It is 8:02 and the first patient is already in the chair. The sensor will not talk to the imaging computer again, so somebody restarts it while the hygienist waits. The front desk is on hold with an insurance line. A patient at the counter has a clear view of a monitor still showing the last patient’s chart. None of this is a crisis. It is just Tuesday.
Small practices run on tight schedules and tighter margins, which is why the compliance conversation usually goes badly. It arrives as a thick binder or a nervous sales pitch instead of a list of things you can do between patients. Our caveat up front, and we mean it: this is general information, not legal or compliance advice. Requirements change, and how they apply to your practice depends on facts we do not know, so a qualified advisor, your compliance consultant, or your attorney has to confirm what applies to you. What follows is the technology half, in the order we would really work.
What the Security Rule Actually Asks For
The HHS summary of the HIPAA Security Rule is shorter and more reasonable than its reputation. It covers electronic protected health information, and regulated entities are expected to ensure the confidentiality, integrity, and availability of what they create, receive, maintain, or transmit. HHS defines those words plainly: confidentiality means the data is not disclosed to unauthorized persons, integrity means it has not been altered or destroyed in an unauthorized manner, and availability means it is accessible and usable on demand by an authorized person.
Here is the sentence small practices should underline. HHS states the rule is intentionally flexible, and that entities must consider their size, complexity, and capabilities, their technical infrastructure, the cost of security measures, and the probability and criticality of potential risks. A four operatory practice is not expected to build what a hospital builds. One term trips everyone up: some specifications are labeled required and some addressable. Addressable does not mean optional. HHS explains that you decide whether it is reasonable and appropriate, and if not, you adopt an alternative that achieves the purpose and document why. Start with a risk analysis. HHS points to a free Security Risk Assessment Tool from the Assistant Secretary for Technology Policy and the Office for Civil Rights, described as useful for small and medium-sized practices.
The Machines Your Vendor Will Not Let You Patch
You are not imagining the problem. In its Fall 2021 cybersecurity newsletter, the HHS Office for Civil Rights described a legacy system as one with components supplanted by newer technology and for which the manufacturer is no longer offering support, and noted that this lack of vendor support makes such systems particularly vulnerable to cyberattacks. That newsletter suggests compensating controls when replacement is not yet possible.
- Cut down who can reach it. OCR suggests restricting access to a reduced number of users. In a small office that is often two or three people rather than everyone.
- Strengthen how people sign in. The newsletter points to strengthening authentication requirements and access controls. Shared logins are the habit most worth ending.
- Turn on better logging. OCR suggests enhancing system activity reviews and audit logging, so you would actually notice something odd.
- Let it do one job only. Limit the machine to essential functions. No email, no browsing, nothing else.
- Wrap it in what you can still support. The newsletter mentions firewall protections and supported anti-malware, plus robust backups and contingency plans that contemplate a higher likelihood of failure.
Backups That Would Actually Get You Open Again
The useful question is not whether you have a backup. It is how many hours pass between a dead server and seeing patients again. Back up the whole machine, not just the database file, because rebuilding a practice management server during a workday is not a plan. Make sure the backup includes the image archive, which often sits on a different drive and gets missed for years. Keep an encrypted copy outside the building, because fire, flood, and ransomware all reach the closet where the server lives. HHS lists contingency planning, including data backup and procedures for restoring data, among the administrative safeguards. Then test it: restore something real on a schedule and write the date in the compliance binder. A backup nobody has restored from is a belief, not a control.
What Can Be Seen From the Waiting Room
The rule also includes physical safeguards, which HHS describes as facility access controls, policies for workstation use and security, and controls over the receipt, removal, movement, and disposal of hardware holding electronic health information. In a real office that becomes small, cheap adjustments.
- Fix the sightlines. Stand where patients stand and look at every monitor. Angle the screen, add a privacy filter, or move it.
- Shorten the screen lock timers. Front desk machines should lock quickly and operatory computers when the room empties. Fast sign-in makes short timers tolerable.
- Decide what happens to old hardware. Retired computers, drives, and the copier all hold images of what passed through them.
- Control who gets into the back. Wherever the server lives should be a locked space, even if that space is a closet.
Business Associate Agreements, Including With Your IT Provider
This is the one small offices most often miss. HHS explains that a covered entity may disclose protected health information to a business associate if it obtains satisfactory assurances, in the form of a contract or other written arrangement, commonly called a business associate agreement. HHS specifically lists a cloud service provider engaged to create, receive, maintain, or transmit electronic health information, and an IT contractor or vendor, giving the examples of an electronic health record vendor and a managed services provider, that supports systems requiring them to handle that information. HHS also addresses the conduit idea directly, stating that entities accessing protected health information on a regular or frequent basis to perform a service are not conduits.
Practically: list every vendor whose people or software touch your systems and confirm you have a signed agreement with each, including your IT provider. We sign them, and if an IT company will not, treat that as information. One honest note. A signed agreement is a contract, not a security control. It makes obligations explicit, it does not make anyone careful. The same goes for tools your team adopts on their own, like texting a radiograph from a personal phone because it was quicker. That is the pattern we described in shadow IT, and it usually means the approved path is too slow.
The Practical Order to Fix Things In
- Run a risk analysis and write it down. Everything else gets prioritized from what it finds.
- Inventory vendors and get agreements signed. Paperwork, one afternoon, no purchase required.
- Turn on multi-factor authentication for email and remote access. Email is the reset path for everything else you own.
- Prove the backup by restoring from it. Then schedule that test to repeat.
- Do the physical pass. Screens, locks, timers, closet, disposal. Mostly free.
- Isolate the machines you cannot patch and set a replacement date. This is where the real money goes, which is why it comes after the free items.
- Train the team in short, frequent doses. Ten minutes at a morning huddle beats an annual lecture nobody remembers.
The Bottom Line
You are not being asked to build a hospital’s security program in a four operatory office. HHS built flexibility into the rule precisely because practices differ in size, capability, and budget. You are being asked to know your risks, make deliberate choices, write them down, and revisit them. Most of the highest value work here costs an afternoon rather than a capital purchase, and we cover why a plan like this pays for itself in why cybersecurity is no longer optional.
Saying it once more, clearly: this is general information, not legal or compliance advice, and a qualified advisor has to confirm what applies to your practice. If you want a partner who handles the technical side, signs a business associate agreement without being asked twice, and works with your compliance consultant instead of around them, that is what we do for practices across Denton County. Contact us today.
Sources:
Comments are closed