HIPAA · MEDICAL & DENTAL

HIPAA is not something you buy. It is something you can show.

No product makes a practice compliant. What HIPAA actually asks is that you put specific safeguards in place and can produce evidence of them. We handle the technical half of that list, and we document it so you are not scrambling when someone asks.

START HERE: THE BAA

If your IT company can reach patient data, it has to sign a Business Associate Agreement.

An IT provider with ongoing access to the systems that hold patient data is a business associate under HIPAA, not a passive pipe. That means a signed Business Associate Agreement before the work starts, spelling out how that data is protected and what happens if something goes wrong.

We sign one. If your current provider has never brought it up, that is worth asking about this week, because the obligation sits with your practice as well as with them.

REQUIRED TODAY

The Security Rule safeguards we put in place

These are current obligations under the HIPAA Security Rule, in force now. Most practices we assess are doing some of this already and are missing the documentation that proves it.

  • RISK ANALYSISA documented assessment of where electronic patient data lives and what could realistically go wrong with it. This is the foundation the rest of the rule is built on, and it is the item auditors ask for first.
  • ACCESS CONTROLEvery person gets their own login. No shared accounts, no generic front-desk password. Sessions log off on their own, and access ends the day someone leaves.
  • AUDIT CONTROLSSystems holding patient data have to record who looked at what, and those records have to be reviewed rather than just collected.
  • BACKUP & CONTINGENCYA data backup plan, a disaster recovery plan, and a way to keep operating in an emergency. These three are flatly required, which surprises most practices.
  • TRANSMISSION SECURITYPatient data has to be protected while it moves between offices, to labs and imaging, and out to the cloud.
  • DEVICE & MEDIA CONTROLSRules for how workstations, drives, and backup media are tracked, reused, and disposed of, so nothing walks out the door with patient data still on it.

PROPOSED, NOT YET LAW

What is likely coming, and why we are not waiting

In January 2025 the federal government proposed the first significant overhaul of the Security Rule in two decades. It would remove much of the flexibility practices currently have and make several safeguards mandatory. It is still a proposal. Final action has been pushed back and is currently expected around 2027, so nothing below is binding yet.

Multi-factor authentication

Would become an explicit requirement for systems that touch patient data, including the practice management system, email, and remote access.

Encryption becomes mandatory

Encryption of patient data at rest and in transit would lose its current flexibility and become required, with narrow exceptions.

Asset inventory and network map

Practices would have to keep a current inventory of their technology and a map of the network, reviewed at least once every 12 months.

We set practices up this way regardless, because it is simply good security and because the alternative is a rushed, expensive scramble when the rule lands. The asset inventory and network map are worth noting: our $99 assessment produces both, which is the exact artifact the proposal would have you review every year.

WHERE WE STOP

What we do not do

We are an IT company, not a law firm or a compliance auditor, and we will not tell you otherwise. Your written policies, workforce training, patient authorization forms, breach notification decisions, and your overall compliance program belong to you and to whoever advises you on them.

What we own is the technical side: the safeguards listed above, kept working, and documented so that when your compliance consultant or an auditor asks for evidence, it already exists. Any IT company that tells you it can make you HIPAA compliant on its own is overselling.

Not sure where your practice stands?

The $99 assessment covers the technical ground the Security Rule cares about: backups and real restore times, access and old accounts, encryption, and a written map of where patient data actually lives.

Start with a $99 assessment