Every few months a vendor tells a practice owner that their product is HIPAA compliant and therefore the practice is too. It does not work like that. Compliance is a property of your organisation, not of a piece of software, and no supplier can hand it to you.
What the HIPAA Security Rule actually does is set out safeguards you are required to have in place and be able to demonstrate. Some of those are administrative and belong with you: policies, training, sanctions, a named security official. Some are physical: who can walk into the server cupboard. And a large block of them are technical, which is where your IT provider either helps you or quietly leaves you exposed.
Below is the technical half, written the way we would walk a clinic through it. If you can answer all twelve with evidence rather than a shrug, you are in better shape than most small practices in North Mississippi.
1. Unique logins for every person
Shared accounts are the single most common finding when we take over a practice. One login for the front desk, one for the therapists, the password on a sticky note because five people need it.
The problem is not only that the password leaks. It is that an audit trail showing that someone accessed a record is worthless if it cannot say which someone. Every person gets their own account. This is not negotiable and it is usually a morning of work to fix.
2. Access limited to what each role needs
A billing clerk does not need the same access as a clinician, and a receptionist does not need administrative rights on the machine. Most practice management systems have role-based permissions built in and most practices have everyone set to the highest tier because it was simpler on setup day.
3. Access removed the day someone leaves
This one is dull and it is the one that bites. We regularly find active accounts belonging to people who left eighteen months ago, still able to log in, still holding a mailbox.
Offboarding should be a checklist, not a memory: disable the account, revoke the multi-factor device, reclaim the laptop, change any shared credentials the person knew, and record the date it was done. That record is the evidence.
4. Multi-factor authentication on everything that has it
If you do one thing after reading this, do this one. A stolen password alone stops being enough to get into your email, your practice management system or your remote access.
The usual objection is that it will slow staff down. In practice, configured sensibly, most people approve a prompt once on a trusted device and forget about it. Weigh that against the alternative, which is an attacker reading your mail for three months before anyone notices.
5. Encryption on laptops and anything that leaves the building
A laptop left in a car is a very different event depending on whether the drive was encrypted. Modern Windows and macOS both include full disk encryption; on a managed fleet it should be switched on and its status reported, not assumed.
The same applies to any USB drive anyone is still using to move records around, which is a habit worth ending regardless.
6. Email that is actually secure when it needs to be
Ordinary email is not a secure channel. If your practice sends anything containing patient information by email, there needs to be a mechanism for that, whether it is an encryption feature on your mail platform, a portal, or a policy that it simply does not happen.
Pick one deliberately. The failure mode is a practice that assumes it is covered because the vendor mentioned encryption somewhere in the sales process.
7. A segmented network
Clinical systems, the front desk, staff phones, guest Wi-Fi for the waiting room and any connected equipment should sit on separate segments that cannot freely reach each other.
The test is simple: from the guest Wi-Fi in your waiting room, can anything see the machine running your practice management software? On a flat network, which is what most small practices have, the answer is usually yes.
8. Backups that are isolated and have been restored
Two separate questions, and practices usually only ask the first. Do backups run, and has anyone ever restored from them?
A backup sitting on a drive attached to the server it protects is not a backup against ransomware, because the ransomware will encrypt both. At least one copy needs to be somewhere the infected network cannot reach. And a restore that has never been tested is a hope: we have seen jobs that reported success for two years and produced nothing usable.
9. Patching, tracked rather than hoped for
Not just Windows updates. Your firewall firmware, your network equipment, the browser, the PDF reader nobody thinks about. Someone should be able to tell you which machines are behind and why.
Watch particularly for anything running an operating system that no longer receives security updates. An old machine running one piece of specialist software is extremely common in clinical settings, and it needs either replacing or isolating on its own segment where it can do less harm.
10. Audit logs that exist and are kept
Your practice management system almost certainly logs access to records. The question is whether logging is switched on, how long entries are retained, and whether anyone would notice something unusual in them.
11. A signed Business Associate Agreement with every vendor that touches patient data
Your IT provider, your practice management vendor, your billing company, your backup provider, anyone hosting your email. Each of those relationships should be covered by a signed agreement.
If a provider is unclear about what you are asking for, that is informative. We sign one before we have access to anything.
12. Documentation that someone could actually hand over
This is the difference between being in reasonable shape and being able to prove it. A network diagram. An inventory of machines. A list of who has access to what. The date of the last restore test. Your risk analysis.
Most practices have none of this, because the knowledge lives in the head of whoever set things up, and it leaves when they do. Keeping it current is part of what a managed service should be doing on your behalf.
Where practices usually are
Honestly? Most single-location clinics we assess score somewhere around five or six of the twelve, and are surprised by which ones they fail. The multi-factor gap and the flat network are the two that come up most, and both are fixable in days rather than months.
The useful thing about this list is that it is finite. It is not an endless compliance treadmill; it is twelve concrete items, and once they are in place, keeping them in place is routine.
- HIPAA
- Compliance
- Security

