BH Practice HIPAA Compliance — 2026 Owner Guide
Required Documentation
- Notice of Privacy Practices
- Business Associate Agreements (BAAs) with every vendor
- Privacy + Security Policies
- Risk Assessment (annual)
- Workforce Training Log
- Access Control Log
- Audit Log Review
- Breach Response Plan
- Contingency Plan
- Sanction Policy
Required BAAs (Common Vendors)
- EHR/Practice Management (TherapyNotes, SimplePractice, etc.)
- Telehealth platform
- Email provider (Google Workspace, Microsoft 365)
- Fax service (SRFax, Doximity)
- Phone service (RingCentral)
- Billing service (Revenant Care)
- Cloud storage (Dropbox, Box)
- Payment processor (Stripe with BAA)
- Cleaning service (if they access office)
- IT support / MSP
Common HIPAA Violations
- Unencrypted laptop stolen (average fine: $250K)
- Employee snooping on records
- Improper disposal of PHI
- Missing BAA for a vendor
- Discussing patient in public
- Fax to wrong number
- Email PHI to wrong person
- Social media post about patient
- Written HIPAA training not documented
- Missing Notice of Privacy Practices signature
Breach Notification Requirements
- Under 500 patients: annual OCR report
- 500+ patients: 60-day media notification
- State-specific notification laws apply
- Patient notification within 60 days
– KD, Revenant Care