IT support for medical and dental practices
Your practice cannot see patients when the imaging server is down or the practice-management software will not open. I keep clinical systems running and your patient data protected, across New York City and Long Island.
Call or text
(929) 779-3188Same-day response on business days. Existing clients get an emergency number for evenings and weekends.
Where practices get caught out
- Imaging and practice-management servers running on hardware well past its life, with no failover and no tested restore.
- Patient information emailed in plain text because the encrypted option is awkward and nobody was trained on it.
- Every member of staff sharing one administrator login, so an audit cannot show who accessed which record.
- Vendors with remote access into the practice network that nobody has reviewed in years — a route in that bypasses everything else you paid for.
- No signed business associate agreement with the people handling the systems that hold protected health information.
What is set up and maintained
- Technical safeguards that map to the HIPAA Security Rule: unique logins, access controls, audit logging, encryption at rest and in transit, and automatic logoff on shared workstations.
- A signed business associate agreement before any work touches systems holding patient data.
- Support for the clinical software you already run — Dentrix, Eaglesoft, Open Dental, athenahealth, eClinicalWorks and the imaging systems attached to them — including coordinating with those vendors on your behalf.
- Encrypted backup of imaging and practice data with restores tested quarterly, so a ransomware event is a bad afternoon rather than a closed practice.
- Encrypted email and secure file transfer that staff will actually use, plus training on the phishing that targets healthcare specifically.
- A written risk analysis and remediation plan — the document HIPAA expects you to have and most small practices do not.
Questions
Will you sign a business associate agreement?
Yes, before work begins on anything that touches protected health information. An IT provider with access to PHI is a business associate under HIPAA, and any provider unwilling to sign a BAA is telling you something important.
Does hiring you make my practice HIPAA compliant?
No, and be wary of anyone who says otherwise. HIPAA compliance covers administrative, physical and technical safeguards, and much of it is policy, training and documentation that belongs to the practice. I handle the technical safeguards and help produce the written risk analysis. The administrative side stays yours, and I will tell you plainly what is still missing.
Can you work with our existing software vendor?
Yes. Most practices have a clinical software vendor who supports the application but not the network, the workstations or the backups underneath it. That gap is where problems live. I handle the infrastructure and deal with your vendor directly so you are not relaying messages between two technical parties.
What happens if we get hit with ransomware?
With tested off-site backups you restore and keep seeing patients. Without them, practices face a genuinely awful choice. Ransomware affecting patient data also triggers HIPAA breach notification duties, which is why backup testing and access control are the first things I look at.
Request a free IT assessment
About an hour, on-site or remote. You get a written summary of what I found and what I would fix first — whether or not you hire me.