Sign BAAs with every vendor touching PHI
EHR, clearinghouse, billing service, email provider, phone/text platform, cloud storage, shredding company, IT support. No BAA means you can’t use them for PHI, full stop. Keep the signed copies in one folder; an auditor asks for these first.Do the security risk assessment
Required by the Security Rule, and the thing small practices most often skip. Walk through where PHI lives (EHR, email, texts, paper, devices), what could go wrong, and what you’ll fix. Use HHS’s free SRA tool, document it, and repeat annually. The assessment being documented matters as much as being done.Write the policies you’ll actually follow
Privacy and security policies scaled to your size: access rules (who sees what in the EHR, unique logins, no shared passwords), device rules (encryption on laptops and phones), texting/email rules, and a sanctions policy. Publish your Notice of Privacy Practices and hand it out at intake.Train everyone, and log it
Initial training for every hire, annual refresh, and a signed log. Most real breaches are a curious employee or a phished password, and training plus access controls is the defense OCR expects to see.Be breach-ready
A one-page plan: who investigates, the 60-day individual notification clock, HHS reporting (immediately if 500+ affected, annual log if fewer), and your cyber insurer’s hotline (coverage).Recurring upkeep goes on the compliance calendar:
annual SRA, annual training, BAA review when vendors change.