How HIPAA programs fail
Found in reviews, punished in breaches.HIPAA failures in startups follow six patterns, and none of them require a breach to hurt — health-system procurement finds them first.
1. The risk analysis that doesn’t exist (or expired in 2023). OCR’s most-cited gap and procurement’s first request. It must be real — PHI mapped, threats assessed — and refreshed when architecture changes. The service exists because this document is the program’s foundation.
2. The missing sub-BAA. PHI flows through a vendor — logging, analytics, an LLM API — with no agreement in place. Every day of that flow is a violation, discovered at the worst moments: incident forensics or a customer’s vendor-chain review.
3. PHI sprawl. Real patient data in staging, in analytics events, in prompts, on laptops. The Security Rule follows the data everywhere it goes; teams that never mapped the flows can’t safeguard or honestly attest anything. The ePHI inventory is the fix.
4. Training as a checkbox. No records, no sanctions policy behind it. OCR asks for completion evidence by name; “we told everyone in Slack” is a finding.
5. Breach clocks nobody knows. Sixty days to individuals, HHS reporting per breach size, and contractual BAA clocks that are often shorter — discovering the deadlines during the incident guarantees missing some.
6. Warranting what doesn’t exist. Signing a customer’s BAA promising safeguards that aren’t built. That converts regulatory exposure into contract breach with your biggest customer — the single most expensive signature in health-tech.
Each failure is cheap to prevent and expensive to discover. Two weeks of measured assessment beats learning your gaps from a health system’s security team.
HIPAA framework guide
What HIPAA actually requires — the Security Rule, risk analysis, BAAs, breach notification — and why no certification exists. A guide for teams handling PHI.
HIPAA Risk Analysis
A done-for-you HIPAA Security Risk Analysis — PHI mapping, threat assessment, and the remediation plan — delivered as the artifact OCR and customers request.
What triggers OCR attention for a small company?
Breach reports (self-reported, as required) and complaints. Small business associates rarely get random audits — they get investigated after incidents, at which point the requested documents are the risk analysis, policies, training records, and BAAs, in that order.
What's the most common finding?
A missing or perfunctory Security Risk Analysis — it leads OCR's cited gaps year after year. Second: missing BAAs discovered mid-incident, which convert a security event into a compliance violation.
How do these failures show up before any breach?
In health-system procurement. Enterprise security reviews request the same documents OCR would, and a stale risk analysis or gappy BAA chain stalls deals quietly — no penalty letter, just a pipeline that stops advancing.
HIPAA for startups — A startup-sized HIPAA program — business associate reality, the minimum defensible posture, and the mistakes that surface in health-system procurement.
How SOC 2 programs fail — The seven failure modes that stall SOC 2 programs — from unowned platforms to aspirational policies — and what the rescue looks like for each.