Guide

The HIPAA paper a solo practice must be able to produce

Summary

A solo practice needs a written set, not a binder: a documented security risk analysis, written Security Rule safeguard policies, a Notice of Privacy Practices, business associate agreements with every vendor that touches PHI, breach and complaint procedures, a records-access process, and evidence of workforce training. HIPAA scales these to your size, but requires you to keep the documentation for six years and produce it if the Office for Civil Rights asks.

By Gale Editorial · Updated 2026-07-26. Every figure cited to a dated source. How we write.

What HIPAA actually requires a solo practice to have in writing

HIPAA does not hand you a checklist, but its three rules — Privacy, Security, and Breach Notification — each demand documentation you can produce on request. The Security Rule requires written policies and procedures, retained for six years from creation or last effective date, whichever is later 1. For a practice of one, the duty is real but scaled: the paper must exist, be followed, and be findable in the hour a patient or a regulator asks for it.

The Office for Civil Rights, which enforces HIPAA, groups the requirements into the Privacy, Security, and Breach Notification Rules plus the Enforcement Rule, and its guidance hub for professionals is the map to all of them 2. Before you build a single policy, confirm the covered-entity test even applies to you — a practice that never transmits health information electronically in a standard transaction may sit outside HIPAA entirely, and that analysis is worth doing first.

The privacy paper: your Notice of Privacy Practices and disclosure rules

The Privacy Rule governs how you use and disclose protected health information, and it requires one patient-facing document above all: a Notice of Privacy Practices that describes your uses and disclosures, patients' rights, and how to complain 3. Behind that notice sit standards you follow but rarely show anyone — the minimum-necessary principle and a written process for each individual right the rule grants.

Two of those processes trip up solo practices. You need a documented way to handle amendment requests, and you need to be able to produce the accounting of disclosures a patient can ask for — a log of disclosures made outside treatment, payment, and health care operations. Neither is hard to maintain, but both are effectively impossible to reconstruct after the fact if you never set them up.

The security paper: a risk analysis and the safeguards it drives

The Security Rule requires administrative, physical, and technical safeguards for electronic PHI, scaled to your practice's size and anchored in a formal risk analysis 4. The risk analysis is the keystone: it is not a form you buy but the assessment that tells you which safeguards you actually need, and OCR treats a missing or stale analysis as the root failure behind most breaches.

You do not have to hire a consultant to do it. ONC and OCR publish a free Security Risk Assessment Tool built for small practices, which walks you through the analysis question by question and produces a dated record you can keep 5. From its output flow the mundane written safeguards: unique logins, screen locks, encryption on anything portable, and an explicit recognition that your phone is a hipaa device the moment PHI reaches it. We cover the security risk analysis, solo edition, as its own walkthrough.

The vendor paper: a business associate agreement for everything that touches PHI

Any vendor that creates, receives, maintains, or transmits PHI on your behalf is a business associate, and you need a signed business associate agreement with each one before it touches data 6. The contract — not a verbal assurance — is the compliance artifact, and it must bind the vendor to safeguard PHI, report incidents, and return or destroy data at termination.

For a solo practice the list is longer than it looks: your EHR, your billing service, your practice email, your telehealth platforms, and your e-fax line each transmit PHI, so each needs a BAA — and whether faxing in 2026 is even compliant is worth checking separately. A vendor that is a pure conduit, like a phone carrier, is not a business associate, but the line is narrow, and when you are unsure the BAA costs you nothing to require.

The breach paper: an incident log and a notification procedure

The Breach Notification Rule requires a procedure ready before you need it: how you investigate a suspected breach, when you notify affected individuals — without unreasonable delay and no later than 60 days — and how and when you report to HHS 7. Breaches affecting fewer than 500 people are logged and reported to HHS annually; larger ones trigger faster notice, including to the media serving the affected area.

What makes this survivable for one person is a simple, standing incident log. When something goes wrong — a misdirected fax, a lost phone — you document the four-factor risk assessment that decides whether it is a reportable breach, and you keep that record. The policy itself is short; the discipline is remembering to write the entry the day the thing happens, not the week you get the complaint.

What 'scalable to your size' means when the practice is one person

Scalable does not mean optional. HIPAA lets a one-person practice write shorter policies and skip safeguards that genuinely do not apply, but every rule still applies in principle, and OCR has reached resolution agreements and penalties with very small practices 8. The realistic minimum is a short, dated policy set you actually follow — not a purchased binder you have never opened, which reads worse in an investigation than a plain one you clearly use.

Here is the paper a solo practice should be able to put a hand on:

DocumentWhat it isWhich rule
Notice of Privacy PracticesPatient-facing notice of uses, rights, and complaintsPrivacy
Security risk analysisDated assessment of ePHI risks, refreshed periodicallySecurity
Safeguards policyYour administrative, physical, and technical controlsSecurity
Business associate agreementsSigned contracts with every PHI vendorPrivacy/Security
Breach response procedureInvestigation steps, four-factor log, notification pathBreach
Access and amendment procedureHow you fulfill records and amendment requestsPrivacy
Training recordProof you and any contractor were trainedPrivacy/Security
Designated officialYou, named in writing as privacy and security officialPrivacy/Security

One person wears every hat. The rule still expects a named privacy official and security official; in a solo practice that is you, documented in a single line. Training is the same — you record that you completed it, and that anyone who works for you did too.

Where solo practices actually get this wrong

Four gaps account for most solo-practice trouble, and none of them requires money to fix. The first is a risk analysis that was never done or never dated, so there is nothing to show. The second is business associate agreements that were assumed but never signed. The third is a Notice of Privacy Practices that exists as a downloaded template but was never given to patients or posted where they can see it.

The fourth is the missing incident log — the small breach that got handled informally and left no paper behind. A single focused afternoon closes all four, and the record you create in that afternoon is the difference between a scaled, defensible practice and one that is merely undocumented. The goal is not perfection; it is being able to hand a reviewer a dated set that shows you took the obligation seriously.

Common questions

No. HIPAA scales to your size, so a one-person practice can keep short, dated policies rather than a corporate binder. What you cannot skip is having them: a risk analysis, safeguards policy, Notice of Privacy Practices, signed business associate agreements, and a breach procedure. A concise set you actually follow protects you better than a purchased manual you have never read.

Yes. The Notice of Privacy Practices requirement follows the covered entity, not the setting. A telehealth-only practice still provides the notice and makes it available electronically to patients. You also need business associate agreements with the platforms that carry the sessions, since a telehealth vendor transmitting PHI on your behalf is a business associate like any other.

The Security Rule requires documentation to be retained for six years from the date it was created or last in effect, whichever is later. That clock covers your policies, your risk analyses, and your training records. Keep superseded versions too; if a question arises about a period years ago, you want the policy that was actually in force at the time, not just the current one.

Usually not. A business associate agreement is required for vendors that create, receive, maintain, or transmit PHI on your behalf. A landlord who never accesses records and an accountant who sees only financial totals typically are not business associates. But an accountant who reviews claims data, or a cleaning service with access to charts, can cross the line, so evaluate access rather than job title.

A missing risk analysis or absent policies is itself a compliance failure, separate from any breach, and OCR has resolved cases against very small practices on exactly that basis. The practical fix is to build and date the core set now rather than during an investigation. A genuine, followed set created before any complaint reads very differently from one assembled after the fact.

Run your practice on Gale

The software is free. Gale earns one flat 3.5% all-in per paid transaction — only on transactions that actually pay. No subscription, no setup fee, no network cut.

Start or manage a practice →

References

  1. 1.Office of the Federal Register (2026). 45 CFR Part 164 — Security and Privacy. eCFR. linkSection 164.316 requires written HIPAA policies and procedures to be documented and retained for six years from creation or last effective date.
  2. 2.HHS Office for Civil Rights (2026). HIPAA for Professionals. U.S. Department of Health and Human Services. linkOCR organizes HIPAA into the Privacy, Security, Breach Notification, and Enforcement Rules; used for rule-structure orientation.
  3. 3.HHS Office for Civil Rights (2026). Summary of the HIPAA Privacy Rule. U.S. Department of Health and Human Services. linkThe Privacy Rule requires a Notice of Privacy Practices, minimum-necessary use, and processes for individual rights such as amendment and accounting.
  4. 4.HHS Office for Civil Rights (2026). Summary of the HIPAA Security Rule. U.S. Department of Health and Human Services. linkThe Security Rule requires administrative, physical, and technical safeguards for ePHI, scaled to practice size and anchored in a risk analysis.
  5. 5.Office of the National Coordinator / ASTP (2026). Security Risk Assessment Tool. HealthIT.gov. linkONC and OCR publish a free Security Risk Assessment Tool sized for small practices to perform and document the required risk analysis.
  6. 6.HHS Office for Civil Rights (2026). Business Associates. U.S. Department of Health and Human Services. linkVendors that create, receive, maintain, or transmit PHI on a practice's behalf are business associates requiring a signed BAA.
  7. 7.HHS Office for Civil Rights (2026). Breach Notification Rule. U.S. Department of Health and Human Services. linkBreaches of unsecured PHI require notice to individuals within 60 days, annual reporting to HHS under 500 affected, and media notice over 500.
  8. 8.HHS Office for Civil Rights (2026). HIPAA Compliance and Enforcement. U.S. Department of Health and Human Services. linkOCR enforces HIPAA through investigations, resolution agreements, and civil money penalties, including against very small practices lacking required documentation.

https://www.gale.care/for-providers/hip-required-policies-solo · 8 sources. Competitor details are cited to dated public sources and maintained as they change; figures are estimates, not commitments. Synthetic demonstration.

Findability, by specialty

How practices like yours get found in local search and AI answers — the honest playbook, per specialty.

SEO for private practices · SEO for AI search / answer engines (all verticals)