Quick answer
In most small practices, HIPAA arrives on the office manager’s desk without a conversation. Nobody hands over a budget or a job description. They just start forwarding the records requests and the vendor paperwork. If that is your situation, the useful thing is knowing where the line falls: training records, records requests, vendor inventory, incident intake, and daily workforce practices are genuinely yours to run. Money for security controls, signatures on business associate agreements, and enforcing the sanctions policy against a clinician are not, and pretending otherwise is how office managers end up carrying a risk they were never given the authority to fix.
This post is written for the person holding the job, not the owner deciding who gets it. We wrote about whether the office manager should be the privacy officer separately. This one assumes the answer already turned out to be you.
What actually belongs to you
Four things run through your desk whether or not anyone made it official.
Training records. The Privacy Rule requires training your workforce on your policies under 45 CFR 164.530(b), and Texas adds a hard deadline. Under Texas Health and Safety Code 181.101 a new employee must complete training on state and federal PHI law within 90 days of hire, tailored to what they actually do. They sign a statement verifying completion, and the practice keeps that statement for six years. The requirement people miss is the retention, not the training. An investigator does not want to hear that you train people. They want the signed records, by name, for the current period.
Records requests. Under 45 CFR 164.524 you have 30 calendar days to act on a request, with one permitted 30-day extension if you send the patient a written explanation and a delivery date. In Texas, electronic records move faster: Health and Safety Code 181.102 gives a practice using a capable EHR 15 business days. Right of access is one of OCR’s most actively enforced provisions, and the cases are rarely dramatic. They are usually a request that sat in someone’s inbox during a staffing gap.
The vendor list. Every vendor that creates, receives, maintains, or transmits PHI on your behalf needs a signed business associate agreement before any PHI moves, under 45 CFR 164.502(e). You are almost certainly the only person who knows the full list, because you are the one who set up the accounts. Building that inventory is yours. Getting the missing agreements signed is not, and we will come back to that.
Incident intake. Staff tell you first. The odd email, the laptop that went home and did not come back, the fax that went to the wrong number. What you own is capturing it accurately and immediately: what happened, when it was discovered, who was involved, what data was touched. What you do not own is deciding whether it legally counts as a breach.
Which deadlines start without anyone telling you?
This is the part that catches office managers, because none of these clocks announce themselves.
The breach clock starts at discovery, not at confirmation. Under 45 CFR 164.404 individual notice is due without unreasonable delay and no later than 60 calendar days after the breach is discovered. If 500 or more individuals are affected, notice to HHS goes contemporaneously with that individual notice under 164.408. When more than 500 residents of a single state are involved, 164.406 adds notice to prominent media serving that area. The practical danger is the weeks that disappear while everyone waits to be sure it was really a breach. Discovery started the clock already.
The training clock starts at hire, not at orientation. Ninety days in Texas, and it runs whether or not anyone scheduled the session.
The records clock starts when the request arrives, including the one a patient made verbally at the front desk that nobody wrote down.
None of these require you to be a compliance professional. They require someone to be tracking dates, which is a thing office managers are already good at and are rarely asked to do here.
What you cannot fix alone
Three things sit above the role, and knowing that is not an excuse. It is how you avoid absorbing a risk you cannot close.
Money. Encryption on the laptops, multifactor authentication on remote access, a backup you actually control instead of one your IT vendor holds. These are purchases. You can identify them and price them. You cannot approve them.
Signatures. A business associate agreement binds the practice. You can build the vendor inventory, flag which agreements are missing, and prepare them for signature. The owner signs.
Enforcement. 45 CFR 164.530(e) requires applying sanctions to workforce members who violate your policies. In a small practice this collides with reality the first time the person who violated the policy is a provider who generates most of the revenue. An office manager cannot sanction a partner. Only the owner can, and if they will not, the sanctions policy is decorative.
The Risk Analysis. The written assessment required under 45 CFR 164.308(a)(1)(ii)(A) is not something you produce between scheduling and payroll. It is the document OCR requests first, and it is the most-failed requirement in HIPAA. In OCR’s Phase 2 audits, only 14 percent of covered entities substantially fulfilled the risk analysis requirement and only 6 percent adequately handled risk management. Across the 2026 OCR settlements we reviewed, failure to conduct an accurate and thorough risk analysis was cited in every one. What you own here is knowing whether the practice has a current one and raising it when the answer is no.
How do you protect yourself while doing this job?
Write down what you escalate. That is the whole answer, and it is worth being blunt about why.
Enforcement runs against the organization, not the office manager. Civil penalties under the 2026 inflation-adjusted amounts start at $145 per violation and reach an annual cap of $2,190,294 for all violations of an identical provision, and settlements routinely carry a corrective action plan lasting two to three years. Those land on the practice. But when something goes wrong, the internal conversation about who knew what is a different conversation, and it is one where the person with a dated email is in a materially better position than the person with a clear memory.
So send the email. Short and specific. The risk analysis was last done in 2021. The IT company has full network access and no BAA on file. Two laptops are unencrypted. Here is what each one would cost to fix. Then keep the reply, including the ones that say not right now.
This is not adversarial. It is how a practice owner gets to make an informed decision instead of discovering the gap through an OCR letter, and it is how you stop carrying a decision that was never yours.
Where to start this month
Pick the one that is worst in your practice and close it.
If you do not know when the last Risk Analysis was signed, find out. If nobody can produce it, that is your escalation email this week. If the vendor list has never been written down, write it down and mark which agreements are missing. If training records are scattered across three years of folders, consolidate them and check who is past 90 days.
None of that requires budget approval, and all of it is evidence that the practice was paying attention.
North Privacy Advisors works with small and mid-size practices on exactly this gap, and the engagement is built so the office manager is not the one carrying it. If you want to know where your practice stands before someone else tells you, start with our HIPAA Risk Analysis service.
Last Updated: August 2, 2026