You run a medical or dental practice. You hold charts, insurance details, and Social Security numbers for thousands of patients. A vendor emailed you about HIPAA, or your malpractice carrier asked whether you've done a security risk analysis, or you heard the HIPAA Security Rule is being tightened, and now your inbox is full of companies promising to make compliance painless. Every one of them sounds confident. Every proposal has a number on it. And you're nodding along to words like "ePHI," "risk analysis," "BAA," and "encryption at rest," hoping the person across the table actually understands what they mean for a practice that has to see patients all day and keep their trust for years.
Here's what most vendors won't lead with. HIPAA already applies to you, and it's about to get more demanding. The Security Rule requires you to protect electronic protected health information with real administrative, technical, and physical safeguards, and it starts with one thing regulators ask for first: a written risk analysis. On top of that, the Department of Health and Human Services has proposed the most significant Security Rule update in years, and it would remove the old "addressable" wiggle room. Under the proposed changes, encryption of ePHI at rest and in transit becomes mandatory, multi-factor authentication becomes mandatory, annual penetration testing and twice-a-year vulnerability scanning become expected, you'd keep a written technology asset inventory and a network map of how ePHI moves, and your Business Associate Agreements would require active verification of your vendors' safeguards, not just a signature.
And the stakes are not theoretical. OCR civil penalties are tiered and, at the top end, reach into the millions per violation category per year. A breach affecting 500 or more patients has to be reported to HHS and the media, and every affected individual notified, generally within 60 days. And OCR's recent enforcement keeps landing on the same two failures: no real risk analysis, and weak vendor management.
So we wrote this down. Not a teaser, the real thing. First we decode the jargon and lay out what HIPAA actually asks for, in plain English, including what the proposed 2026 update would change. Then we give you a ten-minute exercise to map where your ePHI lives. Then the ten questions we'd ask if we were sitting in your chair, each with what a strong answer sounds like, what a weak one sounds like, and a real requirement to hold the vendor to.
Ask these of every vendor you're talking to, including us. The right partner welcomes them and answers straight. The wrong one gets vague. How a vendor handles these ten tells you more than any proposal ever will.
One note on us. We run managed IT and security for practices that handle sensitive patient data, and we help build and maintain the safeguards HIPAA requires: the risk analysis, the technical controls, the vendor oversight, the documentation, and the incident response. We deliver that on one agreement, with the labor included rather than billed by the hour, and we sign a Business Associate Agreement because we're in scope too. We've built our own PCs and servers on our own line in Wichita since 1997.
What HIPAA is. HIPAA is a set of federal rules that require you to protect patients' health information. Three rules matter most: the Privacy Rule, the Security Rule (how you protect the electronic version, ePHI), and the Breach Notification Rule. The Security Rule is where most IT and security work lives.
Who it applies to. You're a "covered entity" if you're a healthcare provider who transmits health information electronically, which covers essentially every medical and dental practice. Any vendor who handles your patients' health information on your behalf, your IT company, your billing service, your cloud EHR, is a "business associate," and both of you carry obligations.
What the Security Rule requires. Administrative, technical, and physical safeguards for ePHI. The foundation is a written risk analysis: identify where ePHI lives, what threatens it, and how you're addressing each risk. From there the Rule expects access controls, audit logging, workforce training, contingency planning, and encryption and other measures historically labeled "addressable."
What's changing. HHS has proposed a major Security Rule update. The "addressable" category effectively goes away for the important controls. Under the proposal, encryption of ePHI at rest and in transit becomes required, MFA becomes required, annual penetration testing and vulnerability scanning every six months become expected, and you'd maintain a written technology asset inventory and a network map, reviewed at least yearly. BAAs would need active verification of your vendors' safeguards. (Verify the final status against HHS, since this is moving through rulemaking.)
Breach notification. If ePHI is exposed, you generally must notify affected individuals and HHS within 60 days of discovery, and if the breach affects 500 or more people, you also notify prominent media. Larger breaches become public on the HHS breach portal.
What OCR looks at. The HHS Office for Civil Rights investigates and enforces. The first thing they ask for is your risk analysis. Recent enforcement keeps returning to two failures: no real risk analysis, and poor vendor management. Penalties are tiered by culpability and run into the millions per category per year at the top end.
Where CybertronIT sits. We're your business associate for IT and security. We help build and run the technical and administrative safeguards, and help you complete and maintain the risk analysis and documentation. We're not your attorney or auditor; the practice remains the covered entity and owns the final accountability.
Here are the ten questions, with why each one matters for a real medical practice. Ask all ten, and watch the reactions as closely as the answers.
The Privacy, Security, and Breach Notification Rules all apply, and the proposed update would make encryption and MFA mandatory and add asset-inventory and vendor-verification requirements. A vendor who can't explain what you must do today and where the standard is heading is selling you a product, not compliance.
The risk analysis is the foundation of the Security Rule and the first thing OCR asks for. A weak vendor skips it, hands you a generic template, or treats it as a one-time form.
ePHI doesn't sit in one place: the EHR, email, billing, a provider's laptop, a personal phone, imaging devices, backups, printers, paper charts. A vendor who scopes only "the server" has missed the laptops, the phones, and the paper, which is where a lot of breaches start.
Encryption both at rest and in transit and MFA move from "addressable" to mandatory under the proposed update, and "everything that touches ePHI" includes email and mobile devices. A weak vendor says "we use strong security" and can't point to the specific control.
Any vendor who touches your ePHI, including your IT company, must sign a BAA, and the proposed update would require you to verify their safeguards. A vendor who dodges signing a BAA has left a gap OCR routinely fines practices for.
Doing a safeguard isn't enough; you have to document it, and the proposed update adds a written asset inventory and network map reviewed at least yearly. A vendor who leaves the paperwork to you has left you holding the part OCR examines.
The Security Rule names all three. A vendor who never mentions logs, access reviews, or training is leaving out safeguards that are required and frequently where breaches trace back to.
A breach generally requires notifying affected individuals and HHS within 60 days, and 500-plus patients means notifying the media and landing on the public HHS breach portal. A vendor who treats a breach as an afterthought is the one you don't want when it happens.
Compliant email, MFA, encryption, monitoring, logging, and testing carry real per-user cost. Guessing 8 users when the real number is 20, part-time and clinical staff included, isn't a rounding error.
If OCR investigates, they start with your risk analysis and work outward into your documentation, BAAs, logs, and training records. A vendor who leaves the proof to you has left you holding the exact part that gets examined.
Everything above is the map. The full checklist is the tool you bring into the room. The free PDF is built to print and carry. It adds a ten-minute exercise to map your own exposure before you take a single sales call, plus where CybertronIT fits and how to score every vendor you talk to. Give us an email and it is yours.
Comments