HIPAA Compliance: What Small Businesses Actually Need to Know
HIPAA isn't just for hospitals. If your business handles any protected health information — even indirectly — you may have compliance obligations you don't know about.
HIPAA Compliance: What Small Businesses Actually Need to Know
When most people hear "HIPAA," they think of hospitals and doctors' offices. And while healthcare providers are certainly covered, HIPAA's reach extends much further than most small business owners realize.
If your business handles, processes, or has access to protected health information (PHI) — even as a vendor or service provider to a healthcare organization — you may have HIPAA obligations. And the penalties for non-compliance can be severe: fines ranging from $100 to $50,000 per violation, with annual caps up to $1.9 million per violation category.
Here's what you actually need to know.
Who Does HIPAA Apply To?
HIPAA applies to two categories of organizations: covered entities and business associates.
Covered entities are the obvious ones: healthcare providers (doctors, dentists, therapists, pharmacies), health plans (insurance companies, HMOs), and healthcare clearinghouses.
Business associates are where many small businesses get caught off guard. A business associate is any organization that creates, receives, maintains, or transmits PHI on behalf of a covered entity. That includes:
- IT companies that manage systems containing patient data
- Billing and coding services
- Accountants and attorneys who access PHI in the course of their work
- Cloud storage providers used by healthcare organizations
- Shredding companies that handle paper records
- Marketing firms that work with patient data
If you provide services to a healthcare organization and your work involves any access to patient information — even incidentally — you're likely a business associate and HIPAA applies to you.
What Does HIPAA Actually Require?
HIPAA has three main rules that covered entities and business associates must follow:
The Privacy Rule
The Privacy Rule establishes standards for how PHI can be used and disclosed. It gives patients rights over their health information — including the right to access their records and request corrections. For businesses, it means you can only use or share PHI in ways that are explicitly permitted by the rule.
The Security Rule
The Security Rule applies specifically to electronic PHI (ePHI) and requires covered entities and business associates to implement administrative, physical, and technical safeguards to protect it. This includes things like:
- Access controls (who can access what data)
- Audit controls (tracking who accessed what and when)
- Encryption of data in transit and at rest
- Workforce training on security policies
- Risk analysis and risk management processes
The Security Rule is notably flexible — it doesn't mandate specific technologies, but it does require you to implement "reasonable and appropriate" safeguards based on your size, complexity, and the sensitivity of the data you handle.
The Breach Notification Rule
If a breach of unsecured PHI occurs, you're required to notify affected individuals, the Department of Health and Human Services (HHS), and in some cases, the media. The timeline is strict: individual notifications must go out within 60 days of discovering the breach.
The Business Associate Agreement (BAA)
If you're a business associate, one of the most important compliance requirements is the Business Associate Agreement (BAA). This is a contract between you and the covered entity you work with that outlines how you'll protect PHI and what happens in the event of a breach.
Covered entities are required to have BAAs in place with all their business associates. If you're providing services to a healthcare organization and haven't signed a BAA, that's a compliance gap — for both of you.
Common Compliance Mistakes Small Businesses Make
1. Assuming HIPAA doesn't apply to them. As we've covered, HIPAA's reach is broader than most people assume. If there's any possibility your business touches PHI, it's worth getting clarity.
2. Treating HIPAA as a one-time project. Compliance isn't a checkbox you check once. It requires ongoing risk assessments, policy updates, workforce training, and documentation. The regulations also evolve over time.
3. Skipping the risk analysis. The Security Rule requires a formal risk analysis — an assessment of the potential risks and vulnerabilities to ePHI in your environment. This is one of the most commonly cited deficiencies in HIPAA audits, and it's foundational to everything else.
4. Inadequate workforce training. Most HIPAA breaches involve human error — an employee who clicks a phishing link, sends an email to the wrong address, or leaves a laptop unattended. Regular, practical training is a compliance requirement and a practical necessity.
5. No incident response plan. When a breach happens, you need to know exactly what to do and how fast. Organizations without a documented incident response plan consistently handle breaches worse and face higher penalties.
Getting Started Without the Overwhelm
HIPAA compliance can feel overwhelming, especially for a small business without a dedicated compliance team. But it doesn't have to be.
The most important first step is understanding your actual obligations. That means:
- Determine if HIPAA applies to you — and in what capacity (covered entity vs. business associate)
- Conduct a risk analysis to identify where PHI exists in your environment and what the risks are
- Document your policies and procedures for how you handle PHI
- Train your workforce on those policies
- Review your vendor relationships and ensure BAAs are in place where required
You don't need to do all of this at once. A phased approach — starting with the risk analysis and working from there — is both practical and defensible.
The Bottom Line
HIPAA compliance isn't just a legal obligation — it's a signal to your clients and partners that you take data privacy seriously. For small businesses that work in or adjacent to healthcare, it's increasingly a competitive requirement as well.
The businesses that handle this well aren't necessarily the largest or best-resourced. They're the ones that understand their obligations, take a systematic approach, and build compliance into how they operate — rather than treating it as an afterthought.
AB Solutions Group helps small businesses navigate HIPAA and other compliance frameworks with practical, right-sized guidance. Schedule a free consultation to talk through your situation.
Explore Topics
Written by
AB Solutions Group
Content creator and writer sharing insights and stories.