Your practice manager forwards you an email: your insurance carrier wants documentation of your latest HIPAA Security Risk Analysis. You start looking. What you find is a training certificate from a few years ago, a privacy policy saved in a shared folder, and a vendor agreement nobody is sure is current. 
What you do not find is a clear record showing how your practice identifies security risks, addresses them, and reviews its safeguards over time. 
That is where many dental, eye care, and medical practices get stuck. HIPAA compliance is not a certificate you earn once. It is an ongoing process built around documented policies, staff responsibilities, technology safeguards, vendor oversight, and incident planning. 
For day-to-day operations, three HIPAA rules matter most. The Privacy Rule governs how protected health information may be used and disclosed. The Security Rule applies to electronic protected health information, or ePHI. The Breach Notification Rule explains what regulated organizations must do after certain breaches of unsecured information. 
In a healthcare practice, ePHI may be stored or transmitted through practice management software, billing systems, email, cloud applications, workstations, mobile devices, backups, and diagnostic imaging. Panoramic dental images, X-rays, retina scans, and intraoral photos can be protected health information just like chart notes and billing records. 
A workable compliance program should include: 
  • A documented Security Risk Analysis that reflects the current environment 
  • Written privacy and security policies staff can follow 
  • Role-based training that is updated when systems or procedures change 
  • Business Associate Agreements where the vendor relationship requires one 
  • A breach response plan with clear responsibilities and escalation steps 
The goal is not paperwork for its own sake. It is to protect patient information and be able to show how the practice manages risk when an insurer, auditor, or regulator asks. 
A Security Risk Analysis, or SRA, is the foundation of the HIPAA Security Rule’s risk-management process. It identifies where the practice creates, receives, maintains, or transmits ePHI and evaluates the threats and vulnerabilities that could affect that information. 
The analysis should cover the full environment, not only a list of computers. That may include practice management and imaging systems, email, remote access, front-desk devices, connected equipment, cloud platforms, backups, third-party integrations, and staff access from mobile or personal devices. 
The current Security Rule does not set one required schedule for every organization. HHS describes risk analysis as an ongoing process. Many practices use an annual review as a practical baseline, with additional review after a security incident or a meaningful change in technology, staffing, vendors, ownership, or operations. 
A useful SRA should lead to action. Each significant finding should have a planned response, a responsible owner, a target date, and a way to confirm that the issue was addressed. 
HIPAA does not require every practice to use the same products or build the same technology environment. It does require reasonable and appropriate administrative, physical, and technical safeguards based on the risks the practice identifies. 
Common areas to review include: 
  • Individual accounts and role-based access, rather than shared logins 
  • Prompt access changes when an employee changes roles or leaves 
  • Multi-factor authentication for email, remote access, cloud services, and administrative accounts 
  • Encryption decisions that are based on risk and documented in writing 
  • Backups that are protected, tested, and recoverable 
  • System monitoring with clear ownership for reviewing and escalating alerts 
Under the current rule, encryption is an addressable implementation specification. Addressable does not mean optional. A practice must determine whether encryption is reasonable and appropriate, document that decision, and use an equivalent alternative when appropriate. The same practical review should cover both stored information and data sent through email, file transfers, portals, or system integrations. 
Backups also need more than a successful status message. Recovery testing should confirm that patient records, schedules, images, and billing data can be restored after an outage or security incident. 
A Business Associate Agreement, or BAA, is generally required when a vendor creates, receives, maintains, or transmits protected health information while performing services on behalf of a covered entity. 
Depending on the services provided, that may include a billing company, cloud hosting provider, practice management vendor, document destruction company, consultant, or IT service provider. Not every company that works with a practice is automatically a business associate; the deciding factor is what the vendor does and whether the service involves PHI. 
Review the vendor list regularly and confirm which relationships require a BAA, whether each agreement is signed and current, and whether relevant subcontractors are covered. A BAA documents responsibilities, but it does not replace basic due diligence about how the vendor protects information and reports incidents. 
HHS proposed a major update to the HIPAA Security Rule in December 2024, and the proposal was published in January 2025. As of August 2026, it has not been finalized, so the current Security Rule remains in effect. 
The proposal would remove the distinction between required and addressable implementation specifications and add more specific requirements for areas such as multi-factor authentication, encryption, asset inventories, network maps, compliance audits, vulnerability testing, incident response, and business associate verification. 
The federal Unified Agenda currently lists July 2027 as the anticipated date for final action. That is an agency planning estimate, not a guaranteed publication date or compliance deadline. The final requirements and timing could still change. 
One change is already in effect. As of February 16, 2026, covered healthcare providers and health plans are required to include applicable information about substance use disorder patient records under 42 CFR Part 2 in their Notices of Privacy Practices. Practices should confirm that their current notice contains the required language and is posted or distributed where required. 
The practical approach is to address known risks now without treating a proposal as current law. Improvements such as stronger account protection, tested recovery, current documentation, and clear vendor oversight reduce risk today and make future changes easier to manage. 
An IT provider should not replace your attorney, privacy officer, or compliance advisor. Its role is to manage and document the technology that supports the compliance program. 
A qualified provider should understand which systems contain ePHI, how access is controlled, how backups are protected, how security alerts are handled, and how the practice will recover after an incident. The provider should also be prepared to sign a BAA when its services make it a business associate. 
InfiNet’s Managed IT Services can support ongoing technology management, while Cyber Security Solutions and IT Support for Healthcare provide relevant security and healthcare-focused context. 
HIPAA compliance should be reflected in the way the practice manages information every day. When policies, technology, vendors, and staff procedures support one another, the work becomes more manageable and the practice is better prepared when questions arise. 
Need help making the technology side of HIPAA easier to manage? Let’s talk. 
An SRA documents where ePHI exists, the threats and vulnerabilities that affect it, and the level of risk. The current rule does not prescribe one fixed schedule. Review frequency should reflect the practice’s environment, with updates when significant changes or incidents affect ePHI. 
Generally, yes, when the provider creates, receives, maintains, or transmits PHI while performing services for the practice. The answer depends on the actual service relationship and access to PHI. 
Yes. Diagnostic images maintained as part of a patient’s record can be PHI. When stored or transmitted electronically, they are subject to the Security Rule’s protections for ePHI. 
Common gaps include incomplete risk analysis, outdated access lists, missing vendor documentation, weak account protection, untested recovery plans, and policies that no longer match how the practice actually works. 
The Notice of Privacy Practices change tied to 42 CFR Part 2 took effect on February 16, 2026. The proposed Security Rule overhaul remains pending as of August 2026, and July 2027 is only the current anticipated date for final action. 
Outcomes depend on the facts and may include technical assistance, corrective action, monitoring, a settlement, or a civil monetary penalty. Clear documentation and timely remediation help a practice explain what happened and how it responded. 
Yes. Monitoring can help identify failed backups, suspicious logins, disabled security tools, unauthorized changes, and other technical issues. It supports compliance when alerts are reviewed, documented, and connected to a response process. 

Talk to our Team