HIPAA Compliance for Legal Companies: A Practical Guide for SMB Law Firms and Legal Service Providers

Legal companies that handle protected health information (PHI) - including law firms representing healthcare clients, personal injury practices, and legal service providers - must comply with HIPAA as Business Associates. Compliance requires a signed BAA, technical safeguards, staff training, and a documented risk analysis.

Is a law firm considered a covered entity or a Business Associate under HIPAA?

Most law firms are Business Associates, not covered entities. A firm becomes a Business Associate when it receives, creates, maintains, or transmits PHI on behalf of a covered entity - such as a hospital, insurer, or healthcare clearinghouse - in the course of providing legal services. Business Associates are subject to the HIPAA Security Rule and the Breach Notification Rule, and must sign a BAA with each covered entity client.

What happens if a law firm violates HIPAA?

Civil monetary penalties range from $100 per violation (unknowing violation) to $50,000 per violation (willful neglect not corrected), with annual caps of $1.9 million per violation category as of 2023 adjustments. Criminal penalties apply for willful violations, with potential imprisonment up to 10 years. HHS OCR may also require a corrective action plan and multi-year monitoring. Reputational damage and loss of healthcare-sector clients are common secondary consequences.

Do all employees at a law firm need HIPAA training?

HIPAA requires training for all workforce members whose work involves PHI, which the Security Rule defines broadly as employees, volunteers, and trainees. In a law firm, this typically includes attorneys, paralegals, legal assistants, IT staff, and administrative personnel who handle client files. Training must be documented, and firms should conduct refresher training annually or when policies change.

Does HIPAA apply to a law firm that only occasionally receives medical records?

Yes. There is no de minimis exception in HIPAA for infrequent PHI handling. If a firm receives PHI from a covered entity - even for a single case - the Business Associate obligations apply. This includes executing a BAA, securing the records, and complying with breach notification requirements. Firms should assess their PHI exposure across all practice areas, including personal injury, workers' compensation, and estate planning.

What is a Business Associate Agreement and who must sign one?

A BAA is a written contract required under 45 CFR §164.308(b)(3) between a covered entity and any Business Associate that will access PHI. The agreement must specify permitted uses of PHI, require the Business Associate to implement HIPAA safeguards, establish breach reporting timelines (60 days), and require the return or destruction of PHI upon contract termination. Law firms must sign BAAs with covered entity clients and also execute BAAs with their own subcontractors that touch PHI.

Are cloud-based case management systems like Clio or MyCase HIPAA-compliant?

Clio and similar cloud-based legal practice management platforms can support HIPAA-compliant workflows, but they require specific configuration and a signed BAA. As of 2024, Clio offers a BAA and supports encryption, access controls, and audit logging. However, HIPAA compliance is a shared responsibility - the vendor provides technical controls, but the law firm must implement appropriate access policies, training, and incident response procedures on top of the platform.

How long must a law firm retain PHI-related records under HIPAA?

The HIPAA Privacy Rule (45 CFR §164.530(j)) requires covered entities and Business Associates to retain HIPAA-related documentation - including policies, procedures, training records, risk analyses, and BAAs - for a minimum of six years from the date of creation or the date it was last in effect, whichever is later. Note that this retention requirement applies to HIPAA compliance documentation, not necessarily to the underlying PHI itself, which may be governed by state law or the covered entity's retention policies.