Security guidance should meet a practice where it is.

HIPAAWorks exists to help small healthcare practices understand their HIPAA Security Rule gaps, decide what to address first, and keep a clear record of the work they do next.

HIPAAWorks founder meeting with a physician and office manager
20

years of cybersecurity and IT-risk experience in healthcare shaped the way HIPAAWorks approaches this work.

The rule is the same. The resources are not.

I spent twenty years in cybersecurity and IT risk before I built this, most of it inside healthcare organizations of every size. I have sat across the table from hospital compliance teams with dedicated staff and multi-year budgets, and I have sat across the table from a two-provider practice where the person responsible for security is also the person who checks patients in at the front desk. The rule does not change depending on which room I am in. The resources in the room change completely.

Small medical, dental, therapy, and specialty practices hold sensitive information and carry the same responsibilities under the HIPAA Security and Privacy Rules as much larger organizations. The law lets an organization weigh its size, capabilities, and costs when choosing reasonable and appropriate safeguards, and that flexibility matters. But it does not remove the work. A small practice still has to understand its risks, protect patient information, train its workforce, manage vendor relationships, and document what it has done.

What I kept seeing, year after year, is that the hard part is rarely convincing someone that security matters — almost everyone I met already believed that. The hard part is turning a broad legal requirement into a next step that a specific, busy practice can actually take this month, and then having something to show for it later.

Security work competes with the work of running a practice.

Large health systems can assign this work to compliance, legal, privacy, and IT departments. In a smaller practice, the same responsibilities land on one person who is already wearing several hats — the practitioner, the office manager, a front-desk lead — squeezed between patient care, billing, staffing, and the hundred other things that keep a practice open. Important follow-up gets delayed not because it isn't understood, but because there is no room left in the week for it.

Every dollar spent on security is a dollar not spent on payroll, clinical systems, or supplies, so the decision is never simple. An electronic health record vendor or an outsourced IT provider can protect part of the environment, but neither one is a substitute for the practice's own risk analysis across every system that touches patient information — and every billing service, cloud tool, or messaging platform added to the mix creates one more agreement to manage and one more set of safeguards to understand. Training has to survive turnover and a full calendar, not just a single orientation session. And work that only exists as a verbal policy or a decision one person remembers is hard to maintain and even harder to demonstrate months later. Written, dated records are what make progress durable.

Too many tools I encountered added another layer of jargon, or produced a report that went stale the day it was downloaded. HIPAAWorks is my attempt to do this differently: plain-language questions, severity-tiered gaps, practical remediation guidance, and a dated evidence trail that grows as the practice does the work.

The direction is becoming more specific.

The current HIPAA Security Rule remains in effect today, unchanged. At the same time, a proposal published by HHS in January 2025 shows where federal expectations may be heading. If it is finalized substantially as written, it would remove the distinction between required and addressable implementation specifications, and it would add specific expectations around encryption, multi-factor authentication, technology asset inventories, network maps, vulnerability scanning, penetration testing, incident recovery, and written documentation. You can read the HHS proposal overview directly.

The federal regulatory agenda currently lists July 2027 as the projected date for final action. That date can move, and the proposal itself can still change before it becomes final — it is a planning signal, not a deadline, and I have written more about what that means for a small practice .

None of that requires predicting the final rule to be useful. A current risk analysis, stronger access controls, a basic inventory of systems and vendors, regular workforce training, and better documentation are worthwhile work under today's rule. They also leave a practice in a stronger position if requirements change.

Built around the realities of a small practice.

A handful of things guide how I built this, and how I keep changing it. Plain language matters more than sounding official — people should be able to understand what is being asked and why without translating a wall of legal or technical terminology first. Guidance is only useful if it is practical: it should reflect the tools a practice already uses and give the team a realistic place to start, not a generic checklist written for no one in particular. Finding a gap is only the beginning — the notes, decisions, status changes, and supporting evidence that follow are what let a practice show, later, what it found and what it did about it. And honest boundaries build trust: no software can replace a practice's judgment or promise a regulatory outcome. HIPAAWorks supports the process; the organization reviews and attests to its own work.

“The goal was never to make security feel smaller. It was to make the next step clear enough to actually take.”

That is still the test I hold every part of the product to. Twenty years in this field taught me that a practice rarely needs someone to tell it security is important — it needs help figuring out what to do next, and a way to keep a record of the work as it goes. That is what I am trying to build here, one practice at a time.

— The founder, HIPAAWorks

See what your practice may need to address next.

The free Quick Check asks seven plain-language questions and gives you an initial view of potential gaps. It takes about five minutes and does not require a card.

Start your free Quick Check