What HIPAA actually asks of a Sarasota practice's IT
The Security Rule requires technical safeguards for electronic patient information: unique logins and role-based access, encryption, audit logging, integrity controls, tested backups, and a documented risk analysis. It doesn't name products, and it expects you to be able to show what you did. Most Sarasota practices we assess have some of it. Very few have all of it, and fewer still have the evidence an auditor asks for.
We provide the technical safeguards as part of our managed plan, sign a Business Associate Agreement, and, through the Compliance add-on, deliver the risk assessment and evidence file. Exactly what we do, requirement by requirement.
Built around the Sarasota medical corridors
Our healthcare clients are concentrated around Sarasota Memorial and the medical offices along Arlington Street and Osprey Avenue, the Lakewood Ranch medical corridor, and the practices downtown and on the keys. We know the EHR and imaging platforms common here, we schedule around clinic hours, and when an imaging workstation fails at 9 AM a technician is on the way, not on a ticket queue.
What's included for practices
- Role-based access, unique logins, same-day offboarding, enforced MFA
- Full-disk encryption on every laptop and portable device, verified
- Encrypted email for PHI, with automatic policies
- Audit logging on the EHR, imaging, and file servers, retained six years
- Daily off-site, immutable backups with a quarterly restore test
- Endpoint detection, email security, managed firewall, staff phishing training
- A signed BAA and vendor BAA review
- Compliance add-on: annual risk assessment, gap report, policy support, evidence file
Common gaps we find in Sarasota practices
- A shared front-desk login every medical assistant knows
- Clinical photos on a camera card or a staff phone, unencrypted
- Guest Wi-Fi on the same network as the EHR
- Audit logs that have never been opened
- A missing BAA with the IT provider, the billing company, or the website vendor
- A risk assessment from years ago, or none
Dermatology, specifically
Dermatology practices carry an unusual amount of PHI in images. We built one Sarasota dermatology practice's entire environment from an empty suite, and it's still a client years later. Read the story, or start with the HIPAA checklist for dermatology practices.
Getting started
A free IT and compliance assessment maps your practice against the Security Rule's technical requirements and gives you a written, prioritized gap list. No cost, no obligation, and if the practice is in good shape, we'll say so.
