The HIPAA paper a solo practice must be able to produce
Summary
A solo practice needs a written set, not a binder: a documented security risk analysis, written Security Rule safeguard policies, a Notice of Privacy Practices, business associate agreements with every vendor that touches PHI, breach and complaint procedures, a records-access process, and evidence of workforce training. HIPAA scales these to your size, but requires you to keep the documentation for six years and produce it if the Office for Civil Rights asks.
By Gale Editorial · Updated 2026-07-26. Every figure cited to a dated source. How we write.
What HIPAA actually requires a solo practice to have in writing
HIPAA does not hand you a checklist, but its three rules — Privacy, Security, and Breach Notification — each demand documentation you can produce on request. The Security Rule requires written policies and procedures, retained for six years from creation or last effective date, whichever is later 1Ref 1Office of the Federal Register (2026).45 CFR Part 164 — Security and Privacy.Section 164.316 requires written HIPAA policies and procedures to be documented and retained for six years from creation or last effective date.. For a practice of one, the duty is real but scaled: the paper must exist, be followed, and be findable in the hour a patient or a regulator asks for it.
The Office for Civil Rights, which enforces HIPAA, groups the requirements into the Privacy, Security, and Breach Notification Rules plus the Enforcement Rule, and its guidance hub for professionals is the map to all of them 2Ref 2HHS Office for Civil Rights (2026).HIPAA for Professionals.OCR organizes HIPAA into the Privacy, Security, Breach Notification, and Enforcement Rules; used for rule-structure orientation.. Before you build a single policy, confirm the covered-entity test even applies to you — a practice that never transmits health information electronically in a standard transaction may sit outside HIPAA entirely, and that analysis is worth doing first.
The privacy paper: your Notice of Privacy Practices and disclosure rules
The Privacy Rule governs how you use and disclose protected health information, and it requires one patient-facing document above all: a Notice of Privacy Practices that describes your uses and disclosures, patients' rights, and how to complain 3Ref 3HHS Office for Civil Rights (2026).Summary of the HIPAA Privacy Rule.The Privacy Rule requires a Notice of Privacy Practices, minimum-necessary use, and processes for individual rights such as amendment and accounting.. Behind that notice sit standards you follow but rarely show anyone — the minimum-necessary principle and a written process for each individual right the rule grants.
Two of those processes trip up solo practices. You need a documented way to handle amendment requests, and you need to be able to produce the accounting of disclosures a patient can ask for — a log of disclosures made outside treatment, payment, and health care operations. Neither is hard to maintain, but both are effectively impossible to reconstruct after the fact if you never set them up.
The security paper: a risk analysis and the safeguards it drives
The Security Rule requires administrative, physical, and technical safeguards for electronic PHI, scaled to your practice's size and anchored in a formal risk analysis 4Ref 4HHS Office for Civil Rights (2026).Summary of the HIPAA Security Rule.The Security Rule requires administrative, physical, and technical safeguards for ePHI, scaled to practice size and anchored in a risk analysis.. The risk analysis is the keystone: it is not a form you buy but the assessment that tells you which safeguards you actually need, and OCR treats a missing or stale analysis as the root failure behind most breaches.
You do not have to hire a consultant to do it. ONC and OCR publish a free Security Risk Assessment Tool built for small practices, which walks you through the analysis question by question and produces a dated record you can keep 5Ref 5Office of the National Coordinator / ASTP (2026).Security Risk Assessment Tool.ONC and OCR publish a free Security Risk Assessment Tool sized for small practices to perform and document the required risk analysis.. From its output flow the mundane written safeguards: unique logins, screen locks, encryption on anything portable, and an explicit recognition that your phone is a hipaa device the moment PHI reaches it. We cover the security risk analysis, solo edition, as its own walkthrough.
The vendor paper: a business associate agreement for everything that touches PHI
Any vendor that creates, receives, maintains, or transmits PHI on your behalf is a business associate, and you need a signed business associate agreement with each one before it touches data 6Ref 6HHS Office for Civil Rights (2026).Business Associates.Vendors that create, receive, maintain, or transmit PHI on a practice's behalf are business associates requiring a signed BAA.. The contract — not a verbal assurance — is the compliance artifact, and it must bind the vendor to safeguard PHI, report incidents, and return or destroy data at termination.
For a solo practice the list is longer than it looks: your EHR, your billing service, your practice email, your telehealth platforms, and your e-fax line each transmit PHI, so each needs a BAA — and whether faxing in 2026 is even compliant is worth checking separately. A vendor that is a pure conduit, like a phone carrier, is not a business associate, but the line is narrow, and when you are unsure the BAA costs you nothing to require.
The breach paper: an incident log and a notification procedure
The Breach Notification Rule requires a procedure ready before you need it: how you investigate a suspected breach, when you notify affected individuals — without unreasonable delay and no later than 60 days — and how and when you report to HHS 7Ref 7HHS Office for Civil Rights (2026).Breach Notification Rule.Breaches of unsecured PHI require notice to individuals within 60 days, annual reporting to HHS under 500 affected, and media notice over 500.. Breaches affecting fewer than 500 people are logged and reported to HHS annually; larger ones trigger faster notice, including to the media serving the affected area.
What makes this survivable for one person is a simple, standing incident log. When something goes wrong — a misdirected fax, a lost phone — you document the four-factor risk assessment that decides whether it is a reportable breach, and you keep that record. The policy itself is short; the discipline is remembering to write the entry the day the thing happens, not the week you get the complaint.
What 'scalable to your size' means when the practice is one person
Scalable does not mean optional. HIPAA lets a one-person practice write shorter policies and skip safeguards that genuinely do not apply, but every rule still applies in principle, and OCR has reached resolution agreements and penalties with very small practices 8Ref 8HHS Office for Civil Rights (2026).HIPAA Compliance and Enforcement.OCR enforces HIPAA through investigations, resolution agreements, and civil money penalties, including against very small practices lacking required documentation.. The realistic minimum is a short, dated policy set you actually follow — not a purchased binder you have never opened, which reads worse in an investigation than a plain one you clearly use.
Here is the paper a solo practice should be able to put a hand on:
| Document | What it is | Which rule |
|---|---|---|
| Notice of Privacy Practices | Patient-facing notice of uses, rights, and complaints | Privacy |
| Security risk analysis | Dated assessment of ePHI risks, refreshed periodically | Security |
| Safeguards policy | Your administrative, physical, and technical controls | Security |
| Business associate agreements | Signed contracts with every PHI vendor | Privacy/Security |
| Breach response procedure | Investigation steps, four-factor log, notification path | Breach |
| Access and amendment procedure | How you fulfill records and amendment requests | Privacy |
| Training record | Proof you and any contractor were trained | Privacy/Security |
| Designated official | You, named in writing as privacy and security official | Privacy/Security |
One person wears every hat. The rule still expects a named privacy official and security official; in a solo practice that is you, documented in a single line. Training is the same — you record that you completed it, and that anyone who works for you did too.
Where solo practices actually get this wrong
Four gaps account for most solo-practice trouble, and none of them requires money to fix. The first is a risk analysis that was never done or never dated, so there is nothing to show. The second is business associate agreements that were assumed but never signed. The third is a Notice of Privacy Practices that exists as a downloaded template but was never given to patients or posted where they can see it.
The fourth is the missing incident log — the small breach that got handled informally and left no paper behind. A single focused afternoon closes all four, and the record you create in that afternoon is the difference between a scaled, defensible practice and one that is merely undocumented. The goal is not perfection; it is being able to hand a reviewer a dated set that shows you took the obligation seriously.
Common questions
Run your practice on Gale
The software is free. Gale earns one flat 3.5% all-in per paid transaction — only on transactions that actually pay. No subscription, no setup fee, no network cut.
Start or manage a practice →References
- 1.Office of the Federal Register (2026). 45 CFR Part 164 — Security and Privacy. eCFR. link ✓Section 164.316 requires written HIPAA policies and procedures to be documented and retained for six years from creation or last effective date.
- 2.HHS Office for Civil Rights (2026). HIPAA for Professionals. U.S. Department of Health and Human Services. linkOCR organizes HIPAA into the Privacy, Security, Breach Notification, and Enforcement Rules; used for rule-structure orientation.
- 3.HHS Office for Civil Rights (2026). Summary of the HIPAA Privacy Rule. U.S. Department of Health and Human Services. linkThe Privacy Rule requires a Notice of Privacy Practices, minimum-necessary use, and processes for individual rights such as amendment and accounting.
- 4.HHS Office for Civil Rights (2026). Summary of the HIPAA Security Rule. U.S. Department of Health and Human Services. linkThe Security Rule requires administrative, physical, and technical safeguards for ePHI, scaled to practice size and anchored in a risk analysis.
- 5.Office of the National Coordinator / ASTP (2026). Security Risk Assessment Tool. HealthIT.gov. link ✓ONC and OCR publish a free Security Risk Assessment Tool sized for small practices to perform and document the required risk analysis.
- 6.HHS Office for Civil Rights (2026). Business Associates. U.S. Department of Health and Human Services. linkVendors that create, receive, maintain, or transmit PHI on a practice's behalf are business associates requiring a signed BAA.
- 7.HHS Office for Civil Rights (2026). Breach Notification Rule. U.S. Department of Health and Human Services. linkBreaches of unsecured PHI require notice to individuals within 60 days, annual reporting to HHS under 500 affected, and media notice over 500.
- 8.HHS Office for Civil Rights (2026). HIPAA Compliance and Enforcement. U.S. Department of Health and Human Services. linkOCR enforces HIPAA through investigations, resolution agreements, and civil money penalties, including against very small practices lacking required documentation.
https://www.gale.care/for-providers/hip-required-policies-solo · 8 sources. Competitor details are cited to dated public sources and maintained as they change; figures are estimates, not commitments. Synthetic demonstration.