What a small clinic should know about technology before it buys a “HIPAA package”
A plain account of the technology decisions behind privacy in a dental or medical office. Not legal advice, and not a certificate.
A package is not a practice
Clinics are sold bundles that say the regulation’s name on the slide and then install a firewall, a backup, and a password rule. Some of that is useful. None of it answers who at the front desk can open a chart, where images are copied, or what happens when a doctor forwards a record from a personal phone.
This note is not legal advice and it is not an audit. It is the technology half of the question, which is the half a fractional CTO can actually see.
The decisions that matter more than the brochure
- Who sees what. Shared logins feel efficient at 8 a.m. They also make it impossible to say who looked at a record.
- Where copies go. Imaging PCs, thumb drives, email forwards, and the laptop in a car are the usual leaks. The chart system can be perfect and still not be the only copy.
- Which vendors touch patient information. The list on the agreement and the list on the credit-card statement should be the same list.
- Whether you can get the data back. A backup that has never been restored is a hope. Ask for the date of the last test, not the date of the last successful copy.
- What the insurance form will claim. If you will have to attest to encryption, unique logins, or a named privacy officer, write down what is true today. Do it before the form is due.
What to do with this
If the answers are fuzzy, do not start by replacing the practice-management system the staff know. Start by naming an owner for the decisions above and writing the current state in a page or two. That page is what the clinic Operating Brief is for.