Skip to main content
CY6Check Your Six

The HIPAA document your practice is most likely missing

It is not a policy binder and it is not a staff training certificate. It is the security risk analysis, and it is the thing that gets asked for first.

5 min readMedical and dental practices of any size

Small practices are rarely careless about patient data. They are usually in reasonable technical shape, with a locked front desk, a supported practice-management system and staff who know not to discuss patients in the lift. What they very often do not have is a current security risk analysis.

That matters more than the gap sounds, because the risk analysis is not one requirement among many. It is the requirement the others are built on: it is how you decide which safeguards are reasonable and appropriate for a practice of your size, which is the standard the Security Rule actually sets.

What it is not

  • It is not a vendor's security certification. Your practice-management vendor being compliant says nothing about your network, your workstations or your staff accounts.
  • It is not a policy binder. Policies describe what you intend. The analysis establishes what you are actually exposed to.
  • It is not annual training records. Useful, and a different control entirely.
  • It is not a penetration test. A test finds technical weaknesses; the analysis weighs them against what they would cost you.

What it has to do

Identify where protected health information lives — including the places nobody lists, like the scanner's hard drive, the old server in the cupboard, and the front-desk machine with the shared login. Then, for each, work out what could realistically go wrong, how likely it is, what it would cost, and what you are going to do about it.

The output is a document with findings, a risk rating for each, and a remediation plan with owners and dates. The following year's version should show what moved. That trail is the thing that demonstrates a functioning program, and it is what separates a practice that took this seriously from one that bought a document.

The three places PHI usually hides

  • Imaging and diagnostic equipment, which frequently runs an operating system the manufacturer stopped supporting years ago and which the vendor will not let you patch.
  • Email. Referral letters, insurer correspondence and appointment queries accumulate in mailboxes nobody has reviewed since the account was created.
  • Staff phones. Not the ones you issued — the personal ones that were added to the practice mailbox one afternoon so somebody could check messages from home.

Federal regulators run a dedicated Risk Analysis Initiative, and by June 2026 it had reached its fourteenth completed enforcement action. If your practice cannot produce a dated risk analysis on request, fix that before buying any new tooling. It is also the cheapest thing on the list, because most of the work is writing down what you already have.

More field notes

All field notes
  • 6 min

    The client security questionnaire nobody warned you about

    A corporate client sends forty questions about your technology, due in a fortnight, written for a company a hundred times your size. Here is how to answer it without either lying or losing the work.

  • 5 min

    Nothing broke. You just hired four people.

    Small professional firms rarely outgrow their technology in a way anyone notices. It degrades one hire at a time, and the symptoms look like unrelated annoyances.

Not sure where you stand?

Start with the six-point check, or book twenty minutes and talk it through with someone who will tell you plainly what needs doing and what does not.

Or call 1-855-966-2967