A Raleigh medical practice that runs an EHR, a billing portal, and a patient text reminder system is also running a HIPAA compliance program, whether the practice manager calls it that or not. Every login, every encrypted laptop, and every signed Business Associate Agreement is part of the technical record OCR will examine when something goes wrong.
This guide breaks down what the HIPAA Security Rule actually requires from a technical standpoint, what the most common violations look like at small and mid-sized Raleigh practices, and how to map each requirement to a control you can verify this quarter. The penalties are real, the deadlines are short, and the Triangle market is competitive enough that a single breach can permanently move patients to a competitor down the street.
Key Takeaways
- The HIPAA Security Rule’s technical safeguards cover five required areas: access controls, audit controls, integrity, person or entity authentication, and transmission security.
- Civil penalties run from $141 per violation at Tier 1 up to $2,134,831 per violation per year at Tier 4 for willful neglect that is not corrected.
- The 2024 Notice of Proposed Rulemaking would make encryption of ePHI at rest and in transit mandatory, require an annual compliance audit, and force 72-hour ePHI restoration after an incident.
- Most small-practice violations trace back to four root causes: missing risk analysis, weak access controls, unencrypted portable devices, and stale or missing Business Associate Agreements.
Why HIPAA Hits Raleigh Practices Differently
Raleigh sits inside the Research Triangle, which the Greater Raleigh Chamber describes as an international center of medical care and research with one of the nation’s highest concentrations of physicians and health care professionals. That density creates two compliance pressures at once: more independent practices competing for the same referral base, and more business associate relationships per office than a comparable practice would carry in a less consolidated market.
The Raleigh region is highly consolidated among health systems and physician groups, with the region’s three largest health systems dominating both sectors, and major Wake County providers include WakeMed Health and Hospitals, UNC REX Healthcare, and Duke Raleigh Hospital. When a Cary or Apex specialist sends a referral or an imaging file to one of those systems, the technical controls on both ends of the connection have to line up or the smaller practice becomes the weak link in the chain.
Future medical office buildings will be positioned strategically following the residential spread throughout surrounding communities outside of the Raleigh and Durham epicenters, such as Clayton, Apex, Holly Springs, Wake Forest, Wendell, and Fuquay-Varina, where remote access, cloud EHRs, and personal mobile devices are the norm rather than the exception. Each of those workflows is a HIPAA touchpoint that has to be inventoried, encrypted, logged, and re-tested on at least an annual cadence to stay defensible.

Raleigh Medical Practice HIPAA Compliance Checklist
- ✓Risk analysis completed and documented within the last 12 months: Required, annual cadence (45 CFR 164.308(a)(1))
- ✓Unique user IDs, MFA, and automatic logoff on every ePHI system: Required (45 CFR 164.312(a))
- ✓Centralized audit logs with 6-year retention and time sync (NTP): Required (45 CFR 164.312(b))
- ✓Full-disk encryption on every laptop, server, and mobile device storing ePHI: Addressable today, mandatory under 2024 NPRM
- ✓Transmission encryption using TLS 1.2 or higher (TLS 1.3 preferred): Required for transmission security (45 CFR 164.312(e))
- ✓Signed, current Business Associate Agreement with every vendor touching PHI: Required before data sharing
- ✓Written incident response and breach notification plan, tested annually: Required (45 CFR 164.308(a)(6))
- ✓Workforce HIPAA training documented at hire and at least annually: Required (45 CFR 164.308(a)(5))
- ✓72-hour ePHI restoration capability validated by live backup test: Proposed under 2024 NPRM
- ✓Annual technology asset inventory with network map of ePHI systems: Proposed under 2024 NPRM
- ✓Termination procedures that revoke system access the same day: Required (cited in Gulf Coast Pain Consultants CMP)
- ✓Maximum civil penalty exposure per identical provision per year (Tier 4): $2,134,831
Sources: 45 CFR 164.308 and 164.312, HHS OCR Enforcement Highlights, HHS Notice of Proposed Rulemaking dated December 27, 2024, and 89 FR 64796 (penalty adjustments effective August 8, 2024).
The Five HIPAA Technical Safeguards You Must Implement
HIPAA access control is a mandatory safeguard outlined in 45 CFR 164.312 for any covered entity or business associate managing electronic protected health information, and the Technical Safeguards there outline the need for controls over access, auditing, integrity, authentication, and transmission security . Some implementation specifications are required and must be in place, while others are addressable: you must implement them if reasonable and appropriate, or document an equivalent alternative and the rationale
.
Core access control expectations include unique user identification, emergency (break-glass) access, automatic logoff, and the ability to encrypt or decrypt data where appropriate. In a Raleigh medical office this maps to a named account for every clinician and biller, no shared front-desk logins on the EHR, screen lock on every workstation that touches PHI, and a documented process for revoking access the same day an employee leaves.
The Audit Controls standard requires a covered entity to implement hardware, software, and procedural mechanisms that record and examine activity in information systems that contain or use ePHI. The practical implementation centralizes logs in a SIEM, normalizes events across EHRs, databases, endpoints, and cloud services, synchronizes time across all systems, and aligns retention to HIPAA’s six-year documentation requirement.
For transmission security, encrypt data in transit with TLS 1.2 or higher (ideally TLS 1.3), use IPsec or VPNs for private links, and apply integrity check s. Enforce HTTPS with modern TLS for web and mobile apps, disable legacy protocols and weak ciphers, secure APIs with TLS and mutual TLS where appropriate, and harden email by requiring TLS between gateway
s.
Business Associate Agreements: The Vendor Gap Most Practices Miss
A business associate is a vendor, hired by the covered entity to perform a service (such as a billing service for a healthcare provider), who comes into contact with protected health information as part of the business associate’s job. It is important to execute HIPAA-compliant Agreements with business associates because if an Agreement does not comply with the relevant standards it is invalid.
A typical Raleigh medical practice signs BAAs with somewhere between 15 and 40 vendors, depending on size and specialty. Vendors and business associates bring unique challenges to access control, so you must classify vendors as business associates and enforce Business Associate Agreements that outline permitted uses, security roles, and breach notification requirements.
One enforcement case that belongs on every practice manager’s desk: in December 2018, a Florida contractor physicians’ group settled with OCR after sharing protected health information with an unknown vendor without a business associate agreement. The takeaway is operational, not legal: keep a living vendor inventory, sign a current BAA before any data moves, and re-verify each vendor’s controls at least once a year.
The 2024 proposed rule would require that business associates verify at least once every 12 months that they have deployed technical safeguards required by the Security Rule to protect ePHI through a written analysis by a subject matter expert and a written certification that the analysis has been performed and is accurate. A practice that already collects annual vendor attestations will not feel that change, while one that signed a BAA five years ago and never looked at it again will.

What HIPAA Penalties Actually Look Like for a Raleigh Medical Practice
OCR uses a four-tier civil penalty structure based on culpability, with inflation-adjusted minimums and maximums updated annually. For penalties assessed on or after August 8, 2024 (for post-November 2, 2015 violations), the per-violation ranges are Tier 1 $141 to $71,162, Tier 2 $1,424 to $71,162, Tier 3 $14,232 to $71,162, and Tier 4 $71,162 to $2,134,831, with an official calendar-year cap of $2,134,831 per identical provision.
OCR also applies lower annual caps under enforcement discretion to Tiers 1 through 3, currently $35,581, $142,355, and $355,808 respectively. Even at the low end, a six-figure penalty against a four-provider Raleigh specialty practice is the kind of event that ends careers, not just budget cycles.
The OCR Director confirmed that 22 investigations of data breaches and complaints resulted in civil monetary penalties or settlements in 2024, making it one of the busiest years for HIPAA enforcement. Notable December 2024 actions included a $1.19 million civil monetary penalty against Gulf Coast Pain Consultants and a $548,265 civil monetary penalty against Children’s Hospital Colorado, plus a $250,000 settlement with the health care clearinghouse Inmediata Health Group
.
State attorneys general have authority under the HITECH Act to bring civil actions for HIPAA violations on behalf of state residents, which creates a second layer of enforcement beyond OCR, and an organization can face penalties from both OCR and one or more state attorneys general for the same breach. The reputational cost in a tight Triangle referral network, where physicians know each other by name, often outlasts the financial penalty by years.
The 2024 Security Rule NPRM: What Is Changing
On December 27, 2024, the Office for Civil Rights at the U.S. Department of Health and Human Services issued a Notice of Proposed Rulemaking to modify the HIPAA Security Rule to strengthen cybersecurity protections for electronic protected health informatio n. While the Department is undertaking this rulemaking, the current Security Rule remains in effect, but the direction of travel is set and worth planning for no
w.
Key proposals include removing the distinction between required and addressable implementation specifications, making all implementation specifications required with specific limited exceptions. The proposed rule would also require regulated entities to conduct a compliance audit at least once every 12 months and require encryption of ePHI at rest and in transit, with limited exceptions.
Other proposals include a 72-hour data restoration requirement so organizations must restore ePHI access and functionality within 72 hours following an incident, 24-hour notification of unauthorized access or major access modifications, an annual technology asset inventory that includes a comprehensive network map for all systems handling ePHI, and annual testing of security measures and backups. Practices already running a mature program will absorb these changes with minor adjustments, while practices that leaned on the addressable label to defer encryption will need to move quickly.
The Most Common HIPAA Violations We See in Triangle Medical Offices
Unauthorized access to patient records and lack of a documented risk analysis are the most frequent violations in small and mid-sized practices. Both show up in enforcement actions because they are easy to skip during busy clinical weeks and impossible to fake when OCR asks for the artifact.
Unencrypted laptops, USB drives, and personal phones sit close behind, and the Gulf Coast Pain Consultants case is a textbook example of what goes wrong without proper access controls. OCR determined that the first time a HIPAA-compliant risk analysis was conducted was on September 30, 2022, that policies and procedures for reviewing logs were not implemented until April 10, 2020 (more than 9 months after OCR informed the practice it was launching an investigation), and that procedures for terminating former workforce members’ access to ePHI were first implemented on April 10, 2020.
Sending PHI by standard email, SMS, or consumer messaging apps such as WhatsApp or iMessage without encryption violates the Security Rule, and healthcare organizations must use HIPAA-compliant, encrypted platforms for all patient communications. The fix is a HIPAA-compliant secure messaging tool, a signed BAA with that vendor, and a written policy that names the approved channels and bans the rest.
Workforce training failures appear in nearly every major enforcement case, not as the headline violation, but as an aggravating factor that makes every other violation worse, and OCR has consistently stated that an untrained workforce is a systemic risk, not just a policy gap. A once-a-year click-through module is not a training program, especially in a Triangle market where staff turnover and travel between clinic locations are routine.
Building Your Raleigh Practice Compliance Roadmap
The Security Rule administrative safeguard provisions require covered entities and business associates to perform a risk analysis, which helps you determine what security measures are reasonable and appropriate for your organization. Start with a current-state inventory of every system holding ePHI, every user with access, and every business associate with a copy of your data, then rank the gaps by likelihood and impact with named owners and target dates.
Implement the highest-risk controls first: multi-factor authentication on the EHR and email, full-disk encryption on every laptop and mobile device, centralized log collection with alerting, and a written and tested incident response plan. Research shows 76% of cloud breaches are linked to human error and 11% of cloud breaches involve accounts without multi-factor authentication, so these four controls alone block the majority of breach scenarios we see across Raleigh, Durham, Cary, and Wake Forest practices in any given quarter.
Documentation must be stored for at least 6 years, either physically on paper or via HIPAA compliance software, which covers policies, risk analyses, sanctions records, training records, and audit logs. When OCR opens a complaint the operational question is not whether you had a policy, it is whether you can produce the artifact that proves the policy was implemented and followed.
Frequently Asked Questions
Does HIPAA apply to my small Raleigh practice if I only have a few providers?
Yes. Every covered entity has to meet the same Privacy, Security, and Breach Notification standards regardless of size, and OCR audits have shown small healthcare providers carry a disproportionate share of fines.
Size offers no protection from enforcement, and a single complaint or breach report can trigger an OCR investigation that lasts years.
Is encryption of ePHI legally required under HIPAA today?
Encryption is currently an addressable implementation specification, which means you must implement it where reasonable and appropriate or document an equivalent alternative with a written justification. The December 27, 2024 Notice of Proposed Rulemaking would change that and require encryption of ePHI at rest and in transit with limited exceptions, so most Raleigh practices should treat full-disk encryption on laptops and TLS on every transmission channel as effectively required now rather than waiting for the final rule.
What is a Business Associate Agreement and which vendors need one?
A BAA is a written contract between a covered entity and any vendor that creates, receives, maintains, or transmits PHI on the practice’s behalf. That includes EHR vendors, billing services, cloud backup providers, IT support companies, secure messaging platforms, and most cloud productivity suites.
If a vendor can touch your patient data, a current BAA needs to be signed before the data moves, and the agreement should define permitted uses, security obligations, breach notification timelines, and downstream subcontractor requirements.
How long do we have to keep HIPAA documentation?
HIPAA requires retention of policies, procedures, risk analyses, sanctions records, training records, and other compliance documentation for at least six years from the date of creation or the date it was last in effect, whichever is later. Many practices align audit log retention to the same six-year window for consistency, which also matches the period during which OCR can typically commence enforcement action for a violation.