HIPAA Compliance for Solo Attorney Practices: A Practical Guide

A practical guide for solo attorneys to achieve HIPAA compliance with realistic costs, steps, and tools. Covers policies, training, and technology.
If you are a solo attorney who handles protected health information (PHI), HIPAA compliance is not optional. Even a one-person practice must meet the same standards as a large firm, and the penalties for non-compliance can reach $50,000 per violation. This guide gives you a practical, step-by-step path to compliance without a compliance department. You can start with the basics this week and build from there.
What HIPAA Requires of Solo Attorneys
HIPAA applies to any attorney who is a “covered entity” or a “business associate” of a covered entity. If you handle PHI for clients who are healthcare providers, insurers, or employers with health plans, you are likely covered. The core requirements are:
- Privacy Rule: You must protect PHI and limit its use and disclosure.
- Security Rule: You must ensure the confidentiality, integrity, and security of electronic PHI (ePHI).
- Breach Notification Rule: You must notify affected individuals, HHS, and sometimes the media if a breach occurs.
- Documentation: You must have written policies and procedures, and you must train your staff (even if that staff is just you).
As a solo, you are both the privacy officer and the security officer. You can delegate, but you are accountable.
Step 1: Conduct a Risk Assessment (This Week)
The risk assessment is the foundation of your compliance. It identifies where PHI lives, how it moves, and what could go wrong. You can do this yourself using a template from HHS or a reputable vendor. The process takes 4-6 hours.
What to inventory:
- All devices: laptop, phone, tablet, desktop.
- All software: email, cloud storage, case management, billing.
- All paper records and filing cabinets.
- How you share information with clients, courts, and other attorneys.
- Physical security: locks, alarms, and access to your office.
What to document:
- Each location of PHI (e.g., “Laptop: C:\Clients\Smith\Medical Records”).
- Each threat (e.g., theft of laptop, phishing email, unencrypted email).
- Each vulnerability (e.g., no password on phone, outdated antivirus).
- Your risk level for each threat.
You can find free templates from the HHS website or from vendors like Compliancy Group. The key is to write it down and update it annually or whenever you change how you handle PHI.
Step 2: Create Your Policies and Procedures
You need written policies that match your practice. Do not copy generic policies from the internet; they must reflect what you actually do. The required policies include:
- Privacy Policy: How you use and disclose PHI, patient rights, and your notice of privacy practices (NPP).
- Security Policy: How you protect ePHI, including passwords, encryption, and device security.
- Breach Notification Policy: How you will detect, investigate, and report a breach.
- Workforce Training Policy: How you train yourself (and any contractors) on HIPAA.
You can write these yourself using templates from the HHS website or from a service like The HIPAA E-Tool. Expect to spend 8-10 hours drafting them. Then, review them with a HIPAA consultant if you can afford it, but it is not required.
Step 3: Train Yourself (and Anyone Who Helps You)
HIPAA requires that all workforce members receive training on your policies. For a solo, that means you. You must complete training at least once a year, and you must document it.
Training options and costs:
- Free: HHS provides a training video and materials. You can watch and then write a one-page summary.
- Low-cost online courses: $25-$75 per year. Providers like MedSafe, HIPAA Training, or Compliancy Group offer solo packages.
- Consultant-led training: $300-$500 per hour. Useful if you want a custom session.
Document the date, the topic, and your name. Keep the certificate or a signed log.
Step 4: Secure Your Technology
Technology is where most solo attorneys fail. Here are the minimum requirements:
- Encryption: All devices must be encrypted. This is built into Windows (BitLocker) and macOS (FileVault). Enable it. If you use a cloud service, ensure it encrypts data at rest and in transit.
- Email: Use a HIPAA-compliant email service. Standard Gmail or Yahoo is not compliant. Options include:
- Paid services: $5-$15 per user per month. Providers like LuxSci, Paubox, or Hushmail offer HIPAA-compliant email.
- Add-on encryption: If you use Microsoft 365, you can add encryption for $2-$5 per user per month.
- Cloud storage: Use a business-grade service with a Business Associate Agreement (BAA). Dropbox Business, Google Workspace, and Microsoft 365 all offer BAAs on their business plans. Costs range from $6-$20 per user per month.
- Password manager: Use one to generate and store strong passwords. LastPass, 1Password, or Bitwarden cost $3-$10 per month.
- Antivirus and firewall: Install on all devices. Windows Defender is free, but consider a paid option like Norton or Malwarebytes for $40-$80 per year.
- Two-factor authentication (2FA): Enable it on every account that contains PHI. This is non-negotiable.
What about client portals? A secure portal for sharing documents is safer than email. Options like Clio, MyCase, or PracticePanther include client portals and are HIPAA-compliant if you sign a BAA. Costs range from $39-$99 per month.
Step 5: Manage Business Associates
Any vendor that sees PHI must sign a Business Associate Agreement (BAA). This includes your email provider, cloud storage, case management software, and even your IT consultant if they have access. You do not need a BAA for your internet service provider or your phone company, because they only transmit data.
How to get BAAs:
- Ask each vendor for their BAA. Most have a standard form.
- Review it to ensure it includes the required elements: use and disclosure limits, breach notification, and return or destruction of PHI.
- Keep a signed copy in a folder, either paper or digital.
If a vendor refuses to sign a BAA, do not use them for PHI. That is a deal-breaker.
Step 6: Prepare for Breach Notification
Even with the best security, breaches happen. You must have a plan. The HIPAA Breach Notification Rule requires:
- Notify affected individuals within 60 days of discovery.
- Notify HHS if the breach affects 500 or more individuals. For smaller breaches, you must report annually.
- Notify the media if the breach affects more than 500 residents of a state.
Your plan should include:
- Who to contact (your cyber liability insurer, a breach coach, or an attorney).
- How to preserve evidence.
- A template for the notification letter.
Cyber liability insurance is highly recommended. Policies cost $500-$1,500 per year for solo practices, depending on your coverage limits. It can cover the cost of notification, credit monitoring, and legal defense.
Costs of HIPAA Compliance for a Solo Attorney
Here is a realistic budget for the first year:
| Item | Cost Range |
|---|---|
| Risk assessment (DIY) | $0 (time only) |
| Policies and procedures (DIY) | $0 (time only) |
| Training (online course) | $25-$75 |
| HIPAA-compliant email | $60-$180/year |
| Cloud storage with BAA | $72-$240/year |
| Password manager | $36-$120/year |
| Antivirus | $40-$80/year |
| Cyber liability insurance | $500-$1,500/year |
| Total first year | $733-$2,195 |
Ongoing annual costs are lower: training, software renewals, and insurance. Expect $500-$1,000 per year after the first year.
Common Mistakes to Avoid
- Using personal email for PHI: Even if you think it is secure, it is not compliant without a BAA.
- Not encrypting your phone: If you use your phone to text clients about their case, it must be encrypted and you must have a secure texting app.
- Ignoring physical security: If you work from home, ensure your files are locked and your computer is not visible to visitors.
- Forgetting to update policies: You must review and update your policies at least annually.
- Not documenting training: If you cannot prove you trained, it did not happen.
FAQ
Q: Do I really need to be HIPAA compliant if I never see medical records?
A: If you are a business associate of a covered entity, yes. Even if you only receive PHI occasionally, the rule applies. It is better to be compliant than to risk penalties.
Q: Can I use free email like Gmail if I have a BAA?
A: No. Free Gmail does not offer a BAA. You need a paid Google Workspace account, which costs $6-$18 per user per month.
Q: What if I only have paper records?
A: The Security Rule applies to ePHI, but the Privacy Rule still applies to all PHI. You must have policies for paper records, including locked storage and proper disposal.
Q: How often do I need to do a risk assessment?
A: HHS recommends annually, and whenever you make significant changes to your technology or processes. It is a best practice to do it at least once a year.
The Bottom Line
HIPAA compliance for a solo attorney is manageable. Start with a risk assessment, write your policies, train yourself, and secure your technology. The cost is modest, especially compared to the potential fines. You can complete the initial steps in a week, and then maintain compliance with annual updates. Do not put it off; the risk is not worth it.