Notes from Valence

HIPAA for solo practitioners: the checklist that matters

A HIPAA checklist for a solo therapist: what the rules actually require, the gaps that show up in one-person practices, and a week-long plan to close them.

8 min read

Most HIPAA guidance is written for hospitals and then handed to therapists, which is why a HIPAA checklist for a solo therapist usually arrives as 140 line items about workforce training programs and facility access controls for a building you do not have. The actual obligations for a one-person practice fit on a page. They are specific and boring, and you can finish nearly all of them in a week.

Nothing here is legal advice, and a compliance attorney is worth the money if you have unusual arrangements. What follows is the shape of the thing: what the rules require, where solo practices tend to be exposed, and what to do about it in an order that makes sense.

What belongs on a HIPAA checklist for a solo therapist?

Seven items carry almost all the weight. The rest of what you read online is usually a subdivision of one of these.

A written risk analysis

The Security Rule requires every covered entity to assess risks to electronic PHI, and it does not exempt small practices. This is the document investigators ask for first, and it is the one most solo practices have never written. HHS and ONC publish a free Security Risk Assessment tool that walks through the questions and produces a report you can save. Give it an afternoon, save the PDF somewhere you will find it, and put a calendar reminder to redo it once a year or whenever you change a major vendor.

BAAs with every vendor that touches PHI

A business associate agreement is required with any company that creates, receives, maintains, or transmits PHI for you. Write out the list for your own practice and it usually runs longer than expected: the EHR, the telehealth platform, whatever sends appointment reminders, email hosting if patient email lands there, cloud storage and backups, the AI scribe if you use one, the billing service or clearinghouse, and the transcription tool you tried once and forgot about.

Two traps. Consumer versions of business tools often cannot be covered by a BAA even when the paid tier can, so check which plan you are actually on. And a vendor advertising “HIPAA compliant” without offering a signed BAA does not meet the requirement, whatever the marketing page claims, because the agreement itself is the thing the rule asks for.

Unique logins and role-based access

Unique user identification is a required specification, not a suggestion. Every person who touches the system needs their own account: you, the virtual assistant who manages your calendar, the biller, the supervisee. Shared credentials break the audit trail permanently, because once two people use one login there is no way to reconstruct who did what.

Access should also match the role. An assistant scheduling appointments needs names and times, not progress notes. Most modern systems support this; the gap is usually that nobody configured it because there was only one person at the start.

Audit logs you could actually produce

Audit controls are required, and the practical test is simple: if a patient asked who has opened their chart in the last year, could you answer? Some platforms log everything and expose none of it, or hold it behind an enterprise tier. Ask your EHR vendor how to pull a record access report before you need one, and confirm how long the logs are retained.

A breach notification plan

An impermissible disclosure of unsecured PHI is presumed to be a breach unless you document a four-factor risk assessment showing low probability of compromise. Deadlines matter here: affected individuals get notice without unreasonable delay and no later than 60 days, and incidents affecting fewer than 500 people are reported to HHS annually, within 60 days of the end of the calendar year. Larger ones go to HHS and the media within 60 days. The HHS breach notification page has the current thresholds and the submission portal.

For a solo practice, the plan can be one page: who you call (your attorney, your malpractice carrier, the affected vendor), what you document, the notice template, and the portal link. Writing it while calm takes twenty minutes. Writing it the morning your laptop goes missing means making every one of those decisions with the 60-day clock already running.

Device encryption

Encryption is an addressable specification, which means you either implement it or document a reasonable equivalent. In practice there is no reasonable equivalent for a therapist’s laptop. Turn on FileVault or BitLocker, set a passcode and auto-lock on your phone, and do the same on any tablet you use for notes.

The payoff is concrete. PHI encrypted to HHS specifications is not “unsecured,” so a stolen encrypted laptop is generally not a reportable breach. That one setting is the difference between an annoying Tuesday and a notification cycle.

Minimum necessary

Requests and disclosures should be limited to what the purpose requires. Where this bites a solo practice is in routine correspondence: sending a full record when a referring physician asked about one medication, or attaching an entire intake packet to an insurance question. HHS guidance covers the exceptions, including disclosures to the patient and treatment-related disclosures to other providers.

Where do solo practices usually fall short?

The failures cluster. Four patterns cover most of what a small practice gets wrong, and all four come from the same root: the practice grew past the tools it started with, and nobody stopped to notice.

The first is texting from a personal phone. HHS has been clear that a provider may text or email a patient who has been warned about the risks of unencrypted communication and still prefers it, and the relevant FAQ is worth reading in full. The rule is not the hard part. The device is. A personal phone with no auto-lock, cloud backups to a personal account, and two years of clinical detail in a green bubble is exposure that no consent form fixes. If patients text you, route it through a system that keeps the record in the chart and off your camera roll.

The second is consumer email. A free personal email account cannot be covered by a BAA, while business tiers of the major providers can be, and moving over is mostly a weekend of forwarding. While you are in there, check what your email client backs up and where.

Third is the video vendor with no BAA, which happens because the platform everyone already had open in another tab worked well enough for a session. Check which plan you are on and whether a BAA was actually signed rather than merely offered somewhere on the pricing page.

The fourth is a shared login with an assistant. It is convenient, and it quietly destroys the audit trail while giving a scheduler full access to clinical documentation. Give them their own account with a scheduling role instead, which most systems let you configure in a few minutes.

Does OCR actually enforce this against small practices?

Yes, and the pattern is worth understanding rather than fearing. HHS publishes its enforcement activity, including resolution agreements with practices of a handful of people. Cases involving small providers commonly begin with a patient complaint or a lost device rather than a random audit, and the investigation widens from there. A missing risk analysis is a frequent finding, because it is the first document requested and the one nobody has.

The useful conclusion is not that you are about to be investigated. It is that the cheapest insurance is documentation you can hand over on the day you are asked. A saved risk analysis, a folder of signed BAAs, and a one-page incident plan change the character of that conversation entirely.

A week that closes most of the gap

  1. On Monday, list every tool that touches patient information, including the ones you use twice a year, and note whether a BAA is signed for each.
  2. Tuesday is for requesting the missing BAAs. Most vendors have a self-serve link or a support macro for this, so it is email work rather than negotiation.
  3. Midweek, turn on full-disk encryption, auto-lock, and MFA on every device and account that reaches PHI, then remove logins for anyone who no longer works with you.
  4. Thursday, run the HHS Security Risk Assessment tool and save the output with the date in the filename.
  5. Finish the week by writing the one-page breach plan and fixing the texting and email path, so patient messages land somewhere that keeps a record.

Put the whole thing in one folder, add a yearly calendar reminder to refresh the risk analysis, and the recurring cost drops to about an hour a year.

What your software should be doing for you

A lot of this list is easier when the platform does not fight you. Ask whether audit logging is on by default or sold as an upgrade, whether role-based access is granular enough to give a scheduler calendar visibility without chart access, and how practices are separated in the vendor’s database. If the tool also listens to sessions, there is a second list of questions to ask an AI scribe vendor.

Valence separates each practice into its own database schema rather than filtering a shared table by a practice ID, keeps the audit log on by default, scopes providers to their own caseload and patients to their own record, and signs BAAs. Session audio from AI notes is never stored, and sessions are not recorded by default.

Whatever you end up running it on, the list does not get longer than this: risk analysis, BAAs, unique logins, audit logs, breach plan, encryption, minimum necessary. Seven items in one folder, refreshed once a year.

Common questions

Does a solo therapist really need a written risk analysis?
Yes. The Security Rule requires a risk analysis from every covered entity regardless of size, and it is the item OCR asks for first. For a one-person practice it is a short document, not a project. The free HHS Security Risk Assessment tool walks through it in an afternoon.
Can I text or email my patients?
Yes, with conditions. HHS has said a provider may email or text a patient who has been warned of the risk of unencrypted communication and still prefers it, and the exchange should be documented. The bigger problem is usually the device: a personal phone with no lock screen and a chat history full of PHI is the actual exposure.
Which vendors need a BAA?
Any vendor that creates, receives, maintains, or transmits PHI on your behalf. In a typical solo practice that means the EHR, the telehealth platform, the texting and email provider, the AI scribe, cloud storage or backups, and often the billing service. Consumer tools without a signed BAA do not qualify, even when they advertise encryption.
What counts as a breach I have to report?
An impermissible use or disclosure of unsecured PHI is presumed to be a breach unless a documented four-factor risk assessment shows a low probability of compromise. Encrypted data that meets HHS specifications is not unsecured, which is why full-disk encryption on your laptop does real work.

One system for the whole practice

Scheduling, reminders, care pathways, group telehealth, intake, and AI notes on the same chart. There's no monthly fee: you pay for the time you spend with patients, capped at $69 per clinician.