
Healthcare
Healthcare IT and security, built around HIPAA reality.
What we see
What we see in healthcare.
- 01
HIPAA risk lives in the workflow, not the policy binder
Most HIPAA gaps we find are operational — shared logins, unencrypted USB drives, EHR sessions left open, stale offboarding. We close those at the workstation and identity layers, not just in a policy PDF. - 02
EHR + cyber stack rarely speak to each other
Your EHR vendor handles the application. Your MSP handles workstations. Neither owns the seam — so a credential-theft incident becomes a 2-vendor incident-response ticket. We own the seam. - 03
Email and identity are where clinic breaches start
Phishing and business email compromise hit scheduling, billing, and provider mailboxes hard. We harden M365/Google email, layer Huntress ITDR, and train staff — see /email-security — instead of hoping the EHR vendor covers it. - 04
Cameras + doors disconnected from clinical access
Patient privacy is a HIPAA control. Door access logs and camera footage need to be reviewable when an incident is investigated — and they almost never are. Waiting rooms and counseling suites need privacy-aware placement, not generic retail CCTV.
Frameworks & regulatory context.
- 01HIPAA Security RuleAdministrative, physical, and technical safeguards mapped to operational controls. Risk analysis, access management, audit logging, encryption, contingency planning.Reference
- 02NIST Cybersecurity FrameworkWe use NIST CSF as the umbrella framework so HIPAA controls fit into broader cybersecurity strategy rather than living in isolation.Reference
- 03Huntress Managed SIEMLog correlation across endpoints, identity, and access control with compliance reporting an auditor accepts.Reference
What we deploy for healthcare.
- 01Cybersecurity (Huntress)Huntress Managed EDR, ITDR, SIEM, SAT with 24/7 SOC. HIPAA aligned controls.Open
- 02Email SecurityBEC/phishing defense for clinic mailboxes — M365/Google hardening + Huntress ITDR/SAT.Open
- 03Managed ITEndpoint monitoring, M365 + Google Workspace, EHR workstation support.Open
- 04Access ControlVerkada door controllers with identity sync and HIPAA-friendly audit logging.Open
- 05Video SurveillancePatient-privacy-aware camera coverage with retention sized to HIPAA risk.Open
- 06Physical Security AssessmentsFacility walkthrough before camera spend — privacy-aware for clinical spaces.Open
- 07Security Risk AssessmentsNIST CSF-mapped identity, email, endpoint, and backup gaps — not a HIPAA stamp.Open
- 08vCISOHIPAA risk analysis, breach prep, OCR audit support, board-ready reporting.Open
- 09Backup & DRImage-based BCDR and SaaS protection sized to the HIPAA Security Rule data backup requirement. Tested restores. Vendor-neutral.Open
Sub-verticals
Sub-verticals under Healthcare.
Tier 1
Dental Offices
HIPAA-aligned dental IT in Lincoln & Omaha: imaging, BEC defense, Huntress or Guardz, after-hours cameras. BAA standard. 531-625-2111.
Tier 1
Primary Care & Family Practice
HIPAA-aligned primary care IT in Lincoln & Omaha: EHR environment, BAA, Huntress or Guardz, clinic access. 531-625-2111.
Tier 1
Specialty Clinics
HIPAA-aligned specialty clinic IT in Lincoln & Omaha: imaging-heavy practices, BAA, Huntress or Guardz, segmented networks. 531-625-2111.
Tier 2
Senior Living
HIPAA-aligned IT for nursing homes and assisted living in Lincoln & Omaha: segmented networks, BEC defense, privacy-aware cameras. 531-625-2111.
Tier 2
Behavioral Health
HIPAA-aligned IT for psychology and therapy practices in Lincoln & Omaha. Privacy-aware cameras, BAA, Huntress or Guardz. 531-625-2111.
Tier 2
Chiropractic
HIPAA-aligned IT for chiropractic clinics in Lincoln & Omaha: M365/Google, EDR, front-door logging, BAA. 531-625-2111.
Healthcare FAQ
Do you sign a Business Associate Agreement?+
Do you work with psychology and therapy practices?+
Can you support our EHR (Athena, Practice Fusion, Epic, eClinicalWorks, etc.)?+
What about after-hours support for clinics?+
Have you handled HIPAA breach scenarios?+
Do you work with dental, chiropractic, and senior living — not just hospitals?+
Do you staff healthcare IT security, or run it as a managed service?+
Healthcare in Lincoln vs Omaha
Lincoln, NE
Lincoln, NE hubIndependent Lincoln clinics — Bryan- and CHI St. Elizabeth-adjacent.
Haymarket and south-Lincoln therapy, dental, chiro, and small senior-living campuses need HIPAA-aligned email, MFA, backups, and privacy-aware cameras — with a BAA. ~15–20 minutes from Hickman. Not a hospital IT department and not a Lincoln clinic storefront.
Omaha, NE
Omaha, NE hubOmaha independent practices in the shadow of hospital systems.
Nebraska Medicine, CHI, and Methodist set clinical gravity; SAINT-fit buyers are independent groups in Aksarben, West Omaha, and Bellevue. Same HIPAA-aligned stack; scheduled on-site. Never “HIPAA certified MSP.”
Related
Keep going.
Written for operators by Colton Porter, Founder & CEO of SAINT Technology Services — U.S. Army veteran. Hickman-based; Lincoln first, Omaha second · Healthcare IT & security.
Call 531-625-2111 or email clientcare@saintsecured.com. Book an assessment at /contact.
Free risk assessment
Run the free HIPAA-overlay risk assessment — scored against the Security Rule controls clinics actually get asked about.
Start the ~4-minute assessment →Bring SAINT to your healthcare environment.
30 minutes. NIST-aligned report. No obligation.
