HIPAA for Law Firms
When Attorney-Client Representation Creates Federal Healthcare Privacy Obligations
lbttechgroup.com · +1 (916) 333-1062 · Sacramento, California · Veteran-Owned
THE OBLIGATION MOST FIRMS DON’T KNOW THEY HAVE
Your law firm may be a HIPAA Business Associate and not know it.
HIPAA is universally understood as a healthcare law. What most Sacramento law firms don’t realize is that HIPAA’s reach extends directly into legal practice whenever a firm represents clients in matters involving Protected Health Information (PHI). A law firm that receives, reviews, stores, or transmits PHI in the course of legal representation becomes a ‘Business Associate’ under HIPAA — and is independently subject to the HIPAA Security Rule, Privacy Rule, and Breach Notification Rule, with the same legal exposure as a healthcare provider.
This is not a theoretical edge case. It applies to a broad range of Sacramento law practices: medical malpractice, personal injury, workers’ compensation, healthcare regulatory work, healthcare transactions, employment law for healthcare employers, and estate planning that touches medical records. If your firm handles client matters that involve patient health records, insurance claims, or clinical documentation, the analysis begins there.
Business Associate
status if you handle PHI
$71,162
max HIPAA penalty per violation category
60 days
breach notification window
BAA
required with covered entity clients
WHEN DOES HIPAA APPLY TO A LAW FIRM?
The practice areas that create Business Associate status.
A law firm becomes a Business Associate when it receives PHI from a Covered Entity — a healthcare provider, health plan, or healthcare clearinghouse — in the course of providing legal services. HIPAA defines a Business Associate as a person or entity that, on behalf of a covered entity, performs functions or activities involving PHI.
Practice Area
HIPAA Applicability
Medical malpractice defense or plaintiff
Firm receives patient records, clinical documentation, and diagnostic information directly from providers or clients. Core PHI exposure. BAA with referring provider typically required.
Personal injury & workers’ compensation
Medical records requested, reviewed, and retained as litigation exhibits. IME reports, treatment records, and pharmacy records all constitute PHI. Firm handling these records is a Business Associate.
Healthcare regulatory & compliance
Firms advising healthcare providers on HIPAA compliance, licensing, or regulatory matters may access systems, policies, and PHI as part of the engagement. Legal services exception has limits.
Healthcare mergers & acquisitions
Due diligence access to provider’s PHI systems, billing records, and patient data. Firm acting as acquirer’s counsel accessing PHI directly triggers Business Associate analysis.
Employment law for healthcare clients
Representing healthcare employers in employee disputes may involve access to employee health records, accommodation records, or occupational health data that constitutes PHI under employer plan arrangements.
Estate planning & probate
Access to decedent’s medical records, Medicare/Medicaid billing histories, and long-term care documentation in estate matters involving healthcare costs may constitute PHI exposure.
Insurance coverage disputes
Reviewing and litigating coverage for medical claims requires access to patient PHI. Defense counsel for insurers in these matters frequently qualifies as Business Associates.
The Legal Services Exception — and Its Limits
HIPAA includes a limited exception for legal services: a law firm is not a Business Associate solely because it receives PHI in connection with litigation if the firm uses the PHI only for the purpose of the representation and returns or destroys it at the conclusion of the engagement. However, if the firm retains PHI in its files, stores it on firm systems, or uses it in ways that go beyond the immediate representation, the exception does not apply. Most firms’ document management practices — long-term file retention, cloud backup of matter files, and docketing system integrations — take them outside the exception.
BUSINESS ASSOCIATE OBLIGATIONS
What HIPAA requires of a law firm holding PHI.
A law firm with Business Associate status is subject to the full scope of HIPAA’s Security Rule requirements for electronic PHI stored or transmitted on firm systems. This means the same administrative, physical, and technical safeguards that healthcare providers implement must be present in the law firm’s IT environment to the extent it holds ePHI.
HIPAA Obligation
What It Means for the Firm
Business Associate Agreement (BAA)
The firm must execute a BAA with each covered entity that provides PHI. The BAA defines the firm’s permitted uses of PHI and its security obligations. Many firms receive PHI without a BAA, creating immediate HIPAA violations.
Security Rule — Administrative Safeguards
Documented risk assessment for ePHI on firm systems, access control policies, workforce security training, and contingency planning.
Security Rule — Technical Safeguards
Access controls, audit logging, encryption, and automatic logoff on all systems where ePHI is stored or transmitted.
Security Rule — Physical Safeguards
Workstation use policies, device controls, and facility access controls for locations where ePHI is accessed.
Breach Notification
If a breach of ePHI occurs on firm systems, the firm must notify the covered entity within 60 days. The covered entity then notifies affected patients and HHS. The firm may have concurrent California notification obligations under Civil Code §1798.82.
Minimum Necessary Standard
The firm may access and use only the PHI that is the minimum necessary to accomplish the purpose of the legal representation.
Subcontractor obligations
IT providers and cloud vendors used by the firm that access ePHI are themselves Business Associates of the firm. The firm must execute BAAs with its IT vendors — including LBT.
THE INTERSECTION: HIPAA + CALIFORNIA RPC
Two independent compliance obligations that run concurrently.
For Sacramento law firms, HIPAA Business Associate status and California RPC cybersecurity obligations are not the same thing — and satisfying one does not satisfy the other. They are parallel, independently enforceable frameworks that share an overlapping technical foundation but differ in enforcement mechanism, scope, and consequence.
Dimension
HIPAA Business Associate vs. California RPC
Enforced by
HIPAA: HHS OCR (federal). California RPC: State Bar Court (professional discipline). Both can apply simultaneously to the same incident.
Applies to
HIPAA: electronic PHI on firm systems. California RPC: all client confidential information, regardless of format or type.
Consequence of breach
HIPAA: civil monetary penalties, potential criminal charges. California RPC: State Bar discipline, public reproval, suspension, disbarment, malpractice liability.
Overlap
The security controls required by HIPAA’s Security Rule are largely congruent with the ‘reasonable efforts’ standard of California RPC Rule 1.6. Implementing one materially advances the other.
Gap
HIPAA only covers ePHI. RPC covers all client confidential information. A firm that meets HIPAA for its medical matter files but has no security controls on its non-PHI client data has satisfied only half the obligation.
COMMON GAPS IN LAW FIRMS HANDLING PHI
Where Sacramento firms most commonly fall short.
⚠ No BAA with the covered entities that provide PHI — the most common and most immediately actionable HIPAA violation for law firms
⚠ No BAA with LBT or other IT vendors — if ePHI is on firm systems managed by LBT, LBT must be a Business Associate under a BAA
⚠ PHI retained in firm files beyond the conclusion of the matter without a documented retention policy or destruction procedure
⚠ ePHI stored on personal attorney devices without device management or encryption — a direct Security Rule violation
⚠ No documented risk assessment for ePHI — the HIPAA Security Rule’s §164.308(a)(1) requirement applies to law firms just as it applies to healthcare providers
⚠ No breach notification procedure calibrated to HIPAA’s 60-day Business Associate notification window
HOW LBT SUPPORTS HIPAA COMPLIANCE FOR LAW FIRMS
IT infrastructure and documentation built for Business Associate compliance.
✓ Business Associate Agreement Execution
LBT executes a HIPAA-compliant BAA with every law firm client whose systems hold ePHI, satisfying the firm’s subcontractor BAA obligation and LBT’s own Business Associate documentation requirements.
✓ ePHI Risk Assessment
A documented HIPAA Security Rule risk assessment specific to the firm’s systems and the ePHI they hold — satisfying §164.308(a)(1) and producing the foundational document required for Business Associate compliance.
✓ Technical Safeguard Implementation
Access controls, encryption, audit logging, and automatic logoff on all firm systems where ePHI is stored or transmitted — satisfying the Security Rule’s technical safeguard requirements for Business Associates.
✓ Endpoint Management for Attorney Devices
Mobile device management and endpoint security for all attorney devices used to access ePHI — including personal devices used for matter-related work, satisfying the Security Rule’s device and media controls requirements.
✓ 60-Day Breach Notification Capability
Incident response procedures that satisfy HIPAA’s Business Associate breach notification requirement — ensuring covered entity clients are notified within 60 days of breach discovery on LBT-managed firm systems.
✓ BAA Vendor Review for Third-Party Platforms
Review of all third-party platforms used by the firm that may access ePHI — document management, cloud storage, email archiving, e-discovery — to ensure BAAs are in place with each subcontractor in the ePHI data flow.
Is Your Business HIPAA for Law Firms Ready?
Schedule a complimentary scoping consultation. LBT will assess your current compliance posture, identify gaps, and show you exactly what it takes to close them — at no cost and no obligation.
BOOK YOUR FREE HIPAA FOR LAW FIRMS ASSESSMENT →
+1 (916) 333-1062 · lbttechgroup.com · Sacramento, California
© 2026 LBT Technology Group, LLC · HIPAA Business Associate Compliance — Legal · Sacramento, CA · Confidential
This document is for informational purposes only and does not constitute legal advice.
