HIPAA Compliance for EHR Systems: Requirements, Checklist & Vendor Guide
Complete guide to HIPAA compliance when selecting and using an EHR system. Includes compliance checklist, vendor comparison, common violations, risk assessment guidance, and state privacy law overview.
Choosing a HIPAA compliant EHR is one of the most consequential decisions your practice will make. It is not simply a technology purchase -- it is a compliance decision that affects your legal exposure, your patients' privacy, and your practice's financial future. A single HIPAA violation can result in fines exceeding $2 million, and the Office for Civil Rights (OCR) has made clear through enforcement actions that "I trusted my EHR vendor" is not a defense.
This guide covers what every practice -- from solo providers to multi-specialty groups -- needs to understand about HIPAA compliance in the context of EHR selection, implementation, and daily use. It is distinct from our broader EHR security guide, which addresses the full spectrum of healthcare cybersecurity. Here, the focus is specifically on HIPAA: what the law requires, how those requirements translate to EHR features and vendor obligations, and how to verify that your practice and your vendor are meeting those requirements together.
If you are still evaluating EHR systems, our EMR directory lets you compare over 700 platforms, and our buying guide covers the full vendor selection framework.
HIPAA and EHR: What Every Practice Must Know
The Health Insurance Portability and Accountability Act (HIPAA) establishes the federal floor for protecting patient health information. For practices using electronic health records, three HIPAA rules are directly relevant.
The Privacy Rule (45 CFR Part 160 and Part 164, Subparts A and E) governs the use and disclosure of protected health information (PHI). It establishes patients' rights to access their records, sets limits on who can see what, and requires a minimum necessary standard for all PHI disclosures. When you configure role-based access in your EHR, you are implementing the Privacy Rule.
The Security Rule (45 CFR Part 164, Subpart C) specifically addresses electronic PHI (ePHI) and requires administrative, physical, and technical safeguards. This is the rule that drives the majority of EHR compliance requirements -- encryption, access controls, audit logs, and disaster recovery all flow from the Security Rule.
The Breach Notification Rule (45 CFR Part 164, Subpart D) requires notification to affected individuals, HHS, and in some cases the media when unsecured PHI is breached. Your EHR vendor's breach notification process and your practice's incident response plan both fall under this rule.
Shared Responsibility: The Critical Concept
HIPAA compliance when using an EHR system is a shared responsibility between your practice (the covered entity) and your EHR vendor (the business associate). Your vendor is responsible for building a system with the technical safeguards HIPAA requires. You are responsible for configuring, using, and maintaining that system in a HIPAA compliant manner.
This shared model is where most compliance failures occur. A vendor can deliver an EHR with strong encryption, granular access controls, and thorough audit logging -- but if your practice uses shared logins, never reviews audit logs, and has not conducted a risk assessment in three years, you are not HIPAA compliant regardless of your vendor's capabilities.
⚠️ The Biggest HIPAA Misconception
"If my EHR vendor is HIPAA compliant, my practice is automatically HIPAA compliant." This is false, and believing it has cost practices millions in OCR settlements. Your vendor provides the tools. You are responsible for using them correctly, training your staff, implementing policies, conducting risk assessments, and maintaining physical safeguards. HIPAA compliance is not a product you buy -- it is a program you build and maintain.
HIPAA Requirements That Affect EHR Selection
When evaluating EHR vendors through a HIPAA compliance lens, you need to assess specific technical and contractual requirements defined in the Security Rule. The following sections map the most critical HIPAA provisions directly to what you should look for -- and demand -- in your EHR vendor.
Business Associate Agreement (BAA) -- Non-Negotiable
Under 45 CFR 164.502(e) and 164.308(b), any entity that creates, receives, maintains, or transmits PHI on your behalf must execute a Business Associate Agreement before accessing any patient data. Your EHR vendor is unambiguously a business associate.
A BAA is not a marketing checkbox. It is a legally binding contract that must specify permitted and required uses and disclosures of PHI, the vendor's obligation to implement appropriate safeguards, breach reporting timelines and procedures (look for 24 to 48 hours, not "as soon as reasonably practicable"), the vendor's obligation to ensure sub-contractors also agree to equivalent BAA terms, and requirements for return or destruction of PHI upon contract termination.
Red flags to watch for: a vendor that asks you to sign their standard Terms of Service and claims it includes BAA provisions (it rarely does); a BAA that does not cover sub-processors (cloud hosting providers, analytics services, AI tools); a BAA with a breach notification timeline longer than 72 hours; and a vendor that cannot produce a BAA upon request during the sales process.
💡 Review the BAA with a Healthcare Attorney
Do not sign a BAA without legal review. Healthcare attorneys routinely identify gaps in vendor-provided BAAs, including missing sub-processor coverage, one-sided liability limitations, and vague breach notification language. A one-hour attorney review ($300 to $500) can prevent compliance gaps that cost six figures to remediate.
Access Controls (45 CFR 164.312(a))
The HIPAA Security Rule requires four access control implementation specifications for any system containing ePHI.
Unique user identification (Required): Every person who accesses the EHR must have a unique login. Shared accounts -- "front desk login," "nurse station account" -- are a direct HIPAA violation. When evaluating an EHR, verify that the system requires unique credentials and that the pricing model does not create perverse incentives to share logins (per-user pricing that encourages account sharing is a systemic compliance risk).
Emergency access procedure (Required): The EHR must support "break the glass" access that allows authorized users to override normal access restrictions during a medical emergency. Every break-the-glass event must be logged and subject to post-event review.
Automatic logoff (Addressable): The system must terminate sessions after a defined period of inactivity. Configure your EHR for 10 to 15 minutes on workstations and 5 minutes on mobile devices. An EHR that does not support automatic session timeout is a non-starter.
Encryption and decryption (Addressable): The system must support encryption of ePHI. While HIPAA designates this as "addressable" rather than "required," failing to encrypt ePHI in 2026 is indefensible. OCR treats the absence of encryption as a significant aggravating factor in every enforcement action.
Audit Controls (45 CFR 164.312(b))
HIPAA requires mechanisms that record and examine activity in information systems containing ePHI. Your EHR audit log must capture, at minimum, the identity of the user who accessed the record, the date and time of access, the specific patient record accessed, the action performed (view, create, edit, delete, print, export), the originating IP address or device, and success or failure status.
Beyond what the logs capture, you need to verify retention requirements. HIPAA requires that documentation of policies and procedures be retained for six years from the date of creation or the date it was last in effect. Your EHR vendor should retain audit logs for at least six years, and you should have unrestricted access to export those logs.
Critically, logging alone is not compliance. You must regularly review audit logs to detect unauthorized access. Ask your EHR vendor whether they offer anomaly detection, automated alerts for unusual access patterns, and reporting dashboards that make log review practical rather than theoretical.
Integrity Controls (45 CFR 164.312(c))
HIPAA requires electronic measures to confirm that ePHI has not been improperly altered or destroyed. In practice, this means your EHR must implement data integrity verification mechanisms such as checksums, digital signatures, or cryptographic hashing for clinical documents, version control that tracks every change to a patient record with a complete audit trail, database-level protections against unauthorized modification, and backup verification processes that confirm data integrity after restoration.
When evaluating vendors, ask specifically how clinical document integrity is maintained. Can a database administrator modify a patient record without leaving an audit trail? If the answer is anything other than an unequivocal "no," the system fails this requirement.
Transmission Security (45 CFR 164.312(e))
All ePHI transmitted over electronic networks must be protected against unauthorized access. The practical standard in 2026 is TLS 1.2 at minimum, with TLS 1.3 preferred, for all data in transit. This includes communication between your browser and the EHR server, between the EHR application and its database, between the EHR and integrated systems (labs, pharmacies, HIEs), and secure messaging between providers and patients.
Any EHR vendor still supporting TLS 1.0 or 1.1 should be immediately disqualified. These protocols have known vulnerabilities and have been deprecated by every major standards body. Check whether the vendor supports HSTS (HTTP Strict Transport Security) and certificate pinning for mobile applications.
Data Backup and Disaster Recovery (45 CFR 164.308(a)(7))
HIPAA's contingency planning requirements mandate a data backup plan, a disaster recovery plan, an emergency mode operations plan, and regular testing of these plans. For EHR systems, this translates to specific recovery objectives.
Recovery Point Objective (RPO) defines the maximum acceptable data loss measured in time. For most ambulatory practices, an RPO of 1 hour means backups must occur at least hourly. For high-volume practices or those handling time-sensitive clinical decisions, an RPO of 15 minutes may be appropriate.
Recovery Time Objective (RTO) defines the maximum acceptable downtime. A 4-hour RTO is reasonable for most practices -- meaning the vendor must restore full EHR functionality within 4 hours of any disruption.
Ask your vendor for documented RPO and RTO commitments, geo-redundant backup storage across physically separated data centers, immutable backup copies that ransomware cannot encrypt or delete, and evidence of a disaster recovery test conducted within the past 12 months. An untested disaster recovery plan is not a plan -- it is an assumption.
ℹ️ Cloud vs On-Premise Backup Obligations
If you use a cloud-based EHR, disaster recovery is primarily the vendor's responsibility -- but you must verify their capabilities and include RPO/RTO commitments in your BAA. If you use an on-premise EHR, the full burden of backup and disaster recovery falls on your practice. This is one of the strongest arguments for cloud deployment: major cloud EHR vendors invest in backup infrastructure that no single practice could replicate. For a deeper comparison, see our cloud EHR guide.
HIPAA Compliance Checklist for EHR Evaluation
The following checklist consolidates every HIPAA requirement that should factor into your EHR vendor evaluation. Use it as a scoring tool during the selection process -- any vendor that cannot satisfy the "How to Verify" column for a given requirement warrants serious scrutiny.
EHR Vendor HIPAA Compliance Comparison
Not all EHR vendors invest equally in HIPAA compliance infrastructure. The following comparison evaluates ten widely adopted EHR platforms across the HIPAA compliance dimensions that matter most when selecting a vendor. For detailed vendor profiles beyond compliance, visit our EMR comparison tool.
Key takeaways from this comparison. Every major EHR vendor now provides a BAA and supports MFA -- these are table stakes. The differentiators that separate strong HIPAA compliance posture from baseline are HITRUST certification (significantly more rigorous than SOC 2 alone), TLS 1.3 support, anomaly detection in audit logging, rapid breach notification timelines, and FHIR-based data portability.
Enterprise vendors like Epic and Oracle Health lead on compliance depth because their hospital system customers require it. Mid-market vendors like athenahealth provide strong compliance infrastructure at a more accessible price point. Smaller vendors may meet baseline HIPAA requirements but lack the advanced compliance certifications and monitoring capabilities that reduce risk.
💡 Do Not Rely on Marketing Claims
Any vendor can claim HIPAA compliance on their website. The verification step is what matters. Request the actual SOC 2 Type II report (not a summary), the HITRUST certification letter, and written answers to every question in the checklist above. Attach vendor responses as an exhibit to your contract. Verbal assurances from a sales representative carry zero weight in an OCR investigation.
ONC Certification vs HIPAA Compliance
One of the most dangerous misconceptions in EHR selection is conflating ONC certification with HIPAA compliance. They are related but fundamentally different, and understanding the distinction is essential.
ONC certification (through the ONC Health IT Certification Program under the 2015 Edition Cures Update criteria) verifies that an EHR system meets specific technical standards for functionality, interoperability, and security capabilities. It is tied to the Promoting Interoperability (formerly Meaningful Use) incentive program. ONC certification confirms the system has the technical capability to support security functions like access controls, audit logging, encryption, and session timeouts.
HIPAA compliance is a broader, ongoing obligation that encompasses how the system is configured, used, and maintained -- not just what it can do. HIPAA addresses administrative safeguards (risk assessments, workforce training, access management policies), physical safeguards (workstation security, device controls), and operational practices that ONC certification does not evaluate.
A vendor can be ONC certified but not fully HIPAA compliant. An ONC-certified EHR with MFA disabled, default admin passwords unchanged, audit logging turned off, and no BAA signed is certified but in clear HIPAA violation. Conversely, a HIPAA compliant EHR that lacks certain interoperability features may not qualify for ONC certification even though it meets every HIPAA security requirement.
ℹ️ ONC Certification: Necessary but Not Sufficient
Think of ONC certification as confirming the EHR has the right tools in the toolbox. HIPAA compliance is about whether those tools are being used correctly every day. Your vendor evaluation must assess both: ONC certification for baseline capability and HIPAA compliance posture for real-world security. Never let a vendor substitute one for the other.
Common HIPAA Violations Involving EHR Systems
Understanding how HIPAA violations actually occur in EHR environments helps you identify and address vulnerabilities in your own practice. The following categories represent the most frequent EHR-related violations found in OCR enforcement actions and settlements.
Insufficient Access Controls (Shared Logins, No MFA)
Shared logins remain one of the most common HIPAA violations OCR encounters during investigations. When multiple staff members use the same EHR account, the audit trail becomes meaningless -- you cannot determine who accessed a specific patient record when. This directly violates the unique user identification requirement (45 CFR 164.312(a)(2)(i)).
The failure to implement multi-factor authentication compounds the risk. Compromised credentials are the leading initial attack vector in healthcare breaches, and a single stolen password to a shared account can expose the entire patient database.
In 2023, Yakima Valley Memorial Hospital paid $240,000 to settle with OCR after 23 security guards were found to have used their EHR access to snoop on patient records. The lack of adequate access controls and monitoring allowed the unauthorized access to persist for months before detection.
Unencrypted ePHI (Laptops, Mobile Devices)
Stolen or lost devices containing unencrypted ePHI account for a significant percentage of reported HIPAA breaches. Under HIPAA's safe harbor provision, the Breach Notification Rule does not apply if the lost or stolen data was encrypted according to NIST standards. Without encryption, the loss of a single laptop triggers a full breach notification.
Lifespan Health System (Rhode Island) paid $1,040,000 in 2020 to settle a breach caused by the theft of a single unencrypted laptop from an employee's car. The laptop contained ePHI of approximately 20,000 patients. Had the laptop been encrypted, no breach notification would have been required.
⚠️ Encryption Is Your Safe Harbor
Under 45 CFR 164.402(2), properly encrypted ePHI that is lost or stolen is not considered a breach. AES-256 encryption on every device that accesses your EHR -- laptops, tablets, smartphones, and USB drives -- is the single most cost-effective HIPAA protection you can implement. The cost of enabling full-disk encryption is zero (BitLocker, FileVault are built into modern operating systems). The cost of a breach from an unencrypted device routinely exceeds $1 million.
Improper Disposal of ePHI
When devices that accessed your EHR are retired, recycled, or disposed of, any ePHI on them must be securely destroyed. This includes hard drives, solid-state drives, mobile devices, and even printers with internal storage.
FileFax Inc. paid $100,000 and New England Dermatology and Laser Center paid $300,640 in separate OCR settlements related to improper disposal of records containing PHI. Any device that has connected to your EHR must be wiped according to NIST SP 800-88 standards before leaving your physical control.
Failure to Conduct Risk Assessments
Risk analysis (45 CFR 164.308(a)(1)(ii)(A)) is the cornerstone HIPAA requirement, and its absence is the most commonly cited deficiency in OCR enforcement actions. Between 2020 and 2025, failure to conduct an adequate risk assessment appeared in over 80% of HIPAA settlements exceeding $500,000.
Premera Blue Cross paid $6.85 million in 2020 -- the second-largest HIPAA settlement in history at the time -- after OCR found that the organization failed to conduct an adequate enterprise-wide risk analysis. The settlement followed a breach that exposed 10.4 million patient records.
Your risk assessment must specifically address your EHR system, including how it is configured, who has access, how data flows between integrated systems, and what vulnerabilities exist in your current deployment.
Inadequate BAAs with EHR Vendors
Operating without a BAA -- or with an inadequate one -- exposes both the practice and the vendor to liability. OCR has imposed penalties on both sides of the relationship.
North Memorial Health Care paid $1.55 million in 2016 for, among other violations, failing to execute a BAA with a major contractor that had access to its patient data. The contractor, Accretive Health, had access to the ePHI of 289,904 patients without a signed BAA in place.
⚠️ Real HIPAA Penalty: $16 Million
Anthem Inc. paid $16 million in 2018 -- the largest HIPAA settlement in history -- after a breach affecting 78.8 million individuals. OCR's investigation found multiple violations including failure to conduct an adequate risk assessment, failure to identify and address risks to ePHI, insufficient access controls, and failure to implement appropriate minimum necessary policies. Your EHR compliance posture must address every one of these areas to avoid becoming a case study.
HIPAA Risk Assessment for EHR Systems
A HIPAA risk assessment is not a one-time exercise. It is the foundation of your compliance program and the first thing OCR asks for during any investigation. Here is what the process involves and how to execute it effectively.
What a HIPAA Risk Assessment Covers
A thorough risk assessment for your EHR system evaluates threats and vulnerabilities across every dimension of ePHI handling. The assessment must identify all locations where ePHI is created, received, maintained, or transmitted (your EHR server, backup systems, laptops, mobile devices, paper printouts, integrated systems), evaluate threats to each location (malware, unauthorized access, physical theft, natural disasters, insider threats), assess the likelihood and impact of each threat, evaluate current safeguards and their effectiveness, and determine residual risk after existing controls are applied.
The output is a documented risk register with risk ratings and a remediation plan that prioritizes the highest-risk items.
How Often to Conduct Risk Assessments
HIPAA does not specify an exact frequency, but the requirement is for ongoing risk management. In practice, this means conducting a full risk assessment at least annually and whenever significant changes occur. Significant changes that trigger a reassessment include implementing a new EHR system or major version upgrade, adding a telehealth module or mobile EHR access, changing EHR vendors or cloud hosting providers, opening a new office location, experiencing a security incident or breach, and significant changes in workforce (new roles, turnover, remote work policies).
Free Tools: HHS Security Risk Assessment Tool
HHS offers the free Security Risk Assessment (SRA) Tool designed specifically for small and medium healthcare practices. The tool walks you through the risk assessment process with guided questions, automatically generates a risk report, and produces documentation that satisfies OCR's expectations for small practice risk analysis.
The SRA Tool is available for Windows download and as an iPad app. It covers all HIPAA Security Rule requirements and generates exportable reports. For practices with fewer than 25 providers, this tool is an excellent starting point that costs nothing to use.
When to Hire a Consultant
Consider engaging a HIPAA compliance consultant when your practice has more than 10 providers or multiple locations, you are implementing a new EHR and want to ensure HIPAA is addressed during the implementation process, you have experienced a breach or received an OCR inquiry, your internal team lacks compliance expertise, or your risk assessment reveals complex issues requiring specialized remediation.
HIPAA compliance consultants typically charge $150 to $300 per hour or $5,000 to $25,000 for a full risk assessment engagement. Given that OCR penalties routinely exceed $100,000, the investment is easily justified for practices with material compliance gaps.
💡 Document Everything
The single most important HIPAA compliance habit is documentation. Document your risk assessments, your remediation actions, your training sessions, your policy reviews, and your vendor BAA management. OCR investigations focus heavily on what you can prove you did, not what you say you did. A well-documented compliance program with identified gaps is vastly preferable to an undocumented program that claims perfection.
HIPAA Compliance: Cloud EHR vs On-Premise EHR
The deployment model of your EHR directly affects how HIPAA compliance responsibilities are distributed. Understanding these differences helps you assess where your compliance obligations lie.
+ Pros
- Cons
For most ambulatory practices, cloud-based HIPAA compliant EHR platforms provide stronger overall compliance posture than what the same practice could achieve with on-premise infrastructure. The physical safeguards, disaster recovery capabilities, and security monitoring that major cloud providers deliver would cost hundreds of thousands of dollars to replicate independently.
The critical variable is the BAA. Your cloud EHR vendor's BAA must explicitly cover all services you use -- hosting, storage, backup, analytics, and any AI features that process ePHI. If the vendor uses sub-processors (AWS, Azure, Google Cloud), those sub-processors must also be covered by BAAs in the chain.
State Privacy Laws Beyond HIPAA
HIPAA sets the federal floor, but multiple state laws impose additional privacy requirements that affect your EHR operations. Failing to comply with state laws -- even if you are fully HIPAA compliant -- creates independent legal exposure.
California (CCPA/CMIA)
California's Confidentiality of Medical Information Act (CMIA) predates HIPAA and in several respects is stricter. CMIA requires patient authorization for disclosures that HIPAA permits under the treatment, payment, and healthcare operations (TPO) exception. The California Consumer Privacy Act (CCPA), as amended by the CPRA, generally exempts PHI already covered by HIPAA but applies to non-clinical patient data (marketing interactions, website analytics, billing inquiries). Practices operating in California must ensure their EHR handles both HIPAA and CMIA consent requirements.
Texas (THIPA)
The Texas Health Privacy Act (THIPA), codified as Texas Health & Safety Code Chapter 181, imposes stricter penalties than HIPAA and provides a private right of action -- meaning individual patients can sue for unauthorized disclosures. THIPA also restricts the use of ePHI for marketing purposes more aggressively than HIPAA's marketing limitations. Texas practices must ensure their EHR consent management and disclosure tracking satisfy both frameworks.
New York (SHIELD Act)
New York's Stop Hacks and Improve Electronic Data Security (SHIELD) Act expanded the definition of "private information" triggering breach notification obligations and imposed specific data security requirements on any entity holding New York residents' data, regardless of where the entity is located. For practices with New York patients, the SHIELD Act's security requirements overlap with but are not identical to HIPAA, and breach notification timelines may differ.
42 CFR Part 2 for Substance Abuse Records
If your practice treats patients with substance use disorders, 42 CFR Part 2 imposes confidentiality protections that exceed HIPAA in critical ways. Part 2 records require written patient consent for nearly all disclosures, including to other treating providers. Your EHR must support record segmentation and granular consent tracking to prevent unauthorized disclosure of SUD treatment information.
The 2024 final rule aligned some Part 2 provisions with HIPAA for TPO purposes but retained key protections including restrictions on use in criminal proceedings and re-disclosure limitations. For a detailed treatment of 42 CFR Part 2 EHR requirements, see our behavioral health EMR guide.
ℹ️ State Law Interaction with HIPAA
When HIPAA and a state privacy law conflict, the stricter standard controls. This is called HIPAA preemption -- federal law preempts state law only when the state law is less protective of patient privacy. If the state law provides greater privacy protection, the state law applies. Your compliance program must account for the laws of every state where your patients reside, not just the state where your practice is located.
HIPAA Compliance for Telehealth EHR
Telehealth introduces additional HIPAA compliance surfaces that do not exist in a traditional office-based EHR environment. If your practice conducts virtual visits, your HIPAA compliance program must address the following considerations.
Video platform compliance: Every component of the telehealth video workflow must be HIPAA compliant. The video platform must use TLS 1.2+ for signaling and SRTP or DTLS for media streams. Sessions must be access-controlled, logged, and subject to automatic timeout. If sessions are recorded (for documentation or quality assurance), recordings must be encrypted at rest and covered under a BAA.
BAA coverage for the full telehealth chain: Your BAA must cover not just the EHR vendor but every service that touches ePHI during a telehealth encounter. This includes the video platform (if separate from the EHR), any AI scribe or transcription service processing the audio, SMS or email services used to send appointment links containing patient identifiers, and cloud infrastructure hosting any component of the telehealth workflow.
Provider and patient location tracking: HIPAA audit requirements extend to telehealth sessions. Your system should log the provider's and patient's locations at the time of the visit, which also supports compliance with state telehealth licensing requirements.
Home office and remote work security: When providers conduct telehealth visits from home, HIPAA physical safeguard requirements follow. This means private spaces where conversations cannot be overheard, screens that cannot be viewed by unauthorized persons, secured home networks, and workstation security policies that apply outside the clinic.
For a thorough guide to telehealth EHR features, vendor comparison, and reimbursement policies, see our telehealth EHR integration guide.
⚠️ Consumer Platforms Are Not HIPAA Compliant
Standard consumer versions of Zoom, Google Meet, FaceTime, and Skype are not HIPAA compliant and must not be used for telehealth visits involving ePHI. Some platforms offer HIPAA-compliant healthcare editions (Zoom for Healthcare, Google Workspace for Healthcare) with BAA support, encryption, and audit logging -- but these are separate products from the consumer versions. Verify the specific edition and confirm a BAA before conducting any virtual visit.
Building a HIPAA Compliance Program Around Your EHR
Passing a HIPAA compliance checklist during vendor selection is the beginning, not the end. Sustained compliance requires an ongoing program with the following elements.
Designate a HIPAA Privacy Officer and Security Officer. These roles are required under 45 CFR 164.308(a)(2) and 45 CFR 164.530(a)(1). In small practices, one person can fill both roles. The privacy officer oversees PHI use and disclosure policies. The security officer manages technical and physical safeguards, including EHR security configuration.
Maintain and regularly update HIPAA policies and procedures. Your policies must address EHR access management (onboarding, role changes, termination), acceptable use of EHR on personal devices, incident response and breach notification, data backup and disaster recovery, patient right of access to records, and minimum necessary standard for ePHI disclosures. Review policies at least annually and update them whenever your EHR configuration, workforce, or operations change.
Conduct workforce training at hire and annually. HIPAA requires security awareness training for all workforce members (45 CFR 164.308(a)(5)). Training must cover proper EHR use (unique logins, locking workstations, access controls), phishing recognition, breach identification and reporting procedures, and consequences of HIPAA violations. Document all training with dates, attendees, and content covered.
Review audit logs regularly. HIPAA requires audit controls, but the value only materializes when logs are reviewed. Establish a monthly review cadence at minimum. Look for access to records outside the user's normal patient population, after-hours access patterns, large-volume record exports, break-the-glass events, and failed login attempts.
Manage vendor BAAs as living documents. Track BAA expiration dates, review BAAs when vendor services change, and audit sub-processor coverage annually. Maintain a BAA inventory that maps every business associate with access to your ePHI.
Frequently Asked Questions
The eight most common questions about HIPAA compliance for EHR systems are answered in the FAQ section at the top of this page. These cover the auto-compliance myth, BAA requirements, penalty structures, risk assessment frequency, ONC versus HIPAA, telehealth HIPAA, state law interaction, and what to ask vendors.
For additional guidance on evaluating EHR systems, use our EMR Match tool to get personalized vendor recommendations, explore the EMR directory to compare platforms, or read our EHR security guide for thorough coverage of cybersecurity topics beyond HIPAA.
HIPAA compliance is not a destination -- it is an ongoing operational discipline. The practices that avoid violations and protect their patients' data are not the ones with the most expensive EHR. They are the ones that treat compliance as a daily responsibility, invest in training and documentation, hold their vendors accountable through verified BAAs and regular audits, and conduct honest risk assessments that drive continuous improvement.
Your EHR vendor provides the technical foundation. What you build on that foundation determines whether your practice is truly HIPAA compliant.
Ready to find a HIPAA compliant EHR for your practice? Get a personalized recommendation or compare top vendors side by side.
Frequently Asked Questions
Is my EHR system automatically HIPAA compliant?
No. HIPAA compliance is a shared responsibility. Your EHR vendor must provide a Business Associate Agreement (BAA) and implement technical safeguards, but your practice is responsible for administrative safeguards (training, policies), physical safeguards (workstation security), and proper use of the system (unique logins, access controls, risk assessments).
What is a BAA and why does my EHR vendor need one?
A Business Associate Agreement (BAA) is a legally binding contract required under HIPAA (45 CFR 164.502(e) and 164.308(b)). It specifies how your EHR vendor will safeguard protected health information (PHI), report breaches, and handle data upon contract termination. Without a signed BAA in place before your vendor accesses any PHI, both your practice and the vendor are in violation of HIPAA.
What are the penalties for HIPAA violations involving EHR systems?
HIPAA penalties are tiered by negligence level. Tier 1 (lack of knowledge) carries fines of $137 to $68,928 per violation. Tier 2 (reasonable cause) ranges from $1,379 to $68,928. Tier 3 (willful neglect, corrected) ranges from $13,785 to $68,928. Tier 4 (willful neglect, not corrected) starts at $68,928 per violation with an annual cap of $2,067,813 per violation category. OCR settlements have exceeded $16 million in individual cases.
How often do I need to conduct a HIPAA risk assessment?
HIPAA requires ongoing risk assessment, which in practice means at least annually and whenever significant changes occur -- such as implementing a new EHR, adding a telehealth module, changing vendors, opening a new office location, or experiencing a security incident. The HHS Security Risk Assessment (SRA) Tool is a free resource to help small and medium practices conduct their own assessments.
Is ONC certification the same as HIPAA compliance?
No. ONC certification verifies that an EHR system meets technical standards for functionality, interoperability, and security capabilities under the Promoting Interoperability program. HIPAA compliance is a separate, broader obligation covering how the system is configured, used, and maintained. A vendor can be ONC certified but not fully HIPAA compliant if, for example, encryption is not enabled, audit logs are not reviewed, or a BAA is not in place.
Does HIPAA apply to telehealth EHR visits?
Yes. All HIPAA requirements apply to telehealth encounters, including encryption of video streams (TLS 1.2+ and SRTP/DTLS), access controls for session participants, audit logging of telehealth events, and BAA coverage for every component of the telehealth workflow -- video platform, transcription services, cloud infrastructure, and messaging tools used to send appointment links.
Do state privacy laws override HIPAA for EHR systems?
State privacy laws do not override HIPAA but can impose additional, stricter requirements. Your practice must comply with both HIPAA and any applicable state laws. For example, California's CMIA requires patient authorization for certain disclosures that HIPAA permits, and Texas's THIPA allows a private right of action for unauthorized disclosures. The stricter standard always controls.
What HIPAA questions should I ask an EHR vendor before signing a contract?
Ask for a signed BAA, SOC 2 Type II report (not just a certificate), HITRUST certification status, encryption standards (AES-256 at rest, TLS 1.2+ in transit), MFA options, audit log access and retention period, breach notification timeline, data portability upon termination, sub-processor list with BAA coverage, and their most recent HIPAA risk assessment date. Get answers in writing and attach them to the contract.
Need Help Choosing the Right EMR?
Use our EMR matching tool to get personalized recommendations based on your practice size, workflow requirements, and budget.