Small clinics search HIPAA IT requirements when a biller asked about a BAA, a cyber-insurance form used the word “ePHI,” or a therapist left and still had the EHR password. What they are often sold is a binder, a “HIPAA-compliant email” sticker, or an MSP that says they are certified.
Plain language: no vendor is meaningfully “HIPAA certified” the way that phrase gets sold. The HIPAA Security Rule asks you to implement safeguards that fit your risk, document them, and manage vendors who can touch electronic protected health information. OCR and your auditor decide outcomes. SAINT implements aligned controls and evidence. We do not guarantee compliance, pass an audit, or survive a breach notice for you.
This checklist is for independent clinics — therapy and psychology, dental, chiropractic, small medical groups — in Lincoln, Omaha, and the Midwest. Vertical pages: healthcare, behavioral health, dental. Sibling context: chiropractic, senior living.
Primary next step: Get Your Free Security & IT Assessment. Bring the questionnaire or the last risk analysis if you have one. Or call 531-625-2111.
What does the Security Rule actually expect from a small clinic’s IT?
HHS describes administrative, physical, and technical safeguards. In an eight-chair office that usually translates to:
- Who can log in, and whether you can take that access away the day someone leaves.
- Whether email and laptops that carry referral notes and superbills are treated as clinical-operations risk, not “just IT.”
- Whether you can restore scheduling and imaging if ransomware or a dead server shows up on a Monday.
- Whether vendors who can see ePHI have a Business Associate Agreement when one is required.
- Whether cameras and doors help you investigate an incident without recording a counseling room by default.
You do not need a hospital CISO. You do need owners, evidence, and a stack someone can operate. NIST CSF is a useful umbrella so HIPAA controls are not a binder that never meets the tenant. We will not pretend a checklist in a blog post is your required risk analysis.
How should identity and access work on day one of the checklist?
Start here. Most clinic findings we see are operational, not exotic:
- Unique logins. Shared “front desk” passwords for EHR, imaging, or the shared mailbox are a finding waiting for a screenshot.
- MFA on email, EHR portals, and any remote access. A password-only VPN into the office is a ransomware door.
- Role-based access so a scheduler does not have global admin in Microsoft 365 “because it was easier.”
- Offboarding the day an associate, temp, or 1099 leaves — email, EHR, VPN, and door fobs. Therapy practices feel this when contractors rotate; dental offices feel it when a biller changes.
- A break-glass admin path that is enrolled in MFA and stored like it matters.
Identity is also where email security and clinic operations collide. Referral notes still ride mail. Business email compromise against a biller looks like a changed bank account on an EOB thread.
What email and endpoint controls map to HIPAA without a fake “certified email” product?
There is no magic HIPAA-certified inbox. There is MFA, forwarding-rule audits, external sender tags, anti-phishing policy, DMARC progress when DNS is ready, and a written first-hour path if someone clicks — phishing playbook. Huntress or Guardz identity detection sits on top so a phished password is not the end of the story. Pick Huntress or Guardz, not both as theater.
Endpoints: patch and monitor the PCs the imaging or EHR vendor “did not want touched,” with a change window. Unsupported Windows on an extraoral-imaging box is still your risk. USB drives in a drawer are still a control conversation. Personal laptops used for telehealth need the same MFA and monitoring story as the front desk — a consumer VPN is not a Security Rule program.
SAINT supports the operating environment around the EHR. Application support stays with that vendor. We will not invent endorsements for Athena, Open Dental, or anyone else we have not scoped in your engagement.
What does contingency planning mean when you are not a hospital?
The Security Rule’s contingency themes are the unglamorous ones: data backup, disaster recovery, and emergency-mode operation sized to your clinic. In practice:
- Image-based backup of the workstations and servers that actually hold schedules, images, and practice-management data.
- SaaS protection for Microsoft 365 or Google Workspace — “it’s in the cloud” is not a restore test.
- Offsite / separated copies. A NAS on the same domain the attacker just phished is not a contingency plan.
- A restore you have run, with a date. Carriers ask this too — 12 insurance controls.
Catalog planning for SAINT backup & DR starts from $12 per user per month with storage billed separately — planning, not checkout. Service: backup & disaster recovery.
Document who you call if the EHR is up but the internet is down, and who you call if it might be compromise instead of an outage. 531-625-2111 is our after-hours path for outages and suspected compromise. Standard tickets follow the 15-minute business-hours target.
How do vendors, BAAs, and “the other company’s computer” fit?
If a vendor can create, receive, maintain, or transmit ePHI for you, you need a Business Associate Agreement when HIPAA requires one. SAINT signs a BAA before PHI-adjacent work. That is standard practice, not a marketing badge.
Also inventory: the copier that scans to email, the offsite transcription service, the IT cousin who still has a global admin, the camera cloud that stores footage of a waiting room. Physical safeguards are part of the same story. Waiting rooms and entries often need coverage; therapy rooms usually do not. Assess before you buy — physical security assessments. Dental operatories and counseling suites are privacy decisions, not a default NVR package.
We are not your OCR attorney and not your survey consultant.
What does a practical clinic checklist look like in one pass?
Use this as an operations punch list, not as a certification:
- Unique identities + MFA on email, EHR, and remote access.
- Offboarding checklist that includes doors.
- Mailbox rules / forwarding audit; BEC path documented.
- EDR (Huntress or Guardz) on clinic workstations, including imaging PCs you are allowed to touch.
- Patch cadence with a window the clinical vendor will accept.
- Backup + a restore test dated in the last 90 days.
- BAA inventory for IT, cloud, and any vendor who can see ePHI.
- Network segmentation: guest Wi-Fi, PCI if you take cards, cameras, and clinical devices are not one flat LAN.
- Privacy-aware camera and door placement.
- Written incident contacts — MSP/SOC, EHR vendor, counsel, carrier — without waiting to invent them during an incident.
- A risk analysis you own. We can help you gather technical evidence. We will not sell you a stamped “compliant” outcome.
Lincoln independent clinics (Haymarket, south Lincoln, Bryan- and CHI St. Elizabeth-adjacent) are a 15–20 minute drive from Hickman. Omaha independent groups in Aksarben, West Omaha, and Bellevue sit in the shadow of hospital systems — same stack, scheduled on-site, never a “HIPAA certified MSP” claim. No storefront.
Therapy-specific depth: HIPAA IT for therapy practices. Dental: HIPAA IT for dental offices and /industries/dental. Secure email across clinic types: secure email for clinics.
If a cyber-insurance renewal is what forced the checklist, do not stop at HIPAA language. Carriers still want the twelve evidencable controls — MFA, EDR, tested backups, SAT — on /tools/insurability. A BAA does not replace an EDR console. An EDR console does not replace a BAA.
Get a clinic-sized plan in writing. Free Security & IT Assessment · 531-625-2111 · healthcare. Alignment and evidence — not a guarantee.


