Most small practices are behaving reasonably and cannot prove any of it. The Security Rule is less prescriptive than people fear and more evidence-driven than they expect.
Two beliefs cause most of the trouble here. The first is that HIPAA prescribes specific technology — it largely does not. The second is that a small practice is somehow out of scope — it is not.
What the Security Rule actually asks is that you assess your risks, implement reasonable and appropriate safeguards, and be able to demonstrate both.
The requirement everyone skips
A documented risk analysis is the foundation of the entire Security Rule, and it is the most commonly missing item in small-practice enforcement actions. Not a vendor checklist. A written assessment of where electronic protected health information lives in your practice, what could go wrong, and what you decided to do about each risk.
Everything else follows from it — and without it, you cannot justify any of your other decisions, because there is no record of the reasoning.
The requirement scales with your size, but the obligation to have performed one does not disappear because you are a two-dentist practice.
What 'reasonable and appropriate' means at small scale
This phrase is genuinely flexible, not a loophole. A four-person practice is not expected to run a security operations centre. It is expected to make sensible decisions in proportion to its size and risk, and to write down why.
In practice, for a small Florida practice, the reasonable baseline looks like this.
- Unique logins for every person. Shared front-desk accounts make it impossible to say who accessed a record, which defeats the audit requirement entirely.
- Multi-factor authentication on email and any remote access.
- Encryption on laptops and any portable device. A stolen encrypted laptop is generally not a reportable breach; an unencrypted one is.
- Backups that have been restored from at least once, with the result recorded.
- Audit logging switched on and retained, in your practice management system and your email tenant.
- Access reviews on a schedule, with a record — especially after staff leave.
- A Business Associate Agreement with every vendor that touches PHI, including your IT provider.
- Documented sanction and incident response procedures. One page each is fine.
The imaging machine problem
Nearly every practice has at least one piece of equipment running an operating system the manufacturer froze years ago and will not let you patch. Panoramic units, older digital sensors, lab equipment.
You are not required to throw it away. You are required to address the risk in a reasonable way, and the accepted approach is compensating controls: isolate the device on its own network segment, restrict what it can talk to, and document the decision in your risk analysis.
What is not acceptable is leaving it on the same flat network as everything else and hoping nobody notices — which is the arrangement we find most often.
Evidence is the thing that fails, not intent
When an auditor or an insurer arrives, they do not ask whether you are careful. They ask to see the risk analysis, the access review records, the patch reports, the restore test results, the BAAs and the training log.
Most practices could pass on substance and fail on paper, because nothing was generating a record as it went along. That is the practical difference between a compliant practice and a merely well-intentioned one — and it is fixable by configuring the controls so they produce evidence automatically rather than reconstructing it annually.
Florida-specific notes
Florida's own breach notification statute sits alongside HIPAA and has its own timelines. Hurricane season also makes the contingency plan requirement more than theoretical here — offsite backup copies and a documented recovery procedure are worth reviewing before each season rather than during a warning.
Frequently asked
Does our IT provider need a Business Associate Agreement?
Yes. Anyone with access to systems containing PHI needs one. An IT provider who will not sign a BAA should not be in your practice.
Is Microsoft 365 HIPAA compliant?
Microsoft will sign a BAA and the platform can be configured appropriately, but no product is compliant on its own. Compliance depends on how it is configured — MFA, audit retention, restricted sharing and controlled forwarding — and on the evidence you keep.
How often should the risk analysis be updated?
At least annually, and whenever something material changes — a new practice management system, a new location, a move to cloud imaging.
What happens if we have a breach?
Notification obligations and timelines depend on scope. This is the moment the incident response plan and your logs matter, which is why both are worth having before you need them.