CybertronIT Blog



Cybertron Blog

Cybertron has been serving the Wichita area since 1997, providing IT Support such as technical helpdesk support, computer support, and consulting to small and medium-sized businesses.

10 Questions Every Medical Practice Should Ask Before Buying a HIPAA Solution

Before you read

You run a medical or dental practice. You hold charts, insurance details, and Social Security numbers for thousands of patients. A vendor emailed you about HIPAA, or your malpractice carrier asked whether you've done a security risk analysis, or you heard the HIPAA Security Rule is being tightened, and now your inbox is full of companies promising to make compliance painless. Every one of them sounds confident. Every proposal has a number on it. And you're nodding along to words like "ePHI," "risk analysis," "BAA," and "encryption at rest," hoping the person across the table actually understands what they mean for a practice that has to see patients all day and keep their trust for years.

Here's what most vendors won't lead with. HIPAA already applies to you, and it's about to get more demanding. The Security Rule requires you to protect electronic protected health information with real administrative, technical, and physical safeguards, and it starts with one thing regulators ask for first: a written risk analysis. On top of that, the Department of Health and Human Services has proposed the most significant Security Rule update in years, and it would remove the old "addressable" wiggle room. Under the proposed changes, encryption of ePHI at rest and in transit becomes mandatory, multi-factor authentication becomes mandatory, annual penetration testing and twice-a-year vulnerability scanning become expected, you'd keep a written technology asset inventory and a network map of how ePHI moves, and your Business Associate Agreements would require active verification of your vendors' safeguards, not just a signature.

And the stakes are not theoretical. OCR civil penalties are tiered and, at the top end, reach into the millions per violation category per year. A breach affecting 500 or more patients has to be reported to HHS and the media, and every affected individual notified, generally within 60 days. And OCR's recent enforcement keeps landing on the same two failures: no real risk analysis, and weak vendor management.

So we wrote this down. Not a teaser, the real thing. First we decode the jargon and lay out what HIPAA actually asks for, in plain English, including what the proposed 2026 update would change. Then we give you a ten-minute exercise to map where your ePHI lives. Then the ten questions we'd ask if we were sitting in your chair, each with what a strong answer sounds like, what a weak one sounds like, and a real requirement to hold the vendor to.

Ask these of every vendor you're talking to, including us. The right partner welcomes them and answers straight. The wrong one gets vague. How a vendor handles these ten tells you more than any proposal ever will.

One note on us. We run managed IT and security for practices that handle sensitive patient data, and we help build and maintain the safeguards HIPAA requires: the risk analysis, the technical controls, the vendor oversight, the documentation, and the incident response. We deliver that on one agreement, with the labor included rather than billed by the hour, and we sign a Business Associate Agreement because we're in scope too. We've built our own PCs and servers on our own line in Wichita since 1997.


HIPAA in plain English

What HIPAA is. HIPAA is a set of federal rules that require you to protect patients' health information. Three rules matter most: the Privacy Rule, the Security Rule (how you protect the electronic version, ePHI), and the Breach Notification Rule. The Security Rule is where most IT and security work lives.

Who it applies to. You're a "covered entity" if you're a healthcare provider who transmits health information electronically, which covers essentially every medical and dental practice. Any vendor who handles your patients' health information on your behalf, your IT company, your billing service, your cloud EHR, is a "business associate," and both of you carry obligations.

What the Security Rule requires. Administrative, technical, and physical safeguards for ePHI. The foundation is a written risk analysis: identify where ePHI lives, what threatens it, and how you're addressing each risk. From there the Rule expects access controls, audit logging, workforce training, contingency planning, and encryption and other measures historically labeled "addressable."

What's changing. HHS has proposed a major Security Rule update. The "addressable" category effectively goes away for the important controls. Under the proposal, encryption of ePHI at rest and in transit becomes required, MFA becomes required, annual penetration testing and vulnerability scanning every six months become expected, and you'd maintain a written technology asset inventory and a network map, reviewed at least yearly. BAAs would need active verification of your vendors' safeguards. (Verify the final status against HHS, since this is moving through rulemaking.)

Breach notification. If ePHI is exposed, you generally must notify affected individuals and HHS within 60 days of discovery, and if the breach affects 500 or more people, you also notify prominent media. Larger breaches become public on the HHS breach portal.

What OCR looks at. The HHS Office for Civil Rights investigates and enforces. The first thing they ask for is your risk analysis. Recent enforcement keeps returning to two failures: no real risk analysis, and poor vendor management. Penalties are tiered by culpability and run into the millions per category per year at the top end.

Where CybertronIT sits. We're your business associate for IT and security. We help build and run the technical and administrative safeguards, and help you complete and maintain the risk analysis and documentation. We're not your attorney or auditor; the practice remains the covered entity and owns the final accountability.


The jargon, decoded

  • PHI / ePHI. Protected Health Information tied to a patient; ePHI is the electronic version: charts in your EHR, images, emails, texts, billing records.
  • Covered Entity. You, the healthcare provider. HIPAA's obligations land on you directly.
  • Business Associate. A vendor that handles your patients' information on your behalf. They carry HIPAA obligations too, and you're required to have an agreement with them.
  • BAA (Business Associate Agreement). The contract HIPAA requires between you and each business associate. Under the proposed update, you'd also verify their safeguards, not just collect a signature.
  • Risk Analysis (SRA). The written, current evaluation of threats to your ePHI. It's the foundation of the Security Rule and the first document OCR asks for.
  • Encryption at rest and in transit. Protecting ePHI both where it's stored and where it moves. Historically "addressable," it becomes mandatory under the proposed update.
  • MFA (Multi-Factor Authentication). Requiring more than a password before someone can reach ePHI. Mandatory under the proposed update.
  • Audit logging / access controls. Recording who accessed what, and limiting people to the ePHI they need. Both are named safeguards OCR checks.
  • Technology asset inventory / network map. A written list of systems that touch ePHI and a map of how it moves, reviewed at least yearly. Proposed as a new requirement.
  • Breach Notification Rule. Requires notifying individuals and HHS (and, for 500+, the media) generally within 60 days of discovering a breach.

The 10 questions

Here are the ten questions, with why each one matters for a real medical practice. Ask all ten, and watch the reactions as closely as the answers.

1. Which HIPAA rules apply to me, what do they require now, and what changes under the proposed 2026 Security Rule update?

The Privacy, Security, and Breach Notification Rules all apply, and the proposed update would make encryption and MFA mandatory and add asset-inventory and vendor-verification requirements. A vendor who can't explain what you must do today and where the standard is heading is selling you a product, not compliance.

2. Have you done a real, written HIPAA risk analysis for my practice, and how do you keep it current?

The risk analysis is the foundation of the Security Rule and the first thing OCR asks for. A weak vendor skips it, hands you a generic template, or treats it as a one-time form.

3. What counts as ePHI in my practice, and where does it actually live?

ePHI doesn't sit in one place: the EHR, email, billing, a provider's laptop, a personal phone, imaging devices, backups, printers, paper charts. A vendor who scopes only "the server" has missed the laptops, the phones, and the paper, which is where a lot of breaches start.

4. Do you provide encryption at rest and in transit and MFA across everything that touches ePHI, and can you prove it?

Encryption both at rest and in transit and MFA move from "addressable" to mandatory under the proposed update, and "everything that touches ePHI" includes email and mobile devices. A weak vendor says "we use strong security" and can't point to the specific control.

5. Do you sign a Business Associate Agreement, and how do you handle BAAs with my other vendors?

Any vendor who touches your ePHI, including your IT company, must sign a BAA, and the proposed update would require you to verify their safeguards. A vendor who dodges signing a BAA has left a gap OCR routinely fines practices for.

6. Who builds and maintains my policies, documentation, asset inventory, and network map?

Doing a safeguard isn't enough; you have to document it, and the proposed update adds a written asset inventory and network map reviewed at least yearly. A vendor who leaves the paperwork to you has left you holding the part OCR examines.

7. How do you handle audit logging, access controls, and workforce training?

The Security Rule names all three. A vendor who never mentions logs, access reviews, or training is leaving out safeguards that are required and frequently where breaches trace back to.

8. What is my incident response and breach-notification plan, and how do we meet the 60-day, 500-patient rules?

A breach generally requires notifying affected individuals and HHS within 60 days, and 500-plus patients means notifying the media and landing on the public HHS breach portal. A vendor who treats a breach as an afterthought is the one you don't want when it happens.

9. What will compliant infrastructure and monitoring actually cost me, per seat, in writing?

Compliant email, MFA, encryption, monitoring, logging, and testing carry real per-user cost. Guessing 8 users when the real number is 20, part-time and clinical staff included, isn't a rounding error.

10. How do you make sure I can prove compliance to OCR, not just claim it?

If OCR investigates, they start with your risk analysis and work outward into your documentation, BAAs, logs, and training records. A vendor who leaves the proof to you has left you holding the exact part that gets examined.


Red flags to listen for

  • No risk analysis. They never mention a written risk analysis, or treat it as a one-time form.
  • Won't sign a BAA. A vendor who touches your ePHI and hesitates to sign a BAA doesn't understand their obligations, or yours.
  • Vague on encryption and MFA. They can't tell you exactly where MFA is enforced or that ePHI is encrypted at rest and in transit, including email and mobile.
  • Ignores your other vendors. No plan for the BAAs and oversight of your EHR, billing, and cloud vendors.
  • Scopes only the server. They miss the laptops, personal phones, imaging devices, and paper.
  • Selling tools, skipping documentation. They leave the policies, asset inventory, and network map to you, the part OCR examines.
  • No incident response, no breach clock. They have no plan for the 60-day and 500-patient rules.
  • Fear without a plan. Heavy on scare tactics about fines, light on a real plan for your specific practice.

Get the full checklist (free)

Everything above is the map. The full checklist is the tool you bring into the room. The free PDF is built to print and carry. It adds a ten-minute exercise to map your own exposure before you take a single sales call, plus where CybertronIT fits and how to score every vendor you talk to. Give us an email and it is yours.

  • Company Name *
  • First Name *
  • Last Name *
  • Comments:
  • Yes, I'd like to subscribe to:
      10 Questions Every Nonprofit Should Ask Before Buy...
      10 Questions Every CPA Firm Should Ask Before Buyi...
      Comment for this post has been locked by admin.
       

      Comments

      Already Registered? Login Here
      No comments made yet. Be the first to submit a comment