The HIPAA document your practice is most likely missing
It is not a policy binder and it is not a staff training certificate. It is the security risk analysis, and it is the thing that gets asked for first.
Small practices are rarely careless about patient data. They are usually in reasonable technical shape, with a locked front desk, a supported practice-management system and staff who know not to discuss patients in the lift. What they very often do not have is a current security risk analysis.
That matters more than the gap sounds, because the risk analysis is not one requirement among many. It is the requirement the others are built on: it is how you decide which safeguards are reasonable and appropriate for a practice of your size, which is the standard the Security Rule actually sets.
What it is not
- It is not a vendor's security certification. Your practice-management vendor being compliant says nothing about your network, your workstations or your staff accounts.
- It is not a policy binder. Policies describe what you intend. The analysis establishes what you are actually exposed to.
- It is not annual training records. Useful, and a different control entirely.
- It is not a penetration test. A test finds technical weaknesses; the analysis weighs them against what they would cost you.
What it has to do
Identify where protected health information lives — including the places nobody lists, like the scanner's hard drive, the old server in the cupboard, and the front-desk machine with the shared login. Then, for each, work out what could realistically go wrong, how likely it is, what it would cost, and what you are going to do about it.
The output is a document with findings, a risk rating for each, and a remediation plan with owners and dates. The following year's version should show what moved. That trail is the thing that demonstrates a functioning program, and it is what separates a practice that took this seriously from one that bought a document.
The three places PHI usually hides
- Imaging and diagnostic equipment, which frequently runs an operating system the manufacturer stopped supporting years ago and which the vendor will not let you patch.
- Email. Referral letters, insurer correspondence and appointment queries accumulate in mailboxes nobody has reviewed since the account was created.
- Staff phones. Not the ones you issued — the personal ones that were added to the practice mailbox one afternoon so somebody could check messages from home.
Federal regulators run a dedicated Risk Analysis Initiative, and by June 2026 it had reached its fourteenth completed enforcement action. If your practice cannot produce a dated risk analysis on request, fix that before buying any new tooling. It is also the cheapest thing on the list, because most of the work is writing down what you already have.