Saved · this browser
Chapter 8 · §164.308(a)(1)+(2)/(3)/(4)/(8)

Your Security Foundation

This is the chapter where you step back and look at the whole picture. The earlier chapters handled the hands-on pieces — your email, your devices, your passwords. This one is about the few decisions that hold all of it together: naming what could go wrong, deciding what to do about it, and saying who’s in charge. It’s mostly writing things down, and most of it you’ve already worked out.

Why this chapter exists, in plain English

Think of the earlier chapters as the hands-on work: your BAAs, your devices, your passwords, your workspace, what to do if something goes wrong, your training, your paperwork, your systems. This chapter zooms out and asks the bigger-picture questions behind all of it — what could go wrong with your patients’ information, what you’re doing about it, and who’s responsible. It’s the part of a new practice’s setup that’s most often left undone, which is exactly why it’s worth a few minutes now (the rule-book name for this cluster is the Security Management Process).

There are seven short topics here. Each one ends in a simple written document — a Risk Analysis, what you’re doing about each risk, a rules-and-consequences policy, a routine for glancing at your sign-in records, and so on — and each is something you can finish in an afternoon.

You won’t be starting from a blank page. The rules-and-consequences topic has a one-click template you can adopt and edit. The “who’s in charge” topic just asks for a name (for a solo practice, your own). Everything else is a short bit of writing built on the work you’ve already done.

01

The seven foundations

7 questions
§164.308(a)(1)(ii)(A)

Risk analysis:

naming what could go wrong with your patients’ health information

This is the heart of the whole thing: you sit down and honestly name what could go wrong with your patients’ health information. The goal is to keep that information private, accurate, and there when you need it — the three things every other safeguard is quietly protecting (the security shorthand for those three is confidentiality, integrity, and availability).

For a solo or small practice, a workable risk analysis is a page or two that names three things: (1) the patient information you handle and where it lives (your EHR, your work email, your backups, your devices — most of which you already listed back in Chapters 1, 2, and 6), (2) the realistic things that could go wrong (a lost laptop, a hacked account, your EHR going down, ransomware, sending something to the wrong person), and (3) your honest gut-check of how likely each one is and how bad it would be. There’s a federal plain-language guide (NIST SP 800-66 Rev. 2) behind this, and the “Adopt template” button below gives you a ready-made version to start from — you are not building anything from scratch.

Loading your inventory…
§164.308(a)(1)(ii)(B)

Risk management:

what you decided to do about each risk, and when

Once you’ve named what could go wrong, this step is simply deciding what to do about each one. For every risk you found, you either (1) do something that makes it smaller, or (2) write down that you’ve chosen to live with it, and why. The one thing you can’t do is quietly ignore it.

Here’s the good news: you’ve already done most of this. Almost every choice you made in the earlier chapters is one of these decisions — signing a BAA handles the “a vendor mishandles my data” risk, locking and scrambling your laptop handles the “it gets stolen” risk, your backups handle the “ransomware locks me out” risk. All this step asks is that you connect the safeguards you already picked back to the risks they cover.

§164.308(a)(1)(ii)(C)

Sanction policy:

what happens when you — or someone who works with you — breaks the rules

This is just a short, written answer to one question: what happens if someone breaks the security rules? For a solo practice, that “someone” is mostly you — but it also covers anyone who ever works with you: an intern, a virtual assistant, a biller, a contractor. The point isn’t to punish anyone. It’s that the policy exists on paper, in case you ever need it.

The usual shape is three steps that get more serious: an honest mistake, a serious or repeated one, and a deliberate one. You don’t have to write it from scratch — the “Adopt template” button below drops in ready-made wording you can keep as-is or edit to fit your practice.

§164.308(a)(1)(ii)(D)

Information system activity review:

how you keep an eye on the access records your systems already keep

You’re not signing up to be a security analyst staring at logs every week. Your EHR and your email already keep a quiet record of who signed in and when — you don’t have to set anything up. All this step asks is that those records don’t go completely ignored.

Here’s the whole job: once in a while, open that sign-in record and glance for anything you don’t recognize — a login from a place you’ve never been, a burst of failed password tries, or anything your system has flagged as unusual — then jot down that you looked. Most EHRs put this under a “security” or “account activity” menu; if you can’t find it, that’s a one-line question for your EHR’s support. Picking a date once a year, alongside the other things you review, is a fine rhythm to start with.

§164.308(a)(2)

Security Official:

the person responsible for your practice's security — for a solo practice, that's you

This one isn’t optional and it isn’t hard: HIPAA just wants one person’s name written down as the one responsible for security. For a solo practice, that’s you. For a small office, it’s usually the owner or practice manager — whoever it is, it just has to be written down.

That person is the one who runs the yearly review, signs the HIPAA Security Manual, and is the point person if something goes wrong. Put the name — plus an optional backup person and a contact line — over in Your Practice; once you do, that name fills itself in on your Security Official policy wherever it’s needed.

What this person actually does when something goes wrong is covered separately, back in If Something Goes Wrong (Chapter 6).

§164.308(a)(3) + (a)(4)

Workforce security and access management:

who can get to what, and how you shut off access when someone leaves

This is about anyone who works with you. HIPAA asks you to do two simple things: check that a person is trustworthy before you give them access to patient information, and turn that access off when they leave.

It also asks you to give each person only the parts they actually need — your biller doesn’t need your therapy notes, for example. The idea is “just enough to do their job,” nothing more.

How much of this applies depends on who has access. If it’s just you right now, it’s short — you’re the only one — and the four-part routine below is there for the day you bring on an intern, assistant, or biller. If people already work with you, that routine is what you run for each of them: check them out before they start, give them only what they need, and switch off their access the day they leave.

§164.308(a)(8)

Periodic evaluation:

the once-a-year check that your setup still fits your practice

This one’s required, and it’s really just a reminder to check back in. Once a year, look over your setup and make sure it still fits your practice — and do it sooner if something big changes (a new vendor, new staff, new software, an incident, or a rule update).

You don’t need a separate process for this. Running through HIPAAPath again on your once-a-year review date is the check — it covers both the tech side and the paperwork side for most solo or small practices.

02

Where you stand

Almost there

Answer all seven questions above and you’ll see where you stand on this chapter.

Can you help us make this better?

How easy is HIPAAPath to use so far?
HardEasy

Please don’t include patient information — this goes to us by email.