Compliance — Healthcare
HIPAA IT support for New York practices
HIPAA sets the floor. New York adds the SHIELD Act, and hospital systems now push their own cybersecurity requirements down to every affiliated practice. We run the safeguards — and keep the evidence — for practices below hospital scale.
Three layers of obligation
A New York practice does not answer to HIPAA alone. Three layers stack, and the newest one arrives through your inbox rather than the Federal Register.
| Layer | What it requires of your IT |
|---|---|
| HIPAA Security Rule | A documented risk analysis, administrative, physical, and technical safeguards for ePHI, and business associate agreements with every vendor that touches it |
| NY SHIELD Act | Reasonable safeguards for the private information of New York residents, plus state breach-notification duties that apply alongside HIPAA — and that reach data HIPAA does not, such as employee records |
| 10 NYCRR 405.46 | New York’s hospital cybersecurity regulation: effective October 2, 2024, full program compliance due October 2, 2025, with 72-hour incident reporting. It binds general hospitals directly — and reaches affiliated practices and vendors through the security requirements hospitals now impose |
That last row matters even if you will never operate a hospital. The 405.46 program deadline has passed, which means every Article 28 hospital in the state now has a cybersecurity program that must account for the practices it affiliates with, refers to, and shares systems with. The security questionnaire from your hospital system is not a formality — it is their compliance obligation landing on your desk. More on the vertical at healthcare.
Risk analysis first
The Security Rule’s risk analysis is the document OCR asks about first in nearly every investigation, and the one most practices hold as a template nobody has read. A real risk analysis is three things: an inventory of where ePHI actually lives, an honest accounting of the threats to it, and a prioritized management plan someone executes. We produce all three in writing — and then we operate the plan, which is the part the template never covered.
What we operate for HIPAA
Safeguards run daily and evidenced continuously — because an unexecuted policy is a finding, not a defense.
Risk analysis and management plan
Performed against your actual environment, revisited on a schedule, with remediation tracked to closure.
Access control and workforce lifecycle
Unique credentials, role-based access, and same-day offboarding, handled through managed IT so it happens every time.
Encryption
ePHI encrypted at rest and in transit — including the laptops that leave the building, which is where breach reports are born.
Email security
Phishing is the leading path into a practice; email security and filtering close it down.
Backup and recovery
The contingency-planning requirement, met with tested restores rather than assumptions — see business continuity.
Audit logging and monitoring
Activity on systems holding ePHI is monitored around the clock by our tooling, with escalation to an engineer.
BAA inventory and vendor oversight
A current record of every business associate, what they touch, and whether an agreement is actually in place.
Training and phishing simulation
Workforce security awareness training with completion records you can produce on request.
Breach readiness
A written incident response plan covering HIPAA’s notification duties and SHIELD’s New York obligations, rehearsed before it is needed.
Built for the practice, not the hospital
Hospital-grade security programs assume a CISO, a compliance office, and a budget line. A four-provider practice with twenty staff needs the same controls at an operable scale: one accountable team running identity, endpoints, email, backups, and evidence, priced per user. That is the engagement we designed. Practices inside PE-backed or MSO groups often face SOC 2-style diligence on top — the overlap with SOC 2 readiness works in your favor.
We prepare and operate safeguards; we are not a law firm or an auditor. Privacy Rule questions, breach determinations, and OCR responses belong with your counsel or compliance consultant — what we give them is a technical environment, and an evidence file, that holds up. Where we handle ePHI, we sign a business associate agreement, because the rule we help you follow applies to us too. Other regimes live at the compliance hub.
Good fit if
Independent or group practice — medical, dental, behavioral health
A hospital system’s security questionnaire just arrived
The EHR vendor manages the application and nobody manages the rest
Your last risk analysis was a purchased template
Your cyber insurer is asking about MFA, EDR, and backups
Common questions
Our EHR is cloud-hosted. Doesn't the vendor handle HIPAA?
The vendor secures their application and signs a BAA for their side. Your endpoints, identities, email, network, staff, and every other system that touches ePHI remain your responsibility — and that is where most practice breaches actually start. Responsibility is shared; the fines are not sent to the vendor.
We comply with HIPAA. Why does the SHIELD Act matter?
SHIELD treats HIPAA compliance as satisfying its safeguard requirement for the data HIPAA covers — but it reaches private information HIPAA does not, such as employee records, and it adds New York notification duties. It broadens your obligations rather than duplicating them.
A hospital system sent us a security questionnaire. Is that normal now?
Yes. Since 10 NYCRR 405.46’s program deadline passed in October 2025, hospitals must account for the security of affiliated practices and vendors, and questionnaires are how they do it. We answer them with you — accurately, with evidence attached, and with a remediation plan for anything we cannot yet answer well.
What does HIPAA IT support include that regular IT support doesn't?
The safeguards themselves overlap with good IT practice; the difference is documentation and evidence — risk analysis, BAA inventory, logging, training records, and breach readiness mapped to the rule. If your current provider cannot hand you those artifacts today, you have IT support, not HIPAA IT support.
Run a practice that can show its work.
A HIPAA security assessment maps your safeguards, your gaps, and your BAA exposure — you keep the findings either way.