HomeServicesIndustriesLocationsBlogContact Get Started →
Compliance · Healthcare

The HIPAA Compliance Checklist Every LA Medical Practice Needs in 2024

By CompBrix Team  ·  April 3, 2024  ·  7 min read

HIPAA compliance isn't optional for any healthcare provider handling Protected Health Information (PHI). But it's often treated as a paperwork exercise — policies documented, boxes checked, and then largely forgotten until an audit or a breach forces the issue.

In 2023, HHS OCR settled 22 HIPAA cases for a combined $7.2 million in penalties. The majority involved relatively straightforward failures that a properly managed IT setup would have prevented. Here's what Los Angeles medical practices need to have in place.

Administrative safeguards

Technical safeguards

Physical safeguards

The items most practices miss

Based on common audit findings, the gaps we see most often are: missing BAAs with cloud vendors (Google Workspace, Dropbox, DocuSign all require signed BAAs before using with PHI), unencrypted devices (a lost laptop with unencrypted PHI is an automatic reportable breach), and outdated risk assessments (the Security Rule requires a current, accurate assessment — not one from 2019).

If your practice hasn't had a formal HIPAA risk analysis in the past 12 months, that's where to start.

Get a free IT assessment for your LA business

We'll review your current setup, identify gaps, and show you exactly what we'd do. No commitment, no obligation.

Schedule Free Assessment →