Guide

The four-question test that decides whether a spreadsheet is enough

Summary

No federal rule requires a solo practice to buy practice management software, so a spreadsheet can be enough. Four questions decide it: whether the sheet holds electronic protected health information, whether it can control and log who opens it, whether a third party hosts it, and whether the risk analysis and policies behind it exist in writing. Fail one and the fix is work, not necessarily a purchase.

By Gale Editorial · Updated 2026-09-02. Every figure cited to a dated source. How we write.

Does any rule require practice management software?

No. The HIPAA Security Rule names outcomes and leaves the product open: a covered entity may use any security measures that reasonably and appropriately implement its standards, weighing its own size, complexity and capabilities, its technical infrastructure, the cost of the measures it is choosing among, and how likely and how serious the risks to that information are 1. Nothing in that section names a vendor, a category of software, or a patient count.

That cuts both ways. The same general rules carry no exemption for a practice of one, and no threshold below which the standards switch off. Size changes how a solo owner complies. It does not change whether.

So a spreadsheet is permitted, and the question moves to arithmetic: what it costs in your own hours to run a sheet at the standard the rule sets, against what a system absorbs for you. Four questions settle that, and every one of them has an answer you can check this afternoon.

All of it assumes the rule reaches you in the first place, which is the covered-entity test and a separate matter from this one.

Question one: is there electronic protected health information in the sheet?

Almost certainly yes, if any row carries a name beside anything about care. A client roster with appointment times, a session log, a superbill tracker, an intake waitlist with a contact number and the reason for the call: each one is electronic protected health information the moment it exists as a file. No count starts the clock. One row is enough.

Solo owners go looking for that number anyway, and it is not there. The general rules set no patient count and no record threshold 1. What the rule flexes is which measure you pick and how you implement it, given your size, your technical capability, your budget and the risks the data faces, never whether a measure is owed at all. A sheet holding twelve clients sits inside the rule for the same reasons as a sheet holding four hundred.

The entity decision does not move it either. A sole proprietor and a professional corporation carry the identical duty here, because the duty attaches to the data and to the role. How the practice was formed does not enter it.

Question two: can the sheet control who opens it, and record who did?

This is where most sheets fail on the merits rather than on paperwork. Once electronic PHI sits on a system, the technical safeguards attach: access control that limits the file to the persons and programs granted rights to it, and audit controls that record and examine activity in the information systems holding that data 2. A file in a synced folder behind one shared login does neither of those things.

Two of the specifications in that section, automatic logoff and encryption, are labelled addressable instead of required. Addressable is not a synonym for optional. It means the practice assesses whether the measure is reasonable and appropriate in its own setting, adopts it where it is, and otherwise documents why not, along with any reasonable alternative it adopted 1.

A spreadsheet can satisfy all of this, and by default it satisfies none of it.

Closing the gap on a sheet looks like ordinary computer hygiene done deliberately: one account per person and no shared credentials, full-disk encryption switched on for every device the file touches, a screen lock that fires without being asked, and a version history or access log somebody opens on a schedule. Put the schedule in the calendar. The rule asks for records that get examined, so the review matters as much as the feature that produces the log.

Question three: who else is holding the file?

If the sheet lives in a hosted service, that service is holding protected health information on your behalf, and the rule has a name for the relationship. A business associate is a person or entity that creates, receives, maintains, or transmits protected health information for a function the rule regulates, on the covered entity's behalf 3. What the vendor does with the data is the trigger. Patient volume never enters it.

Once that is true, the arrangement needs a contract meeting one of the business associate contract specifications the rule sets out, and what triggers it is the third-party arrangement itself 4. A solo practice with one client and a cloud sheet stands in the same position as a group with fifty.

But not every vendor around a practice qualifies. ONC's 2015 guide for small practices, an explainer and not binding regulation, puts the test in plain language: the service has to actually involve access to, or the use or disclosure of, the information, and the guide works that line through examples such as a web designer who can reach the records against one who cannot 5.

So ask, in writing, before the file moves anywhere: will this vendor sign a business associate agreement for the specific plan you are on. Keep the reply. It is the one item on this list that no amount of care with the file substitutes for.

Question four: does any of this exist in writing?

Usually not, and this is the question a sheet-based practice fails most quietly. Before any safeguard gets chosen, the rule requires a risk analysis, described in its own text as an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity and availability of the electronic protected health information the practice holds 6. That specification is required outright, with no addressable substitute available for it.

The policies that come out of it have a form and a shelf life. They are kept in writing, which may be electronic, retained six years from the date of creation or the date they were last in effect, whichever is later, made available to the people who implement them, and reviewed periodically as the practice changes 7.

But the writing is the part no purchase settles. A system can carry the encryption, the per-user accounts and the log. The risk analysis is a document about your practice, and the policies describe what your practice does, so both follow you across whatever tool ends up holding the data.

Scoring the four answers

Three of the four have answers a sheet can reach with work you do once and then maintain. The third one does not behave that way: a hosted service either holds a signed business associate contract or it does not, and no version of careful spreadsheet habits produces one. Score that question first.

QuestionWhat the sheet has to showWhere the rule sets it
Is there electronic PHI in it?any name attached to care, at any volume45 CFR 164.306
Who can open it, and who did?per-person access plus an activity log that gets reviewed45 CFR 164.312
Who else holds the file?a signed business associate contract45 CFR 160.103 and 164.314
Does it exist in writing?a risk analysis, and policies retained six years45 CFR 164.308 and 164.316

A practice that can answer all four keeps the sheet without arguing about it. A practice that cannot has a list of specific gaps, and most of them cost hours instead of money. Owners who bill payers commonly hit the ceiling before the others do, and that belongs to the insurance question.

When the sheet stops being the cheap option

Buy when a failure has a name. A second person who needs their own login is one, because per-person access stops being a setting and becomes a subscription. A hosted service that will not sign the contract is another. Buying because the sheet feels unprofessional is not a name, and a contract signed on that basis still runs its full term.

A second trigger is worth watching, and it is time. The week you spend an hour reconstructing something a system would have logged, the sheet has stopped being free.

When you do buy, read the exit before the demo. What format the data leaves in, on whose timeline, and at what price. Then work the stack in order instead of starting with whichever vendor got a meeting first, and keep the risk analysis and the written policies in your own hands, because they describe the practice and outlive any tool that holds the data.

Common questions

There is no such number. The Security Rule's general rules set no patient count and no record threshold, and the flexibility they grant runs to which measures a practice picks and how it implements them, weighed against size, technical capability, cost and the risks involved. One row with a name attached to care puts the file inside the rule, on the same terms as four hundred rows.

Yes, once the hosting vendor is under a business associate contract meeting the rule's specifications and the file itself meets the same safeguards as any other. The vendor qualifies as a business associate because it maintains protected health information on the practice's behalf, and the trigger is that arrangement, whatever the patient volume happens to be. Ask in writing whether the vendor signs one for the specific plan in use, and keep the reply.

No. Encryption is one implementation specification, and an addressable one, which means it gets assessed, adopted where reasonable, and otherwise documented, along with any reasonable alternative adopted. Access control and audit controls sit alongside it, and the required risk analysis comes before all of them. An encrypted sheet with no written analysis behind it still carries a gap.

A risk analysis covering the risks and vulnerabilities to the electronic protected health information held, and the policies and procedures adopted in response. Both are kept in written form, which may be electronic, retained six years from creation or from the date they were last in effect, whichever is later, made available to whoever implements them, and reviewed as the practice changes.

When a named failure appears: a second person needing separate access, a hosted service that will not sign a business associate contract, or a recurring hour each week spent reconstructing what a system would have logged. Payer billing usually reaches that point before patient count does. A vague sense that the sheet looks unprofessional is not a trigger, and the contract still runs its term.

Run your practice on Gale

The software is free. Gale earns one flat 3.5% all-in per paid transaction — only on transactions that actually pay. No subscription, no setup fee, no network cut.

Start or manage a practice →

References

  1. 1.U.S. Department of Health and Human Services (Office for Civil Rights) (2024). Security standards: General rules. Code of Federal Regulations, Title 45, Part 164, Subpart C (govinfo.gov, U.S. Government Publishing Office). linkthe absence of any patient-count or practice-size exemption in the Security Rule's general rules, the latitude to use any security measures that reasonably implement the standards and the factors (size, complexity and capabilities, technical infrastructure, cost) that shape that choice, and what an Addressable implementation specification obliges a practice to do.
  2. 2.U.S. Department of Health and Human Services (2024). 164.312 Technical safeguards.. Code of Federal Regulations, Title 45, Part 164, Subpart C (GovInfo, U.S. Government Publishing Office). linkthe technical safeguards that attach once electronic PHI exists on any system, a spreadsheet included: access control limited to the persons and programs granted rights, audit controls that record and examine system activity, and automatic logoff and encryption as addressable specifications.
  3. 3.U.S. Department of Health and Human Services (2024). 160.103 Definitions.. Code of Federal Regulations, Title 45, Part 160, Subpart A (GovInfo, U.S. Government Publishing Office). linkthe definition of a business associate as an entity that creates, receives, maintains, or transmits PHI for a regulated function on a covered entity's behalf, which is what a vendor hosting the practice's spreadsheet becomes.
  4. 4.U.S. Department of Health and Human Services (2024). 164.314 Organizational requirements.. Code of Federal Regulations, Title 45, Part 164, Subpart C (GovInfo, U.S. Government Publishing Office). linkthe requirement that a third-party arrangement holding PHI be covered by a contract meeting one of the rule's business-associate-contract implementation specifications, triggered by the arrangement itself and not by patient volume.
  5. 5.Office of the National Coordinator for Health Information Technology (ONC), U.S. Department of Health and Human Services (2015). Guide to Privacy and Security of Electronic Health Information. HealthIT.gov (Version 2.0, April 2015). linkthe plain-language business associate test used here, that a vendor qualifies only where the service involves access to, or the use or disclosure of, PHI, and its worked small-practice examples; identified in the text as a 2015 ONC explainer rather than binding regulation.
  6. 6.U.S. Department of Health and Human Services (Office for Civil Rights) (2024). Administrative safeguards. Code of Federal Regulations, Title 45, Part 164, Subpart C (govinfo.gov, U.S. Government Publishing Office). linkthe Required (not Addressable) status of the risk analysis implementation specification, and its description as an accurate and thorough assessment of the potential risks and vulnerabilities to ePHI.
  7. 7.U.S. Department of Health and Human Services (Office for Civil Rights) (2024). Policies and procedures and documentation requirements. Code of Federal Regulations, Title 45, Part 164, Subpart C (govinfo.gov, U.S. Government Publishing Office). linkthe documentation duty relied on here: policies and procedures kept in written (possibly electronic) form, retained six years from creation or last-effective date whichever is later, made available to those who implement them, and periodically reviewed.

https://www.gale.care/for-providers/se-spreadsheet-vs-software-test · 7 sources. Competitor details are cited to dated public sources and maintained as they change; figures are estimates, not commitments. Synthetic demonstration.

Findability, by specialty

How practices like yours get found in local search and AI answers — the honest playbook, per specialty.

SEO for private practices · SEO for AI search / answer engines (all verticals)