Skip to content
  • About Us
    • Who We Serve
  • Solutions
    • HIPAA for Covered Entities
    • OSHA for Healthcare
    • HIPAA for Business Associates
    • SRA for Covered Entities
    • Abyde Incident Response Program
    • Abyde Reseller Program
  • Resources
  • News
  • Events
  • Partners
  • Contact Us
  • Login
    • HIPAA for Covered Entities
    • OSHA for Healthcare
    • HIPAA for Business Associates
    • SRA for Covered Entities
SIGN UP
BOOK A DEMO

Top 5 HIPAA Myths That Put Your Practice at Risk

October 21, 2025

Running a healthcare practice means juggling patient care, staff, and countless responsibilities. Somewhere in the mix, HIPAA can feel like one more thing on the never-ending list. Understandably, compliance might not always top your priorities.

But that’s precisely where many practices get caught off guard. Misunderstanding what HIPAA truly requires can lead to costly mistakes. Even the most well-intentioned practices can fall for common HIPAA misconceptions that put them at risk.

It’s time to debunk myths and get your practice back on track.

 

Myth 1: HIPAA only applies to large hospitals

We hate to break it to you, but if your practice handles Protected Health Information (PHI), you must follow HIPAA. It doesn’t matter if your practice has five employees or 5,000; it’s held to the same standards. 

HIPAA investigators can and will continue to investigate small practices. In fact, one of the most recent fines was a single facility healthcare provider for $250,000 after a ransomware attack exposed several HIPAA violations. 

Smaller practices often don’t have the same IT departments, legal teams, or budgets as large hospitals, which makes HIPAA violations even more damaging. A fine or breach can strain finances, disrupt daily operations, and erode patient trust, which took years to build.

 

Myth 2: We do HIPAA training – we’re good!

Full HIPAA compliance is much more than training. Thorough HIPAA training is necessary, but ensuring staff are educated on their responsibilities is only scratching the surface of a compliant practice.

One of the most commonly missed HIPAA requirements is the Security Risk Analysis (SRA). The SRA is a thorough review of all physical, administrative, and technical safeguards your practice currently has in place.

 Does your practice have an alarm? If so, does every staff member have individual codes to disarm it? Does your practice deploy antivirus software? Does your staff ensure patients are unable to see computers with PHI? These are all example questions of what the SRA assesses. 

The SRA is a required document that is strongly recommended to be completed annually. Proposed legislation would require this document yearly for all regulated entities, and Business Associates would have to submit their documentation and be certified by a cybersecurity expert. 

 

Unfortunately, only 14% of practices could produce a compliant SRA during the last round of HIPAA audits, making this a commonly missed requirement. 

The Office for Civil Rights (OCR) is investing more resources to ensure all regulated entities know this document is essential. The OCR has introduced a Risk Analysis Initiative, fining and highlighting practices as an example of missing the SRA. 

While the SRA is one of the largest requirements for HIPAA, all of its requirements come together like a puzzle. The SRA, training, proper technical safeguards, Business Associate Agreements, documentation, and more all ensure that a practice upholds HIPAA legislation. 

 

Myth 3: My IT company handles HIPAA for me

If only it were that easy. While having an IT company is encouraged to ensure that your technical safeguards are in place to protect PHI, that doesn’t necessarily mean they handle all your HIPAA requirements. 

For example, while your IT company can equip your email systems with compliant email encryption, it cannot prevent a breach if a staff member accidentally emails PHI to the wrong patient. If you are investigated because of this, although your IT team can provide technical knowledge, the OCR will request more information about training, documentation, and other areas not within your IT team’s expertise.

The human factor is often the weakest link in data protection. Even the best encryption can’t prevent an employee from falling for a phishing scam or leaving a chart open on their desk. That’s why consistent staff training and clear procedures are as essential as your technical defenses.

While your IT company can assist with the technical side of HIPAA, it’s strongly recommended that you utilize a compliance platform for training, documentation, your SRA, and more to address the other requirements. 

Relying solely on your IT provider can leave your practice vulnerable. HIPAA requires comprehensive compliance, secure technology, thorough documentation, SRAs, training, and ongoing monitoring.

 

Myth 4: If a patient posts their own info online, I can comment

Even if your patient posts a glowing review of how wonderful their experience was with your practice, you cannot comment on a personal response. By commenting on an individual response, you are confirming that this reviewer was a patient at your practice, a big HIPAA no-no. 

When answering any review, keep it brief and generic. For instance, “Thank you for your kind words. If you have any questions or further feedback, contact 123-456-7891.” is a compliant response. If you’d like to use a patient’s experience in marketing material, communicate with them through a secure channel and provide a media consent form. 

If you receive a negative response, take the reviewer offline and provide a secure communication channel, like a phone number or encrypted email. You should never get upset while responding online. Practices have been fined for inappropriate responses, such as leaking PHI to prove a point. 

 

Myth 5: A data breach automatically means a fine

You can take a deep breath, because not every data breach turns into a hefty fine. 

Even with strong safeguards, no healthcare practice is entirely immune to risk. With ransomware attacks on the rise, cybercriminals are constantly evolving their tactics to exploit the sensitivity of patient data.

It’s important to remember that HIPAA fines stem from missing or insufficient compliance measures, not the breach itself. That’s why proactive compliance is so critical. When your practice maintains proper safeguards and documentation, you significantly reduce your practice’s risks. 

During an investigation, the OCR will ask for documentation or proof that your practice protected patient data before the situation, how your practice handled the breach, and what your practice currently has in place following the incident. If your documentation is compliant, proving your practice takes the proper precautions and promotes a culture of compliance, the OCR can close the investigation, meaning no fine. 

What HIPAA Really Means for Your Practice

Knowledge is power, and when it comes to HIPAA, it’s also protection. 

With an intelligent compliance solution, your team can become empowered and aware of how to protect your practice and your patients’ data. The proper compliance software can equip your team with the right tools and knowledge so your practice can proactively identify gaps and take control, automating and streamlining compliance.

Meet with a compliance expert today to learn more about HIPAA compliance for your practice.

RECENT POSTS

  • Dental Practice HIPAA Settlement
    What Every Dental Practice Can Learn From the $140K Shen Smiles Settlement
  • Ambry Phishing Settlement
    $700K HIPAA Settlement: What the Ambry Genetics Phishing Breach Teaches Every Practice
  • Azul Vision Right of Access
    Right of Access Enforcement Hits Eye Care: Inside the Azul Vision Settlement
PrevPreviousAbyde Takes the Spotlight: Named One of Florida’s Top 50 Companies to Watch
NextHow to Stay HIPAA Compliant When Patients Request Their Medical RecordsNext

Related posts

Dental Practice HIPAA Settlement
Abyde News, Fines, HIPAA

What Every Dental Practice Can Learn From the $140K Shen Smiles Settlement

October 9, 2026 Penelope Schweitzer No comments yet

October 9, 2026 The latest HIPAA penalty doesn’t involve a hospital system or a massive ransomware attack. It involves a practice that probably looks a lot like yours. Dr. Linda Shen is the owner of Shen Smiles, a solo dental practice with one location in Drums, Pennsylvania. It all started with one patient asking for their health records. It ended with a $140,000 penalty and a much closer look at how the practice handled HIPAA. The lesson? Every HIPAA-regulated practice, big or small, can face enforcement. What happened? It’s unclear when the patient first asked for their records, but patient records need to be provided within 30 days from the initial request. In April 2020, the patient’s attorney filed a complaint with the Office for Civil Rights (OCR). The patient had asked for their health records multiple times and never got it. Once OCR started digging, the missed request turned out to be just the beginning. Patient records weren’t properly maintained, staff had never received formal HIPAA Privacy Rule training, and there were no policies for handling patient requests. Dr. Shen admitted that the records were never provided because a former employee had taken them. That’s another violation, this theft is a breach, which means it needed to be reported to the OCR, patients needed to be notified, and given options to protect themselves (such as credit monitoring). These are baseline requirements every Covered Entity is expected to have in place. No compliance framework, like policies and training, means no HIPAA playbook, so when a patient asks for records (or records go missing), staff is unprepared and unaware how to handle the situation. In July 2024, OCR proposed a $140,000 Civil Money Penalty. Dr. Shen appealed, but ultimately settled on the full amount. The Takeaway for Practices Patient access has been an OCR priority for years through its HIPAA Right of Access Initiative. And as this case shows, one complaint is all it takes to open the door to a review of your entire compliance program. Now is the time to ask: Do we have written HIPAA policies our team can find? Do we have a process to answer every record request within 30 days? Can we prove every team member has completed HIPAA training? If any of those gave you pause, now’s the time to fix it, before OCR comes asking. Looking for the first step? Meet with one of our compliance experts to see where you currently stand.

Ambry Phishing Settlement
Abyde News, Fines, HIPAA

$700K HIPAA Settlement: What the Ambry Genetics Phishing Breach Teaches Every Practice

September 21, 2026 Penelope Schweitzer No comments yet

September 21, 2026   The HHS Office for Civil Rights (OCR) has announced its biggest HIPAA settlement of the year, reaching nearly a million dollars.  Ambry, a genetic testing and clinical genomics provider based in Aliso Viejo, California is at the center of this enforcement. A settlement was reached over a 2020 phishing attack that exposed the Protected Health Information (PHI) of more than 225,000 individuals. This settlement is a clear reminder that even large organizations trip up on HIPAA requirements.    What happened In January 2020, an employee email account at Ambry was compromised through a phishing attack.  The breach potentially exposed a wide range of PHI, including names, addresses, dates of birth, Social Security Numbers, financial details, and more. Ambry reported the breach to OCR in March 2020, which kicked off the investigation.    Where OCR found gaps OCR’s investigation identified several HIPAA Security Rule gaps, including: No accurate, thorough risk analysis of risks and vulnerabilities to ePHI No process for cutting off access to ePHI when an employee left or no longer needed access No unique user IDs for tracking who was accessing ePHI systems These are baseline HIPAA requirements that every Covered Entity and Business Associate is expected to have in place.   The settlement terms Ambry paid $700,000 and agreed to a two-year corrective action plan, under which it must: Complete a thorough risk analysis of ePHI confidentiality, integrity, and availability Build and execute a risk management plan addressing what that analysis turns up Review and update Security Rule policies and procedures as needed Implement unique user identification across all ePHI systems Train the whole workforce on those updated policies The takeaway for practices When 90% of healthcare hacks start with a successful phishing attempt, it’s key your team is aware of the role they play to keep data safe. Every practice should ask; Do we know exactly where our ePHI lives and how it moves through our systems? Do we have a current, documented risk analysis? Would we catch it fast if a former employee’s access wasn’t revoked? Looking for the first step of addressing these gaps? Meet with one of our compliance experts to see where you currently stand. 

Azul Vision Right of Access
Abyde News, Fines, HIPAA

Right of Access Enforcement Hits Eye Care: Inside the Azul Vision Settlement

September 1, 2026 Penelope Schweitzer No comments yet

September 1, 2026   The Office for Civil Rights (OCR) announced its 55th settlement under the HIPAA Right of Access Initiative, and this one is a good reminder that “we’ll get to it” is an easy shortcut to a massive financial penalty.   What happened Azul Vision, Inc., a California optometry enterprise healthcare provider, took nearly two years to provide a patient her healthcare records failed to give a patient timely access to her health records. She requested her records in January 2023. She didn’t actually receive them until January 2025, or two years later, and only after OCR opened an investigation following her complaint in April 2023.   The importance of Right of Access The HIPAA Privacy Rule’s Right of Access is straightforward: patients are entitled to their healthcare records within 30 days of a request, with one possible 30-day extension if needed.    The cost Azul Vision agreed to a two-year, OCR-monitored corrective action plan and paid $50,000. The corrective action plan requires the practice to: Review and revise its written policies and procedures for Privacy Rule compliance.  Regularly report to HHS a log of every PHI access request it receives, including when it came in and when it was resolved, Train all workforce members on right of access requirements and the practice’s own procedures.   Practical takeaways Have a documented, assigned process for access requests: not an informal “someone will handle it” arrangement. Track every request against the 30-day (or extended 60-day) clock: If nothing is timestamping requests, nothing is catching the ones that slip. Train staff specifically on right of access: this is a distinct Privacy Rule obligation from general HIPAA awareness, and it’s clearly one OCR is actively enforcing.   The bottom line A single records request that went unanswered turned into a $50,000 penalty, two years of federal monitoring, and a detrimental hit to the organization’s reputation. That’s a steep price for what really comes down to a missing process. If your team can’t answer “what happens the moment a patient asks for their records?” right now, that’s the gap to close before your practice ends up as OCR’s next enforcement case. Want a streamlined way to close your compliance gaps? Meet with an Abyde expert today!

  • Facebook
  • Instagram
  • LinkedIn
  • YouTube
Abyde Logo

1.800.594.0883 | info@abyde.com

Automated HIPAA and OSHA Compliance

Our Reviews

From Our Blog
  • Don’t Get Caught Off Guard: HIPAA Audits are Back!
  • Don’t Be a Statistic: Why OSHA Compliance Matters in Healthcare
  • What Money Doesn’t Cover: The True Price of HIPAA Non-Compliance
  • HIPAA: It’s Not Just a Training – Your Guide to Continuous Compliance
Solutions
  • HIPAA for Covered Entities
  • OSHA for Healthcare
  • HIPAA for Business Associates
  • SRA for Covered Entities
  • Abyde Incident Response Program
  • Abyde Reseller Program
Resources
  • News
  • Events
  • Partners
  • HIPAA Badges
  • OSHA Badges
  • Learning Center
  • Compliance FAQs
Company
  • About Us
  • Who We Serve
  • Pricing
  • Contact Us
  • Newsletter
  • Jobs
  • COPYRIGHT © 2026 ABYDE
  • |

  • TERMS & CONDITIONS
  • |

  • PRIVACY POLICY
  • |

  • SECURITY MEASURES
  • |

  • E-SIGNATURE TERMS