What this page covers, and what it doesn't
We are not a law firm and not a compliance certification body. No IT vendor can make a practice HIPAA compliant on its own, and there is no federal HIPAA certification for IT providers, whatever a sales deck says. Compliance is a program: policies, designated privacy and security officers, workforce training, risk analysis, and the technical safeguards that protect electronic protected health information.
We own the technical safeguards, sign a Business Associate Agreement, and, through our Compliance add-on, provide the annual risk assessment, gap tracking, and evidence file an auditor or your compliance consultant will ask for. This page explains exactly what that means, requirement by requirement, in plain language.
The HIPAA Security Rule, in plain language
The Security Rule requires covered entities and their business associates to ensure the confidentiality, integrity, and availability of electronic PHI. It organizes the requirements into administrative, physical, and technical safeguards, and it requires a documented risk analysis to decide how each one is implemented. It doesn't prescribe specific products. It does expect you to be able to show what you did and why.
For a Sarasota-area practice, electronic PHI lives in more places than the EHR: the practice management system, imaging workstations and clinical photos, email, scanned documents on shared drives, the backup, the phone system's voicemail, and sometimes a staff member's phone. Every one of those has to be accounted for.
What we actually do
Access controls. Every staff member gets a unique login. Roles limit who can reach what: a medical assistant doesn't open billing, a biller doesn't open imaging. Accounts are disabled the day someone leaves, across the EHR, email, imaging, and remote access. Screens lock after a short idle period in exam rooms and at the front desk. Multi-factor authentication is enforced on email, remote access, and the EHR wherever the vendor supports it.
Encryption. Full-disk encryption on every laptop and any device that leaves the building, verified rather than assumed. Email containing PHI goes through an encrypted channel. Backups are encrypted at rest and in transit. Clinical cameras and memory cards are either encrypted or emptied into the record on a schedule.
Audit controls. Audit logging turned on in the EHR and reviewed periodically for unusual access. Logins to imaging and file servers logged. Logs retained for the six-year HIPAA documentation period.
Integrity and transmission security. Endpoint detection on every device, email security, a managed firewall, and secure remote access so PHI isn't altered or intercepted in transit.
Backup and contingency. Daily, encrypted, off-site, immutable backups of records and images. A restore tested at least quarterly and recorded. A written contingency plan stating who does what and how long recovery should take, kept in the client portal and in a printed copy at the practice.
Business Associate Agreements. We sign one with every healthcare client, and we help you confirm BAAs are in place with your EHR vendor, billing company, cloud storage, and any marketing vendor that touches patient data.
Workforce security. Security awareness training and phishing simulations for everyone who handles PHI, with completion records kept.
Risk analysis and documentation (Compliance add-on). An annual risk assessment, a written gap report with owners and dates, remediation tracking, policy documentation support, and an audit-ready evidence file.
Common gaps we find in Sarasota-area practices
- A shared front-desk login that every medical assistant knows
- Clinical photos on a camera card or a staff phone with no encryption
- Backups running to a drive on the server, never restored
- Guest Wi-Fi for patients on the same network as the EHR
- No one has ever opened the audit log
- A Business Associate Agreement missing for the IT provider, the billing company, or the website vendor
- A risk assessment from years ago, or none at all
- Remote access through a consumer tool with no MFA
None of these are unusual. All of them are findings in an audit, and all of them are fixable in the first 30 days.
HIPAA for dermatology, specifically
Dermatology practices carry an unusual amount of PHI in images: clinical photography, dermoscopy, body mapping, before-and-after sets for cosmetic work. Images need to move from the device into the record automatically, be included in the encrypted backup, and never end up on a personal phone. Equipment vendors with standing remote access need logging and a BAA. Cosmetic before-and-after photos used in marketing need a documented authorization process. We build all of that into the practice's workflow. Our dermatology checklist walks through it.
What a breach actually obligates you to do
Under the Breach Notification Rule, a breach of unsecured PHI requires notifying affected individuals without unreasonable delay and no later than 60 days, notifying HHS, and, for breaches affecting 500 or more people, notifying the media. "Unsecured" is the key word: PHI that was encrypted to HHS standards and whose key wasn't compromised generally isn't reportable. That is the practical reason encryption everywhere matters more than almost any other control.
Our incident response process is built around that: isolate, preserve evidence, determine whether the data was encrypted, and work with your counsel on the notification analysis. Consult legal counsel for your specific obligations; we provide the technical facts they need.
Working with your compliance officer or consultant
Many practices already work with a compliance consultant or have a designated privacy officer. We don't replace them. We coordinate with them: they own policy and training, we own the technical safeguards and the evidence, and the risk assessment is a shared document. If you don't have anyone in that role, we'll tell you plainly that you need one, and help you find the right fit.
What it costs
The technical safeguards above are part of the managed plan, priced per user. The Compliance add-on, covering the annual risk assessment, gap report, documentation support, and evidence file, is a flat monthly addition quoted alongside the plan based on the size of the practice. See the plan.
The physical safeguards most practices forget
The Security Rule's physical safeguards get less attention than the technical ones, and they're where we see the easiest findings. Server closets that double as supply closets with no lock. Workstations in exam rooms facing the door with the schedule on screen. Retired computers and copiers leaving the building with drives intact. A laptop that goes home every night with the practice's patient list on it and no encryption. We address each of these in onboarding: locked and labeled network equipment, privacy filters and screen locks where patients can see monitors, documented secure disposal for every retired device, and encryption verified on everything portable.
What an auditor or your insurer will ask to see
Whether the request comes from HHS, a cyber insurer, or a hospital system you contract with, the evidence they want is the same. A current risk analysis with dated findings and remediation. Proof MFA is enforced, not merely available. Access logs showing who reached patient records. Encryption status for every device. The last successful restore test with the date and what was recovered. Signed Business Associate Agreements. Training completion records. An incident response plan with named roles. With the Compliance add-on, all of that lives in one evidence file we maintain, so the answer to a questionnaire or an audit request is a document, not a scramble.
Getting started
A free IT and compliance assessment maps your current setup against the Security Rule's technical requirements and gives you a written list of gaps in priority order. No cost, no obligation. If your practice is in good shape, we'll say so.

