Cybersecurity protects your systems. Cybersecurity risk management protects your business.®

HIPAA for Law Firms

When Attorney-Client Representation Creates Federal Healthcare Privacy Obligations

lbttechgroup.com · +1 (916) 333-1062 · Sacramento, California · Veteran-Owned

THE OBLIGATION MOST FIRMS DON’T KNOW THEY HAVE

Your law firm may be a HIPAA Business Associate and not know it.

HIPAA is universally understood as a healthcare law. What most Sacramento law firms don’t realize is that HIPAA’s reach extends directly into legal practice whenever a firm represents clients in matters involving Protected Health Information (PHI). A law firm that receives, reviews, stores, or transmits PHI in the course of legal representation becomes a ‘Business Associate’ under HIPAA — and is independently subject to the HIPAA Security Rule, Privacy Rule, and Breach Notification Rule, with the same legal exposure as a healthcare provider.

This is not a theoretical edge case. It applies to a broad range of Sacramento law practices: medical malpractice, personal injury, workers’ compensation, healthcare regulatory work, healthcare transactions, employment law for healthcare employers, and estate planning that touches medical records. If your firm handles client matters that involve patient health records, insurance claims, or clinical documentation, the analysis begins there.

Business Associate

status if you handle PHI

$71,162

max HIPAA penalty per violation category

60 days

breach notification window

BAA

required with covered entity clients

WHEN DOES HIPAA APPLY TO A LAW FIRM?

The practice areas that create Business Associate status.

A law firm becomes a Business Associate when it receives PHI from a Covered Entity — a healthcare provider, health plan, or healthcare clearinghouse — in the course of providing legal services. HIPAA defines a Business Associate as a person or entity that, on behalf of a covered entity, performs functions or activities involving PHI.

Practice Area

HIPAA Applicability

Medical malpractice defense or plaintiff

Firm receives patient records, clinical documentation, and diagnostic information directly from providers or clients. Core PHI exposure. BAA with referring provider typically required.

Personal injury & workers’ compensation

Medical records requested, reviewed, and retained as litigation exhibits. IME reports, treatment records, and pharmacy records all constitute PHI. Firm handling these records is a Business Associate.

Healthcare regulatory & compliance

Firms advising healthcare providers on HIPAA compliance, licensing, or regulatory matters may access systems, policies, and PHI as part of the engagement. Legal services exception has limits.

Healthcare mergers & acquisitions

Due diligence access to provider’s PHI systems, billing records, and patient data. Firm acting as acquirer’s counsel accessing PHI directly triggers Business Associate analysis.

Employment law for healthcare clients

Representing healthcare employers in employee disputes may involve access to employee health records, accommodation records, or occupational health data that constitutes PHI under employer plan arrangements.

Estate planning & probate

Access to decedent’s medical records, Medicare/Medicaid billing histories, and long-term care documentation in estate matters involving healthcare costs may constitute PHI exposure.

Insurance coverage disputes

Reviewing and litigating coverage for medical claims requires access to patient PHI. Defense counsel for insurers in these matters frequently qualifies as Business Associates.

The Legal Services Exception — and Its Limits

HIPAA includes a limited exception for legal services: a law firm is not a Business Associate solely because it receives PHI in connection with litigation if the firm uses the PHI only for the purpose of the representation and returns or destroys it at the conclusion of the engagement. However, if the firm retains PHI in its files, stores it on firm systems, or uses it in ways that go beyond the immediate representation, the exception does not apply. Most firms’ document management practices — long-term file retention, cloud backup of matter files, and docketing system integrations — take them outside the exception.

BUSINESS ASSOCIATE OBLIGATIONS

What HIPAA requires of a law firm holding PHI.

A law firm with Business Associate status is subject to the full scope of HIPAA’s Security Rule requirements for electronic PHI stored or transmitted on firm systems. This means the same administrative, physical, and technical safeguards that healthcare providers implement must be present in the law firm’s IT environment to the extent it holds ePHI.

HIPAA Obligation

What It Means for the Firm

Business Associate Agreement (BAA)

The firm must execute a BAA with each covered entity that provides PHI. The BAA defines the firm’s permitted uses of PHI and its security obligations. Many firms receive PHI without a BAA, creating immediate HIPAA violations.

Security Rule — Administrative Safeguards

Documented risk assessment for ePHI on firm systems, access control policies, workforce security training, and contingency planning.

Security Rule — Technical Safeguards

Access controls, audit logging, encryption, and automatic logoff on all systems where ePHI is stored or transmitted.

Security Rule — Physical Safeguards

Workstation use policies, device controls, and facility access controls for locations where ePHI is accessed.

Breach Notification

If a breach of ePHI occurs on firm systems, the firm must notify the covered entity within 60 days. The covered entity then notifies affected patients and HHS. The firm may have concurrent California notification obligations under Civil Code §1798.82.

Minimum Necessary Standard

The firm may access and use only the PHI that is the minimum necessary to accomplish the purpose of the legal representation.

Subcontractor obligations

IT providers and cloud vendors used by the firm that access ePHI are themselves Business Associates of the firm. The firm must execute BAAs with its IT vendors — including LBT.

THE INTERSECTION: HIPAA + CALIFORNIA RPC

Two independent compliance obligations that run concurrently.

For Sacramento law firms, HIPAA Business Associate status and California RPC cybersecurity obligations are not the same thing — and satisfying one does not satisfy the other. They are parallel, independently enforceable frameworks that share an overlapping technical foundation but differ in enforcement mechanism, scope, and consequence.

Dimension

HIPAA Business Associate vs. California RPC

Enforced by

HIPAA: HHS OCR (federal). California RPC: State Bar Court (professional discipline). Both can apply simultaneously to the same incident.

Applies to

HIPAA: electronic PHI on firm systems. California RPC: all client confidential information, regardless of format or type.

Consequence of breach

HIPAA: civil monetary penalties, potential criminal charges. California RPC: State Bar discipline, public reproval, suspension, disbarment, malpractice liability.

Overlap

The security controls required by HIPAA’s Security Rule are largely congruent with the ‘reasonable efforts’ standard of California RPC Rule 1.6. Implementing one materially advances the other.

Gap

HIPAA only covers ePHI. RPC covers all client confidential information. A firm that meets HIPAA for its medical matter files but has no security controls on its non-PHI client data has satisfied only half the obligation.

COMMON GAPS IN LAW FIRMS HANDLING PHI

Where Sacramento firms most commonly fall short.

⚠ No BAA with the covered entities that provide PHI — the most common and most immediately actionable HIPAA violation for law firms

⚠ No BAA with LBT or other IT vendors — if ePHI is on firm systems managed by LBT, LBT must be a Business Associate under a BAA

⚠ PHI retained in firm files beyond the conclusion of the matter without a documented retention policy or destruction procedure

⚠ ePHI stored on personal attorney devices without device management or encryption — a direct Security Rule violation

⚠ No documented risk assessment for ePHI — the HIPAA Security Rule’s §164.308(a)(1) requirement applies to law firms just as it applies to healthcare providers

⚠ No breach notification procedure calibrated to HIPAA’s 60-day Business Associate notification window

HOW LBT SUPPORTS HIPAA COMPLIANCE FOR LAW FIRMS

IT infrastructure and documentation built for Business Associate compliance.

✓ Business Associate Agreement Execution

LBT executes a HIPAA-compliant BAA with every law firm client whose systems hold ePHI, satisfying the firm’s subcontractor BAA obligation and LBT’s own Business Associate documentation requirements.

✓ ePHI Risk Assessment

A documented HIPAA Security Rule risk assessment specific to the firm’s systems and the ePHI they hold — satisfying §164.308(a)(1) and producing the foundational document required for Business Associate compliance.

✓ Technical Safeguard Implementation

Access controls, encryption, audit logging, and automatic logoff on all firm systems where ePHI is stored or transmitted — satisfying the Security Rule’s technical safeguard requirements for Business Associates.

✓ Endpoint Management for Attorney Devices

Mobile device management and endpoint security for all attorney devices used to access ePHI — including personal devices used for matter-related work, satisfying the Security Rule’s device and media controls requirements.

✓ 60-Day Breach Notification Capability

Incident response procedures that satisfy HIPAA’s Business Associate breach notification requirement — ensuring covered entity clients are notified within 60 days of breach discovery on LBT-managed firm systems.

✓ BAA Vendor Review for Third-Party Platforms

Review of all third-party platforms used by the firm that may access ePHI — document management, cloud storage, email archiving, e-discovery — to ensure BAAs are in place with each subcontractor in the ePHI data flow.

Is Your Business HIPAA for Law Firms Ready?

Schedule a complimentary scoping consultation. LBT will assess your current compliance posture, identify gaps, and show you exactly what it takes to close them — at no cost and no obligation.

BOOK YOUR FREE HIPAA FOR LAW FIRMS ASSESSMENT →

+1 (916) 333-1062 · lbttechgroup.com · Sacramento, California

© 2026 LBT Technology Group, LLC · HIPAA Business Associate Compliance — Legal · Sacramento, CA · Confidential

This document is for informational purposes only and does not constitute legal advice.

Cybersecurity Guidance for Law Firms

HIPAA for Law Firms

When Attorney-Client Representation Creates Federal Healthcare Privacy Obligations

BABusiness Associate

Status if you handle PHI

60Days

Breach notification window

$71,162Maximum penalty

Per violation category

Why this matters

THE OBLIGATION MOST FIRMS DON’T KNOW THEY HAVE

HIPAA is universally understood as a healthcare law. What most Sacramento law firms don’t realize is that HIPAA’s reach extends directly into legal practice whenever a firm represents clients in matters involving Protected Health Information (PHI). A law firm that receives, reviews, stores, or transmits PHI in the course of legal representation becomes a ‘Business Associate’ under HIPAA — and is independently subject to the HIPAA Security Rule, Privacy Rule, and Breach Notification Rule, with the same legal exposure as a healthcare provider.

This is not a theoretical edge case. It applies to a broad range of Sacramento law practices: medical malpractice, personal injury, workers’ compensation, healthcare regulatory work, healthcare transactions, employment law for healthcare employers, and estate planning that touches medical records. If your firm handles client matters that involve patient health records, insurance claims, or clinical documentation, the analysis begins there.

Practice-area exposure

WHEN DOES HIPAA APPLY TO A LAW FIRM?

The practice areas that create Business Associate status.

A law firm becomes a Business Associate when it receives PHI from a Covered Entity — a healthcare provider, health plan, or healthcare clearinghouse — in the course of providing legal services. HIPAA defines a Business Associate as a person or entity that, on behalf of a covered entity, performs functions or activities involving PHI.

01

Medical malpractice defense or plaintiff

Firm receives patient records, clinical documentation, and diagnostic information directly from providers or clients. Core PHI exposure. BAA with referring provider typically required.

02

Personal injury & workers’ compensation

Medical records requested, reviewed, and retained as litigation exhibits. IME reports, treatment records, and pharmacy records all constitute PHI. Firm handling these records is a Business Associate.

03

Healthcare regulatory & compliance

Firms advising healthcare providers on HIPAA compliance, licensing, or regulatory matters may access systems, policies, and PHI as part of the engagement. Legal services exception has limits.

04

Healthcare mergers & acquisitions

Due diligence access to provider’s PHI systems, billing records, and patient data. Firm acting as acquirer’s counsel accessing PHI directly triggers Business Associate analysis.

05

Employment law for healthcare clients

Representing healthcare employers in employee disputes may involve access to employee health records, accommodation records, or occupational health data that constitutes PHI under employer plan arrangements.

06

Estate planning & probate

Access to decedent’s medical records, Medicare/Medicaid billing histories, and long-term care documentation in estate matters involving healthcare costs may constitute PHI exposure.

07

Insurance coverage disputes

Reviewing and litigating coverage for medical claims requires access to patient PHI. Defense counsel for insurers in these matters frequently qualifies as Business Associates.

08

The Legal Services Exception — and Its Limits

HIPAA includes a limited exception for legal services: a law firm is not a Business Associate solely because it receives PHI in connection with litigation if the firm uses the PHI only for the purpose of the representation and returns or destroys it at the conclusion of the engagement. However, if the firm retains PHI in its files, stores it on firm systems, or uses it in ways that go beyond the immediate representation, the exception does not apply. Most firms’ document management practices — long-term file retention, cloud backup of matter files, and docketing system integrations — take them outside the exception.

Explore Business Associate obligations

Three responsibility areas connect agreements, safeguards, and response.

Select an area to see what it means for a law firm holding PHI.

Agreements

Privacy & Agreements

Define permitted PHI use, minimum-necessary access, and the agreements governing covered entities and the firm.

Business Associate Agreement (BAA)

The firm must execute a BAA with each covered entity that provides PHI. The BAA defines the firm’s permitted uses of PHI and its security obligations. Many firms receive PHI without a BAA, creating immediate HIPAA violations.

Minimum Necessary Standard

The firm may access and use only the PHI that is the minimum necessary to accomplish the purpose of the legal representation.

Parallel obligations

THE INTERSECTION: HIPAA + CALIFORNIA RPC

Two independent compliance obligations that run concurrently.

For Sacramento law firms, HIPAA Business Associate status and California RPC cybersecurity obligations are not the same thing — and satisfying one does not satisfy the other. They are parallel, independently enforceable frameworks that share an overlapping technical foundation but differ in enforcement mechanism, scope, and consequence.

Federal

HIPAA Business Associate

Healthcare privacy, security, and breach responsibilities.

California

California RPC

Professional responsibility and client confidentiality.

Comparison dimensionHow the obligations intersect
01Enforced by

HIPAA: HHS OCR (federal). California RPC: State Bar Court (professional discipline). Both can apply simultaneously to the same incident.

02Applies to

Law firms handling PHI while providing services to a covered entity or Business Associate.

03Consequence of breach

HIPAA: civil monetary penalties, potential criminal charges. California RPC: State Bar discipline, public reproval, suspension, disbarment, malpractice liability.

04Overlap

The security controls required by HIPAA’s Security Rule are largely congruent with the ‘reasonable efforts’ standard of California RPC Rule 1.6. Implementing one materially advances the other.

Common law-firm gaps

COMMON GAPS IN LAW FIRMS HANDLING PHI

Where Sacramento firms most commonly fall short.

01

No BAA with the covered entities that provide PHI

the most common and most immediately actionable HIPAA violation for law firms

02

No BAA with LBT or other IT vendors

if ePHI is on firm systems managed by LBT, LBT must be a Business Associate under a BAA

03

PHI retained in firm files beyond the conclusion of the matter without a documented retention policy or destruction procedure

PHI retained in firm files beyond the conclusion of the matter without a documented retention policy or destruction procedure

04

ePHI stored on personal attorney devices without device management or encryption

a direct Security Rule violation

05

No documented risk assessment for ePHI

the HIPAA Security Rule’s §164.308(a)(1) requirement applies to law firms just as it applies to healthcare providers

06

No breach notification procedure calibrated to HIPAA’s 60-day Business Associate notification window

No breach notification procedure calibrated to HIPAA’s 60-day Business Associate notification window

How LBT supports law firms

IT infrastructure and documentation built for Business Associate compliance.

Schedule a complimentary scoping consultation. LBT will assess your current compliance posture, identify gaps, and show you exactly what it takes to close them.

Discuss your firm’s HIPAA program
01
Business Associate Agreement Execution

LBT executes a HIPAA-compliant BAA with every law firm client whose systems hold ePHI, satisfying the firm’s subcontractor BAA obligation and LBT’s own Business Associate documentation requirements.

02
ePHI Risk Assessment

A documented HIPAA Security Rule risk assessment specific to the firm’s systems and the ePHI they hold — satisfying §164.308(a)(1) and producing the foundational document required for Business Associate compliance.

03
Technical Safeguard Implementation

Access controls, encryption, audit logging, and automatic logoff on all firm systems where ePHI is stored or transmitted — satisfying the Security Rule’s technical safeguard requirements for Business Associates.

04
Endpoint Management for Attorney Devices

Mobile device management and endpoint security for all attorney devices used to access ePHI — including personal devices used for matter-related work, satisfying the Security Rule’s device and media controls requirements.

05
60-Day Breach Notification Capability

Incident response procedures that satisfy HIPAA’s Business Associate breach notification requirement — ensuring covered entity clients are notified within 60 days of breach discovery on LBT-managed firm systems.

06
BAA Vendor Review for Third-Party Platforms

Review of all third-party platforms used by the firm that may access ePHI — document management, cloud storage, email archiving, e-discovery — to ensure BAAs are in place with each subcontractor in the ePHI data flow.

Next step

Protect PHI without disrupting how your firm practices law.

Schedule a complimentary scoping consultation. LBT will assess your current compliance posture, identify gaps, and show you exactly what it takes to close them—at no cost and no obligation.

This document is for informational purposes only and does not constitute legal advice.