Most healthcare practices in Columbus assume HIPAA compliance is mostly a paperwork exercise — a policy binder, a signed business associate agreement, an annual training video. The technical side gets treated as the EHR vendor's problem. In practice, the Security Rule holds the practice responsible for the network, devices, and staff access surrounding that EHR, not just the software itself — and that's usually where the real gaps sit.

Below is a practical checklist covering the areas that actually get examined after a breach or a patient complaint, along with what genuinely closes each gap — not generic policy language, but the specific controls that matter for a clinic, practice group, or behavioral health provider operating with 25 to 250 employees.

1. Access Controls and Audit Logging

Why it's the top gap

Unique logins, role-based access, and automatic session timeouts sound basic — but shared front-desk logins and former-employee accounts that were never disabled are among the most common findings in real healthcare IT risk assessments.

Every user touching patient data needs their own credentials, access scoped to their role, and activity that's actually logged — not just theoretically loggable. Audit trails are what let a practice answer the question every investigator eventually asks: who accessed this record, and when.

2. Encrypted, Tested Backups and Continuity Planning

Why it's the top gap

A backup that hasn't been restore-tested is a guess, not a safeguard. If your EHR or imaging system goes down and the most recent clean restore point is weeks old, patient care stops along with it.

Backups need to be encrypted at rest and in transit, automated rather than manual, and periodically tested with an actual restoration — with a documented recovery time that matches how long your practice can realistically operate on paper.

3. Business Associate Agreements That Match Reality

Every vendor that touches patient data — your EHR platform, billing service, IT provider, even a scheduling app — needs a current business associate agreement. The common gap isn't a missing signature; it's a BAA on file for a system the practice stopped using two years ago, while the vendor actually holding the data today has no agreement at all.

4. Endpoint and Device Security

Laptops, tablets, and phones that touch patient data — including personal devices used for on-call access — need encryption, remote wipe capability, and endpoint detection, not just a password screen. A lost device without these controls is a reportable breach; a lost device with them typically isn't.

5. Incident Response and Breach Notification Timelines

HIPAA's breach notification rule runs on a clock — generally 60 days from discovery for notifying affected individuals. Practices without a documented incident response plan tend to lose the first several days of that window deciding who's responsible for what, rather than executing a plan they already have.

6. Annual Risk Assessments — Not One-Time Projects

A risk assessment done once, three years ago, doesn't reflect a new EHR module, a new location, or the new biller who was granted admin access last spring. HIPAA expects this to be a living process, revisited at least annually and after any material change to the environment.

What to Do Next

None of the six areas above require replacing your EHR or overhauling your practice's workflow — they require an honest inventory of where you actually stand today versus where the Security Rule expects you to be. That gap is exactly what a proper HIPAA-aligned IT risk assessment is built to find.

If your practice is also feeling general growing pains alongside the compliance picture, it's worth reading the signs your business has outgrown its current IT setup — the two issues often show up together. You can also see how this fits into a broader security posture in our overview of the top cybersecurity risks facing Columbus small businesses.