Most healthcare IT compliance guidance is written for a hospital system's IT department, and a fifteen-provider practice doesn't have one
Search for HIPAA compliance guidance and the advice is remarkably consistent: assign a compliance officer, establish a formal risk management committee, implement a documented change control process, maintain a dedicated security team that reviews access logs on a regular cycle. Sound advice, all of it. It also describes an organizational structure most healthcare practices don't have and aren't going to build.