
Practices do not get targeted. They get found, by automated scanners sweeping the whole internet looking for something unpatched. Very little of what follows is exotic, and almost all of it is preventable.
A business firewall, configured for your practice rather than left on defaults, with remote access limited to the people who need it. The router your internet provider supplies handles connectivity, so we put a proper firewall in front of it.
Guest Wi-Fi lives on its own network, separate from the one your practice management software runs on. So does anything a vendor plugs in. A patient in the waiting room and the machine holding patient records should never be on the same segment.
Endpoint protection on every workstation and server, monitored centrally so an alert reaches a person who can act on it. Operating systems and applications get patched on a schedule, because most of what gets exploited in a small office already had a fix available months earlier.
Machines that can no longer receive security updates get replaced or taken off the network. There is no configuration that makes an unsupported system safe to leave sitting on a network with patient data on it.
Most incidents in a practice start with somebody clicking something in an email or reusing a password. Multi-factor authentication on email and remote access removes a large part of that risk on its own, so we set it up first.
Prevention is only half of security work. If something does get through, what counts is how fast you can get back to a clean copy of your data and how sure you are that the copy is clean. That is why backup belongs in this conversation.
The technical safeguards HIPAA asks about are largely the same things listed above, documented. Doing the work first and writing it down second is easier than the other way around, and it holds up better if anyone ever asks.
We are based in Katy and support dental, medical, optometry, and veterinary practices across greater Houston and southeast Texas.