HIPAA Compliant IT Services: The Complete Guide for Healthcare Practices
Risk assessments, BAAs, compliant email and texting, EHR and telehealth security, real penalty costs, and audit prep — the full HIPAA IT guide for practices.
By Scott McAuley · Aug 3, 2026 · 13 min read
Here is the uncomfortable truth about HIPAA compliance: you cannot buy it. There is no software, no server, no IT contract that makes a practice "HIPAA compliant," because HIPAA doesn't certify products — it regulates how your organization handles protected health information, every day, across people, processes, and technology.
What you *can* do is build an IT foundation on which compliance is achievable, documented, and defensible — and that's where most practices quietly fail. Not because anyone is careless with patients, but because the practice grew, technology accumulated, and nobody ever mapped what HIPAA actually requires onto what the IT setup actually does.
This guide is that map. It's written for practice owners, administrators, and office managers — not IT people — and it covers the whole territory: what the rules require, the risk assessment you're legally obligated to perform, business associate agreements, compliant email and messaging, EHR and telehealth infrastructure, what violations genuinely cost, and how to be ready when a regulator or auditor asks for your documentation.
What HIPAA Actually Requires From Your Technology
HIPAA is three rules working together:
- The Privacy Rule governs who may access and disclose protected health information (PHI) and for what purposes.
- The Security Rule governs electronic PHI (ePHI) specifically — this is where nearly all IT obligations live.
- The Breach Notification Rule dictates what you must do, and how fast, when PHI is exposed.
The Security Rule organizes its requirements into three categories of safeguards. If you remember one framework from this guide, make it this one:
| Safeguard category | What it means | Examples in a real practice |
|---|---|---|
| Administrative | Policies, people, and process | Risk assessments, workforce training, sanction policies, access management procedures, a named security officer |
| Physical | Protecting places and devices | Locked server closets, screen positioning, workstation policies, secure disposal of old drives and copiers |
| Technical | The technology controls themselves | Unique logins, automatic logoff, encryption at rest and in transit, audit logging, access controls |
Notice something: only one of the three categories is about technology. A practice with perfect firewalls and no training program, no policies, and no risk assessment is not compliant — it's just well-equipped and undocumented. Any IT provider who talks only about tools is solving a third of the problem. (Our [compliance support](/services/compliance-support) practice exists precisely because the other two-thirds is where audits are won and lost.)
A second concept worth knowing: Security Rule specifications are either *required* or *addressable*. Addressable does not mean optional — it means you must implement it, implement an equivalent alternative, or document a legitimate reason it doesn't apply. "We never got around to it" is not an addressable determination. It's a finding.
The Security Risk Assessment: Your Legal Starting Point
The single most commonly missed HIPAA obligation is also the foundational one: a documented security risk assessment (SRA). It is explicitly required, it is the first thing OCR (the Office for Civil Rights, HIPAA's enforcer) asks for in an investigation, and "no or inadequate risk assessment" appears in enforcement action after enforcement action.
A real SRA:
1. Inventories every place ePHI lives and moves — EHR, email, texts, billing systems, laptops, phones, backup drives, the fax-to-email service everyone forgot about
2. Identifies threats and vulnerabilities to each — from ransomware to a stolen laptop to a departed employee whose login still works
3. Rates likelihood and impact so you can prioritize honestly
4. Documents your current controls and the gaps
5. Produces a remediation plan with owners and dates — and evidence over time that you actually worked the plan
That last point matters more than practices realize: regulators treat a risk assessment with an un-worked remediation plan as worse than naive — it's documented knowledge of a problem you chose not to fix.
Cadence: perform one annually, and additionally whenever something material changes — new EHR, new location, merger, move to telehealth. If your practice has never done one, that's the first project, before any tool purchases. It's also, conveniently, the same discipline as a general [IT assessment](/resources/what-is-it-assessment-houston-business), just with a regulatory lens.
Business Associate Agreements: The Paperwork That Decides Liability
Every vendor that creates, receives, stores, or transmits PHI on your behalf is a business associate, and federal law requires a signed Business Associate Agreement (BAA) with each one before PHI flows. No BAA means you are out of compliance the moment data moves — regardless of how secure the vendor is.
Walk your vendor list with this lens and the gaps appear fast:
- Your IT provider — they have admin access to everything; an MSP serving healthcare must sign a BAA without hesitation. (If a prospective provider hedges on this, the meeting is over. More red flags like this in our guide to [HIPAA-ready IT support for Houston medical practices](/resources/hipaa-compliant-it-support-houston-medical-practices).)
- Email and productivity platforms — Microsoft 365 and Google Workspace both offer BAAs, but only on certain plans, and only if you actually execute them and configure the services correctly. The plan tier your practice bought matters; our comparison of [Microsoft 365 vs. Google Workspace](/resources/microsoft-365-vs-google-workspace-houston-businesses) touches the licensing details.
- EHR and billing vendors — usually covered, but verify the BAA is signed and on file, not just "included in the terms somewhere."
- Backup, phone/VoIP, texting, transcription, shredding, cloud storage — the classic forgotten category. If voicemails, call recordings, or texts can contain patient information, those vendors need BAAs too.
Keep every BAA in one place, know what each one obligates the *vendor* to do, and review the list annually as part of the SRA. When a vendor has a breach, the first question is "was there a BAA, and what did it say?"
Compliant Email, Messaging, and Patient Communication
Communication is where compliant practices leak. The EHR is locked down; then a staff member emails a schedule with patient names to their personal Gmail to work from home, and you have a reportable incident.
The baseline for email: encryption in transit and at rest, a signed BAA with the platform, access controls and MFA on every mailbox, and — critically — configuration. A Microsoft 365 tenant with a BAA is not compliant out of the box; encryption policies, data loss prevention rules, and retention settings have to be deliberately set up. This is routine work for an IT partner who lives in healthcare and a common gap for one who doesn't.
Patient texting deserves its own paragraph, because it's simultaneously the communication channel patients most prefer and the one most practices are doing non-compliantly. Standard SMS is not encrypted, and texting PHI over it from personal phones is one of the most common violations in small practices. The rules, the consent requirements, and the compliant platform options are a full topic of their own — our sister publication Talk Is Cheap covers healthcare communications compliance in depth in its guide to [HIPAA compliant communications](https://talkischeap.io/hipaa-compliant-communications), including what makes a texting platform acceptable and how to document patient consent. The short version for this guide: no PHI over standard SMS, ever; use a platform with encryption and a BAA; and put it in your policies so "everyone knew" is documented.
Phone systems count too. Modern VoIP platforms store voicemails and call recordings as data — if those can contain PHI, the platform needs a BAA and proper configuration like any other system. Our [VoIP phone systems](/services/voip-phone-systems) practice handles that configuration for healthcare clients as standard.
EHR Hosting and Support Done Right
Your EHR is the crown jewels, and its compliance posture depends on decisions that are easy to get wrong:
- Cloud vs. on-premise. Cloud EHRs shift much of the infrastructure security burden to the vendor (verify it in the BAA); on-premise EHRs make *you* responsible for server hardening, patching, physical security, and backup. Neither is automatically better, but on-premise without dedicated IT support is where we find the scariest gaps — unpatched servers running years-old software with full patient databases on them.
- Access control discipline. Unique logins per user (shared logins are both a violation and an audit-trail killer), role-based permissions so the front desk doesn't see what the physician sees, automatic logoff on exam-room workstations, and a same-day deprovisioning process when staff leave. Departed-employee accounts that still work are among the most common findings in practice assessments.
- Audit logging. The Security Rule requires the ability to examine who accessed what. Your EHR logs this — but logs nobody reviews are theater. Someone (internal or your IT partner) should be reviewing access reports for anomalies, like an employee opening records of patients they never treat.
- Integration sprawl. Every lab interface, e-prescribing connection, and billing integration is another data flow to secure and another line in your risk assessment.
This is the daily work of our [healthcare IT practice](/industries/healthcare) — supporting the EHR is table stakes; supporting it *defensibly* is the job.
Telehealth Security
Telehealth went from novelty to standard of care in a few short years, and the temporary enforcement discretion that let practices use consumer video tools during the public health emergency is over. The current standard:
- A video platform with encryption and a signed BAA (consumer-grade FaceTime/personal Zoom setups don't qualify)
- Access controls on sessions — waiting rooms, authenticated links, no publicly guessable meeting URLs
- Endpoint security on the devices clinicians use from home — practice-managed, encrypted, screen-locked, not the family laptop
- Network guidance for remote clinicians, ideally VPN or zero-trust access back to practice systems rather than raw home Wi-Fi
- Recording policy — decide whether sessions are ever recorded, and if so where recordings live, since they're PHI with unusually high sensitivity
Telehealth also expands your risk assessment scope: every clinician's home setup is now part of your environment. Practices rarely update the SRA to reflect this; auditors have noticed.
Backup, Disaster Recovery, and the Houston Factor
HIPAA explicitly requires a data backup plan, a disaster recovery plan, and an emergency mode operation plan — the ability to keep critical functions running during an incident. This is one of the few places where federal law and Gulf Coast geography say exactly the same thing.
A compliant, Houston-grade posture looks like: encrypted backups following the 3-2-1 pattern (multiple copies, multiple media, at least one off-site and out of the flood plain), documented recovery time objectives for the EHR, *tested* restores on a schedule — an untested backup is a hope, not a plan — and a written procedure for operating when systems are down (paper workflows, phone triage, patient communication). Ransomware makes this double-duty: the same tested, isolated backups that get you through a hurricane are your leverage against extortion. Our [backup and disaster recovery](/services/backup-disaster-recovery) service builds these plans with the HIPAA documentation included, because the plan you can't produce in writing doesn't exist as far as an auditor is concerned.
What Violations Actually Cost
HIPAA penalties are tiered by culpability — how much you knew, and whether you tried:
| Tier | Culpability | Per-violation range* | Annual cap* |
|---|---|---|---|
| 1 | Unknowing (couldn't reasonably have known) | ~$140 – $71,000 | ~$2.1M |
| 2 | Reasonable cause (knew or should have, but not neglect) | ~$1,400 – $71,000 | ~$2.1M |
| 3 | Willful neglect, corrected within 30 days | ~$14,000 – $71,000 | ~$2.1M |
| 4 | Willful neglect, not corrected | ~$71,000+ | ~$2.1M |
*Figures are adjusted for inflation annually and rounded here — treat as directional, and see the fact-check appendix.
Read the table's real message: the penalty structure is a referendum on *effort*. An organization with a current risk assessment, signed BAAs, training records, and a worked remediation plan that still gets breached lands in the low tiers — and OCR frequently resolves such cases with corrective action plans rather than fines. An organization that can't produce a risk assessment is, almost by definition, in willful neglect territory.
And the fine is rarely the biggest number. Breach notification costs, mandatory credit monitoring, legal fees, state attorney general actions, the practice-crippling distraction of an investigation, and patient trust are routinely more expensive than the penalty. For a small practice, the operational disruption alone — see our analysis of [the real cost of IT downtime](/resources/real-cost-it-downtime-houston-small-businesses) — can exceed anything OCR levies.
Being Audit-Ready (Instead of Audit-Scared)
Audit preparation is mostly a filing exercise — *if* you've been doing the work. Maintain a binder (physical or digital) that contains:
1. Current and prior security risk assessments, with remediation plans and evidence of progress
2. Policies and procedures — access management, sanctions, incident response, device and media disposal, remote work
3. Training records — who was trained, on what, when, with new-hire and annual cadence
4. Every signed BAA
5. Incident log — even minor incidents, with your response documented; a practice with zero recorded incidents ever looks unexamined, not clean
6. System documentation — asset inventory, access reviews, backup test results
If a records request arrived tomorrow with a two-week deadline, could you produce all six? That question — not any single tool — is the honest measure of your compliance posture. Practices that can answer yes sleep through OCR letters. Practices that can't should start with item one, this quarter.
Where Automation Fits (Carefully)
Healthcare practices are adopting AI phone agents, automated scheduling, and intake tools fast — and every one of them touches PHI, which means every one of them belongs in your risk assessment and BAA file like any other vendor. Done right, automation actually *improves* compliance: consistent scripts, complete logs, no sticky notes with patient callbacks. Done casually, it's a new breach surface with a vendor you never vetted. Our sister company Talos Automation has published a thorough treatment of running [AI voice agents in medical practices](https://talosautomation.ai/blog/complete-guide-ai-voice-agents-medical-practices) under HIPAA — BAAs, data flows, and where recordings live — which we recommend before piloting anything. On the infrastructure side, our own [AI and automation](/services/ai-automation) team handles the integration and security review when clients bring these tools in.
Getting From Here to Compliant
If this guide has surfaced gaps, the sequence is straightforward, and it's the same one we run for new healthcare clients:
1. Risk assessment first — you can't fix what you haven't mapped
2. Close the paperwork gaps — BAAs, policies, training records
3. Remediate technical findings by risk order — usually MFA, encryption, access cleanup, and backup testing lead the list; [the general cybersecurity baseline for SMBs](/resources/small-business-cybersecurity-guide) covers each of these in depth
4. Operationalize — annual assessments, quarterly access reviews, ongoing training, so compliance becomes maintenance instead of a crisis project
Texas Management Group has supported Houston-area healthcare organizations since 2014 — practices in and around the largest medical complex in the world don't get to treat compliance as optional, and neither do we. If you want an honest read on where your practice stands, [contact us](/contact) for a HIPAA-focused assessment: we'll map your gaps, hand you the findings in writing, and you can act on them with us or without us.
*Scott McAuley is the founder and CEO of Texas Management Group, and founder of Talos Automation and Talk Is Cheap — 25+ years running IT, communications, and automation for Texas businesses.*
Frequently Asked Questions
What makes an IT service "HIPAA compliant"?
Strictly, nothing — HIPAA doesn't certify products or providers. A HIPAA-capable IT service is one that signs a Business Associate Agreement, implements the Security Rule's administrative, physical, and technical safeguards across your environment, and produces the documentation (risk assessments, policies, logs) that makes your compliance defensible.
Is a HIPAA risk assessment really required, or just recommended?
Required. The Security Rule explicitly mandates a documented security risk assessment, and it's the first document regulators request in an investigation. Best practice is annually, plus after any material change like a new EHR, a new location, or adopting telehealth.
Who needs to sign a Business Associate Agreement with my practice?
Every vendor that creates, receives, stores, or transmits PHI on your behalf: your IT provider, email platform, EHR and billing vendors, backup and cloud services, phone/VoIP and texting platforms, transcription, and shredding services. No BAA means non-compliance the moment PHI flows, regardless of how secure the vendor is.
Can my practice text patients under HIPAA?
Not over standard SMS — it's unencrypted. Texting PHI requires a secure messaging platform with encryption and a signed BAA, plus documented patient consent and a written policy. Appointment reminders with minimal information are lower-risk but should still follow a documented approach.
Is regular Microsoft 365 or Google Workspace HIPAA compliant?
They can be — both offer BAAs on qualifying business plans — but neither is compliant out of the box. You must be on an eligible plan, execute the BAA, and configure encryption, data loss prevention, retention, and MFA correctly. An unconfigured tenant with a signed BAA is still a finding waiting to happen.
What do HIPAA violations cost?
Civil penalties are tiered by culpability, ranging from roughly $140 to over $71,000 per violation with annual caps above $2 million per provision (inflation-adjusted). In practice, breach response costs — notification, legal fees, credit monitoring, lost patient trust — routinely exceed the fines. Documented good-faith effort is the biggest factor in landing in the low tiers.
Does HIPAA apply to telehealth visits?
Fully. The pandemic-era enforcement discretion for consumer video tools has ended. Telehealth now requires an encrypted platform with a signed BAA, session access controls, secured clinician devices, and inclusion of remote setups in your risk assessment.