2026-06-03

5 HIPAA Myths That Put Solo Practices at Risk

Solo practitioners hear a lot of confident, wrong advice about HIPAA. Here are the five myths we see most, and what the record actually shows.

Myth 1: "I'm too small for OCR to care about."

OCR enforcement is complaint-driven and breach-driven, not size-driven. A single unhappy client, a stolen laptop, or a misdirected email can open an inquiry no matter how small you are. OCR has settled with solo and small practices repeatedly — including a three-clinician practice fined after a complaint revealed it had no written policies at all. Small doesn't mean invisible; it means you have fewer resources to absorb the disruption, which is an argument for more preparation, not less.

Myth 2: "My EHR is HIPAA-compliant, so I'm covered."

No product makes you compliant. Your EHR vendor signing a BAA covers their obligations as your business associate — it does nothing for yours. The Security Rule requires your risk analysis, your policies, your training records. "We used a compliant EHR" has never been a defense to a documentation request.

Myth 3: "HIPAA compliance means buying a template pack."

A folder of generic templates with [PRACTICE NAME] placeholders fails the two tests OCR actually applies: is the policy tailored to how your practice operates, and was it in effect (adopted, dated, followed)? A template that says you review audit logs weekly when you've never opened your EHR's access report is worse than no policy — it's documented evidence you don't follow your own procedures.

Myth 4: "I don't email clients, so the Security Rule barely applies to me."

If you keep records in an EHR, take video sessions, use a smartphone, back up to the cloud, or accept card payments, you have an electronic PHI footprint. The Security Rule applies in full. The policies just need to fit your footprint — which is exactly what "reasonable and appropriate" means.

Myth 5: "I did a risk assessment once, so I'm done."

HIPAA documentation has a maintenance obligation: review and update "as needed in response to environmental or operational changes." Changed EHRs? New telehealth platform? Hired a billing contractor? State passed a new privacy law? Each one is a trigger. The six-year retention rule also means old versions need to be kept, not overwritten.

The honest takeaway

The compliance bar for a solo practice is genuinely modest: a tailored policy set, adopted with dates and signatures, reviewed when things change, with the paper trail to prove it. The risk isn't that the bar is high — it's that most solo practices haven't cleared even the modest version, and the gap only becomes visible the day something goes wrong.

Need your HIPAA policies handled?

Answer 12 questions, get all 10 required policies tailored to your practice. 14-day free trial.

Start free trial →