Patient care should never wait on a computer
A practice runs on a handful of systems that must simply work: scheduling, records, imaging, billing. HIPAA applies in full regardless of headcount, and the practice is accountable for vendors it did not choose and cannot change.
What you are carrying
- HIPAA Security Rule obligations apply at any size, with real penalties
- Clinical systems and imaging devices often run unsupported software
- Any downtime is measured in patients sitting in a waiting room
- Business associate agreements are required with every vendor touching PHI
- Front-desk staff turnover means constant access changes
What we do about it
- Security risk analysis and remediation plan in the form HIPAA expects
- Network segmentation so imaging and clinical devices are isolated, not exposed
- Recovery targets set in hours, with tested restores for clinical systems
- Business associate agreement in place, and help reviewing your other vendors'
- Role-based access with same-day joiner and leaver processing
- Audit logging and access review evidence retained for inspection
HIPAA does not usually penalise a practice for having a weakness. It penalises the practice that never looked. Most clinics we meet are in reasonable technical shape and have no current risk analysis to show for it — and the analysis is the part that gets asked for, every time.
How it usually works
What we find in medical and dental clinics
The HIPAA Security Rule is more specific than most practices realise, and the part enforcement is currently focused on is the one most often missing.
A risk analysis is explicitly required by the Security Rule. It is not a recommendation and not something the EHR vendor did for you.
45 CFR 164.308(a)(1)(ii)(A) (opens in a new tab)How it got that way
The requirement sits at 45 CFR 164.308(a)(1)(ii)(A) and predates most practices' current systems. Many practices reasonably assumed a HIPAA-compliant EHR meant a compliant practice — it does not, because the rule is about the environment, not the software.
What we do
We produce one, track the remediation it generates, and the following year's version shows what moved.
Enforcement is actively targeting exactly this. OCR's Risk Analysis Initiative had reached its fourteenth enforcement action by June 2026.
HHS Office for Civil Rights enforcement actions (opens in a new tab)How it got that way
OCR announced the initiative specifically because the risk analysis requirement was so widely unmet. It is a deliberate focus rather than incidental enforcement.
What we do
The assessment is the deliverable that answers this, and it is written to be handed to a regulator rather than to us.
A business associate agreement moves liability, not risk. Signing one does not make anyone else responsible for your environment.
45 CFR 164.308(b) (opens in a new tab)How it got that way
The agreement is a contract about handling protected health information. It was never a transfer of the practice's own Security Rule obligations, but it is frequently read as one.
What we do
We sign one, and we are equally clear about which obligations stay with the practice regardless.
Every rule above links to the rule itself rather than to our summary of it. If something here does not apply to your firm, that is worth knowing before you budget for it.
Compared honestly
What a generalist provider brings to medical and dental clinics
The technical work of securing a clinic is not unusual. Knowing which of your vendors' requirements are unreasonable is.
A generalist
Documents HIPAA compliance as a checklist item.
CY6
Produces a security risk analysis in the form HIPAA expects, with the remediation it generates tracked — the document that gets asked for.
A generalist
Keeps imaging and clinical devices on the same network as everything else, because they work there.
CY6
Segments them, because those devices routinely run software the manufacturer stopped supporting years ago.
A generalist
Accommodates whatever your clinical vendor requires.
CY6
Tells you plainly when a vendor's own requirements are the security problem, and helps you raise it with them.
Plenty of generalist providers are good at their job. The distinction here is context, not competence.
Rules in play
What you are likely to be measured against
We are not your compliance counsel, and we will say so. What we do is make sure the technical controls and the evidence behind them stand up when someone asks.
- HIPAA Security Rule (45 CFR Part 164 Subpart C)
- HIPAA Breach Notification Rule
- State medical-privacy law
- Payer and clearinghouse security requirements
Not sure where you stand?
Start with the six-point check, or book twenty minutes and talk it through with someone who will tell you plainly what needs doing and what does not.
Or call 1-855-966-2967