What Healthcare Practices Get Wrong About HIPAA (And How to Fix It)
HIPAA mistakes are rarely intentional, but they can still cost your practice dearly. Here are the most common gaps healthcare practices overlook and the practical steps you can take to close them.


HIPAA Is Not a One-Time Checkbox
Many practices treat HIPAA like a project with a finish line. They complete their initial training, sign their business associate agreements, and file their policies away. Then years go by without a second look.
The reality is that HIPAA is an ongoing program, not a one-time setup. Staff turns over. Software changes. New communication tools get added. Every one of those changes can introduce new risk if no one is watching. The practices that stay in good shape are the ones that build HIPAA awareness into their daily routines, not just their annual training calendar.
The Most Common Risk Areas Practices Miss
After years of watching how healthcare practices operate, a few problem areas come up again and again. None of them are exotic. Most are hiding in plain sight.
1. Uncontrolled Access to Patient Records
Every staff member who can log in to your practice management system should have access only to what their job requires. A front-desk coordinator generally does not need the same level of access as a clinical provider. When everyone shares a single login or when permissions never get updated after a role change, patient data becomes far more exposed than it needs to be.
- Review user accounts at least twice a year.
- Remove or downgrade access immediately when an employee leaves or changes roles.
- Avoid shared passwords, even for convenience.
2. Texting and Email Without Safeguards
Standard SMS text messages and personal email accounts are not considered secure channels for protected health information. Yet many practices still use them to coordinate care, send appointment reminders with clinical details, or follow up on lab results.
If your practice uses text or email to communicate with patients, the tool you use should have encryption, audit logs, and a signed business associate agreement with the vendor. Patient convenience matters, but the channel has to meet a minimum security threshold first.
3. Outdated or Missing Business Associate Agreements
A business associate agreement, commonly called a BAA, is a written contract that holds your vendors accountable for handling patient data appropriately. You need one with any outside company that touches protected health information on your behalf. That includes your billing service, your EHR vendor, your website chat tool, your patient communication platform, and sometimes your IT support company.
The most common mistake is not having a BAA at all for a newer vendor. The second most common mistake is having one that was signed years ago and has never been reviewed to reflect how your relationship with that vendor has changed.
4. Workforce Training That Does Not Stick
Annual training videos that staff click through in ten minutes are better than nothing, but they are not enough on their own. Real HIPAA awareness means your team knows what to do when something unusual happens, such as a misdirected fax, a suspicious email, or a patient asking to see their own records.
Consider short, role-specific refreshers throughout the year. Front desk staff need to understand different scenarios than clinical assistants or billing coordinators. Training that maps to real job situations is far more effective than generic compliance modules.
5. Your Website and Digital Presence
This one surprises a lot of practice owners. Your website can carry HIPAA risk signals even if no one at your practice is deliberately sharing patient data through it.
Common examples include contact forms that collect health-related information without proper security protections, patient portal login pages that are not encrypted, and third-party tracking tools that may inadvertently capture information about a visitor's health-related browsing behavior. If your website has not been reviewed from a privacy and security standpoint recently, it is worth adding that to your list.
Your Notice of Privacy Practices: Is It Current?
Your Notice of Privacy Practices, the document that explains to patients how you use and protect their information, must accurately reflect what your practice actually does. If you have added new services, new vendors, or new communication methods since your notice was last updated, it may no longer be accurate. Most practices update this document far less often than they update everything else around it.
What a Basic HIPAA Review Should Cover
You do not need a full audit every year, but you do need a structured review on a regular basis. A reasonable review should touch on at least the following areas:
- Access controls: Who can access what systems and data, and is that list still accurate?
- Vendor agreements: Do you have current BAAs with every vendor that handles patient data?
- Communication tools: Are all channels used to communicate protected health information appropriately secured?
- Training records: Is training documented, and does it reflect current workflows?
- Incident response: Does your team know what to do if a possible breach occurs, and is there a written plan?
- Digital properties: Have your website and patient-facing digital tools been reviewed for possible privacy risk signals?
The Cost of Waiting
Practices often put off HIPAA reviews because nothing has gone wrong yet. That logic has a flaw. Gaps in your safeguards do not announce themselves. A misdirected email, an unsecured form, or a former employee with active credentials can sit unnoticed for months. The sooner you find a gap, the cheaper and simpler it is to fix.
More importantly, patients trust your practice with some of the most sensitive information in their lives. Protecting that information is not just a regulatory obligation. It is a core part of delivering good care.
Where to Start
If your practice has not done a formal review in the past 12 months, start with your vendor list. Write down every software tool and outside service you use. For each one, ask two questions: does this vendor handle any patient data, and do we have a current signed BAA on file? That single exercise will surface more issues than most practices expect, and it gives you a concrete starting point for everything else.
Frequently asked questions
- How often does a healthcare practice need to update its HIPAA policies?
- Your HIPAA policies should be reviewed at least once a year and any time there is a significant change to your operations, such as adding a new software vendor, changing communication tools, or hiring staff in new roles. Policies that no longer match how your practice actually works create risk even if they were accurate when first written.
- Do we need a business associate agreement with every software vendor we use?
- You need a BAA with any vendor that creates, receives, maintains, or transmits protected health information on your behalf. This includes billing services, EHR and practice management platforms, patient communication tools, and website chat or scheduling tools that collect health-related information. If you are unsure whether a specific vendor qualifies, treat that as a signal to review the relationship more closely.
- Is it a problem if staff use personal email or text messages to contact patients?
- Standard personal email and SMS text messages are generally not considered secure enough for protected health information because they lack encryption and audit controls. Your practice should use communication tools that include appropriate security features and that are covered under a signed business associate agreement with the vendor.
- What should a practice do if a possible HIPAA breach is discovered?
- Your practice should have a written incident response plan that defines who is notified internally, how the situation is documented, and what steps are taken to contain the issue. The HIPAA Breach Notification Rule sets specific timelines for notifying affected individuals and, in some cases, the Department of Health and Human Services, so acting quickly and keeping clear records from the start is important.

Jerett Patterson has over 20 years of experience designing web and mobile experiences for major medical institutions, including Houston Methodist, Memorial Hermann, and MD Anderson Cancer Center. At Mederi, he specializes in translating complex clinical systems into patient-centered digital experiences that meet ADA/WCAG accessibility standards and HIPAA compliance requirements, helping healthcare organizations modernize their digital presence without sacrificing trust, clarity, or conversion.
See your own website's signals
Sentinel scans your site for accessibility, privacy, and speed issues, ranked by what to fix first.
Get started

