BH Practice HIPAA Compliance 2026 — What Owners Must Do

BH Practice HIPAA Compliance — 2026 Owner Guide

Required Documentation

  1. Notice of Privacy Practices
  2. Business Associate Agreements (BAAs) with every vendor
  3. Privacy + Security Policies
  4. Risk Assessment (annual)
  5. Workforce Training Log
  6. Access Control Log
  7. Audit Log Review
  8. Breach Response Plan
  9. Contingency Plan
  10. Sanction Policy

Required BAAs (Common Vendors)

  • EHR/Practice Management (TherapyNotes, SimplePractice, etc.)
  • Telehealth platform
  • Email provider (Google Workspace, Microsoft 365)
  • Fax service (SRFax, Doximity)
  • Phone service (RingCentral)
  • Billing service (Revenant Care)
  • Cloud storage (Dropbox, Box)
  • Payment processor (Stripe with BAA)
  • Cleaning service (if they access office)
  • IT support / MSP

Common HIPAA Violations

  1. Unencrypted laptop stolen (average fine: $250K)
  2. Employee snooping on records
  3. Improper disposal of PHI
  4. Missing BAA for a vendor
  5. Discussing patient in public
  6. Fax to wrong number
  7. Email PHI to wrong person
  8. Social media post about patient
  9. Written HIPAA training not documented
  10. Missing Notice of Privacy Practices signature

Breach Notification Requirements

  • Under 500 patients: annual OCR report
  • 500+ patients: 60-day media notification
  • State-specific notification laws apply
  • Patient notification within 60 days

Revenant Care HIPAA Compliant

– KD, Revenant Care