Medical & Dental
IT for Michigan medical and dental practices that cannot pause the schedule
HIPAA Security Rule work done properly, imaging and practice management systems that stay up through a full day of patients, and maintenance scheduled around your operatories rather than our convenience.
Downtime in a practice is not an inconvenience, it is a room full of waiting patients
A law firm with a slow morning loses billable hours. A practice with a slow morning has patients in chairs, a hygienist unable to see radiographs, and a front desk that cannot verify insurance. The cost is immediate, visible, and repeats every fifteen minutes the problem lasts.
That reality drives how we design. Imaging and practice management servers get the highest recovery tier. Maintenance happens outside patient hours, without exception. Workstations at operatories are standardized so a failure means swapping a machine, not rebuilding one while a patient waits.
On the compliance side, the HIPAA Security Rule requires a documented risk analysis, and the technical safeguards behind it are the part most practices have never actually had done. We handle the technical scope: access controls, audit logging, encryption decisions, device inventory, and the documentation that makes it defensible if OCR ever asks.
One thing worth being blunt about: encryption is an addressable specification in the Security Rule, not a required one. That distinction is where practices get into trouble, because addressable does not mean optional. It means you implement it or document why you reasonably did not. Almost nobody does the second part.
What goes wrong without the right setup
- A cryptolocker event on an unsegmented network reaching the imaging server, which is often the one system with no recent tested restore
- Shared front-desk logins making it impossible to determine who accessed a specific patient record
- A backup that appeared successful for months but cannot restore the practice management database because it was copied while live
- Patching scheduled during patient hours by a provider working off their own calendar
- No business associate agreement with a vendor who has had ePHI access for years
- A departed employee whose access was never removed, discovered during an audit rather than at departure
Built for practice environments
Compliance
HIPAA obligations we handle the technical side of
Security Rule risk analysis
The documented, periodic risk analysis required under 45 CFR 164.308. We handle the technical scope and produce evidence you can hand to an auditor or your compliance consultant.
Access controls and unique user IDs
Individual accounts for every person, role-based permissions, automatic logoff, and no shared front-desk logins. Shared credentials are the most common finding we correct.
Audit controls and log review
System activity logging enabled and retained, with documented review, so you can determine after the fact who accessed which record and when.
Business associate agreements
A tracked register of every vendor touching ePHI with a BAA on file, including the ones practices forget, like backup providers, IT vendors, and VoIP carriers.
Contingency planning
Data backup plan, disaster recovery plan, and emergency mode operations, all documented and tested, which the Security Rule requires and most practices have never rehearsed.
Workforce security and termination
Documented access provisioning and same-day removal on departure, with evidence retained. This is the single most frequently failed control we find.
As a photographer, my computer is essential to my business, so when it started acting up I contacted Andrew. He came out the next day and was thorough, professional, and very knowledgeable.
Questions
Medical & Dental IT questions
Are you saying our practice is not HIPAA compliant?
We are saying most practices we assess have technical gaps they were not aware of, which is different. Usually the policies exist in a binder from a compliance consultant and the technical safeguards those policies describe were never actually implemented. The binder says automatic logoff is enabled. Nobody enabled it.
Does HIPAA require encryption?
Not exactly, and this trips up almost everyone. Encryption is an addressable implementation specification, not a required one. Addressable does not mean optional. It means you either implement it, or you document a reasonable alternative and why encryption was not reasonable and appropriate for your situation. Practices that skip encryption without that documentation have the worst of both options. We just encrypt, because the alternative is a paperwork exercise defending a weaker position.
Will you sign a business associate agreement?
Yes, before we touch anything. We also audit your other vendors for BAAs, because the ones practices miss are consistently the same: the backup provider, the phone carrier if calls contain protected health information, the shredding company, and the copier vendor whose machines store images.
Can you support our imaging system? The vendor is very particular.
Usually yes, and we treat the vendor's requirements as requirements rather than suggestions. Imaging and CAD/CAM systems often have specific driver, network, and sometimes deliberately unpatched configurations. We document those exceptions, isolate them where we cannot patch them, and coordinate with the vendor directly rather than relaying messages through your office manager.
What happens if we have a breach?
We contain it, determine scope, and preserve evidence. Simultaneously we help you work the notification analysis, because the HIPAA clock starts at discovery and runs 60 days for individual notification, with different thresholds for HHS and media notice depending on how many records are involved. Knowing the record count is a technical question, which is why your IT provider needs to be capable of answering it accurately and quickly.
We are a small practice. Do you have a minimum?
Five employees. A three-person office is better served by a break-fix provider, and we will name one rather than take work we would price badly. Most practices we serve run between eight and forty-five people across one to four locations.
Want a second opinion on where you stand?
The assessment scores your environment against the requirements that apply to you specifically, and the written report is yours to keep either way.
No pressure, no obligation. If we are not the right fit we will tell you and point you somewhere better.