Every IBCLC in private practice knows they need to be "HIPAA compliant." Many are less sure what that means day to day. They may avoid texting a patient or emailing a growth chart, or use iMessage and hope the issue never comes up.
Neither approach is necessary. A small lactation practice can meet its HIPAA obligations without treating compliance as a full-time project. This guide covers the requirements and the measures you can skip.
Do I Even Need to Comply with HIPAA?
Almost certainly yes. HIPAA's covered entity definition requires a healthcare provider to transmit health information electronically in connection with a standard transaction. These transactions include electronic claims, eligibility inquiries, referral authorizations, and similar payer-related transactions. If you are strictly cash-pay and never submit electronic claims or conduct other HIPAA-standard transactions with insurers, you may not be a covered entity under the strict legal definition.
Most experts strongly recommend HIPAA-level compliance for all healthcare providers, and many state privacy laws impose similar obligations. If you bill any insurance, submit electronic claims, conduct eligibility checks, or plan to in the future, you are unambiguously covered. Cash-pay IBCLCs also handle sensitive health information that deserves the same level of protection.
HIPAA does not require a small practice to build hospital-level security infrastructure. The regulations scale to the size and complexity of your practice. What is reasonable for a 200-bed hospital is not expected of a solo IBCLC.
The Three HIPAA Rules That Matter
HIPAA has many provisions, but three rules cover 95% of what you need to worry about.
1. The Privacy Rule
What it requires: Protect the confidentiality of Protected Health Information (PHI). PHI is individually identifiable health information, including patient names, addresses, dates of birth, diagnoses, treatment records, photos, and anything else that could identify a specific patient.
What this means for you:
- Don't share patient information without authorization. You can share PHI with the patient, other providers involved in their care (treatment), for payment activities, and for healthcare operations. Everything else requires written patient authorization.
- Minimum necessary standard. When sharing PHI, share only the minimum amount needed for the purpose. If a pediatrician asks how a baby is feeding, you don't need to send your entire chart. A summary of the feeding assessment and plan is sufficient.
- Patient rights. Patients can access their records. Under 45 CFR 164.524, you must respond within 30 calendar days of the request, with one possible 30-day extension. They can also request corrections and ask who received their information. You need a process for handling these requests.
- Notice of Privacy Practices (NPP). You must provide patients with a written notice explaining how you use and protect their health information. A simple one-page document that patients sign at their first visit is enough. Templates are widely available online.
2. The Security Rule
What it requires: Protect electronic PHI (ePHI) through administrative, physical, and technical safeguards. This is the rule most IBCLCs worry about, but the requirements are straightforward.
Administrative safeguards (policies and procedures):
- Risk assessment. Identify where your ePHI lives and what threats exist. For a solo IBCLC, a simple inventory works: "Patient records are in my EHR (encrypted, cloud-based, BAA in place). I access them on my laptop (password-protected, encrypted drive). I communicate with patients through my EHR's messaging (encrypted, HIPAA-compliant)." You don't need a 50-page document. A one-page risk assessment is appropriate for a solo practice.
- Workforce training. Employees and contractors, such as an office manager, billing assistant, or intern, need basic HIPAA training. If it is just you, your own knowledge satisfies this requirement.
- Incident response plan. Know what to do if patient data is compromised. (See the Breach Notification section below.)
Physical safeguards:
- Device security. Lock your laptop when you step away. Do not leave your tablet in your car. Use a privacy screen if you chart in public spaces such as coffee shops.
- Workstation security. If you chart in a home office, lock the door and do not let family members use your work devices.
Technical safeguards:
- Access controls. Unique username and password for every system that contains ePHI. No shared logins.
- Encryption. ePHI should be encrypted in transit (HTTPS, TLS) and at rest (encrypted hard drives, encrypted databases). Under the current Security Rule, encryption is technically an "addressable" specification. You must either implement it or document why an equivalent alternative is appropriate. In practice, encryption is effectively required for any modern practice, and HHS has proposed making it mandatory. A cloud-based, HIPAA-compliant EHR handles most of this for you.
- Audit logs. Your EHR should log who accessed what and when. This is a system feature, not something you manage manually.
- Automatic logoff. Set your devices to auto-lock after a period of inactivity.
3. The Breach Notification Rule
What it requires: If someone accesses, uses, or discloses unsecured PHI in a way the Privacy Rule does not permit, you must:
- Notify affected patients without unreasonable delay and in no case later than 60 days after discovering the breach (45 CFR 164.404)
- Notify HHS (Department of Health and Human Services) (45 CFR 164.408). If the breach affects fewer than 500 individuals, log it and report it within 60 days of the end of the calendar year in which it was discovered. If 500 or more individuals are affected, notify HHS contemporaneously with patient notification, no later than 60 days after discovery.
- Notify prominent media outlets (45 CFR 164.406). This separate trigger applies only if the breach affects more than 500 residents of a single state or jurisdiction. The deadline is also no later than 60 days after discovery.
- Document the breach - what happened, what data was involved, what corrective actions you took
Common breach scenarios for solo IBCLCs:
- Your laptop is stolen with unencrypted patient data. If the data is encrypted, it is not a reportable breach.
- You accidentally send a patient's chart to the wrong email address
- You discuss a patient by name in a Facebook group
Encrypt your devices, use HIPAA-compliant communication channels, and never discuss identifiable patient information on social media, even in "private" professional groups.
Business Associate Agreements (BAAs)
Small practices most often overlook this HIPAA requirement.
A Business Associate is any vendor that creates, receives, stores, or transmits PHI on your behalf. You must have a signed Business Associate Agreement (BAA) with each vendor. The BAA is a legal contract that requires the vendor to protect PHI and comply with HIPAA.
Vendors that require BAAs:
| Vendor Type | Examples | BAA Needed? |
|---|---|---|
| Practice management / EHR software | NuBloom, Jane, SimplePractice | Yes |
| Email provider (if used for patient communication) | Google Workspace, Microsoft 365 | Yes (if you email PHI) |
| Cloud storage (if used for patient files) | Google Drive, Dropbox | Yes (if you store PHI) |
| Payment processor | Square (HIPAA-enabled features), others that store PHI | Yes (if PHI is transmitted - note that some processors like Stripe do not sign BAAs, so avoid sending PHI through them) |
| Messaging platform | Your EHR's messaging, secure messaging apps | Yes |
| Phone/SMS provider (if used for patient communication) | Twilio, Spruce | Yes |
| Billing service (if you outsource) | Any third-party billing company | Yes |
| Telehealth platform | Zoom for Healthcare, Doxy.me | Yes |
| Appointment scheduling (if separate from EHR) | Calendly, Acuity | Yes (if it captures PHI) |
| IT support (if they access your systems) | Any managed IT provider | Yes |
Vendors that do NOT require BAAs:
- Your internet service provider
- Phone carrier (for voice calls, not texts containing PHI)
- Cleaning service for your office
- Payment processor for non-health-related transactions
Most healthcare-focused software vendors provide BAAs as part of their service. Look for "HIPAA" or "BAA" on their pricing or security page. If a vendor will not sign a BAA, it is not appropriate for handling PHI. Find an alternative.
NuBloom provides a BAA with every account, as do major healthcare platforms. If a software company you are evaluating does not mention HIPAA compliance or BAAs, choose another vendor.
What You Can and Can't Use for Patient Communication
Texting and email cause many problems for solo IBCLCs. You use them every day, but they are not always HIPAA-compliant.
Texting
Regular SMS (iMessage, Android Messages): No. Standard text messages are not encrypted end-to-end in a way that satisfies HIPAA. Even iMessage, which is encrypted, does not meet HIPAA requirements because Apple will not sign a BAA and you cannot audit or control message retention.
HIPAA-compliant messaging through your EHR: Yes. Use your practice management system's built-in messaging feature. Patients receive a notification (email or SMS) that they have a new message, then log into the patient portal to read it. The message content stays within the HIPAA-compliant system.
What if a patient texts you? You cannot control what patients do. If a patient texts you with a clinical question, respond with a brief acknowledgment and direct them to your secure messaging system: "Got your message! Please send clinical questions through the patient portal so we can keep your health information secure. Here's the link."
Regular email (Gmail, Outlook, Yahoo): Not recommended for PHI. Most major email providers use TLS encryption in transit, but personal email providers will not sign a BAA. You also cannot control message retention or audit access, and patients may reply from insecure providers, creating an unprotected chain of PHI.
Google Workspace or Microsoft 365 with BAA: Acceptable if configured with encryption and you only send PHI to the patient directly. It is still risky because patients may reply from insecure email providers, creating a chain of unprotected PHI.
Use your EHR's messaging for clinical communication. Use email for non-PHI communication, such as appointment reminders (without clinical details), general practice announcements, and billing inquiries (without health information).
Phone Calls
Regular phone calls: Yes, generally fine. HHS guidance on audio-only telehealth confirms that voice calls over a traditional landline are not electronic transmissions of PHI under the Security Rule. The Privacy Rule's reasonable-safeguards standard still applies to all calls (landline, mobile, or VoIP). You can discuss patient care over the phone, but do not discuss patients by name on speakerphone in a public place. If you use a VoIP system, the underlying Security Rule applies. Use a HIPAA-compliant phone service and get a BAA from the provider.
Telehealth Video
Regular Zoom, FaceTime, Google Meet: No (outside of the COVID-era enforcement discretion, which has expired). Telehealth-specific platforms with BAAs: Yes. Examples include Zoom for Healthcare, Doxy.me, and many EHR-integrated video features.
The Minimum Viable HIPAA Checklist
This checklist covers the essentials for a solo IBCLC:
- Use a HIPAA-compliant practice management system with a signed BAA (handles EHR, messaging, scheduling, billing)
- Encrypt your devices. Enable FileVault on Mac, BitLocker on Windows, and device encryption on tablets.
- Use strong, unique passwords on all systems containing PHI. Use a password manager.
- Enable two-factor authentication (2FA/MFA) on your EHR, email, and any system with PHI access.
- Set up automatic screen lock. Set it to 5 minutes or less on all devices.
- Complete a risk assessment. Use a one-page document listing where PHI lives and how it is protected.
- Provide a Notice of Privacy Practices. Patients should acknowledge the written notice before their first visit. With NuBloom, it is signed automatically during the online booking flow.
- Have BAAs in place with every vendor that touches PHI
- Don't text, email, or message PHI through non-compliant channels.
- Know your breach notification obligations: who to notify, when, and how.
- Train any staff or interns on basic HIPAA practices.
- Back up your data. Your EHR should handle this automatically.
You do not need a compliance officer or a 100-page policy manual. You also do not need a $5,000 consultant. You need a secure system, basic security hygiene, and BAAs with your vendors. If you are just getting started, our Starting Your IBCLC Private Practice guide covers the full business setup. Our IBCLC Billing Guide covers CPT codes and superbills.
Common HIPAA Mistakes in Lactation Practice
Texting patients about clinical matters. This is the most common violation. "Baby's weight looks great! Keep doing what you're doing" seems harmless, but it is PHI in an insecure channel.
Posting patient photos on social media. Even with the face blurred, a photo can be a potential violation if identifying details are visible, such as a hospital bracelet, location, or unique physical features. Always get explicit written consent, and think twice even then.
Sharing patient stories in professional Facebook groups. "I had a mom today with XYZ" can identify a patient if it includes enough details, even without the patient's name. This is especially risky in small communities where IBCLC groups overlap with the patient's social circle.
Using personal devices without encryption. Enable device-level encryption on your phone, laptop, and tablet. If an unencrypted device with patient data is lost or stolen, that is a reportable breach.
Not having BAAs. Using Google Drive to store patient charts without a Google Workspace BAA, or Calendly to schedule appointments that capture health information without a BAA, are technical violations even if no breach occurs.
Sending detailed appointment reminders. "Reminder: your lactation consultation re: nipple pain and low supply is tomorrow at 10 AM" contains PHI when sent through an insecure channel. Keep reminders generic: "Reminder: your appointment with [practice name] is tomorrow at 10 AM."
Your software does most of the work
The most effective way to reduce your HIPAA workload is to choose a practice management system that is already compliant. It can handle most technical safeguards:
- Encryption at rest and in transit. Your data is encrypted in the database and during transmission.
- Access controls and audit logs. The system tracks who accessed what.
- Automatic backups. Your data is backed up and recoverable.
- Secure messaging. Patient communication stays within the encrypted system.
- BAA provided. The vendor contractually agrees to protect your PHI.
When evaluating software, ask:
- Do you provide a signed BAA?
- Is data encrypted at rest and in transit?
- Where is data stored? (US-based data centers for US providers)
- Do you maintain audit logs?
- What happens to my data if I cancel?
- Do you have SOC 2 or HITRUST certification? (Nice to have, not required for small practices)
Our practice management software comparison covers pricing, features, and compliance for 8 tools.
For documentation best practices during HIPAA-compliant home visits, see our Home Visit Documentation guide.
NuBloom provides a BAA with every account, encrypts all data at rest and in transit, and includes secure patient messaging. It sends no PHI by SMS or email. The Notice of Privacy Practices and your intake and consent forms are signed during online booking, so they are on file before the first visit.
Sources
- HHS HIPAA for Professionals. Main HIPAA compliance hub
- HHS HIPAA Security Rule. EPHI safeguard requirements
- HHS Breach Notification Rule. Reporting obligations
- HHS Business Associate Guidance. BAA requirements and definitions
- HHS Right of Access (45 CFR 164.524). Patient records access right and the 30-day deadline
- HHS Audio-Only Telehealth Guidance. Voice call and VoIP applicability