Blog Post

The Clock Is Ticking: HIPAA Fines Start at $100 Per Violation

If you run a medical practice, dental office, physical therapy clinic, home health agency, or any business that handles patient health information — you are a covered entity under HIPAA. And the Department of Health and Human Services is auditing more small businesses than ever before.

In 2024, the HHS Office for Civil Rights settled 22 HIPAA enforcement actions against small healthcare providers and their business associates. Fines range from $10,000 to $1.5 million per violation category. And here’s what most IT providers won’t tell you: the fines apply to your business even when the breach was caused by a vendor’s security failure.

This guide breaks down exactly what HIPAA requires from a small business IT standpoint, what the technical safeguards actually look like in practice, and how to know if your current IT provider is leaving you exposed.


Who HIPAA Applies To

HIPAA doesn’t care about your company size. If you are a:

  • Covered entity — health plans, healthcare clearinghouses, healthcare providers (anyone who electronically transmits protected health information, or PHI)
  • Business associate — any vendor that accesses, stores, or transmits PHI on your behalf (this includes your IT provider, email platform, cloud storage, and backup services)

Both categories carry full HIPAA compliance obligations.

Common small business examples that are covered:

  • Medical practices (family, dental, specialty)
  • Mental health counselors and therapists
  • Physical therapy and rehabilitation clinics
  • Home health agencies and hospice
  • Pharmacies (with patient counseling programs)
  • Health insurance agents and brokers
  • Medical billing companies
  • Fitness studios that collect health data via apps or wearables

The Two Rules That Actually Matter for IT

HIPAA compliance is built on two primary rules from the HIPAA Security Rule (45 CFR §§ 164.302–164.318):

#### 1. The Administrative Safeguards (§ 164.308)

This is the policy and training layer. Required elements include:

  • Security Management Process — ongoing risk analysis to identify where PHI is vulnerable
  • Workforce Security — defining who has access to PHI and training them appropriately
  • Information Access Management — role-based access controls, minimum necessary standard
  • Security Awareness Training — all staff trained on phishing, password hygiene, and incident reporting
  • Incident Procedures — written incident response plan with defined steps for a breach
  • Contingency Planning — data backup and disaster recovery plans specifically for PHI

Most small businesses are completely missing the written policies. HHS investigators ask for these first. If you don’t have them documented, you’re already non-compliant.

#### 2. The Technical Safeguards (§ 164.312)

This is where your IT infrastructure either protects you or exposes you. Required technical safeguards include:

a) Access Control (§ 164.312(a)(1))

Unique user logins for every employee. No shared accounts. Automatic logoff after period of inactivity. Encryption and decryption as a safety mechanism (not optional).

*IT red flag:* “We all use the same admin password for simplicity.”

b) Audit Controls (§ 164.312(b))

System-level logging that records who accessed what data and when. These logs must be reviewable and retained for at least 6 years.

*IT red flag:* “We don’t have centralized logging set up — too expensive.”

c) Integrity Controls (§ 164.312(c)(1))

Mechanisms to authenticate that PHI hasn’t been improperly modified or destroyed. This means version control on documents, write protection on archives, and change management processes.

d) Transmission Security (§ 164.312(e)(1))

Encryption of PHI in transit (TLS 1.2+ for email and web) and at rest (AES-256 for stored data). Any PHI sent over email must be encrypted unless the receiving party has a signed Business Associate Agreement (BAA).

*IT red flag:* “We just use regular Gmail or Outlook for patient communication.”


The BAA Problem: Why Your Free Software Is a Liability

This one surprises almost every small healthcare provider.

When you use Google Workspace, Microsoft 365, Dropbox, Slack, Zoom, or any cloud service to store or transmit patient health information, you must have a signed BAA with that vendor before any PHI goes through their systems.

Google Workspace and Microsoft 365 both offer BAAs. But:

  • The BAA must be actively configured — just having an account doesn’t activate it
  • Google Workspace’s BAA covers certain services but excludes some (Google Voice, YouTube, consumer Google Maps)
  • Microsoft 365’s BAA has specific configuration requirements (Intune, Defender, sensitivity labels must be enabled)
  • Free or consumer-tier accounts do not include BAA coverage

Using any of these platforms without a properly configured BAA is a HIPAA violation — regardless of whether a breach ever occurs.

Your IT provider should be managing BAA compliance as a standard part of your setup. If they don’t know what a BAA is, they are not a HIPAA-compliant IT provider.


What a Breach Actually Costs

The direct costs are just the beginning:

| Cost Category | Estimated Impact |

|—|—|

| Breach investigation | $15,000–$50,000 |

| Legal defense | $10,000–$100,000+ |

| OCR penalty (per violation) | $100–$50,000 per violation |

| State AG penalty | Additional $5,000–$50,000 per violation |

| Patient notification costs | $1–$5 per affected patient |

| Lost business / reputation | Immeasurable |

For a small practice with 1,000 patient records, a breach notification alone can cost $5,000–$25,000. The average total cost of a healthcare data breach in 2024 was $10.9 million across all business sizes.

The worst part: many breaches are entirely preventable. The leading causes in small healthcare organizations:

  1. Phishing attacks (45% of breaches)
  2. Stolen or leaked credentials (25%)
  3. Unpatched systems and software (15%)
  4. Lost or stolen devices (10%)
  5. Insider threats (5%)

Every single one of these is an IT infrastructure problem — meaning your IT provider either prevents them or creates them.


How to Evaluate Your Current IT Provider on HIPAA

Ask these questions directly. If they can’t answer confidently, that’s your red flag.

1. “Do you have experience with HIPAA technical safeguards?”

They should be able to explain encryption standards, access controls, audit logging, and BAA management in plain language.

2. “Can you show me our current risk analysis?”

A real HIPAA compliance posture starts with a documented risk analysis. If your IT provider has never done one, they’re flying blind — and so are you.

3. “What BAAs do we have in place, and which services do they cover?”

If they can’t give you a BAA inventory, you don’t know what you’re covered for.

4. “Do you monitor our systems 24/7?”

HIPAA’s security management process standard requires ongoing monitoring. Break-fix IT (waiting for something to break before fixing it) is not compliant with HIPAA’s requirements.

5. “What would we do if we had a breach tomorrow?”

They should have a documented incident response plan. If the answer is “we’d figure it out,” that’s not a plan.


What SDTEK Does Differently for Healthcare Clients

For healthcare organizations, IT isn’t just about keeping computers running — it’s about keeping your patients’ data safe and your practice compliant.

SDTEK’s HIPAA-aligned IT approach for small healthcare providers includes:

  • BAA-covered cloud platform configuration — Google Workspace and Microsoft 365 configured for HIPAA compliance from day one
  • Managed detection and response — 24/7 monitoring with rapid incident response before a small incident becomes a reportable breach
  • Encrypted email and file sharing — end-to-end encryption for all PHI in transit and at rest
  • Risk analysis and documentation — the written policies HHS investigators will ask for, maintained and updated annually
  • Workforce security training — phishing simulations and security awareness training for all staff
  • Disaster recovery with PHI focus — backups tested and validated specifically for healthcare data retention requirements
  • Business associate management — tracking and reviewing BAAs with all your vendors

We work with healthcare providers throughout San Diego, Fort Wayne, and remotely — from solo practitioners to multi-location clinics.


HIPAA Compliance Checklist for Small Healthcare Businesses

Use this checklist to assess your current posture:

Technical Safeguards:

  • [ ] All devices (laptops, phones, tablets) are encrypted at rest
  • [ ] Unique logins for every employee — no shared accounts
  • [ ] Multi-factor authentication enabled on all accounts accessing PHI
  • [ ] Automatic screen lock after 5 minutes of inactivity
  • [ ] Email encryption enabled for any PHI transmission
  • [ ] Audit logs are being collected and reviewed
  • [ ] All software and operating systems are patched within 30 days of release
  • [ ] Portable devices (USB drives, laptops) have remote wipe capability

Policy & Documentation:

  • [ ] Written Security Risk Analysis on file
  • [ ] HIPAA policies and procedures documented
  • [ ] Business Associate Agreements with all PHI-accessing vendors
  • [ ] Incident Response Plan written and tested
  • [ ] Workforce security training records on file
  • [ ] Contingency (backup and disaster recovery) plan documented

If you see gaps, don’t wait. HHS OCR’s compliance audit protocol is a self-assessment tool available free on their website — use it. Or talk to an IT provider who takes HIPAA seriously.


Frequently Asked Questions

“We’re a small practice with 3 employees — does HIPAA really apply to us?”

Yes. HIPAA applies to any size covered entity. Size does not exempt you from requirements.

“We had our IT company set up our systems. Doesn’t that mean we’re covered?”

Not automatically. HIPAA compliance is the covered entity’s legal responsibility. If your IT provider made configuration errors, the liability is still yours. You need a provider who actively manages compliance, not just sets up accounts.

“Is cloud storage HIPAA compliant?”

Cloud storage itself is not inherently HIPAA compliant or non-compliant — it depends entirely on how it’s configured. The platform must offer a BAA, the BAA must be actively enabled, and your IT provider must configure the environment according to HIPAA technical safeguards. Consumer-grade cloud services (iCloud, personal Dropbox) do not offer BAAs and are never HIPAA compliant.

“How often do we need to do a security risk analysis?”

At minimum annually, and whenever there is a significant change in your environment (new software, new staff, new office location, new remote work arrangements). The analysis must be documented in writing.

“Does HIPAA require us to have a dedicated IT person?”

HIPAA does not mandate a specific job title — it mandates that the technical safeguards be in place and managed. Most small healthcare providers lack the in-house expertise to manage this properly, which is why most partner with a managed IT provider experienced in healthcare compliance.

“What happens if we get audited and don’t have documentation?”

You face civil penalties starting at $100 per violation with no upper limit, plus state-level penalties. The investigation will ask for your risk analysis, policies, training records, BAA inventory, and incident logs. Missing documentation is treated as equivalent to non-compliance.


*For a free HIPAA IT readiness assessment, contact SDTEK. We’ll review your current environment and identify your compliance gaps — at no cost.*

🛡️ Get Your Free Assessment
🔐

Before You Go...

Is Your Business at Risk?

Download our free 15-Point IT Security Checklist and find out where you're vulnerable — takes just 5 minutes.

Get the Free Checklist
Scroll to Top