ANNUAL INDUSTRY CONFERENCE
October 15–17, 2026 · Atlanta
See the conference · Get tickets
FOR SPONSORS • EXHIBITORS
October 15–17, 2026 · Atlanta
Request Prospectus • Supporters • Apply
PRACTICE DECISION TOOLS
FOR Doctors, Specialists, NPs, PAs
Calculators • Marketing • CMT Patient Study • All tools
RESEARCH & PROOF
National Stats, Industry Research
Research Briefs • Visuals • Legal Op • Natl Stats
Cybersecurity and Privacy for the Small Practice in the AI Era
Small practices hold the same sensitive data as hospitals, with a fraction of the security staff. The Change Healthcare attack showed how fast a breach elsewhere becomes a cash crisis at home. AI tools add a new way for patient information to leave the building.
Updated October 2026: evidence grades replaced with evidence types; funding disclosed on every source.
Start here: the questions this brief answers
Tap a question for the short answer, then jump to the evidence.
Federal regulators are penalizing small practices that skip the basics: a neurology practice paid $25,000 after a ransomware attack because it had not done an adequate risk analysis. A proposed HIPAA Security Rule update would require multifactor authentication, encryption and more, but is not final and is not expected before 2027. The practical priorities are the same either way: a documented risk analysis, multifactor authentication, encrypted backups, business associate agreements with every AI vendor, and a staff rule never to paste patient information into consumer chatbots.
“In a relationship-based practice, a data breach isn't an IT problem. It's a broken promise. Protecting your members' information is part of the membership, whether it's written in the contract or not.”
Are small practices really targets?
Yes. Federal enforcement includes small practices, and outside attacks hit small practices hard: after the 2024 Change Healthcare attack, 80% of practices in an AMA survey lost revenue and 55% used personal funds to cover expenses.
Go to the full answer ↓What is HHS actually enforcing?
Risk analysis. A small neurology practice paid $25,000 in 2025 after ransomware, in what HHS called its eighth Risk Analysis Initiative enforcement action. By June 2026 the count had reached 14, and 76% of 2025 enforcement actions penalized a risk analysis failure.
Go to the full answer ↓Is the new HIPAA Security Rule in effect?
No. It was proposed in January 2025. As of mid-2026 it had not been finalized, and reporting indicated HHS moved the final action target to 2027.
Go to the full answer ↓Can my staff use ChatGPT with patient information?
Not consumer versions without a business associate agreement. OpenAI has said HIPAA does not apply to its consumer health tool. Use only tools whose vendors sign a BAA.
Go to the full answer ↓Does HIPAA apply to a cash-only practice?
Possibly not, if the practice never conducts standard electronic transactions such as insurance claims. State privacy laws may still apply, and members expect the same protection. Confirm with counsel.
Go to the full answer ↓A breach somewhere else becomes your cash crisis
On February 21, 2024, attackers hit Change Healthcare, a claims and payment clearinghouse. UnitedHealth Group eventually put the number of people affected at about 192.7 million.1 Practices that had never been breached themselves suddenly could not get paid.
Practices with recurring membership revenue were likely less exposed to a claims outage than insurance-dependent practices. That is CMT inference. They remain fully exposed to their own breaches, and to the trust damage a breach does in a relationship-based model.
What regulators enforce now, and what's coming
On April 25, 2025, HHS's Office for Civil Rights announced a $25,000 settlement with Comprehensive Neurology, a small New York practice. Ransomware had encrypted its systems in December 2020, affecting 6,800 people. OCR found the practice had not conducted an adequate risk analysis. HHS described it as its 12th ransomware enforcement action and the 8th under its Risk Analysis Initiative.3 Policy and Law
The existing HIPAA Security Rule. Risk analysis is required; some safeguards, such as encryption, are "addressable" rather than mandatory.4
HHS proposes a major Security Rule update (RIN 0945-AA22): mandatory multifactor authentication and encryption, asset inventories and network maps, vulnerability scans twice a year, annual penetration tests, and restoring critical systems within 72 hours.5
Not finalized. Reporting indicates HHS moved the final action to its long-term agenda, targeting July 2027.4
OCR's own recommendations already point where the proposed rule is going: know where electronic patient information lives, use strong authentication, encrypt data in transit and at rest, review system activity, and train staff.3
AI tools are a new door out of the building
Under HIPAA, a vendor that creates, receives, maintains or transmits protected health information for a covered entity is a business associate and must sign a business associate agreement.6 That includes AI scribes, AI inbox tools and transcription services. Consumer chatbots are different: OpenAI's health lead has said HIPAA does not apply to its consumer ChatGPT Health product.7 In the AMA's 2026 survey, 86% of physicians called data privacy critical to AI adoption.8
Allowed with safeguards
- AI scribes and assistants whose vendors sign a BAA
- EHR-integrated AI features covered by your EHR agreement
- De-identified use, if your counsel confirms the method
Not allowed
- Pasting patient names, notes or images into consumer chatbots
- Free transcription apps without a BAA
- Personal accounts on any AI tool for practice work
HIPAA applies to health care providers who transmit health information electronically in connection with standard transactions, such as insurance claims.9 Some cash-only practices may fall outside that definition. State privacy laws can still apply, and members will not care about the technicality if their data leaks. CMT recommends HIPAA-level safeguards regardless. Confirm your status with counsel.
The ten-minute security self-check
Which of these are true for your practice today?
What independent data show about incidents, safeguards and AI use
No verified survey isolates concierge or DPC practices. The figures below cover health care broadly or medical groups of all kinds, so read them as the environment membership practices operate in, not as a measure of membership practices themselves.
Safeguard adoption is less well measured. In a 2024 MGMA poll of 326 practices, 72% increased cybersecurity spending, citing rising insurance costs, threats and new security measures.13 A 2021 MGMA poll of 810 respondents found 82% carried cyber insurance, up from 54% in 2018.14 The most recent size-specific measure of multifactor authentication CMT could verify is older: a KLAS and CHIME analysis of 2018 survey data found MFA remained a gap for about half of small organizations.15 Practice Insight Enforcement keeps pointing at the same root cause. By June 2026, OCR had brought 14 enforcement actions under its Risk Analysis Initiative.16 Policy and Law
Hackers do most of the damage, about a third of breaches occur at vendors, and regulators most often penalize a missing or weak risk analysis. For a small practice, that points to three priorities: the risk analysis, a BAA and security review for every vendor (AI tools included), and a staff AI policy that gives people approved tools so they do not reach for unapproved ones. The insurance and MFA figures are dated, so treat them as direction rather than current rates. That reading is CMT's inference from the evidence above.
Do the risk analysis
It is the requirement regulators enforce most, and the map for everything else.
Lock the doors
Multifactor authentication, encryption, tested backups and BAAs, starting this quarter.
Lead the culture
Make privacy part of the membership promise, and say so to members.
How this brief was built
CMT reviewed HHS Office for Civil Rights enforcement announcements, the January 2025 HIPAA Security Rule proposed rule and reporting on its status, HHS guidance on covered entities and business associates, an AMA survey on the Change Healthcare attack and reporting on that breach. Breach counts come from The HIPAA Journal's analysis of the HHS OCR breach portal; counts change as entities file late reports, so the February 2026 and June 2026 figures differ. Safeguard and insurance figures come from MGMA Stat polls (single-question polls of MGMA members, labeled Practice Insight), a KLAS and CHIME analysis of 2018 survey data, and a Wolters Kluwer survey (company-conducted and not peer-reviewed, labeled Industry Research). No source isolates concierge or DPC practices. This brief is educational and is not legal or cybersecurity advice.
How to read the evidence types
Every key finding is labeled by evidence type. Labels describe the type of evidence, not its value. Each type answers different questions. Funding is disclosed on every source.
Randomized trials and systematic reviews.Best for cause and effect.
Large observational studies and government data.Best for trends at scale.
Surveys, smaller studies and expert consensus.Best for real-world experience.
Company-sponsored or company-reported data that is not peer-reviewed.Best for early signals and operating data.
Statutes, regulation and official guidance.Best for what is required.
What we don't know
- Breach and ransomware rates among concierge and DPC practices specifically.
- Current rates of multifactor authentication, risk analysis completion and cyber insurance in small practices; the best verified figures are from 2018 to 2021.
- How many small practices use AI tools without a BAA in place.
- The final content and timing of the HIPAA Security Rule update.
- How regulators will treat AI scribes and assistants that store audio or transcripts.
How to cite this brief
External review: this brief has not yet been reviewed by an outside expert. When review is complete, the reviewer is credited by name above with any conflicts of interest, and the version number is updated. Reviewers check accuracy and fairness; CMT is responsible for the final content.
Corrections policy: when an error is identified, CMT corrects it in the open and updates the version number above. Send corrections to the editor through conciergemedicinetoday.net.
Related CMT Research Briefs
References
- TechTarget HealthTech Security. Change Healthcare data breach victim count rises to 193 million. August 2025. www.techtarget.comFunding: not stated (news report)
- California Medical Association. AMA survey finds cyberattack continues to threaten the viability of physician practices (survey March 26 to April 3, 2024; more than 1,400 respondents). April 2024. cmadocs.orgFunding: not stated (conducted by the American Medical Association; reported by the California Medical Association)
- U.S. Department of Health and Human Services, Office for Civil Rights. HHS Office for Civil Rights settles HIPAA ransomware cybersecurity investigation with neurology practice. April 25, 2025. www.hhs.govFunding: federal (U.S. Department of Health and Human Services publication)
- Cyberz. HIPAA Security Rule changes in 2026: what actually changed, and what slipped to 2027. July 30, 2026. cyberz.proFunding: not stated (company blog)
- U.S. Department of Health and Human Services. HIPAA Security Rule to strengthen the cybersecurity of electronic protected health information (proposed rule, RIN 0945-AA22). Federal Register. January 6, 2025. www.federalregister.govFunding: federal (U.S. Department of Health and Human Services publication)
- U.S. Department of Health and Human Services. Business associates (guidance). www.hhs.govFunding: federal (U.S. Department of Health and Human Services publication)
- Medical Economics. OpenAI launches ChatGPT Health, directly linking patient portals to the AI chatbot. January 8, 2026. www.medicaleconomics.comFunding: not stated (news report)
- American Medical Association. More than 80% of physicians use AI professionally: AMA survey (2026 Physician Survey on Augmented Intelligence). O'Reilly KB. AMA. March 12, 2026. www.ama-assn.orgFunding: not stated (conducted and published by the American Medical Association)
- U.S. Department of Health and Human Services. Covered entities and business associates. www.hhs.govFunding: federal (U.S. Department of Health and Human Services publication)
- The HIPAA Journal. Largest healthcare data breaches of 2025 (updated count from the HHS OCR breach portal). June 5, 2026. www.hipaajournal.comFunding: not stated (analysis published by The HIPAA Journal)
- Steve Alder. 2025 healthcare data breach report. The HIPAA Journal (analysis of HHS OCR breach portal data). February 13, 2026. www.hipaajournal.comFunding: not stated (analysis published by The HIPAA Journal)
- Wolters Kluwer Health. Shadow AI: providers are using unapproved tools to improve workflow (survey of 518 U.S. health care workers, 256 providers and 262 administrators, December 2025). January 22, 2026. www.wolterskluwer.comFunding: industry (conducted and published by Wolters Kluwer Health)
- MGMA Stat poll. Confronting the rising price tag of cybersecurity in medical practices (326 applicable responses). Medical Group Management Association. September 17, 2024. www.mgma.comFunding: not stated (conducted and published by MGMA)
- MGMA Stat poll. With cyberattacks on the rise, cyberinsurance may provide peace of mind (810 applicable responses). Medical Group Management Association. May 25, 2021. www.mgma.comFunding: not stated (conducted and published by MGMA)
- KLAS Research and CHIME. How aligned are provider organizations with the Health Industry Cybersecurity Practices (HICP) guidelines? Analysis of 600+ organizations in the 2018 Most Wired survey. Reported by Healthcare Innovation, June 28, 2019. www.hcinnovationgroup.comFunding: not stated (published by KLAS Research and CHIME)
- Healthcare Innovation. In breach settlements, OCR continues to call out weak risk analyses. June 2026. www.hcinnovationgroup.comFunding: not stated (news report)
Educational and informational only. This CMT Research Brief does not constitute medical, legal, tax, financial, accounting or other professional advice, and it does not create a professional relationship of any kind. Statements about laws, regulations, tax rules and payer policies are general, may not reflect the rules in your state, and can change after publication. Consult a qualified attorney, accountant, tax adviser, compliance professional or licensed clinician before acting on anything here.
Independence. Concierge Medicine Today is an independent publication. It does not accept payment for favorable coverage, and it does not favor one practice model over another. Company names and products are mentioned for context only and are not endorsements. Funding is disclosed for every source in the reference list.
Accuracy. CMT verifies figures against their original or best available sources at the time of publication. Where a figure is an estimate, an inference or a company-reported number, the brief says so. This content is not without possible error or omission.
© 2007-2026 Concierge Medicine Today, LLC. All rights reserved.

