthcare providers who transmit health information electronically (physicians, dentists, therapists, chiropractors, pharmacies)
- Health plans (insurers, HMOs, employer-sponsored health plans)
- Healthcare clearinghouses
But Business Associates are where many small businesses are surprised to find themselves:
A Business Associate is any organization that creates, receives, maintains, or transmits Protected Health Information (PHI) on behalf of a covered entity. That includes:
- IT providers who manage systems containing patient data
- Billing companies that process medical claims
- Accounting firms with access to financial records tied to patient information
- Legal firms handling healthcare clients’ protected information
- Shredding and document destruction companies
- Cloud storage providers storing PHI
- Answering services that take patient calls
- Medical transcription services
If you’re an IT company, law firm, accountant, or any kind of service provider working with a healthcare organization and you touch their data — you’re likely a Business Associate, and HIPAA applies to you.
This matters because Business Associates carry the same liability as covered entities. You can be fined for violations even if you’re not the healthcare provider. The HHS Office for Civil Rights (OCR) has levied millions of dollars in fines against Business Associates over the past several years.
The 2026 HIPAA Security Rule Updates
The HIPAA Security Rule hasn’t been substantially updated since 2013 — until now. The U.S. Department of Health and Human Services finalized significant Security Rule updates in early 2025, with compliance timelines rolling into 2026.
Key changes that affect small businesses and their IT providers:
Mandatory vs. Addressable Safeguards
The old Security Rule used “required” and “addressable” specifications — and many organizations interpreted “addressable” as optional. The 2026 updates eliminate most of that ambiguity. The new rule makes significantly more technical safeguards explicitly mandatory, including:
- Encryption of ePHI at rest and in transit — no longer something you can choose to skip if you document an alternative
- Multi-factor authentication (MFA) for accessing systems containing ePHI
- Network segmentation to isolate systems containing PHI from general network traffic
- Vulnerability scanning — at minimum annually; after significant changes
- Penetration testing — minimum annually
- Technology asset inventory — you must document every system, device, and application that touches ePHI
Annual Risk Analysis Requirements
The Security Rule has always required a risk analysis, but enforcement has been inconsistent. The 2026 updates tighten this requirement significantly — the risk analysis must now be:
- Conducted at least annually (not just “periodically”)
- Documented with specific scope, methodology, and findings
- Followed by a documented risk management plan with timelines
OCR has cited incomplete or absent risk analyses in the majority of enforcement actions over the past five years. This is the single most common HIPAA compliance failure for small organizations.
72-Hour Breach Notification (Proposed)
The current breach notification requirement is 60 days from discovery. The 2026 proposed changes would shorten this to 72 hours for reporting to HHS — bringing HIPAA in line with other data breach laws. Organizations need incident response plans that can actually execute within that window.
The Technical Safeguards You Actually Need
Here’s what HIPAA’s Technical Safeguard requirements translate to in plain IT terms:
Encryption
All ePHI must be encrypted — both at rest (stored on devices, servers, cloud) and in transit (email, file transfers, remote access). This means:
- Full disk encryption on all laptops and desktops that could contain PHI (BitLocker for Windows, FileVault for Mac)
- Encrypted email when sending PHI (Microsoft Purview Message Encryption, ProtonMail, or similar)
- TLS encryption on all web-facing systems
- Encrypted backups
Access Controls
Only authorized individuals should be able to access ePHI — and that access should be role-based (minimum necessary).
- Unique user IDs for every person (no shared logins)
- Multi-factor authentication for remote access and cloud systems
- Automatic session timeouts
- Role-based access controls so employees only see what their job requires
Audit Controls
You must be able to generate audit logs showing who accessed what ePHI, when, and from where. This requires:
- Centralized logging
- Log retention (minimum 6 years)
- Regular log review
Integrity Controls
Mechanisms to ensure ePHI isn’t improperly altered or destroyed — essentially, this means:
- Verified backup procedures with tested restores
- Change management processes for systems containing PHI
- Version control for critical documents
Transmission Security
All ePHI transmitted over networks must be protected against unauthorized access — which means secure VPN for remote access, encrypted email, and HTTPS for any web portals.
The Risk Assessment Process
A HIPAA risk assessment isn’t a checkbox — it’s a structured process for identifying where your ePHI lives, what threats exist, and what your current controls are.
Step 1: Identify and scope ePHI
Where does PHI exist in your environment? EHR systems, email, shared drives, portable devices, backups, paper records that get scanned — all of it.
Step 2: Identify threats and vulnerabilities
What could go wrong? Ransomware, insider theft, lost/stolen devices, misconfigured cloud storage, email phishing. Rate each by likelihood.
Step 3: Assess current controls
What safeguards do you have in place today? Encryption, MFA, backups, training, access controls. How effective are they?
Step 4: Determine risk levels
For each threat, assess the current risk level (likelihood × impact). Identify gaps.
Step 5: Document and implement a remediation plan
Prioritize gaps by risk level. Create a documented plan with owners and timelines. This document is what OCR wants to see.
A good managed IT provider will run this process with you — and keep it updated annually. SDTEK’s healthcare IT services include annual risk assessment as part of compliance-oriented engagements.
Common HIPAA Violations (And How They Happen)
The most frequent violations OCR investigates and fines:
1. Unsecured ePHI on lost or stolen devices
A laptop with unencrypted patient data gets stolen from a car. This is one of the most common breach types — and entirely preventable with full disk encryption and remote wipe capability.
2. Impermissible disclosures via email
PHI sent via unencrypted personal email, or accidentally CC’d to the wrong recipient. Encrypted email and employee training prevent most of these.
3. Lack of business associate agreements (BAAs)
Covered entities are required to have signed BAAs with all Business Associates before sharing PHI. Many small practices fail to get BAAs from their IT provider, cloud vendor, or billing company.
4. No risk analysis
As noted above — this is the most cited violation in OCR enforcement actions. If you can’t produce a documented risk assessment, you’re exposed.
5. Insider access violations
Employees accessing PHI beyond their role requirements. Role-based access controls and audit logging catch and deter this.
Penalties in 2026:
- Tier 1 (unknowing violation): $141–$71,162 per violation
- Tier 2 (reasonable cause): $1,424–$71,162 per violation
- Tier 3 (willful neglect, corrected): $14,232–$71,162 per violation
- Tier 4 (willful neglect, not corrected): $71,162–$2,134,831 per violation
These are per-violation figures — and violations can be counted per record in a breach. A breach involving 500 patient records can multiply quickly.
How a Managed IT Provider Handles HIPAA Compliance
HIPAA compliance isn’t a one-time project — it’s an ongoing program. A qualified managed IT provider handles the technical layer of that program, including:
- Annual risk assessment — documented, scoped, remediation-planned
- Endpoint encryption — BitLocker/FileVault deployed and verified on all devices
- MFA deployment — enforced across email, remote access, and cloud systems
- Patch management — security patches applied on a consistent cycle to close known vulnerabilities
- Encrypted backup — tested, documented, and retained per HIPAA requirements
- Security awareness training — employees trained annually on phishing, PHI handling, and incident reporting
- Audit logging — centralized logs retained and monitored
- Business Associate Agreement — a compliant MSP will sign a BAA with you, because they’re handling ePHI
- Incident response — documented process for identifying, containing, and reporting breaches within required timelines
What a managed IT provider doesn’t handle: administrative safeguards like policies and procedures, workforce sanctions policies, and the organizational side of compliance. You’ll want a HIPAA compliance consultant or privacy officer for those. But the technical foundation — which is where most small organizations have the biggest gaps — is exactly what managed IT covers.
SDTEK provides healthcare IT compliance support for small practices and business associates in Fort Wayne, IN and San Diego, CA. Learn more about our cybersecurity services or contact us to discuss your specific compliance situation.
Frequently Asked Questions
Does HIPAA apply to my small business if I’m not a healthcare provider?
Possibly. If your business provides services to healthcare organizations and you have access to patient data — even indirectly — you may be a Business Associate under HIPAA. IT providers, billing companies, accounting firms, legal practices, and many other service providers fall under this category and face the same compliance requirements and penalties as covered entities.
What happens if my small business has a HIPAA violation?
The HHS Office for Civil Rights investigates complaints and self-reported breaches. Penalties range from $141 to over $2 million per violation depending on the severity and whether it was corrected. OCR can also require a corrective action plan with ongoing monitoring. Criminal penalties apply in cases of intentional disclosure.
Do I need a full-time compliance officer for HIPAA?
Not necessarily. Many small practices and Business Associates use a part-time compliance consultant or designate an existing staff member as their Privacy/Security Officer. A managed IT provider handles the technical safeguards, which is often the largest gap. What you do need is documentation — policies, risk assessments, training records, and audit logs.
What’s the most important thing I can do for HIPAA compliance right now?
Complete a documented risk assessment. OCR cites absent or incomplete risk analyses in the majority of enforcement actions. If you can’t produce one, you’re exposed regardless of what other controls you have in place. Start there.
How do the 2026 HIPAA Security Rule updates affect my business?
The 2026 updates make more safeguards explicitly mandatory (vs. the old “addressable” ambiguity), require annual risk assessments with documented remediation plans, and strengthen requirements around MFA, encryption, and incident response timelines. If your HIPAA compliance posture hasn’t been reviewed since before 2025, it needs an update.
Don’t Wait for a Breach to Find Out Where You Stand
HIPAA compliance is one of those things where the cost of doing it right is almost always less than the cost of doing it wrong. A breach notification, OCR investigation, and potential fine will cost you far more — in time, money, and reputation — than getting your technical safeguards in place.
SDTEK works with small healthcare practices and business associates to build and maintain the technical foundation of HIPAA compliance. If you’re not sure where you stand, start with a conversation.
Schedule a HIPAA compliance consultation →
FAQPage Schema (JSON-LD):
{
"@context": "https://schema.org",
"@type": "FAQPage",
"mainEntity": [
{
"@type": "Question",
"name": "Does HIPAA apply to my small business if I'm not a healthcare provider?",
"acceptedAnswer": {
"@type": "Answer",
"text": "Possibly. If your business provides services to healthcare organizations and you have access to patient data — even indirectly — you may be a Business Associate under HIPAA. IT providers, billing companies, accounting firms, legal practices, and many other service providers fall under this category and face the same compliance requirements and penalties as covered entities."
}
},
{
"@type": "Question",
"name": "What happens if my small business has a HIPAA violation?",
"acceptedAnswer": {
"@type": "Answer",
"text": "The HHS Office for Civil Rights investigates complaints and self-reported breaches. Penalties range from $141 to over $2 million per violation depending on the severity and whether it was corrected. OCR can also require a corrective action plan with ongoing monitoring. Criminal penalties apply in cases of intentional disclosure."
}
},
{
"@type": "Question",
"name": "Do I need a full-time compliance officer for HIPAA?",
"acceptedAnswer": {
"@type": "Answer",
"text": "Not necessarily. Many small practices and Business Associates use a part-time compliance consultant or designate an existing staff member as their Privacy/Security Officer. A managed IT provider handles the technical safeguards, which is often the largest gap. What you do need is documentation — policies, risk assessments, training records, and audit logs."
}
},
{
"@type": "Question",
"name": "What's the most important thing I can do for HIPAA compliance right now?",
"acceptedAnswer": {
"@type": "Answer",
"text": "Complete a documented risk assessment. OCR cites absent or incomplete risk analyses in the majority of enforcement actions. If you can't produce one, you're exposed regardless of what other controls you have in place. Start there."
}
},
{
"@type": "Question",
"name": "How do the 2026 HIPAA Security Rule updates affect my business?",
"acceptedAnswer": {
"@type": "Answer",
"text": "The 2026 updates make more safeguards explicitly mandatory, require annual risk assessments with documented remediation plans, and strengthen requirements around MFA, encryption, and incident response timelines. If your HIPAA compliance posture hasn't been reviewed since before 2025, it needs an update."
}
}
]
}