Skip to main content
CY6Check Your Six

Patient care should never wait on a computer

A practice runs on a handful of systems that must simply work: scheduling, records, imaging, billing. HIPAA applies in full regardless of headcount, and the practice is accountable for vendors it did not choose and cannot change.

What you are carrying

  • HIPAA Security Rule obligations apply at any size, with real penalties
  • Clinical systems and imaging devices often run unsupported software
  • Any downtime is measured in patients sitting in a waiting room
  • Business associate agreements are required with every vendor touching PHI
  • Front-desk staff turnover means constant access changes

What we do about it

  • Security risk analysis and remediation plan in the form HIPAA expects
  • Network segmentation so imaging and clinical devices are isolated, not exposed
  • Recovery targets set in hours, with tested restores for clinical systems
  • Business associate agreement in place, and help reviewing your other vendors'
  • Role-based access with same-day joiner and leaver processing
  • Audit logging and access review evidence retained for inspection
Straight answer

HIPAA does not usually penalise a practice for having a weakness. It penalises the practice that never looked. Most clinics we meet are in reasonable technical shape and have no current risk analysis to show for it — and the analysis is the part that gets asked for, every time.

How it usually works

What we find in medical and dental clinics

The HIPAA Security Rule is more specific than most practices realise, and the part enforcement is currently focused on is the one most often missing.

  1. A risk analysis is explicitly required by the Security Rule. It is not a recommendation and not something the EHR vendor did for you.

    How it got that way

    The requirement sits at 45 CFR 164.308(a)(1)(ii)(A) and predates most practices' current systems. Many practices reasonably assumed a HIPAA-compliant EHR meant a compliant practice — it does not, because the rule is about the environment, not the software.

    What we do

    We produce one, track the remediation it generates, and the following year's version shows what moved.

    45 CFR 164.308(a)(1)(ii)(A) (opens in a new tab)
  2. Enforcement is actively targeting exactly this. OCR's Risk Analysis Initiative had reached its fourteenth enforcement action by June 2026.

    How it got that way

    OCR announced the initiative specifically because the risk analysis requirement was so widely unmet. It is a deliberate focus rather than incidental enforcement.

    What we do

    The assessment is the deliverable that answers this, and it is written to be handed to a regulator rather than to us.

    HHS Office for Civil Rights enforcement actions (opens in a new tab)
  3. A business associate agreement moves liability, not risk. Signing one does not make anyone else responsible for your environment.

    How it got that way

    The agreement is a contract about handling protected health information. It was never a transfer of the practice's own Security Rule obligations, but it is frequently read as one.

    What we do

    We sign one, and we are equally clear about which obligations stay with the practice regardless.

    45 CFR 164.308(b) (opens in a new tab)

Every rule above links to the rule itself rather than to our summary of it. If something here does not apply to your firm, that is worth knowing before you budget for it.

Compared honestly

What a generalist provider brings to medical and dental clinics

The technical work of securing a clinic is not unusual. Knowing which of your vendors' requirements are unreasonable is.

  • A generalist

    Documents HIPAA compliance as a checklist item.

    CY6

    Produces a security risk analysis in the form HIPAA expects, with the remediation it generates tracked — the document that gets asked for.

  • A generalist

    Keeps imaging and clinical devices on the same network as everything else, because they work there.

    CY6

    Segments them, because those devices routinely run software the manufacturer stopped supporting years ago.

  • A generalist

    Accommodates whatever your clinical vendor requires.

    CY6

    Tells you plainly when a vendor's own requirements are the security problem, and helps you raise it with them.

Plenty of generalist providers are good at their job. The distinction here is context, not competence.

Rules in play

What you are likely to be measured against

We are not your compliance counsel, and we will say so. What we do is make sure the technical controls and the evidence behind them stand up when someone asks.

  • HIPAA Security Rule (45 CFR Part 164 Subpart C)
  • HIPAA Breach Notification Rule
  • State medical-privacy law
  • Payer and clearinghouse security requirements

Not sure where you stand?

Start with the six-point check, or book twenty minutes and talk it through with someone who will tell you plainly what needs doing and what does not.

Or call 1-855-966-2967