Yes, even Direct Care and DPC practices need to be HIPAA compliant. As a business owner in health care it's worth knowing what to look out for. However, it's not worth stressing over. Here's a fairly thorough list of what you'll need for a Direct Care practice. Bookmark this, and you'll be good-to-go.
HIPAA Compliance Fundamentals
Just because you don't deal with insurance doesn't mean the Health Insurance Portability and Accountability Act (HIPAA) doesn't apply to your practices. Anybody who stores, reads, manages, inputs, or smells patient health information (PHI) falls under HIPAA laws.
Here are the main areas and key requirements:
Administrative Safeguards
- Security Officer: Designate a responsible individual for security compliance
- Can be anybody within your company - even yourself.
- Workforce Training: Regular training on privacy and security policies
- Anybody who is hired should go through HIPAA training (there are free videos online), and bring up HIPAA in 1-2 staff meetings per year.
- Access Management: Control who can access patient information
- Small teams are OK to allow access by all, but ensure training is strict and you talk about when it's appropriate to access PHI and when it is not.
- Incident Response: Procedures for handling security breaches
- Malpractice insurance normally includes some kind of assistance. If you keep patient addresses and email addresses, you should be fine.
Physical Safeguards
- Facility Access Controls: Secure physical access to areas with patient data
- Any printed / physical items with PHI on them should be either behind locked doors or in the shred bins to be collected at least weekly (if not daily).
- Workstation Security: Protect computers and devices containing PHI
- I recommend hiring an IT person / company to manage computers. At the very least, ensure all computers must be accessed via a password before accessing patient data.
- Device Controls: Manage hardware and electronic media containing patient information
- Same as physical / printed stuff with PHI - any USB drives, servers, etc. with PHI present should be behind locked doors or password-protected.
Technical Safeguards
- Access Control: Unique user identification and automatic logoff
- Don't leave your computer on indefinitely. Each staff should have their own login to each computer and each software program to log usage.
- Audit Controls: Monitor access to electronic patient information
- Make sure only appropriate staff have access, and any employees that leave should have permissions revoked / users deleted from programs.
- Integrity: Protect PHI from improper alteration or destruction
- Create backups when possible. If you use online software, ensure they have a backup plan for PHI (if they say they're HIPAA compliant, they must). The old military saying goes: two is one and one is none!
- Transmission Security: Encrypt data when sending outside of your clinic
- Email isn't secure. If you're sending any PHI over email, either password-protect documents, or ensure you have permission in writing from the patient.
- The fact that faxes are still used is silly. Just be sure that any faxes you send are only sent to those that you have a BAA agreement with - or are also a healthcare facility that has their own HIPAA compliance procedures.
Essential Security Measures
NOTE: If you aren't sure what any of this means - that's ok. Find a trusted IT person or company, and they should help you out. Even better - consider doing a trade with an IT person or company. They'll mostly spend time setting up your systems and then doing minor maintenance periodically - it's a trade worth making! Give them this list - a good IT person will explain what each item means in your terms and will ensure it's handled appropriately.
Password Management
- Require strong, unique passwords for all systems
- Implement multi-factor authentication where possible
- Use a password manager for secure credential storage
- I recommend Dashlane as a paid solution, Vaultwarden as a free, self-hosted, open-source solution.
- Regular password updates and security reviews
Data Encryption
- At Rest: Encrypt all stored patient data
- In Transit: Use secure protocols for data transmission
- Email: Use encrypted email services for patient communication
- NOTE: While many email companies will promise encryption, email is extremely hard to encrypt. Either obtain patient permission to communicate via email, or utilize patient portals or other means to transmit PHI.
- Backup: Encrypt all backup files and storage media
Network Security
- Secure Wi-Fi networks with WPA3 encryption
- Regular firewall updates and monitoring
- Virtual Private Networks (VPNs) for remote access
- Network segmentation to isolate patient data systems
Security Tip
Never use public Wi-Fi for accessing patient information. Always use a VPN or cellular connection when working remotely to ensure data transmission security.
Business Associate Agreements (BAAs)
Any vendor that handles patient data on your behalf requires a signed Business Associate Agreement. You should have a generic one on hand just in case, but most vendors will have one of their own that you'll sign together.
Ask your malpractice insurance provider for a generic BAA agreement - they should have one on hand you can use!
Risk Assessment and Management
Here's a few items that once you have some room in your schedule, you can put on a list for an office manager or admin assistant to make sure these items are happening:
Annual Risk Assessments
Conduct comprehensive annual assessments covering:
- Physical security vulnerabilities
- Technical system weaknesses
- Administrative process gaps
- Workforce security awareness
Documentation Requirements
Maintain detailed records of:
- Security policies and procedures
- Training completion records
- Risk assessment findings
- Incident response activities
- System access logs
What if there's a Data Breach?
Don't panic. The worst thing you can do is ignore the problem. Here's a quick step-by-step in case something happens:
Immediate Response (0-24 hours)
- Contain the breach - Stop ongoing unauthorized access
- Assess the scope - Determine what data was compromised
- Document everything - Create detailed incident records
- Notify key personnel - Alert your security officer and legal counsel / malpractice
Your legal counsel / malpractice company will likely come up with future plans on how to deal with the breach. It would likely look something like this:
Short-term Response (1-30 days)
- Risk assessment - Evaluate potential harm to patients
- Notification requirements - Determine if breach notification is required
- Patient notification - Notify affected patients within 60 days if required
- Regulatory reporting - Report to HHS within 60 days if required
Long-term Response (30+ days)
- Root cause analysis - Identify how the breach occurred
- System improvements - Implement additional safeguards
- Policy updates - Revise security procedures as needed
- Staff retraining - Address any workforce security gaps
You can do this!
HIPAA compliance might seem daunting - but just know that if you treat Patient Health Information like it's valuable information that deserves attention, you're off to a good start.
Utilize your network of professionals - including your own malpractice provider, any lawyer friends or acquaintances you have, or those in our Skool community below.
Have a question? Ask the DirectCareTools community...
Join our community of DPC owners and providers on Skool. Ask questions and get real answers from Jason, DPC physicians, and other Direct Care owners.