There's a persistent belief in small healthcare practices that HIPAA enforcement is something that happens to hospitals and large health systems — that OCR doesn't have the bandwidth or interest to audit a two-provider internal medicine practice in Lewiston or a solo dentist in Brunswick. That belief is wrong, and it's getting more expensive to hold.
OCR's compliance audit program has included small practices since its inception. Resolution agreements and corrective action plans have involved dental offices, ophthalmology practices, behavioral health providers, and solo practitioners. The fine structure scales to organizational size, but the obligation to comply does not.
What Maine Healthcare Looks Like
Maine's healthcare landscape is dominated by small and solo practices, rural clinics, and community health centers. The MaineCare population, critical access hospitals, and independent providers across a state where the next clinic can be an hour's drive mean that a significant portion of Maine's healthcare providers are small organizations — often with limited IT infrastructure, minimal security staff, and a staff of five to fifteen people managing patient care alongside administrative responsibilities.
These organizations hold protected health information. They use EHR systems — often cloud-based. Staff access patient records from workstations, laptops, and in some cases personal devices. Billing involves transmitting PHI to clearinghouses and payers. Many send clinical communications via email. Some use patient portals.
Every one of these activities is within scope of the HIPAA Security Rule, and none of the Security Rule's requirements are suspended for small organizations.
The Required Risk Analysis
45 CFR §164.308(a)(1)(ii)(A) requires every covered entity to conduct "an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of electronic protected health information held by the covered entity." This is a required safeguard — not addressable, not optional.
The HHS Office for Civil Rights has been explicit about what this means and what it doesn't. A risk analysis is not:
- Signing up for a HIPAA compliance software subscription
- Completing a vendor's self-assessment questionnaire about your EHR
- Having a HIPAA policy binder that's never been reviewed
- An IT assessment of your network security
It is a documented process that identifies where ePHI lives in your organization, what threats could affect it, what vulnerabilities exist, what controls you have, and what the residual risk is after those controls are applied. The HHS guidance on risk analysis identifies nine required elements. If your analysis doesn't address all nine, it's incomplete.
For a small Maine practice, this doesn't require a large consulting engagement or expensive software. HHS publishes a free Security Risk Assessment (SRA) Tool, available through HealthIT.gov, that walks through the required elements and produces documentation you can retain. It's not glamorous, but it works, and it's specifically designed for small and medium-sized practices.
What OCR Finds in Small Practice Investigations
When OCR investigates a small healthcare practice — usually triggered by a breach notification or a complaint — the most common finding is that no risk analysis was ever conducted, or that one was done once years ago and never updated. The practice may have good instincts about security: staff are trained not to share passwords, laptops are locked, the EHR vendor has a signed BAA. But without the documented risk analysis, OCR's position is that the Security Management Process requirement hasn't been met.
Recent enforcement actions involving smaller organizations include:
Green Ridge Behavioral Health (2023): A behavioral health practice in Maryland. Settlement of $40,000. Finding included risk analysis and risk management failures. 1,755 individuals affected.
Community Eye Center of California (2024): Ophthalmology practice. Settlement of $250,000. Risk analysis and access control failures. 4,500 individuals affected.
Dental practices: Multiple corrective action plans since 2019 have involved practices with patient populations in the range of 1,000-8,000. Settlement amounts have ranged from $10,000 to $100,000.
The pattern: a relatively small breach occurs, OCR investigates, and what they find isn't primarily about the incident itself — it's about the absence of a functioning security management program, starting with no documented risk analysis.
Maine's Double Obligation
Maine healthcare providers have a second notification obligation that runs alongside HIPAA: the Maine Information Security Incident Notification Act (10 M.R.S. § 1347). A breach of ePHI at a Maine practice triggers both:
- HIPAA Breach Notification: notify affected individuals within 60 days; notify HHS. Notify media if >500 individuals in the state.
- Maine law: notify affected Maine residents and the Attorney General within 30 days.
Maine's 30-day window is more aggressive than HIPAA's 60-day window. If you're managing a breach response, the Maine obligation is your controlling deadline. A breach response plan that's calibrated to HIPAA's 60 days may put you out of compliance with Maine law.
Starting Points for Small Maine Practices
If your practice hasn't completed a documented HIPAA risk analysis, or hasn't updated one since you changed EHR systems, moved to the cloud, or added a patient portal, here's where to start:
Use the HHS SRA Tool. It's free, it's built for small practices, and it produces documentation you can save and show to OCR. Download at healthit.gov/topic/privacy-security-and-hipaa/security-risk-assessment-tool. Set aside a few hours with whoever owns your IT decisions, and work through it systematically.
Inventory your ePHI locations before you start. Where is patient data stored? Your EHR is obvious. What about billing system, scheduling software, email with attached referrals, the shared drive where staff save patient intake forms? Scope your analysis to all of these before you begin, not just the EHR.
Document the assessment, not just the results. OCR wants to see that you actually went through the process — the methodology, the assets reviewed, the threats identified, the current controls assessed, the risk ratings assigned. A completed SRA Tool export satisfies this.
Date it and schedule the next one. A risk analysis is a point-in-time document that requires periodic updates. Add a calendar reminder for 12 months out, or sooner if you change systems, hire significantly, or experience an incident.
Get your BAAs in order. While you're doing the risk analysis, confirm that every vendor with access to ePHI has a signed Business Associate Agreement. This comes up in every OCR investigation. The EHR vendor likely has one; the scheduling software, the billing service, the cloud storage provider, and the IT support company may not.
This Doesn't Require a Large Consulting Engagement
A small Maine practice doesn't need a $50,000 HIPAA consulting project to achieve a defensible Security Rule compliance posture. The basics — a documented risk analysis, an updated and signed BAA inventory, staff training records, and a simple incident response procedure — are achievable with modest time investment.
The gap for most small practices isn't knowledge; it's documentation. OCR can't see your security instincts or your staff's good judgment. They can see your risk analysis, your BAAs, your training records, and your policies. Those are the things that matter in an investigation.
SOURCES
- 45 CFR §164.308(a)(1) — Security Management Process: ecfr.gov
- HHS, "Guidance on Risk Analysis Requirements under the HIPAA Security Rule": hhs.gov/hipaa/for-professionals/security/guidance/guidance-risk-analysis/index.html
- HHS/ONC Security Risk Assessment Tool: healthit.gov/topic/privacy-security-and-hipaa/security-risk-assessment-tool
- OCR HIPAA Enforcement Actions: hhs.gov/hipaa/for-professionals/compliance-enforcement/agreements/index.html
- Maine AG Office, Data Breach Notification: maine.gov/ag/consumer/identity_theft/data_breach.shtml
Running a healthcare practice in Maine and not sure where your HIPAA compliance stands? Schedule a consultation to talk through what a risk analysis looks like for your specific practice.
