HIPAA for Small Arizona Practices: The Nine Things OCR Actually Looks For
A working HIPAA Security Rule gap assessment for practices under 50 people, built around the failures that show up repeatedly in enforcement actions.
The short answer
When an OCR investigation opens, the requests are documentary and specific. The failures that recur in enforcement actions are a missing or stale risk analysis, no risk management plan, unencrypted devices, incomplete business associate agreements, shared logins, and audit logs nobody reviews.
Small practices tend to approach HIPAA as a binder. Somebody bought a policy template years ago, it sits on a shelf, and the assumption is that the binder is the compliance.
The Office for Civil Rights does not read binders. When an investigation opens, usually because of a breach report or a patient complaint, the requests are specific and documentary. Here is what gets asked for, based on the pattern in published enforcement actions, and the gaps that recur in practices of ten to fifty people.
This is operational guidance, not legal advice. Your compliance counsel should review anything you implement.
One: an actual risk analysis
This is the most cited failure in HIPAA enforcement, by a wide margin. The Security Rule requires an accurate and thorough assessment of risks and vulnerabilities to electronic protected health information across the whole organization.
A vendor's security scan is not a risk analysis. Neither is a checklist your IT provider filled out. A risk analysis inventories every place ePHI lives, including the ones you forget: the imaging system, the billing clearinghouse, the fax server, the laptop the practice manager takes home, the phone with the patient photos on it. Then it identifies threats to each, assesses likelihood and impact, and documents what you decided to do.
It has to be written, dated, and updated. An analysis from 2019 does not describe a practice that added telehealth and three cloud systems since.
Two: a risk management plan that follows from it
The analysis identifies risks. The management plan says what you are doing about each one, who owns it, and by when. Findings with no remediation record is a documented admission that you knew and did nothing, which is worse than not having looked.
Three: encryption, or a written reason why not
The Security Rule describes encryption as addressable, a term many practices misread as optional. Addressable means you implement it or document why it is unreasonable or inappropriate and record the alternative safeguard.
In practice, for a small practice in 2026, there is no defensible reason not to encrypt laptops and portable media. Full disk encryption is built into the operating system you already own. Lost unencrypted laptops have generated a long line of settlements.
Four: business associate agreements, all of them
Every vendor that creates, receives, maintains, or transmits ePHI on your behalf needs an agreement. The list is longer than most practices think: your practice management vendor, your billing company, your IT provider, your cloud backup, your document shredding service, your answering service, your transcription vendor, and increasingly, any AI tool that touches patient information.
Keep them in one place with expiration dates. Not having the agreement when asked is a finding regardless of how secure the vendor actually is.
Five: access controls with unique identifiers
Every user gets their own login. The shared front desk account is a Security Rule violation and it also destroys your ability to investigate anything, because the audit log says the front desk did it.
Access is role-based and minimum necessary. The billing coordinator does not need clinical notes. Reviewed when roles change and terminated when people leave, with documentation of the termination.
Six: audit controls and log review
The rule requires mechanisms that record and examine activity in systems containing ePHI. Most practice management systems have this capability and most practices have never enabled the review side.
Somebody needs to look, periodically, and document that they looked. The classic case is an employee accessing a family member's or a local celebrity's record. Your logs would show it. Nobody reads the logs.
Seven: workforce training with records
Training at hire and periodically after, on your actual policies, with a signed record of who attended and when. The training does not need to be elaborate. The record needs to exist.
Eight: contingency planning
Data backup, disaster recovery, and an emergency mode operation plan. That last one asks how you continue treating patients when the systems are down, which is a clinical question as much as a technical one. Test the restore and write down the date.
Nine: an incident response process someone has read
Including who determines whether an incident is a reportable breach, the risk assessment you perform to make that call, and the notification timelines. Arizona's own breach notification statute may apply alongside HIPAA depending on the data involved, and the timelines are not identical.
What is coming
The proposed update to the Security Rule published in early 2025 would remove much of the addressable and required distinction and make specific controls mandatory, including multi-factor authentication, encryption, asset inventory, and regular vulnerability scanning and penetration testing. It has not been finalized as of this writing, and the final version may differ.
The practical advice is unchanged either way. Every control in that proposal is something a well-run practice should already have. Building toward them now means the final rule is a paperwork exercise rather than a project.
Get the gap assessment
The HIPAA Security Rule Gap Assessment workbook covers all administrative, physical, and technical safeguards with a plain-language question for each, a current-state column, a gap severity rating, and a remediation tracker. It includes the ePHI location inventory sheet and a business associate agreement register.
Complete it, and you have the beginning of the documentation OCR would ask for, along with an honest picture of where you stand.
Frequently asked questions
What does OCR ask for in a HIPAA investigation?
Documentary evidence: your written risk analysis, your risk management plan, business associate agreements, access control and termination records, audit log review records, training attendance records, and your contingency and incident response plans. A binder of purchased policy templates is not what gets requested.
Is a security scan the same as a HIPAA risk analysis?
No, and this is the most cited failure in HIPAA enforcement. A risk analysis inventories every place electronic protected health information lives, identifies threats to each, assesses likelihood and impact, and documents decisions. A vendor scan or an IT checklist does not satisfy the requirement.
Is encryption required under HIPAA?
Encryption is addressable under the Security Rule, a term many practices misread as optional. Addressable means you implement it or document why it is unreasonable or inappropriate and record the alternative safeguard. A small practice today has no defensible reason to leave laptops and portable media unencrypted.
Which vendors need a business associate agreement?
Every vendor that creates, receives, maintains, or transmits electronic protected health information on your behalf. The list is longer than most practices think: practice management, billing, IT provider, cloud backup, shredding, answering service, transcription, and increasingly any AI tool touching patient information.
