The HIPAA Security Rule is written to survive changes in technology, which is why it reads as vague. In practice, for a practice under fifty people, it comes down to a manageable set of controls plus the documentation proving they exist.
The controls
- Access control: unique logins, role-based permissions, automatic screen lock, and access reviews you can show.
- Encryption: full-disk on every device that touches PHI, and encryption in transit for email and file transfer.
- Audit controls: logging that records who accessed what, retained long enough to investigate.
- Contingency plan: backup, disaster recovery and an emergency mode operation plan — tested, not just written.
- Business associate agreements with every vendor that can reach PHI, including your IT provider.
The documents
A risk analysis is the document auditors ask for first and the one most small practices don't have. It has to be written, dated, specific to your environment and updated when things change — not a template with your name pasted on top.
In an audit, an undocumented control and a missing control look identical.
This is why we document continuously rather than annually, and why a technician attends the IT portion of the audit with you. The evidence should already exist before anybody asks for it.