HIPAA for solo practitioners: the checklist that matters
A HIPAA checklist for a solo therapist: what the rules actually require, the gaps that show up in one-person practices, and a week-long plan to close them.
8 min read
Most HIPAA guidance is written for hospitals and then handed to therapists, which is why a HIPAA checklist for a solo therapist usually arrives as 140 line items about workforce training programs and facility access controls for a building you do not have. The actual obligations for a one-person practice fit on a page. They are specific and boring, and you can finish nearly all of them in a week.
Nothing here is legal advice, and a compliance attorney is worth the money if you have unusual arrangements. What follows is the shape of the thing: what the rules require, where solo practices tend to be exposed, and what to do about it in an order that makes sense.
What belongs on a HIPAA checklist for a solo therapist?
Seven items carry almost all the weight. The rest of what you read online is usually a subdivision of one of these.
A written risk analysis
The Security Rule requires every covered entity to assess risks to electronic PHI, and it does not exempt small practices. This is the document investigators ask for first, and it is the one most solo practices have never written. HHS and ONC publish a free Security Risk Assessment tool that walks through the questions and produces a report you can save. Give it an afternoon, save the PDF somewhere you will find it, and put a calendar reminder to redo it once a year or whenever you change a major vendor.
BAAs with every vendor that touches PHI
A business associate agreement is required with any company that creates, receives, maintains, or transmits PHI for you. Write out the list for your own practice and it usually runs longer than expected: the EHR, the telehealth platform, whatever sends appointment reminders, email hosting if patient email lands there, cloud storage and backups, the AI scribe if you use one, the billing service or clearinghouse, and the transcription tool you tried once and forgot about.
Two traps. Consumer versions of business tools often cannot be covered by a BAA even when the paid tier can, so check which plan you are actually on. And a vendor advertising “HIPAA compliant” without offering a signed BAA does not meet the requirement, whatever the marketing page claims, because the agreement itself is the thing the rule asks for.
Unique logins and role-based access
Unique user identification is a required specification, not a suggestion. Every person who touches the system needs their own account: you, the virtual assistant who manages your calendar, the biller, the supervisee. Shared credentials break the audit trail permanently, because once two people use one login there is no way to reconstruct who did what.
Access should also match the role. An assistant scheduling appointments needs names and times, not progress notes. Most modern systems support this; the gap is usually that nobody configured it because there was only one person at the start.
Audit logs you could actually produce
Audit controls are required, and the practical test is simple: if a patient asked who has opened their chart in the last year, could you answer? Some platforms log everything and expose none of it, or hold it behind an enterprise tier. Ask your EHR vendor how to pull a record access report before you need one, and confirm how long the logs are retained.
A breach notification plan
An impermissible disclosure of unsecured PHI is presumed to be a breach unless you document a four-factor risk assessment showing low probability of compromise. Deadlines matter here: affected individuals get notice without unreasonable delay and no later than 60 days, and incidents affecting fewer than 500 people are reported to HHS annually, within 60 days of the end of the calendar year. Larger ones go to HHS and the media within 60 days. The HHS breach notification page has the current thresholds and the submission portal.
For a solo practice, the plan can be one page: who you call (your attorney, your malpractice carrier, the affected vendor), what you document, the notice template, and the portal link. Writing it while calm takes twenty minutes. Writing it the morning your laptop goes missing means making every one of those decisions with the 60-day clock already running.
Device encryption
Encryption is an addressable specification, which means you either implement it or document a reasonable equivalent. In practice there is no reasonable equivalent for a therapist’s laptop. Turn on FileVault or BitLocker, set a passcode and auto-lock on your phone, and do the same on any tablet you use for notes.
The payoff is concrete. PHI encrypted to HHS specifications is not “unsecured,” so a stolen encrypted laptop is generally not a reportable breach. That one setting is the difference between an annoying Tuesday and a notification cycle.
Minimum necessary
Requests and disclosures should be limited to what the purpose requires. Where this bites a solo practice is in routine correspondence: sending a full record when a referring physician asked about one medication, or attaching an entire intake packet to an insurance question. HHS guidance covers the exceptions, including disclosures to the patient and treatment-related disclosures to other providers.
Where do solo practices usually fall short?
The failures cluster. Four patterns cover most of what a small practice gets wrong, and all four come from the same root: the practice grew past the tools it started with, and nobody stopped to notice.
The first is texting from a personal phone. HHS has been clear that a provider may text or email a patient who has been warned about the risks of unencrypted communication and still prefers it, and the relevant FAQ is worth reading in full. The rule is not the hard part. The device is. A personal phone with no auto-lock, cloud backups to a personal account, and two years of clinical detail in a green bubble is exposure that no consent form fixes. If patients text you, route it through a system that keeps the record in the chart and off your camera roll.
The second is consumer email. A free personal email account cannot be covered by a BAA, while business tiers of the major providers can be, and moving over is mostly a weekend of forwarding. While you are in there, check what your email client backs up and where.
Third is the video vendor with no BAA, which happens because the platform everyone already had open in another tab worked well enough for a session. Check which plan you are on and whether a BAA was actually signed rather than merely offered somewhere on the pricing page.
The fourth is a shared login with an assistant. It is convenient, and it quietly destroys the audit trail while giving a scheduler full access to clinical documentation. Give them their own account with a scheduling role instead, which most systems let you configure in a few minutes.
Does OCR actually enforce this against small practices?
Yes, and the pattern is worth understanding rather than fearing. HHS publishes its enforcement activity, including resolution agreements with practices of a handful of people. Cases involving small providers commonly begin with a patient complaint or a lost device rather than a random audit, and the investigation widens from there. A missing risk analysis is a frequent finding, because it is the first document requested and the one nobody has.
The useful conclusion is not that you are about to be investigated. It is that the cheapest insurance is documentation you can hand over on the day you are asked. A saved risk analysis, a folder of signed BAAs, and a one-page incident plan change the character of that conversation entirely.
A week that closes most of the gap
- On Monday, list every tool that touches patient information, including the ones you use twice a year, and note whether a BAA is signed for each.
- Tuesday is for requesting the missing BAAs. Most vendors have a self-serve link or a support macro for this, so it is email work rather than negotiation.
- Midweek, turn on full-disk encryption, auto-lock, and MFA on every device and account that reaches PHI, then remove logins for anyone who no longer works with you.
- Thursday, run the HHS Security Risk Assessment tool and save the output with the date in the filename.
- Finish the week by writing the one-page breach plan and fixing the texting and email path, so patient messages land somewhere that keeps a record.
Put the whole thing in one folder, add a yearly calendar reminder to refresh the risk analysis, and the recurring cost drops to about an hour a year.
What your software should be doing for you
A lot of this list is easier when the platform does not fight you. Ask whether audit logging is on by default or sold as an upgrade, whether role-based access is granular enough to give a scheduler calendar visibility without chart access, and how practices are separated in the vendor’s database. If the tool also listens to sessions, there is a second list of questions to ask an AI scribe vendor.
Valence separates each practice into its own database schema rather than filtering a shared table by a practice ID, keeps the audit log on by default, scopes providers to their own caseload and patients to their own record, and signs BAAs. Session audio from AI notes is never stored, and sessions are not recorded by default.
Whatever you end up running it on, the list does not get longer than this: risk analysis, BAAs, unique logins, audit logs, breach plan, encryption, minimum necessary. Seven items in one folder, refreshed once a year.