ANNUAL INDUSTRY CONFERENCE
October 15–17, 2026 · Atlanta
See the conference · Get tickets

FOR SPONSORS • EXHIBITORS
October 15–17, 2026 · Atlanta
Request Prospectus • Supporters • Apply

PRACTICE DECISION TOOLS
FOR Doctors, Specialists, NPs, PAs
Calculators • Marketing • CMT Patient Study • All tools

RESEARCH & PROOF
National Stats, Industry Research
Research Briefs • Visuals • Legal Op • Natl Stats

Cybersecurity and Privacy for the Small Practice in the AI Era | CMT Research Brief No. 36
Educational content only. Not medical, legal, tax, financial or accounting advice. Read the disclaimer.
Concierge Medicine Today
CMT Research Brief No. 36 · Operations · October 2026
Research Brief No. 36OperationsPrimary evidence: Policy and Law

Cybersecurity and Privacy for the Small Practice in the AI Era

Small practices hold the same sensitive data as hospitals, with a fraction of the security staff. The Change Healthcare attack showed how fast a breach elsewhere becomes a cash crisis at home. AI tools add a new way for patient information to leave the building.

Updated October 2026: evidence grades replaced with evidence types; funding disclosed on every source.

Start here: the questions this brief answers

Tap a question for the short answer, then jump to the evidence.

The 30-second answer

Federal regulators are penalizing small practices that skip the basics: a neurology practice paid $25,000 after a ransomware attack because it had not done an adequate risk analysis. A proposed HIPAA Security Rule update would require multifactor authentication, encryption and more, but is not final and is not expected before 2027. The practical priorities are the same either way: a documented risk analysis, multifactor authentication, encrypted backups, business associate agreements with every AI vendor, and a staff rule never to paste patient information into consumer chatbots.

From the Editor-in-Chief
“In a relationship-based practice, a data breach isn't an IT problem. It's a broken promise. Protecting your members' information is part of the membership, whether it's written in the contract or not.”
Michael Tetreault Editor-in-Chief, Concierge Medicine Today
Are small practices really targets?

Yes. Federal enforcement includes small practices, and outside attacks hit small practices hard: after the 2024 Change Healthcare attack, 80% of practices in an AMA survey lost revenue and 55% used personal funds to cover expenses.

Go to the full answer ↓
What is HHS actually enforcing?

Risk analysis. A small neurology practice paid $25,000 in 2025 after ransomware, in what HHS called its eighth Risk Analysis Initiative enforcement action. By June 2026 the count had reached 14, and 76% of 2025 enforcement actions penalized a risk analysis failure.

Go to the full answer ↓
Is the new HIPAA Security Rule in effect?

No. It was proposed in January 2025. As of mid-2026 it had not been finalized, and reporting indicated HHS moved the final action target to 2027.

Go to the full answer ↓
Can my staff use ChatGPT with patient information?

Not consumer versions without a business associate agreement. OpenAI has said HIPAA does not apply to its consumer health tool. Use only tools whose vendors sign a BAA.

Go to the full answer ↓
Does HIPAA apply to a cash-only practice?

Possibly not, if the practice never conducts standard electronic transactions such as insurance claims. State privacy laws may still apply, and members expect the same protection. Confirm with counsel.

Go to the full answer ↓
Written for:Practice ownersPractice administratorsIT and compliance leadsPhysicians adopting AI tools
Part 1 · The risk

A breach somewhere else becomes your cash crisis

On February 21, 2024, attackers hit Change Healthcare, a claims and payment clearinghouse. UnitedHealth Group eventually put the number of people affected at about 192.7 million.1 Practices that had never been breached themselves suddenly could not get paid.

Effects on physician practices after the Change Healthcare attack
AMA survey, March 26 to April 3, 2024; more than 1,400 respondents, 78% from practices with 10 or fewer physicians
Lost revenue from unpaid claims80%Used personal funds for expenses55%Could not buy supplies44%Could not make payroll31%
Analysis and chart: Concierge Medicine TodaySource: AMA survey, via California Medical Association.2 Self-selected respondents.
Membership practice angle

Practices with recurring membership revenue were likely less exposed to a claims outage than insurance-dependent practices. That is CMT inference. They remain fully exposed to their own breaches, and to the trust damage a breach does in a relationship-based model.

Part 2 · The rules

What regulators enforce now, and what's coming

On April 25, 2025, HHS's Office for Civil Rights announced a $25,000 settlement with Comprehensive Neurology, a small New York practice. Ransomware had encrypted its systems in December 2020, affecting 6,800 people. OCR found the practice had not conducted an adequate risk analysis. HHS described it as its 12th ransomware enforcement action and the 8th under its Risk Analysis Initiative.3 Policy and Law

In effect now

The existing HIPAA Security Rule. Risk analysis is required; some safeguards, such as encryption, are "addressable" rather than mandatory.4

January 6, 2025

HHS proposes a major Security Rule update (RIN 0945-AA22): mandatory multifactor authentication and encryption, asset inventories and network maps, vulnerability scans twice a year, annual penetration tests, and restoring critical systems within 72 hours.5

Mid-2026

Not finalized. Reporting indicates HHS moved the final action to its long-term agenda, targeting July 2027.4

OCR's own recommendations already point where the proposed rule is going: know where electronic patient information lives, use strong authentication, encrypt data in transit and at rest, review system activity, and train staff.3

Part 3 · AI and patient data

AI tools are a new door out of the building

Under HIPAA, a vendor that creates, receives, maintains or transmits protected health information for a covered entity is a business associate and must sign a business associate agreement.6 That includes AI scribes, AI inbox tools and transcription services. Consumer chatbots are different: OpenAI's health lead has said HIPAA does not apply to its consumer ChatGPT Health product.7 In the AMA's 2026 survey, 86% of physicians called data privacy critical to AI adoption.8

Allowed with safeguards

  • AI scribes and assistants whose vendors sign a BAA
  • EHR-integrated AI features covered by your EHR agreement
  • De-identified use, if your counsel confirms the method

Not allowed

  • Pasting patient names, notes or images into consumer chatbots
  • Free transcription apps without a BAA
  • Personal accounts on any AI tool for practice work
The cash-practice question

HIPAA applies to health care providers who transmit health information electronically in connection with standard transactions, such as insurance claims.9 Some cash-only practices may fall outside that definition. State privacy laws can still apply, and members will not care about the technicality if their data leaks. CMT recommends HIPAA-level safeguards regardless. Confirm your status with counsel.

Part 4 · Build

The ten-minute security self-check

Interactive self-check

Which of these are true for your practice today?

Check what is true today.

What independent data show about incidents, safeguards and AI use

No verified survey isolates concierge or DPC practices. The figures below cover health care broadly or medical groups of all kinds, so read them as the environment membership practices operate in, not as a measure of membership practices themselves.

772
large breaches (500+ people) on the federal breach portal for 2025, a record, affecting about 139.7 million people
Population Data 10
57.5%
of 2025 breaches occurred at health care providers; 35.8% at business associates (preliminary count)
Population Data 11
76%
of 2025 HIPAA enforcement actions included a penalty for a risk analysis failure
Population Data 11
17%
of 518 health care workers admitted using unapproved AI tools at work
Industry Research 12

Safeguard adoption is less well measured. In a 2024 MGMA poll of 326 practices, 72% increased cybersecurity spending, citing rising insurance costs, threats and new security measures.13 A 2021 MGMA poll of 810 respondents found 82% carried cyber insurance, up from 54% in 2018.14 The most recent size-specific measure of multifactor authentication CMT could verify is older: a KLAS and CHIME analysis of 2018 survey data found MFA remained a gap for about half of small organizations.15 Practice Insight Enforcement keeps pointing at the same root cause. By June 2026, OCR had brought 14 enforcement actions under its Risk Analysis Initiative.16 Policy and Law

What this means for a membership practice

Hackers do most of the damage, about a third of breaches occur at vendors, and regulators most often penalize a missing or weak risk analysis. For a small practice, that points to three priorities: the risk analysis, a BAA and security review for every vendor (AI tools included), and a staff AI policy that gives people approved tools so they do not reach for unapproved ones. The insurance and MFA figures are dated, so treat them as direction rather than current rates. That reading is CMT's inference from the evidence above.

Learn

Do the risk analysis

It is the requirement regulators enforce most, and the map for everything else.

Build

Lock the doors

Multifactor authentication, encryption, tested backups and BAAs, starting this quarter.

Lead

Lead the culture

Make privacy part of the membership promise, and say so to members.

Methods, limitations and evidence types

How this brief was built

CMT reviewed HHS Office for Civil Rights enforcement announcements, the January 2025 HIPAA Security Rule proposed rule and reporting on its status, HHS guidance on covered entities and business associates, an AMA survey on the Change Healthcare attack and reporting on that breach. Breach counts come from The HIPAA Journal's analysis of the HHS OCR breach portal; counts change as entities file late reports, so the February 2026 and June 2026 figures differ. Safeguard and insurance figures come from MGMA Stat polls (single-question polls of MGMA members, labeled Practice Insight), a KLAS and CHIME analysis of 2018 survey data, and a Wolters Kluwer survey (company-conducted and not peer-reviewed, labeled Industry Research). No source isolates concierge or DPC practices. This brief is educational and is not legal or cybersecurity advice.

How to read the evidence types

Every key finding is labeled by evidence type. Labels describe the type of evidence, not its value. Each type answers different questions. Funding is disclosed on every source.

Clinical Trial Evidence
Randomized trials and systematic reviews.Best for cause and effect.
Population Data
Large observational studies and government data.Best for trends at scale.
Practice Insight
Surveys, smaller studies and expert consensus.Best for real-world experience.
Industry Research
Company-sponsored or company-reported data that is not peer-reviewed.Best for early signals and operating data.
Policy and Law
Statutes, regulation and official guidance.Best for what is required.

What we don't know

  • Breach and ransomware rates among concierge and DPC practices specifically.
  • Current rates of multifactor authentication, risk analysis completion and cyber insurance in small practices; the best verified figures are from 2018 to 2021.
  • How many small practices use AI tools without a BAA in place.
  • The final content and timing of the HIPAA Security Rule update.
  • How regulators will treat AI scribes and assistants that store audio or transcripts.

How to cite this brief

Concierge Medicine Today. “Cybersecurity and Privacy for the Small Practice in the AI Era.” CMT Research Brief No. 36. October 2026. https://conciergemedicinetoday.net/practice-cybersecurity-ai-era

External review: this brief has not yet been reviewed by an outside expert. When review is complete, the reviewer is credited by name above with any conflicts of interest, and the version number is updated. Reviewers check accuracy and fairness; CMT is responsible for the final content.

Corrections policy: when an error is identified, CMT corrects it in the open and updates the version number above. Send corrections to the editor through conciergemedicinetoday.net.

Sources

References

  1. TechTarget HealthTech Security. Change Healthcare data breach victim count rises to 193 million. August 2025. www.techtarget.comFunding: not stated (news report)
  2. California Medical Association. AMA survey finds cyberattack continues to threaten the viability of physician practices (survey March 26 to April 3, 2024; more than 1,400 respondents). April 2024. cmadocs.orgFunding: not stated (conducted by the American Medical Association; reported by the California Medical Association)
  3. U.S. Department of Health and Human Services, Office for Civil Rights. HHS Office for Civil Rights settles HIPAA ransomware cybersecurity investigation with neurology practice. April 25, 2025. www.hhs.govFunding: federal (U.S. Department of Health and Human Services publication)
  4. Cyberz. HIPAA Security Rule changes in 2026: what actually changed, and what slipped to 2027. July 30, 2026. cyberz.proFunding: not stated (company blog)
  5. U.S. Department of Health and Human Services. HIPAA Security Rule to strengthen the cybersecurity of electronic protected health information (proposed rule, RIN 0945-AA22). Federal Register. January 6, 2025. www.federalregister.govFunding: federal (U.S. Department of Health and Human Services publication)
  6. U.S. Department of Health and Human Services. Business associates (guidance). www.hhs.govFunding: federal (U.S. Department of Health and Human Services publication)
  7. Medical Economics. OpenAI launches ChatGPT Health, directly linking patient portals to the AI chatbot. January 8, 2026. www.medicaleconomics.comFunding: not stated (news report)
  8. American Medical Association. More than 80% of physicians use AI professionally: AMA survey (2026 Physician Survey on Augmented Intelligence). O'Reilly KB. AMA. March 12, 2026. www.ama-assn.orgFunding: not stated (conducted and published by the American Medical Association)
  9. U.S. Department of Health and Human Services. Covered entities and business associates. www.hhs.govFunding: federal (U.S. Department of Health and Human Services publication)
  10. The HIPAA Journal. Largest healthcare data breaches of 2025 (updated count from the HHS OCR breach portal). June 5, 2026. www.hipaajournal.comFunding: not stated (analysis published by The HIPAA Journal)
  11. Steve Alder. 2025 healthcare data breach report. The HIPAA Journal (analysis of HHS OCR breach portal data). February 13, 2026. www.hipaajournal.comFunding: not stated (analysis published by The HIPAA Journal)
  12. Wolters Kluwer Health. Shadow AI: providers are using unapproved tools to improve workflow (survey of 518 U.S. health care workers, 256 providers and 262 administrators, December 2025). January 22, 2026. www.wolterskluwer.comFunding: industry (conducted and published by Wolters Kluwer Health)
  13. MGMA Stat poll. Confronting the rising price tag of cybersecurity in medical practices (326 applicable responses). Medical Group Management Association. September 17, 2024. www.mgma.comFunding: not stated (conducted and published by MGMA)
  14. MGMA Stat poll. With cyberattacks on the rise, cyberinsurance may provide peace of mind (810 applicable responses). Medical Group Management Association. May 25, 2021. www.mgma.comFunding: not stated (conducted and published by MGMA)
  15. KLAS Research and CHIME. How aligned are provider organizations with the Health Industry Cybersecurity Practices (HICP) guidelines? Analysis of 600+ organizations in the 2018 Most Wired survey. Reported by Healthcare Innovation, June 28, 2019. www.hcinnovationgroup.comFunding: not stated (published by KLAS Research and CHIME)
  16. Healthcare Innovation. In breach settlements, OCR continues to call out weak risk analyses. June 2026. www.hcinnovationgroup.comFunding: not stated (news report)
Disclaimer

Educational and informational only. This CMT Research Brief does not constitute medical, legal, tax, financial, accounting or other professional advice, and it does not create a professional relationship of any kind. Statements about laws, regulations, tax rules and payer policies are general, may not reflect the rules in your state, and can change after publication. Consult a qualified attorney, accountant, tax adviser, compliance professional or licensed clinician before acting on anything here.

Independence. Concierge Medicine Today is an independent publication. It does not accept payment for favorable coverage, and it does not favor one practice model over another. Company names and products are mentioned for context only and are not endorsements. Funding is disclosed for every source in the reference list.

Accuracy. CMT verifies figures against their original or best available sources at the time of publication. Where a figure is an estimate, an inference or a company-reported number, the brief says so. This content is not without possible error or omission.

© 2007-2026 Concierge Medicine Today, LLC. All rights reserved.