Mon–Fri, 9:00 AM – 5:00 PM PST

Compliance

HIPAA for a small practice: what your IT actually has to do

Plain-language translation of the Security Rule into the controls, documents and evidence an auditor will ask for.

The HIPAA Security Rule is written to survive changes in technology, which is why it reads as vague. In practice, for a practice under fifty people, it comes down to a manageable set of controls plus the documentation proving they exist.

The controls

  • Access control: unique logins, role-based permissions, automatic screen lock, and access reviews you can show.
  • Encryption: full-disk on every device that touches PHI, and encryption in transit for email and file transfer.
  • Audit controls: logging that records who accessed what, retained long enough to investigate.
  • Contingency plan: backup, disaster recovery and an emergency mode operation plan — tested, not just written.
  • Business associate agreements with every vendor that can reach PHI, including your IT provider.

The documents

A risk analysis is the document auditors ask for first and the one most small practices don't have. It has to be written, dated, specific to your environment and updated when things change — not a template with your name pasted on top.

In an audit, an undocumented control and a missing control look identical.

This is why we document continuously rather than annually, and why a technician attends the IT portion of the audit with you. The evidence should already exist before anybody asks for it.

Book free consultation (opens in a new tab) Build your quote

Let's take IT off your plate.

A free onsite consultation: we assess your network and security, flag the risks we find, and show you exactly what it costs to fix them.