“HIPAA compliance” gets used as a vague catch-all in IT sales conversations. Here’s what it actually requires from a practice’s technology — and from any vendor, including an IT provider, that touches patient data.
Who actually has to comply
HIPAA applies to two categories: covered entities (healthcare providers, health plans, and healthcare clearinghouses that handle Protected Health Information, or PHI) and their business associates — any vendor that creates, receives, maintains, or transmits PHI on a covered entity’s behalf. That second category is the one people miss. If an IT provider manages servers, email, or backups for a medical or dental practice, that provider is a business associate under the law, full stop — regardless of whether security was ever part of the sales conversation.
The three safeguard categories
HIPAA’s Security Rule organizes requirements into three buckets. All three apply to any system that touches PHI:
- Administrative safeguards: a designated security officer, a documented risk assessment (required, not optional, and not a one-time exercise), workforce training, and a formal incident response plan.
- Physical safeguards: controlling physical access to workstations and servers that store or access PHI — locked server rooms, screen privacy in patient-facing areas, device disposal procedures.
- Technical safeguards: encryption of PHI at rest and in transit, unique user IDs for every person accessing a system (no shared logins), audit logging, and automatic session logoff.
Business Associate Agreements
A Business Associate Agreement (BAA) is a required contract between a covered entity and any vendor handling PHI on its behalf — it spells out how that vendor will protect the data and what happens if something goes wrong. If an IT provider won’t sign a BAA, that alone is disqualifying for a healthcare client, regardless of how good their general IT service is.
Breach notification rules
If unsecured PHI is breached, covered entities must notify affected individuals within 60 days of discovery. Breaches affecting 500 or more individuals also require immediate notification to the Department of Health and Human Services (HHS) and, in most cases, local media. Breaches under 500 can be reported to HHS annually in a batch, but individual notification still applies on the same 60-day clock either way.
What penalties actually look like
HHS’s Office for Civil Rights (OCR) enforces HIPAA through a tiered penalty structure based on the level of culpability — penalties are lowest when a covered entity didn’t know and couldn’t reasonably have known about a violation, and highest for willful neglect that goes uncorrected. Depending on the tier, per-violation penalties can range from roughly $100 up to tens of thousands of dollars, with annual caps that run into the millions for repeated violations of the same requirement. The exact figures are adjusted periodically for inflation, but the structure itself — penalties scale sharply with negligence — has stayed consistent.
What this looks like day to day
In practice, a HIPAA-compliant IT setup means: encrypted email for anything containing PHI (see our encrypted secure email service), unique logins and multi-factor authentication for every user, audit logs that can show who accessed what and when, workstations that auto-lock after inactivity, an annual documented risk assessment, and a tested incident response plan — not just a backup policy, but an actual plan for what happens in the first hour of a problem. Much of this overlaps directly with general cybersecurity best practice; see our piece on ransomware protection for how that connects to breach response specifically.
How Mii2 approaches HIPAA compliance
We work with medical, dental, and other healthcare-adjacent practices across Union County and the surrounding area — including towns like Summit, Union, and Elizabeth — where this isn’t an abstract requirement, it’s a condition of operating. That means signed BAAs, encrypted communications, documented risk assessments, and the same layered security approach covered in our managed cybersecurity services. See our full regulatory compliance page for how we structure this for regulated clients generally.
HIPAA IT Compliance — Common Questions
Does a general IT company have to be HIPAA compliant, or just healthcare providers?
Both. Any vendor that creates, receives, maintains, or transmits PHI on a covered entity’s behalf — including an IT provider managing servers, email, or backups — is a “business associate” under HIPAA and must sign a BAA and meet the same safeguard requirements.
Is a risk assessment really required every year?
HIPAA requires risk assessments to be conducted regularly and whenever there’s a significant change to systems or operations — most compliance programs treat this as an annual minimum, since gaps found during an OCR audit or breach investigation are a common source of penalties.
What’s the difference between HIPAA compliance and general cybersecurity?
They overlap heavily but aren’t identical — HIPAA specifies particular documentation (BAAs, risk assessments) and notification timelines that general cybersecurity best practice doesn’t require. A HIPAA-compliant setup is a secure setup with specific legal paperwork and process requirements layered on top.
