August 13, 2026

Podcasts

HIPAA Compliance Is a Culture Problem, Not a Checklist Problem

HIPAA breaches rarely happen from ignorance of the law. They happen from culture. Here's what private practice owners need to know and do right now.

Most private practice owners think about HIPAA the same way they think about a fire extinguisher: mount it on the wall, check the expiration date once a year, hope you never need it.

That mindset is exactly what creates exposure.

I had a long conversation with Yves Martin, bestselling author and founder of Mquall, on the Private Practice Survival Guide podcast, and his framing stopped me cold. HIPAA compliance is not primarily a technology problem. It is not even primarily a documentation problem. It is a culture problem. And culture is something every practice owner controls, starting today.

What's Actually Changing in 2026

Before we get into the culture argument, let's get current on what's shifting legislatively, because some of this is already in effect and some of it is close enough that you should be moving now.

Multifactor authentication was previously framed as a best practice, something you should do if you can. That language is shifting toward mandatory. If your staff accesses any patient data through a portal, EMR, or shared cloud system without MFA enabled, you are sitting on a compliance gap that regulators are actively closing.

Encryption requirements are expanding. Encrypting data in transit, meaning email and file transfers, has long been expected. What's newer is the push toward encrypting data at rest, information sitting on local machines, shared drives, or practice-owned devices. A BAA with Google does not cover this. Encryption during storage is a separate requirement, and assuming your vendor handles it without verifying is a fast path to exposure.

Biannual vulnerability scanning and annual penetration testing are becoming part of the expected standard of care for practices of any size. Yves runs these assessments for small therapy practices at around $1,000. That is not a large number compared to the cost of a breach investigation or a CMS audit. According to HIPAA for Professionals at HHS, the Security Rule requires covered entities to conduct accurate and thorough risk assessments, and regulators use that standard when evaluating whether a breach reflected negligence or good-faith effort.

The Substance Abuse Records Rule Most Practices Are Missing

Here is the one that caught even me off guard. Effective February of this year, there is a regulation in force requiring practices to update their Notice of Privacy Practices to address substance abuse records.

A lot of practice owners are reading that and thinking, "That doesn't apply to me, I don't treat addiction."

Yves's point is the one worth sitting with: when you request records from other providers, referral notes, prior treatment summaries, transition of care documentation, substance abuse information can arrive in that data without you expecting it. The moment it lands in your system, you are subject to the regulation. Easier and cleaner to update your NPP now than to discover the gap after an audit.

If your privacy forms have not been reviewed since late 2024, this is the week to open them.

The BAA Misunderstanding That's Everywhere

I want to address something I hear from practice owners constantly, because it represents one of the most common forms of false confidence in HIPAA compliance: "We have a BAA with Google, so we're covered."

A Business Associate Agreement protects the way your data is stored within that vendor's system. It does not govern how data is transmitted. When your front desk coordinator emails a face sheet, a referral summary, or an eval report, that transmission needs its own encryption layer, separate from whatever BAA you've signed. The BAA and the transmission encryption are not the same thing, and conflating them creates real exposure.

This is not a critique of Google. The gap exists across every major platform. The responsibility for understanding where your BAA ends and your own obligation begins sits with the practice owner.

The Scenarios That Actually Get Practices in Trouble

Yves and I walked through a set of real-world scenarios during the episode, and I want to name a few here because they represent the kind of thing that gets dismissed as minor until it isn't.

  • A third-party cleaning crew with after-hours building access can view unsecured paper records. If those records are not locked away, that is a compliance gap regardless of whether anyone actually looked.
  • A caregiver transporting a patient does not automatically have the right to receive clinical information about that patient. The authorization form governs what gets shared and with whom, not the relationship or the convenience of the moment.
  • A therapist who mentions a patient's diagnosis or history to a front desk staff member who has no clinical role in that patient's care has created an internal disclosure breach. It doesn't require a stranger. It requires only the wrong person inside your own office.

The through line in all of these is not technology. It is judgment, and judgment is a culture output.

Building the Culture That Carries the Compliance

Yves made a point I keep returning to: most employees genuinely want to protect patient information. They are not malicious. They are busy, undertrained, and working in environments where privacy culture has never been made explicit.

The fix is not a longer policy manual. The fix is making privacy a visible, recurring priority. Bring it up at staff meetings. Post a reminder in the break room. Make it part of onboarding and part of annual reviews. When someone makes a mistake, correct it in a way that reinforces the standard rather than creating fear around reporting.

Practices with strong privacy culture are the ones that survive audits, even when a breach has occurred, because they can demonstrate documented training, corrective action processes, and leadership commitment. Auditors have discretion. Negligence produces the worst outcomes. Good-faith effort, consistently documented, produces a very different result.

For practices building out the HR infrastructure that supports this kind of culture work, Fractional HR Services is exactly where this conversation belongs. Policy development, onboarding structure, performance frameworks, and staff accountability systems are the operational layer underneath every compliance outcome.

Start With the Free Tool

If you have not done a formal HIPAA risk assessment, start with the Security Risk Assessment Tool available directly from HHS. It is free, it is kept current, and it will walk you through the three-step framework Yves outlined: inventory everything, evaluate what could go wrong and how likely it is, then build a mitigation plan.

Do this annually. Document it. Keep the record.

For practices that want a more technical review, including network vulnerability scanning and penetration testing, that work is accessible at a price point that makes sense for a small or mid-sized practice. You do not need to spend five figures to get defensible results.

Coding Accuracy and Compliance Are Connected

One thing I would add from my perspective as someone who works inside the billing side of private practice operations: HIPAA compliance and coding compliance are not separate disciplines. Both require documentation accuracy. Both carry audit risk. Both are areas where a culture of accountability either protects you or exposes you.

For practices wanting to examine whether their billing documentation would hold up under scrutiny, the Coding Compliance Audit is a direct starting point. Clean documentation is not just a revenue protection strategy, it is a compliance one.

Speech therapy, occupational therapy, and physical therapy practices carry particular exposure in this area. If you want to understand how your documentation standards connect to both reimbursement and regulatory risk, our work with speech therapy practices is a good place to start that conversation.

The Bottom Line

You are probably not going to achieve perfect HIPAA compliance. That is the honest answer. What you can achieve is a practice where every reasonable precaution is documented, every staff member understands the standard, and every audit trail shows a team that took this seriously.

The practices that get into serious trouble are not the ones that tried and fell short. They are the ones that never built the culture to begin with.

If you want to talk through where your practice stands, on compliance, billing infrastructure, or the HR systems that support both, let's see if we're the right fit. Book a Discovery Call and we will start there.