Guide · Updated July 2026

How HIPAA programs fail

Found in reviews, punished in breaches.

HIPAA failures in startups follow six patterns, and none of them require a breach to hurt — health-system procurement finds them first.

1. The risk analysis that doesn’t exist (or expired in 2023). OCR’s most-cited gap and procurement’s first request. It must be real — PHI mapped, threats assessed — and refreshed when architecture changes. The service exists because this document is the program’s foundation.

2. The missing sub-BAA. PHI flows through a vendor — logging, analytics, an LLM API — with no agreement in place. Every day of that flow is a violation, discovered at the worst moments: incident forensics or a customer’s vendor-chain review.

3. PHI sprawl. Real patient data in staging, in analytics events, in prompts, on laptops. The Security Rule follows the data everywhere it goes; teams that never mapped the flows can’t safeguard or honestly attest anything. The ePHI inventory is the fix.

4. Training as a checkbox. No records, no sanctions policy behind it. OCR asks for completion evidence by name; “we told everyone in Slack” is a finding.

5. Breach clocks nobody knows. Sixty days to individuals, HHS reporting per breach size, and contractual BAA clocks that are often shorter — discovering the deadlines during the incident guarantees missing some.

6. Warranting what doesn’t exist. Signing a customer’s BAA promising safeguards that aren’t built. That converts regulatory exposure into contract breach with your biggest customer — the single most expensive signature in health-tech.

Each failure is cheap to prevent and expensive to discover. Two weeks of measured assessment beats learning your gaps from a health system’s security team.

Frequently Asked
What triggers OCR attention for a small company?

Breach reports (self-reported, as required) and complaints. Small business associates rarely get random audits — they get investigated after incidents, at which point the requested documents are the risk analysis, policies, training records, and BAAs, in that order.

What's the most common finding?

A missing or perfunctory Security Risk Analysis — it leads OCR's cited gaps year after year. Second: missing BAAs discovered mid-incident, which convert a security event into a compliance violation.

How do these failures show up before any breach?

In health-system procurement. Enterprise security reviews request the same documents OCR would, and a stale risk analysis or gappy BAA chain stalls deals quietly — no penalty letter, just a pipeline that stops advancing.

Related Guides

HIPAA for startups — A startup-sized HIPAA program — business associate reality, the minimum defensible posture, and the mistakes that surface in health-system procurement.

How SOC 2 programs fail — The seven failure modes that stall SOC 2 programs — from unowned platforms to aspirational policies — and what the rescue looks like for each.