Medical & Dental

IT for Michigan medical and dental practices that cannot pause the schedule

HIPAA Security Rule work done properly, imaging and practice management systems that stay up through a full day of patients, and maintenance scheduled around your operatories rather than our convenience.

Downtime in a practice is not an inconvenience, it is a room full of waiting patients

A law firm with a slow morning loses billable hours. A practice with a slow morning has patients in chairs, a hygienist unable to see radiographs, and a front desk that cannot verify insurance. The cost is immediate, visible, and repeats every fifteen minutes the problem lasts.

That reality drives how we design. Imaging and practice management servers get the highest recovery tier. Maintenance happens outside patient hours, without exception. Workstations at operatories are standardized so a failure means swapping a machine, not rebuilding one while a patient waits.

On the compliance side, the HIPAA Security Rule requires a documented risk analysis, and the technical safeguards behind it are the part most practices have never actually had done. We handle the technical scope: access controls, audit logging, encryption decisions, device inventory, and the documentation that makes it defensible if OCR ever asks.

One thing worth being blunt about: encryption is an addressable specification in the Security Rule, not a required one. That distinction is where practices get into trouble, because addressable does not mean optional. It means you implement it or document why you reasonably did not. Almost nobody does the second part.

What goes wrong without the right setup

  • A cryptolocker event on an unsegmented network reaching the imaging server, which is often the one system with no recent tested restore
  • Shared front-desk logins making it impossible to determine who accessed a specific patient record
  • A backup that appeared successful for months but cannot restore the practice management database because it was copied while live
  • Patching scheduled during patient hours by a provider working off their own calendar
  • No business associate agreement with a vendor who has had ePHI access for years
  • A departed employee whose access was never removed, discovered during an audit rather than at departure

Built for practice environments

Imaging and practice management server priority tier
Application-aware backup for Dentrix, Eaglesoft, Open Dental, and similar
Maintenance windows outside patient hours, always
Standardized operatory and front-desk workstation images
Automatic logoff configured per HIPAA requirements
Encryption at rest on all endpoints, with decisions documented
Guest Wi-Fi fully segmented from clinical systems
Secure ePHI exchange with referring providers and labs
eFax with retention controls for records requests
BAA in place with us and tracked for your other vendors
Annual risk analysis, technical scope
Breach notification support with the 60-day clock in mind
Book a 15-Minute Fit Call Get the Free Checklist

Compliance

HIPAA obligations we handle the technical side of

Security Rule risk analysis

The documented, periodic risk analysis required under 45 CFR 164.308. We handle the technical scope and produce evidence you can hand to an auditor or your compliance consultant.

Access controls and unique user IDs

Individual accounts for every person, role-based permissions, automatic logoff, and no shared front-desk logins. Shared credentials are the most common finding we correct.

Audit controls and log review

System activity logging enabled and retained, with documented review, so you can determine after the fact who accessed which record and when.

Business associate agreements

A tracked register of every vendor touching ePHI with a BAA on file, including the ones practices forget, like backup providers, IT vendors, and VoIP carriers.

Contingency planning

Data backup plan, disaster recovery plan, and emergency mode operations, all documented and tested, which the Security Rule requires and most practices have never rehearsed.

Workforce security and termination

Documented access provisioning and same-day removal on departure, with evidence retained. This is the single most frequently failed control we find.

As a photographer, my computer is essential to my business, so when it started acting up I contacted Andrew. He came out the next day and was thorough, professional, and very knowledgeable.
Deborah GillespieOwner and Photographer

Questions

Medical & Dental IT questions

Are you saying our practice is not HIPAA compliant?

We are saying most practices we assess have technical gaps they were not aware of, which is different. Usually the policies exist in a binder from a compliance consultant and the technical safeguards those policies describe were never actually implemented. The binder says automatic logoff is enabled. Nobody enabled it.

Does HIPAA require encryption?

Not exactly, and this trips up almost everyone. Encryption is an addressable implementation specification, not a required one. Addressable does not mean optional. It means you either implement it, or you document a reasonable alternative and why encryption was not reasonable and appropriate for your situation. Practices that skip encryption without that documentation have the worst of both options. We just encrypt, because the alternative is a paperwork exercise defending a weaker position.

Will you sign a business associate agreement?

Yes, before we touch anything. We also audit your other vendors for BAAs, because the ones practices miss are consistently the same: the backup provider, the phone carrier if calls contain protected health information, the shredding company, and the copier vendor whose machines store images.

Can you support our imaging system? The vendor is very particular.

Usually yes, and we treat the vendor's requirements as requirements rather than suggestions. Imaging and CAD/CAM systems often have specific driver, network, and sometimes deliberately unpatched configurations. We document those exceptions, isolate them where we cannot patch them, and coordinate with the vendor directly rather than relaying messages through your office manager.

What happens if we have a breach?

We contain it, determine scope, and preserve evidence. Simultaneously we help you work the notification analysis, because the HIPAA clock starts at discovery and runs 60 days for individual notification, with different thresholds for HHS and media notice depending on how many records are involved. Knowing the record count is a technical question, which is why your IT provider needs to be capable of answering it accurately and quickly.

We are a small practice. Do you have a minimum?

Five employees. A three-person office is better served by a break-fix provider, and we will name one rather than take work we would price badly. Most practices we serve run between eight and forty-five people across one to four locations.

Want a second opinion on where you stand?

The assessment scores your environment against the requirements that apply to you specifically, and the written report is yours to keep either way.

No pressure, no obligation. If we are not the right fit we will tell you and point you somewhere better.

Call Book a Fit Call