Why Your Cloud EHR Doesn't Make Your Practice HIPAA Compliant
COMPLIANCE · Jan 17, 2026 · 5 min read
SimplePractice, TherapyNotes, and Dentrix are HIPAA compliant. Your practice probably isn't. Here's what cloud EHRs don't protect.
Your Cloud EHR Is Compliant. Your Practice Isn't.
"We use SimplePractice, so we're HIPAA compliant."
We hear this every week. It's dangerously wrong.
What Your EHR Vendor Actually Guarantees
When SimplePractice, TherapyNotes, Jane App, or any cloud EHR says they're "HIPAA compliant," they mean:
Their servers:
- Encrypted at rest
- Encrypted in transit
- Access controlled
- Audit logged
- Regularly assessed
Their responsibility:
- Their data centers
- Their application code
- Their employees
- Their backup systems
Not their responsibility:
- Your laptop
- Your WiFi
- Your passwords
- Your staff
- Your phone
- Your home office
The Shared Responsibility Model
Think of it like renting a secure office building:
Building owner provides:
- Locked exterior doors
- Security cameras in hallways
- Fire suppression
- Secure server room
You're responsible for:
- Locking your office door
- Not propping open the fire exit
- Shredding sensitive documents
- Controlling who has your keys
Your EHR vendor secured the building. Everything inside your "unit" is on you.
What Cloud EHRs Don't Protect
1. The device you use to access it
Your laptop could be:
- Unencrypted (data exposed if stolen)
- Running outdated software (vulnerable to exploits)
- Infected with malware (keyloggers capturing passwords)
- Shared with family members (kids installing games with malware)
2. The network you connect from
Your WiFi could be:
- Using weak encryption (WPA2-Personal or worse)
- Shared with neighbors (apartment building)
- Running on a compromised router (default passwords)
- Monitored by attackers (coffee shop)
3. The credentials you use
Your login could be:
- A password you use everywhere (credential stuffing)
- Written on a sticky note (physical access)
- Shared with staff (no accountability)
- Missing MFA (one password away from breach)
4. The other software on your device
Your computer might have:
- Browser extensions harvesting data
- Personal email with phishing links
- Pirated software with backdoors
- Outdated plugins with known vulnerabilities
Real Breach Scenarios
Scenario 1: Stolen laptop
- Therapist's laptop stolen from car
- EHR password saved in browser
- Disk not encrypted
- Attacker accesses all patient records
- EHR vendor not liable. Practice is.
Scenario 2: Phishing attack
- Front desk clicks email link
- Enters EHR credentials on fake site
- Attacker logs in from overseas
- Downloads entire patient database
- EHR vendor not liable. Practice is.
Scenario 3: Home WiFi compromise
- Dentist works from home
- Uses same network as teenager
- Teen downloads infected game
- Malware captures EHR session
- EHR vendor not liable. Practice is.
What HIPAA Actually Requires (Beyond the EHR)
Access Controls (§164.312(a)):
☐ Unique login for every user
☐ Auto-logout after inactivity
☐ Role-based access (not everyone sees everything)
☐ Emergency access procedures documented
Audit Controls (§164.312(b)):
☐ Logging on your devices (not just EHR)
☐ Network access logs
☐ Review process for suspicious activity
☐ 6-year retention
Integrity Controls (§164.312(c)):
☐ Verification that data isn't altered
☐ Backup verification
☐ Malware protection
Transmission Security (§164.312(e)):
☐ Encrypted email for PHI
☐ Secure file sharing
☐ VPN for remote access
Device Security:
☐ Full disk encryption
☐ Endpoint protection (modern antivirus)
☐ Mobile device management
☐ Patch management
The Documentation Problem
Even if you do everything right technically, HIPAA requires:
- Risk assessment - Annual, documented, comprehensive
- Policies and procedures - Written, reviewed, acknowledged
- Training records - Who was trained, when, on what
- Incident response plan - What to do when things go wrong
- Business associate agreements - With everyone who touches PHI
Your EHR vendor provides their BAA. They don't write your policies, train your staff, or document your risk assessment.
The Audit Scenario
OCR shows up and asks for:
- Your most recent risk assessment
- Evidence of staff HIPAA training
- Audit logs from the last 6 months
- Your incident response plan
- Device encryption verification
Can you produce all of this? Your EHR can't help you.
What Smart Practices Do
1. Treat the EHR as one layer
- Compliant EHR + insecure devices = not compliant
- All layers must be secured
2. Encrypt everything
- Laptops: BitLocker (Windows) or FileVault (Mac)
- Phones: Usually default, verify
- Tablets: MDM with encryption requirement
3. Enable MFA everywhere
- EHR (if available)
- Email (absolutely required)
- Any cloud service with PHI
4. Secure the network
- Business-class router/firewall
- Separate guest WiFi
- VPN for remote access
5. Document everything
- Annual risk assessment
- Written policies
- Training records
- Incident response tested
The Cost Comparison
"We're cloud-based, we're fine" approach:
- $0/month on security
- $100,000+ when breach occurs
- $50,000+ in fines
- Reputation: destroyed
Proper security approach:
- $200-300/user/month
- Breach likelihood reduced 90%+
- Audit-ready documentation
- Sleep at night: priceless
Bottom Line
Your cloud EHR is a secure filing cabinet. But if you leave the office door unlocked, the cabinet doesn't matter.
HIPAA compliance requires:
- Secure EHR ✓ (you have this)
- Secure devices (probably not)
- Secure network (probably not)
- Secure credentials (maybe not)
- Documentation (definitely not)
One out of five isn't compliant.
Think your practice is covered because you use a cloud EHR? Let us show you what's actually exposed. Get Free Assessment
Need Help With Your Practice’s Security?
Free assessment, no obligation, real answers.
(469) 306-9520 • Serving Dallas-Fort Worth