SERVING RICHMOND, VA ยท SHORT PUMP ยท GLEN ALLEN ยท MIDLOTHIAN ยท SCOTT’S ADDITION ยท HENRICO

HIPAA Compliance in Richmond Audit-Ready Without the Overwhelm.

One breach letter can undo a decade of patient trust. We run HIPAA compliance for Richmond practices end to end โ€” risk analysis, safeguards, BAAs, training, and the documentation that survives an OCR audit.

15+
YEARS
1,000+
BUSINESSES
<30 min
RESPONSE
4.9★
GOOGLE
  • Gap assessment against the full framework
  • Remediation done for you, not just flagged
  • Evidence collection & audit-ready binders
  • Continuous monitoring after certification

Free · Takes 3 minutes · No sales call required

Start My Free HIPAA Gap Assessment

For the Richmond region healthcare organizations and their business associates. Response within 30 minutes.













No spam. No contract required. Your information is used only to prepare for your assessment call and is never sold or shared.

What We Do

HIPAA Compliance Services: Six Capabilities That Build an Audit-Ready Program

Each service maps directly to a HIPAA Security Rule specification — and to the specific gap OCR most commonly finds during enforcement actions. We build programs that hold up when OCR requests documentation, not programs that look complete until they are examined.

SRA — 164.308(a)(1)

HIPAA Security Risk Analysis — The Required Foundation

We conduct a comprehensive, documented Security Risk Analysis covering all ePHI locations, threats, vulnerabilities, likelihood and impact ratings, and existing safeguards — mapped to the specific implementation specifications of 45 CFR 164.308(a)(1)(ii). The SRA report includes the methodology, findings, and a risk management plan that satisfies OCR’s documentation expectations for covered entities and business associates across the Richmond region.

What it prevents: OCR enforcement actions citing missing or inadequate SRAs as the foundational violation. The SRA is the single most cited missing control in HIPAA settlements. OCR’s 2024 initiative specifically targets this gap.

Without it: the SRA is required by name in the Security Rule and in every OCR audit protocol. Its absence is not a secondary finding — it is the primary violation from which all other findings flow. No the Richmond region practice should be without a documented, current SRA.

SentinelOne + Intune

Technical Safeguards — Access Control, Encryption, Audit Logging

MFA enforcement across Microsoft 365 and clinical systems, encrypted device management via Microsoft Intune, audit log configuration per 164.312(b), automatic logoff on all ePHI-access workstations, and role-based access controls limiting PHI visibility to minimum necessary. SentinelOne provides endpoint detection and 24/7 SOC coverage for anomalous ePHI access — including after-hours activity that most the Richmond region practices have no visibility into. The proposed December 2024 Security Rule NPRM would make MFA and encryption mandatory rather than addressable — organizations implementing them now are ahead of the final rule.

What it prevents: unauthorized ePHI access, after-hours account compromise, and the technical safeguard failures that appear in the majority of OCR enforcement actions.

Without it: an EHR that is described as “HIPAA compliant” does not substitute for the technical controls required on every device and account that accesses it. Technical safeguard gaps appear in the majority of OCR enforcement actions.

Microsoft Defender + DMARC

Email Security and ePHI Protection

Microsoft 365 Defender filters phishing, malicious attachments, and spoofed senders before they reach clinical inboxes. We enforce SPF, DKIM, and DMARC so attackers cannot impersonate your practice domain to patients or referral partners. For the Richmond region medical billing companies and specialty practices that transmit ePHI via email, we implement secure email transport with TLS enforcement and message-level encryption where required. Phishing is the most common initial access vector in healthcare breaches — including the Peninsula billing contractor scenario above.

What it prevents: credential phishing, account takeover, ePHI exfiltration via email forwarding, and the breach notification cascade that follows a compromised clinical email account.

Without it: one convincing phishing email opens a clinical mailbox containing years of patient records. The 4,200-record Peninsula billing breach above began exactly this way — a single credential click forwarded records for two weeks before anyone noticed.

vCISO Advisory

Business Associate Agreement Management

We inventory all vendors, contractors, subcontractors, and cloud services with any access to ePHI; execute and maintain properly structured BAAs for each; document the BAA inventory in your HIPAA program file; and establish a vendor review cadence so new services do not slip through without BAA execution. BAA templates are reviewed against current OCR guidance to ensure they include all required provisions. For the Richmond region practices migrating EHR platforms or adding billing contractors, BAA execution before access is granted is non-negotiable — the VCU Health settlement established that missing BAAs are enforcement-worthy violations independent of any breach.

What it prevents: enforcement actions for missing BAAs — an independent violation category that compounded VCU Health’s penalty exposure in 2019 and is a common secondary finding in OCR investigations.

Without it: every vendor with ePHI access who lacks a fully executed BAA is a standing HIPAA violation. Most the Richmond region practices have unexecuted BAA gaps they are not aware of — cloud backup, IT providers, billing systems, and EHR implementation vendors all typically require them.

KnowBe4

Workforce Security Awareness Training — 164.308(a)(5)

Annual HIPAA Security Rule training for all workforce members with PHI access, delivered through KnowBe4’s healthcare-specific training library; simulated phishing campaigns targeting the social engineering techniques most commonly used against the Richmond region healthcare staff; and documented completion records maintained for six years in a format that satisfies OCR documentation requests. Training records include date, content covered, and individual completion confirmation. For behavioral health providers, training covers both HIPAA and 42 CFR Part 2 obligations simultaneously.

What it prevents: workforce-caused breaches from phishing and unintentional disclosure, and the training documentation gaps that appear in nearly every multi-violation OCR enforcement action.

Without it: training documentation gaps are cited in nearly every OCR enforcement action involving multiple violations. A workforce that has not been trained on Security Rule requirements is both a breach risk and a compliance liability — and “we told them verbally” does not satisfy the documentation requirement.

Tested Backups + IR Plan

Backup and Breach-Ready Incident Response — 164.308(a)(6)

A documented incident response plan mapped to HIPAA’s breach notification requirements; immutable, regularly tested backups that support same-day recovery from ransomware without negotiating with attackers; a documented breach risk assessment workflow for OCR’s four-factor test; and a breach notification workflow that satisfies both the 60-day HIPAA reporting deadline and Virginia’s breach notification law under Va. Code 18.2-186.6 (“without unreasonable delay,” with AG notification required for every reportable breach). For the Richmond region practices, the Virginia AG notification requirement applies in addition to — not instead of — the federal HIPAA notification rules.

What it prevents: the compounding penalty of a breach plus a late or missing notification — two separate violations. Organizations that miss the notification window face enforcement on both the underlying breach and the notification failure.

Without it: the ransom note becomes your recovery strategy, and a breach you could have contained in hours becomes a 60-day notification clock you are already behind on. The behavioral health ransomware scenario above lost records permanently because no tested backup existed.

Who We Serve

HIPAA Compliance for Every Richmond-area Healthcare Setting

the Richmond region healthcare spans large health systems, independent practices, behavioral health networks, specialty groups, and a significant business associate ecosystem. Each vertical has specific compliance challenges that a general IT provider cannot address.

Covered Entity

Physician Practices — Richmond and Peninsula

Independent and affiliated physician practices across the Richmond region — from Richmond Short Pump medical offices to Peninsula groups near HCA Virginia in Glen Allen — typically have one IT generalist managing clinical workstations, EHR access, and network infrastructure without the compliance specialization the Security Rule requires. Capital Techies provides SRA documentation, technical safeguard implementation on Epic, eClinicalWorks, athenahealth, and similar platforms, and OCR-ready evidence packages sized for practices with 5 to 50 providers. Practices affiliated with VCU Health, HCA Virginia, or Bon Secours need compliance programs that align with their health system’s obligations and their own independent business associate or covered entity status.

Dual Compliance Burden

Behavioral Health Providers — Peninsula and Southside

the Richmond region behavioral health practices — serving veterans and active-duty personnel near the Federal Reserve Bank of Richmond and Defense Supply Center Richmond, alongside civilian populations in Chesterfield and Midlothian — face a dual compliance burden: HIPAA Security Rule requirements and 42 CFR Part 2 restrictions on substance use disorder records, which carry stricter confidentiality requirements than standard PHI. Capital Techies builds access control architectures that enforce both frameworks simultaneously — Part 2 records get heightened access controls and segregated storage while general PHI follows standard HIPAA technical safeguard requirements. Commingling SUD and general PHI in a shared system creates simultaneous HIPAA and Part 2 violations.

Medical Billing / RCM

Medical Billing and Revenue Cycle Companies

Medical billing companies, revenue cycle management firms, and coding services operating in the Richmond region are HIPAA business associates with direct liability to OCR under the Omnibus Rule — liability that is independent of their covered entity clients’ compliance programs. Many operate under the mistaken belief that HIPAA is the physician practice’s responsibility. OCR has settled enforcement actions directly against business associates. A billing contractor handling claims for Peninsula or Southside practices that experiences a breach faces the same notification requirements and enforcement exposure as the practice itself. Capital Techies builds HIPAA compliance programs sized for billing and RCM companies: SRA, technical safeguards, BAA inventory with covered entity clients, and six years of documentation.

Covered Entity

Dental Practices — the Richmond region

Dental practices that transmit health information electronically for billing purposes are HIPAA covered entities subject to the full Security Rule. Many the Richmond region dental offices operate under the mistaken belief that their dental practice management software’s “HIPAA compliance” features satisfy their obligations. They do not — the security of the software does not substitute for the organization’s own SRA, access controls, workforce training, BAA inventory, and incident response plan. Capital Techies builds HIPAA compliance programs for the Richmond region dental practices that are appropriately sized for a small practice without cutting corners on required controls. Dental records, X-rays, and treatment plans are ePHI and subject to the same protection requirements as any other covered entity.

Covered Entity

Specialty Clinics — Richmond and Greenbrier Corridor

Orthopedic, dermatology, ophthalmology, cardiology, and other specialty clinics across Richmond and the Chesterfield Greenbrier corridor handle ePHI across multiple systems: EHR, diagnostic imaging, patient portal, scheduling, and billing — often from different vendors with different security postures. Each integration and each vendor with ePHI access requires a BAA. Each system is in scope for the SRA. Capital Techies maps every ePHI data flow across a specialty clinic’s environment, identifies BAA gaps, implements technical safeguards on every ePHI-capable system, and produces the OCR-ready documentation package that demonstrates a complete compliance program — not just the EHR vendor’s marketing materials.

Covered Entity + BA

Healthcare Context: VCU Health, HCA Virginia, and Bon Secours

VCU Health (Virginia’s largest health system, headquartered in Henrico and Richmond with approximately 35,000 employees and 12 hospitals) established the enforcement precedent that shapes OCR’s expectations for Virginia healthcare organizations with the 2019 $2.175M settlement. HCA Virginia (Glen Allen, 8 facilities, serving the Greater Peninsula) and Bon Secours Medical Center (310 beds, Chesterfield) anchor the regional health system landscape. Independent practices, specialty groups, and business associates that receive referrals from or provide services to these health systems are covered entities or business associates in their own right — their HIPAA obligations are independent of the health system’s program. Capital Techies serves independent providers throughout the Richmond region healthcare ecosystem.

What Is Happening to Richmond-area Healthcare Organizations

Four HIPAA Breach Scenarios That Hit Richmond-area Healthcare Right Now

These are not hypotheticals. Each scenario below mirrors threat patterns and regulatory fact patterns documented in OCR enforcement actions and Virginia-area incident reporting — tailored to the healthcare organizations that serve the Peninsula, Southside, and Richmond.

The Peninsula Medical Billing Contractor Phished Out of 4,200 Patient Records

A medical billing contractor working with a Peninsula-area health system received what looked like a Microsoft 365 password-reset notification. The practice manager clicked the link, entered her credentials, and went back to work. Over the next two weeks, the attacker used her email account to forward patient records to an outside address — records belonging to 4,200 patients, including insurance IDs, dates of service, and diagnostic codes. Under Virginia’s breach notification law (Va. Code 18.2-186.6), the organization was required to notify the Virginia Attorney General without unreasonable delay. Under HIPAA, notification to HHS OCR and affected individuals was required within 60 days of discovery. Both deadlines were missed.

Consequence: HIPAA breach notification violation on top of the underlying security failure, missing BAA exposure with covered entity clients, and OCR enforcement targeting the billing company directly as a business associate. Source: Va. Code 18.2-186.6; 45 CFR 164.400-414.

The Behavioral Health Practice That Paid Ransom and Still Lost the Records

A the Richmond region behavioral health practice serving patients across Chesterfield and Midlothian ran its clinical records on a server with no offsite backup and no endpoint detection. A ransomware operator encrypted every patient record on a Friday evening. The practice paid the ransom on Monday. The decryption key worked on roughly 60% of files. The remaining records — session notes, substance use disorder treatment records subject to 42 CFR Part 2, and billing histories — were unrecoverable. The breach triggered HIPAA notification obligations for all affected patients and HHS OCR. The practice had never completed a Security Risk Analysis.

Consequence: ransom paid, records partially lost, 42 CFR Part 2 SUD records breached, HIPAA SRA violation confirmed as the foundational gap — the same gap OCR’s 2024 enforcement initiative specifically targets. Source: Sophos State of Ransomware 2025; HHS OCR Risk Analysis Initiative, Oct. 2024.

The Specialty Clinic With No Risk Analysis Facing an OCR Audit

A specialty clinic in Richmond received an OCR audit notification after a patient filed a complaint about a misdirected fax. The fax issue was a minor disclosure. But the OCR investigation expanded into the clinic’s entire Security Rule compliance program — and found no documented Security Risk Analysis, no formal access control policy, no workforce training records, and no Business Associate Agreement with its EHR implementation vendor. What began as a minor complaint resolved as a multi-violation enforcement action. OCR’s October 2024 Risk Analysis Enforcement Initiative means practices are now being investigated proactively for SRA failures, not just in response to breaches.

Consequence: a single complaint triggered a full Security Rule audit, uncovering four independent violation categories. OCR’s documented pattern is to expand investigations beyond the triggering event when the underlying compliance program is absent. Source: HHS OCR OCR Risk Analysis Initiative, Oct. 2024; HHS enforcement case results.

The Practice With a Vendor Who Had PHI Access and No BAA

A Henrico physician group migrated to a new EHR platform. The implementation vendor had full access to patient records during the migration window — roughly six weeks. No Business Associate Agreement was executed before access was granted. A routine cyber insurance renewal audit flagged the gap. The insurer required a retroactive documentation process and suspended coverage during the remediation window. Separately, OCR’s investigative focus on BAA gaps means the missing agreement was an independent violation — not merely a technical oversight. The VCU Health settlement in 2019 involved exactly this scenario: a missing BAA with a related entity that had ePHI access.

Consequence: missing BAA is an independent HIPAA violation regardless of whether a breach occurred; cyber insurance coverage suspended during remediation; VCU Health precedent established OCR will pursue missing BAA violations at $2.175M scale. Source: HHS OCR, VCU Health Hospitals settlement, Nov. 27, 2019.

Definition

What Is HIPAA Compliance — and What It Is Not

HIPAA compliance for covered entities and business associates means implementing and documenting the administrative, physical, and technical safeguards required by the HIPAA Security Rule (45 CFR Part 164, Subpart C) to protect electronic Protected Health Information (ePHI). Compliance is not a one-time certification or a software purchase. It is an ongoing program with four core requirements: (1) conducting and documenting an annual Security Risk Analysis, (2) implementing safeguards based on that analysis, (3) training workforce members on Security Rule requirements, and (4) maintaining documentation for six years. HHS OCR enforces HIPAA and has levied over $135 million in civil money penalties since 2008.

What HIPAA compliance includes: a documented Security Risk Analysis (SRA) mapped to 45 CFR 164.308(a)(1); access control implementation per 164.312(a)(1) with unique user IDs and role-based minimum necessary access; audit logging per 164.312(b); encryption of ePHI at rest and in transit per 164.312(a)(2)(iv) and 164.312(e)(2)(ii); workforce training per 164.308(a)(5); incident response planning per 164.308(a)(6); Business Associate Agreements (BAAs) for every vendor with ePHI access; and six-year documentation retention per 164.316(b)(2).

What HIPAA compliance is not: a one-time certification, a checklist completed once and filed away, or a feature of your EHR software. No healthcare organization becomes “HIPAA certified” — compliance is demonstrated through implemented controls and documented evidence of an ongoing program. Purchasing an EHR that the vendor describes as “HIPAA compliant” does not transfer your compliance obligations to the vendor. Signing a BAA with a cloud storage provider does not substitute for a Security Risk Analysis. Completing a single training session once does not satisfy the annual training requirement under 164.308(a)(5).

Who needs it: every HIPAA covered entity (healthcare providers that transmit health information electronically, health plans, and healthcare clearinghouses) and every business associate that creates, receives, maintains, or transmits ePHI on behalf of a covered entity. In the Richmond region and Richmond healthcare market, that includes VCU Health-affiliated practices, HCA Virginia providers, Bon Secours Medical Center-affiliated groups, independent physician practices, behavioral health providers, dental offices, medical billing and revenue cycle management companies, and specialty clinics across the Peninsula and Southside.

the Richmond region enforcement context: VCU Health — Virginia’s largest health system, headquartered in Henrico and Richmond — settled with HHS OCR for $2.175 million on November 27, 2019, after VCU Health initially underreported a breach affecting 16,342 patients and lacked a Business Associate Agreement with its own parent entity. That settlement established the enforcement posture OCR applies to Virginia health organizations. OCR’s October 2024 Risk Analysis Enforcement Initiative is the direct successor — targeting organizations that never built a documented SRA-based compliance program. Capital Techies builds those programs for the Richmond region healthcare organizations before OCR asks for them.

The Numbers

HIPAA and Healthcare Security: Six Numbers Every Richmond-area Practice Needs to Know

Every figure below is sourced and attributable. These are the numbers your practice administrator, compliance officer, and board need to understand before an OCR investigation arrives.

$2.175M
HHS OCR settlement with VCU Health Hospitals (Nov. 27, 2019) — for underreporting a 16,342-patient breach and lacking a Business Associate Agreement with its parent entity. A Virginia health system. the Richmond region.
Source: HHS Office for Civil Rights, official settlement (hhs.gov), Nov. 2019

Oct. 2024
OCR launched its Risk Analysis Enforcement Initiative — specifically targeting covered entities and business associates that have failed to conduct adequate HIPAA Security Rule risk analyses. By April 2025, multiple settlements had resulted.
Source: HHS OCR Risk Analysis Initiative announcement; National Law Review; Feldesman LLP, 2025

Dec. 2024
HHS OCR published a Security Rule NPRM proposing mandatory multi-factor authentication and mandatory encryption for all ePHI — removing the “addressable” flexibility that allowed organizations to skip these controls.
Source: HHS OCR HIPAA Security Rule NPRM, 89 Fed. Reg., Dec. 27, 2024

$10.22M
Average cost of a US data breach in 2025 — the highest average in the world for the 15th consecutive year. Healthcare breaches consistently rank at the top of industry-specific costs.
Source: IBM Cost of a Data Breach Report 2025

44%
Share of all data breaches in which ransomware appeared in 2025 — up from 32% the prior year, now the most common action type in breaches across all industries including healthcare.
Source: Verizon Data Breach Investigations Report (DBIR) 2025

$1.53M
Average ransomware recovery cost in 2025 excluding any ransom payment — and that is the median for organizations that survived. Many the Richmond region practices would not recover from a figure at this scale.
Source: Sophos State of Ransomware 2025

COMPLIANCE, HANDLED

Healthcare Compliance Frameworks for Richmond-area Organizations

You do not need to memorize the acronyms. You need to pass the audit and keep your clients’ trust. That is our job.

HIPAA SECURITY RULE

Security Risk Analysis mapped to 164.308(a)(1); technical safeguard implementation (access control, encryption, audit logging, automatic logoff); workforce training do…

HIPAA PRIVACY RULE AND BRE

Breach risk assessment workflow applying OCR’s four-factor test; breach notification letter preparation for affected individuals; HHS OCR breach portal reporting suppo…

VIRGINIA BREACH LAW

Incident response plan with Virginia-specific notification workflow; notification letter preparation for affected residents; Virginia AG Computer Crime Section notific…

HHS OCR RISK ANALYSIS REQU

Comprehensive SRA covering all ePHI locations, threat and vulnerability assessment, likelihood and impact ratings, existing safeguard evaluation, and risk management p…

See the full framework detail
Framework Who Needs It What Capital Techies Does Deliverable
HIPAA Security Rule (45 CFR Part 164) All covered entities and business associates handling ePHI — required regardless of organization size. Includes all the Richmond region physician practices, behavioral health providers, dental offices, billing companies, and specialty clinics that transmit health information electronically. Security Risk Analysis mapped to 164.308(a)(1); technical safeguard implementation (access control, encryption, audit logging, automatic logoff); workforce training documentation; BAA management for all vendors; incident response planning per 164.308(a)(6) Annual SRA report, 164.308-164.312 evidence folder, BAA inventory and executed agreements, training completion records, breach response runbook
HIPAA Privacy Rule and Breach Notification Rule All covered entities — governs use and disclosure of all PHI (not just electronic), patient rights, and breach notification obligations to HHS OCR and affected individuals. Breach notification to HHS required within 60 days of discovery for breaches affecting 500 or more individuals. Breach risk assessment workflow applying OCR’s four-factor test; breach notification letter preparation for affected individuals; HHS OCR breach portal reporting support; minimum necessary access policy documentation Breach notification templates for individuals and HHS OCR, four-factor risk assessment documentation, minimum necessary access policies
Virginia Breach Law (Va. Code 18.2-186.6) Any entity owning or licensing computerized data including personal information of Virginia residents — covers every the Richmond region healthcare organization. Requires notification “without unreasonable delay,” not a fixed number of days. AG notification required for every reportable breach regardless of size. Incident response plan with Virginia-specific notification workflow; notification letter preparation for affected residents; Virginia AG Computer Crime Section notification package; breach response coordination covering both HIPAA and Virginia timelines simultaneously Incident response plan with dual-track notification workflow, AG notification package template, breach response runbook aligned to both state and federal timelines
HHS OCR Risk Analysis Requirement (45 CFR 164.308(a)(1)) Every HIPAA covered entity and business associate — required annually or upon significant operational change. OCR’s October 2024 enforcement initiative specifically targets organizations that have failed to conduct adequate, documented risk analyses. This is the most commonly cited missing control in OCR enforcement actions. Comprehensive SRA covering all ePHI locations, threat and vulnerability assessment, likelihood and impact ratings, existing safeguard evaluation, and risk management plan — specific to each the Richmond region organization’s environment, not a generic template Documented SRA report meeting OCR’s guidance requirements, risk management plan with prioritized remediation items, annual SRA refresh schedule
Cyber Insurance Requirements Every the Richmond region healthcare organization carrying cyber liability coverage — or seeking renewal at standard premiums. Carriers now require documented MFA, EDR deployment, tested backups, and security awareness training as conditions of coverage and claim payment. MFA implementation and documentation, EDR deployment (SentinelOne), tested backup with recovery evidence, patch management documentation, security awareness training records — all maintained in a format that survives post-claim carrier audit Controls attestation package with evidence documentation, renewal-ready questionnaire support, gap remediation for coverage requirements
42 CFR Part 2 (Substance Use Disorder Records) Behavioral health practices and treatment providers handling substance use disorder records — applies in addition to HIPAA with stricter confidentiality requirements and patient consent rules. Relevant for the Richmond region providers serving the region’s veteran and active-duty military population. Separate access control architecture for SUD records, logical segregation from general PHI, consent tracking implementation, staff training on Part 2 vs. HIPAA distinction, prohibition on re-disclosure enforcement Compliant record segregation architecture, consent audit trail documentation, Part 2 policy documentation, workforce training records covering both frameworks

Free HIPAA Gap Assessment

Find Out Exactly Where Your HIPAA Program Has Gaps — In 15 Minutes

Most the Richmond region healthcare practices have larger HIPAA gaps than they realize — and OCR’s enforcement data confirms it. Our free HIPAA Gap Assessment identifies your specific exposure areas across the Security Rule’s required and addressable specifications and gives you a written summary with no obligation.

  • 15-minute call with a Capital Techies HIPAA advisor, not a salesperson
  • We map your current safeguards against Security Rule specifications
  • We identify your highest-risk gaps: missing SRA, access control failures, BAA inventory holes
  • You receive a written gap summary whether or not you become a client
  • No contract required. No sales pressure — ever.
  • Serving physician practices, behavioral health, dental, billing companies, and specialty clinics across all Richmond region of the Richmond region
Start My Free Assessment

Client Feedback

What Our Clients Say

Real reviews from Capital Techies clients on Google.

FAQ

HIPAA Compliance Questions from Richmond-area Healthcare Organizations

Authoritative answers to the questions the Richmond region physician practices, behavioral health providers, dental offices, billing companies, and specialty clinics ask most often about HIPAA compliance, OCR enforcement, and Security Rule implementation.

How much does HIPAA compliance cost for a practice in Richmond?
For a small to mid-size physician practice in Richmond or the Richmond region, a properly documented HIPAA Security Risk Analysis typically costs between $2,500 and $6,000 as a standalone engagement, depending on the number of locations and systems in scope. Practices that engage Capital Techies for an ongoing HIPAA advisory or managed IT program have the annual SRA included as part of the engagement. What HIPAA compliance costs far less than is the alternative: VCU Health paid $2.175 million to HHS OCR in a 2019 settlement, and the average US healthcare data breach cost $10.22 million in 2025 per IBM. The Security Rule applies to every covered entity regardless of size — a three-physician practice in Chesterfield faces the same legal requirements as a large health system. The SRA is the first required step, and Capital Techies conducts them in a format that satisfies OCR’s documentation expectations rather than a generic checklist.
What is a HIPAA risk analysis and is it required?
A HIPAA Security Risk Analysis (SRA) is a documented assessment required under 45 CFR 164.308(a)(1) that identifies all locations where electronic Protected Health Information (ePHI) is stored, transmitted, or received; evaluates the threats and vulnerabilities to that information; rates the likelihood and impact of potential violations; and documents the safeguards in place to reduce risk to an acceptable level. Yes, it is required — by name, in the regulation. HHS OCR launched a dedicated Risk Analysis Enforcement Initiative in October 2024 specifically because missing or inadequate SRAs are the most common finding in OCR audits and investigations. By April 2025, OCR had settled multiple enforcement actions under this initiative. The SRA must be conducted annually or whenever a significant operational change occurs — a new EHR system, a new office location, or a new vendor with ePHI access all constitute significant operational changes that trigger an SRA update. It cannot be a generic checklist: OCR’s guidance requires it to be specific to your organization’s actual environment.
What happens if my practice is audited by OCR?
An OCR audit or investigation begins with a document request — typically your Security Risk Analysis, policies and procedures, workforce training records, BAA inventory, and incident response plan. Organizations that have maintained their HIPAA program documentation can respond within the required timeframe and often resolve audits with a corrective action plan rather than a civil money penalty. Organizations that lack documentation face a much harder path: OCR’s audit findings become the basis for enforcement action, and civil money penalties can reach $2.19 million per violation category per year for willful neglect not corrected. OCR’s October 2024 Risk Analysis Enforcement Initiative means practices are now being investigated proactively for SRA failures — not just in response to patient complaints or reported breaches. Capital Techies builds the documentation before an OCR contact arrives, because reactive compliance after OCR initiates an investigation is significantly more expensive than proactive compliance beforehand. The difference is whether you can hand OCR an organized program file or scramble to reconstruct documentation that was never created.
Do medical billing companies need to be HIPAA compliant?
Yes. Medical billing companies, revenue cycle management firms, and coding services that handle PHI on behalf of covered entities are HIPAA business associates and carry direct legal liability to OCR under the Omnibus Rule. This means implementing the same technical and administrative safeguards as a covered entity, executing Business Associate Agreements with each covered entity client, and maintaining six years of compliance documentation. OCR has settled enforcement actions directly against business associates for Security Rule violations — without requiring a covered entity violation as a prerequisite. A medical billing company in the Richmond region that suffers a ransomware attack involving patient billing records is subject to the same breach notification requirements and enforcement exposure as the physician practice it serves. Capital Techies builds HIPAA compliance programs specifically for the Richmond region-area business associates, including billing and RCM companies, that satisfy the same requirements imposed on covered entities.
What is a Business Associate Agreement and do I need one for every vendor?
A Business Associate Agreement (BAA) is a contract required by HIPAA that documents a vendor’s obligation to protect PHI they handle on a covered entity’s behalf. Every vendor, contractor, or cloud service with access to your ePHI requires a signed BAA — including your EHR vendor, billing company, IT provider, cloud backup platform, transcription service, and any other service that stores, transmits, or processes patient data. Missing BAAs are an independent HIPAA violation separate from any underlying breach. The VCU Health 2019 settlement ($2.175 million) included a finding that VCU Health lacked a BAA with its own parent entity — demonstrating that even well-resourced health systems have BAA gaps, and that OCR treats those gaps as enforcement-worthy violations. Capital Techies inventories all vendor relationships with ePHI access, executes properly structured BAAs, and maintains the complete BAA inventory in your HIPAA program documentation file.
What is the Virginia breach notification law and what does it require for healthcare organizations?
Virginia Code 18.2-186.6 requires businesses — including healthcare organizations — to notify affected Virginia residents and the Virginia Attorney General’s Computer Crime Section without unreasonable delay after a breach of unencrypted personal information. Virginia does not use a fixed number of days — the “without unreasonable delay” standard applies, and notification may only be delayed at law enforcement’s written request when it would impede a criminal investigation. AG notification is required for every reportable breach regardless of how many individuals are affected. For the Richmond region healthcare organizations, this Virginia state requirement runs concurrently with HIPAA’s breach notification obligations to HHS OCR and affected individuals — meaning both sets of notifications must be prepared simultaneously after a breach is discovered. Civil penalties under Virginia law can reach $150,000 per breach. Capital Techies builds breach notification workflows that satisfy both the federal HIPAA requirements and Virginia’s state law requirement in a single coordinated response.
Does behavioral health have different HIPAA requirements than general medical practices?
Behavioral health providers face the same HIPAA Security Rule requirements as other covered entities, but they also carry obligations under 42 CFR Part 2 for substance use disorder records — which impose stricter confidentiality requirements than standard PHI and cannot be disclosed without patient consent in most circumstances, including to other treating providers. A the Richmond region behavioral health practice serving the region’s veteran and active-duty military population must manage both frameworks simultaneously: HIPAA governs all patient records, while Part 2 adds a separate layer of protection specifically for SUD records. Commingling SUD records with general PHI in a shared EHR system creates simultaneous HIPAA and Part 2 exposure. Capital Techies builds access control architectures for the Richmond region behavioral health providers that enforce both frameworks — Part 2 records receive heightened access controls and audit logging while general PHI follows standard HIPAA technical safeguard requirements, without creating operational barriers for clinical staff.
What does OCR’s October 2024 Risk Analysis Enforcement Initiative mean for the Richmond region practices?
HHS OCR announced in October 2024 a targeted enforcement initiative focused on covered entities and business associates that have failed to conduct adequate Security Risk Analyses — the single most commonly cited missing control in HIPAA enforcement actions. By April 2025, multiple settlements had resulted from this initiative. For the Richmond region physician practices, clinics, and business associates, the initiative means OCR is actively pursuing compliance program adequacy — not just responding to patient complaints or large-scale breaches. If your practice has not conducted a documented, organization-specific SRA in the last 12 months, you have the primary gap OCR is now targeting. Capital Techies conducts SRAs that satisfy OCR’s documentation expectations: specific to your organization’s environment, covering all ePHI locations, and supported by a risk management plan — not a generic template purchased online or completed as a checkbox exercise.
Does my dental practice in the Richmond region need HIPAA compliance?
Yes. Dental practices that transmit health information electronically — including submitting billing claims to insurance carriers — are HIPAA covered entities subject to all Security Rule requirements. This includes conducting an annual Security Risk Analysis, implementing access controls on patient records, encrypting ePHI at rest and in transit, executing BAAs with every vendor with patient data access (including dental software vendors, billing services, digital X-ray systems, and cloud storage), and maintaining six years of documentation. Many the Richmond region dental offices operate under the mistaken belief that their dental practice management software’s “HIPAA compliance” features satisfy their obligations. They do not — the software vendor’s security posture does not substitute for the dental practice’s own SRA, access controls, workforce training, and incident response plan. Capital Techies builds HIPAA compliance programs for the Richmond region dental practices that are appropriately sized without cutting corners on required Security Rule controls.
What is the HIPAA Security Rule NPRM from December 2024 and should I be implementing changes now?
HHS OCR published a Notice of Proposed Rulemaking (NPRM) on December 27, 2024 proposing substantial strengthening of the HIPAA Security Rule’s cybersecurity requirements. Key proposed changes include mandatory multi-factor authentication for all ePHI access (removing the current “addressable” flexibility), mandatory encryption of ePHI at rest and in transit with no opt-out, and enhanced technical safeguard specifications that align the Security Rule more closely with modern cybersecurity practice. As of mid-2026, the NPRM remains in the rulemaking process — but organizations that implement MFA and encryption now satisfy both the current rule and the proposed enhanced requirements simultaneously. Capital Techies implements MFA and encryption as standard components of every HIPAA technical safeguard engagement. the Richmond region practices that implement these controls now are positioned ahead of the final rule regardless of when it takes effect — and those controls are required by the existing rule as addressable specifications that must be implemented when reasonable and appropriate.

How Exposed Is Your Business Right Now?

Get your free Cyber Risk Score in under 3 minutes. We check for exposed credentials, email spoofing gaps, dark web leaks, and unpatched systems. You get a letter grade and a plain-English report. No sales call required.

Get Your Free Cyber Risk Score →

Free · Takes 3 minutes · No sales call required