// Case File · IT Support

The HIPAA Security Risk Assessment Most Small Practices Have Never Done

Ask a small practice for its HIPAA security risk assessment and the usual answer is a pause, then some version of: “Our EHR is HIPAA-compliant, so we’re covered.”

It isn’t, and you aren’t. No product makes a practice compliant. The Security Rule requires the practice to conduct and document a risk analysis of how it creates, stores and transmits electronic patient information — the EHR is one line item in that analysis, not a substitute for it.

This matters for a blunt reason: when a breach happens and the Office for Civil Rights comes asking, the risk assessment is the first document they request. Not having one is itself a finding — and it turns an unlucky incident into a negligent one.

What a risk assessment actually is

Strip away the audit-speak and it’s four questions, answered honestly and written down:

  1. Where is patient data, exactly? The EHR, yes — but also the billing system, email inboxes, scanned documents on the front-desk PC, the shared drive, text messages with patients, and the laptop the biller takes home.
  2. What could realistically go wrong at each spot? Stolen laptop, phished email account, ransomware, a departed employee whose login still works, a lost phone with the patient portal open.
  3. What’s currently protecting each one? Encryption, MFA, access controls, backups, audit logs — or, frequently, nothing but habit.
  4. What’s the plan to close the gaps, and by when? Documented, dated, and actually executed. Regulators distinguish sharply between “found the gap and was fixing it” and “never looked.”

The gaps we find in almost every small practice

What it costs to skip

OCR settlements with small practices regularly cite the missing risk analysis as the core violation — the incident is what got attention, the missing paperwork is what got fined. Add breach-notification costs, patient attrition, and cyber-insurance claims denied because the application said controls existed that didn’t.

Against that, the assessment itself is days of work, most of it once.

Getting it done without it eating your month

A practical sequence for a small practice:

  1. Inventory every place PHI lives — the honest list, including the embarrassing spots.
  2. Assess threats and current safeguards against each item.
  3. Fix the cheap, high-impact gaps first: MFA everywhere, disk encryption, individual logins, tested backups.
  4. Document all of it — the analysis, the decisions, the dates.
  5. Repeat annually, and whenever the environment changes.

This is exactly what our healthcare IT support includes for practices across Los Angeles: we run the risk assessment, document it, remediate what it finds, and sign a BAA — because we’re inside your compliance scope too.

Get a free practice IT assessment → We’ll tell you in plain English where your PHI actually lives, what’s protecting it, and what an auditor would flag — before an auditor does.

Want a straight answer about your own setup? Atomcase offers a free IT assessment — no obligation.

Get a Free IT Assessment → or call us: (321) 844-7711