HIPAA Compliance for Law Firms: 7 Breach Risks

by The Creator | Aug 14, 2026

HIPAA compliance for law firms checklist showing encryption, access controls, and breach response procedures

HIPAA compliance for law firms is not optional when you handle client health information, even if you are not a healthcare provider. Personal injury attorneys, workers’ compensation specialists, disability lawyers, and any firm that touches medical records in the course of representation are considered business associates under the Health Insurance Portability and Accountability Act. That designation carries the same data protection obligations as a hospital or clinic, and violations can cost your firm up to $1.5 million annually per violation category, plus the reputational damage and client lawsuits that follow a breach.

The recent breach at Buist Byars & Taylor LLC, a law firm that reported unauthorized access affecting at least 12 individuals’ sensitive personal information, illustrates what happens when legal practices underestimate their HIPAA obligations. The firm discovered the incident, launched an investigation, and now faces scrutiny from both regulators and affected clients. For a small or midsize law firm, even a dozen compromised records can trigger federal investigations, mandatory breach notifications, corrective action plans, and the distraction of managing crisis communications while trying to serve clients.

You are probably asking: does my firm really need to follow HIPAA? The honest answer depends on whether you create, receive, maintain, or transmit protected health information (PHI) on behalf of a covered entity like a hospital, insurer, or healthcare provider. If you represent clients in cases involving medical treatment, request records from physicians, store medical files in your case management system, or share health data with insurers during settlement negotiations, you are a business associate. The size of your firm does not matter. A solo practitioner with one personal injury case has the same compliance duty as a 50-attorney firm.

What are the core HIPAA compliance requirements for law firms?

HIPAA’s Security Rule requires you to protect electronic PHI (ePHI) through three categories of safeguards: administrative, physical, and technical. Administrative safeguards include conducting a security risk assessment, designating a privacy officer, training employees on data handling, and creating policies for incident response. Physical safeguards mean controlling who can access your servers, locking file cabinets that hold paper records, and ensuring workstations displaying ePHI are not visible to unauthorized visitors. Technical safeguards demand encryption of ePHI at rest and in transit, unique user IDs and passwords, automatic logoff, and audit logs that track who accessed which records and when.

Many law firms stumble on the risk assessment. The Department of Health and Human Services Office for Civil Rights (OCR) expects you to document every system, application, and vendor that touches ePHI, identify vulnerabilities (unencrypted laptops, weak passwords, outdated software), estimate the likelihood and impact of a breach, and implement or document why you rejected specific safeguards. This is not a one-time checkbox. The rule requires periodic reassessment, especially when you add new technology, change case management software, or hire a new cloud provider.

Business associate agreements (BAAs) are another compliance cornerstone. Every vendor that processes, stores, or transmits ePHI on your behalf (your cloud backup service, document management platform, e-discovery provider, transcription service, IT support partner) must sign a BAA that spells out their security obligations, breach notification duties, and your right to audit. Operating without signed BAAs is a per-violation penalty waiting to happen, because OCR presumes that any vendor without a BAA was not properly supervised.

What are the most common HIPAA breach risks in small law firms?

Unencrypted email is the top offender. Attorneys routinely send medical records, treatment summaries, and disability evaluations via standard email to clients, opposing counsel, and insurance adjusters. If that email is intercepted or the recipient’s inbox is compromised, you have just experienced a reportable breach. The fix is straightforward: use encrypted email (either through your email provider’s TLS settings verified to both parties, or a secure portal for document exchange) and train staff never to attach ePHI to unencrypted messages.

Inadequate vendor vetting comes next. Law firms often select case management software, cloud storage, or virtual receptionist services based on features and price, without asking whether the vendor is willing to sign a BAA or whether they encrypt data at rest. If a vendor suffers a breach and you have no BAA, OCR will hold you responsible for failing to ensure the vendor’s safeguards. Always request a BAA before onboarding, review the vendor’s security practices (ask for SOC 2 reports or third-party audits), and maintain a master list of all business associates.

Missing access controls allow any employee to view any file. Receptionists, paralegals, and billing staff may not need access to every client’s medical history. Role-based access ensures that users see only the ePHI necessary for their job function, reducing the risk of curiosity browsing or accidental disclosure. Audit logs then let you prove who accessed what and when, which is essential if you must investigate a suspected breach or demonstrate compliance during an OCR audit.

The absence of an incident response plan turns a manageable event into chaos. When an employee clicks a phishing link, a laptop is stolen, or a ransomware attack locks your files, every hour you delay breach notification increases penalties. HIPAA requires notification to affected individuals within 60 days of discovering a breach, notification to OCR if 500 or more records are involved, and in some cases notification to media. A written plan that assigns roles (who investigates, who notifies clients, who contacts OCR, who talks to the press) and includes template letters speeds response and demonstrates to regulators that you took the breach seriously.

How much do HIPAA violations actually cost law firms?

OCR’s penalty tiers start at $137 per violation (updated annually for inflation) for violations the firm did not know about and could not have avoided with reasonable diligence, and climb to $68,928 per violation for willful neglect that is not corrected within 30 days. The annual cap per violation category is $2,067,813. That means if your firm failed to encrypt ePHI (one category), failed to conduct a risk assessment (another category), and failed to train employees (a third category), OCR can impose penalties across all three.

Beyond federal fines, state attorneys general can bring enforcement actions under HIPAA, and affected individuals can sue for damages under state privacy and negligence laws. The Buist Byars & Taylor breach, though involving only 12 individuals, triggered an investigation that will cost the firm legal fees, forensic analysis, credit monitoring for affected clients, and potential settlements. For a small firm, those costs can exceed six figures even before any OCR penalty.

Reputational damage is harder to quantify but no less real. Clients trust law firms with their most sensitive information. A breach announcement on your website, mandatory letters to clients explaining that their Social Security numbers and medical diagnoses were exposed, and coverage in local legal news erodes that trust. Referral sources (physicians, other attorneys, insurance adjusters) may steer cases elsewhere if they doubt your data security.

Do I need HIPAA compliance for law firms if I only handle a few medical record requests per year?

Yes. HIPAA does not set a minimum threshold. If you request, receive, or store even one medical record in the course of representation, you are creating or receiving PHI on behalf of a covered entity (the healthcare provider who released the record). The rule applies whether you handle one case or a thousand. The difference is that a firm with occasional PHI exposure can implement simpler safeguards (a secure portal for receiving records, encryption on all devices, a brief staff training session, and a single BAA with your IT provider) rather than enterprise-grade compliance programs.

Some attorneys assume that attorney-client privilege exempts them from HIPAA. It does not. Privilege protects the content of your communications from discovery in litigation, but it does not override the federal duty to secure ePHI. Courts have consistently held that law firms acting as business associates must comply with the Security Rule, and privilege is no defense to an OCR enforcement action.

What practical steps can a small law firm take to achieve HIPAA compliance?

Start with a security risk assessment. You can use the free tool published by the Office of the National Coordinator for Health IT (HealthIT.gov Security Risk Assessment Tool) or hire a consultant who understands legal practice workflows. Document every place ePHI lives: laptops, desktop computers, smartphones, cloud case management, email archives, backup drives, and paper files. Identify risks (devices without encryption, default passwords, open Wi-Fi in the conference room) and create a remediation plan with deadlines and assigned owners.

Encrypt all devices and communication channels. Windows and macOS offer built-in full-disk encryption (BitLocker and FileVault). Enable it on every laptop and desktop. Configure your email server to require TLS encryption, or adopt a secure client portal (many case management platforms include one) for exchanging documents with clients and co-counsel. Encrypt backup drives and cloud storage.

Implement unique user credentials and automatic logoff. Every person who accesses your systems should have their own username and password, never shared. Require strong passwords (at least 12 characters, mixing letters, numbers, and symbols) and enable multi-factor authentication wherever possible. Configure workstations to lock after 10 minutes of inactivity so that ePHI is not left visible if someone steps away from their desk.

Train your team annually. Staff turnover, new software, and evolving threats mean that a one-time training is insufficient. Hold a 30-minute session each year covering what PHI is, why it matters, how to recognize phishing, how to use the secure portal, and whom to contact if they suspect a breach. Document attendance and keep training records for six years, the HIPAA retention standard.

Obtain signed business associate agreements from every vendor. Create a simple spreadsheet listing your cloud providers, IT support firm, transcription service, legal research platform, and any other vendor that might access ePHI. Request a BAA from each. If a vendor refuses (claiming they are a mere conduit), evaluate whether that claim is accurate under HIPAA guidance or whether you need to switch vendors.

Draft a breach response plan. Write a two-page document that names your privacy officer (often the managing partner or office manager in a small firm), defines what constitutes a suspected breach (unauthorized access, lost laptop, ransomware), assigns investigation steps (preserve logs, interview staff, consult counsel), and includes timelines for notification. Keep a template breach notification letter ready, so you can customize and send it quickly if needed.

How does HIPAA compliance for law firms compare to other regulatory obligations?

HIPAA sits alongside state bar ethics rules, which require attorneys to protect client confidentiality and to stay abreast of technology risks. Many state bars have issued ethics opinions affirming that competent representation includes understanding cybersecurity. HIPAA gives you a concrete checklist to meet those ethics duties when health data is involved. Similarly, if your firm handles financial information for clients, you may face Federal Trade Commission Safeguards Rule obligations or state data breach notification laws. The good news is that HIPAA’s technical safeguards (encryption, access controls, audit logs) satisfy or exceed most other data protection regimes, so compliance in one area often carries over to another.

Compliance and regulatory exposure is a persistent challenge for professional services firms, and law practices are no exception. Ignoring HIPAA because you are not a hospital is a mistake that can cost you clients, cash, and credibility. Addressing it systematically transforms compliance from a burden into a differentiator, because you can truthfully tell clients and referral sources that you protect their information with the same rigor as their doctor’s office.

What should I do if my law firm has already experienced a data breach?

Act immediately. Contain the breach by disconnecting affected systems, changing passwords, and preserving logs. Do not delete anything, because forensic evidence is critical for understanding the scope and for regulators. Contact legal counsel experienced in data breach response. Determine within 24 to 48 hours whether the incident meets HIPAA’s definition of a breach (an impermissible use or disclosure of PHI that compromises its security or privacy). If it does, you have 60 days from discovery to notify affected individuals, and you must notify OCR within 60 days if it affects 500 or more people (or log it and report at year-end if fewer than 500).

Offer affected clients credit monitoring or identity theft protection services. While not legally required, it demonstrates good faith and can reduce the risk of individual lawsuits. Document every step you take in response: when you discovered the breach, how you investigated, whom you notified, what corrective measures you implemented. OCR will request this documentation, and a thorough record shows you took the event seriously and moved to prevent recurrence.

Use the breach as a catalyst for broader improvements. Update your risk assessment to reflect the vulnerability that was exploited (phishing, unpatched software, weak passwords), remediate it across all systems, retrain staff, and refine your incident response plan. Every breach, no matter how small, is an opportunity to harden your defenses and build client trust through transparency and accountability.

How can partnering with an MSP help law firms meet HIPAA requirements?

A managed service provider that understands legal industry cybersecurity can shoulder much of the technical and administrative burden. An MSP can conduct your annual risk assessment, implement and monitor encryption across all endpoints, configure access controls and audit logging in your case management system, apply security patches promptly, and provide employee training tailored to law firm workflows. Critically, a qualified MSP will sign a business associate agreement with your firm, accepting downstream liability for safeguarding ePHI in the systems they manage.

Look for an MSP that has worked with other law firms or healthcare business associates, asks detailed questions about your data flows, offers 24/7 monitoring and incident response, and provides clear documentation of their security controls. The right partner does not just keep your systems running. They translate HIPAA’s technical jargon into practical steps, maintain compliance documentation, and help you demonstrate to clients and regulators that you take data protection seriously. This frees you to focus on practicing law while knowing that your technology and compliance posture are in expert hands.

Frequently Asked Questions

Are all law firms required to comply with HIPAA?

Only law firms that create, receive, maintain, or transmit protected health information on behalf of a covered entity (such as hospitals, insurers, or healthcare providers) must comply with HIPAA. Personal injury, workers’ compensation, disability, medical malpractice, and healthcare litigation practices typically fall into this category. If your firm never handles medical records or health data, HIPAA does not apply, but you may still be subject to state privacy laws and bar ethics rules requiring data protection.

What is the penalty for a law firm’s first HIPAA violation?

Penalties depend on the level of culpability. If OCR finds you did not know and could not reasonably have known about the violation, fines start at $137 per violation. If the violation stems from reasonable cause (not willful neglect), fines range from $1,379 to $68,928 per violation. Willful neglect that is corrected within 30 days costs $13,785 to $68,928 per violation, and willful neglect not corrected can reach $68,928 per violation with an annual cap of $2,067,813 per violation category. First-time violators who cooperate and remediate quickly may receive lower penalties, but there is no formal first-offense waiver.

Do I need a business associate agreement with my IT support company?

Yes, if your IT support company has access to systems or data that contain electronic protected health information. Most IT providers who manage servers, cloud storage, email, or case management systems for law firms will access ePHI in the course of maintenance, troubleshooting, or backups. A signed business associate agreement is mandatory under HIPAA, and operating without one exposes your firm to penalties even if the IT company never causes a breach.

How long do I have to notify clients after discovering a data breach?

HIPAA requires notification to affected individuals without unreasonable delay and no later than 60 calendar days after you discover the breach. Discovery means the first day any employee, officer, or agent of your firm knows or should have known about the breach. If the breach affects 500 or more individuals, you must also notify OCR and prominent media outlets within the same 60-day window. For breaches affecting fewer than 500 people, you log the incident and report it to OCR annually.

Can I use regular email to send medical records to clients?

You can use email only if it is encrypted end-to-end or if both sender and recipient email servers support and enforce Transport Layer Security (TLS) encryption. Most consumer email services (Gmail, Outlook.com, Yahoo) support TLS, but you cannot guarantee the recipient’s server does. Best practice is to use a HIPAA-compliant secure portal or encrypted email service designed for healthcare data exchange, and to obtain a business associate agreement from the email provider if they can access message content.

What should be included in a law firm’s HIPAA risk assessment?

A complete risk assessment inventories all systems and devices that store or transmit ePHI (laptops, desktops, smartphones, servers, cloud applications, backups), identifies vulnerabilities (missing encryption, weak passwords, outdated software, inadequate access controls), evaluates the likelihood and impact of each threat (ransomware, lost device, insider snooping, phishing), and documents current safeguards and any gaps. The assessment must be in writing, updated periodically (at least annually or whenever you change technology), and used to drive a remediation plan with assigned responsibilities and deadlines.

Keep reading

Sources

Source: Buist Byars & Taylor LLC Data Breach, Investigated by Federman & Sherwood