All insights
Security

What HIPAA-aligned IT actually looks like in practice

Jun 22, 2026 · 8 min read · ClinicOps team

'Are we HIPAA compliant?' is the wrong question — HIPAA doesn't certify IT setups, and no tool can make you compliant by itself. The right question is: if an auditor or a breach investigator looked at our systems tomorrow, could we show reasonable safeguards? Here's what that looks like concretely for a small-to-mid practice.

Access control that maps to job roles

Every workforce member gets a unique account (no shared front-desk logins), access is granted by role, and there's a documented process for granting and — critically — revoking it. The Security Rule calls this workforce clearance and access termination; in practice it means role-based groups in Microsoft 365 and an offboarding procedure that runs the same day someone leaves.

MFA everywhere, no exceptions that outlive their reason

Compromised credentials are the leading breach vector in healthcare. Multi-factor authentication on every account — including part-timers, contractors, and that one legacy billing login — is the single highest-value control. Track coverage as a number (we target 95%+) and review exceptions monthly.

Encryption at rest and in transit

Every laptop and desktop encrypted (BitLocker via Intune), TLS on everything, and no PHI in personal email or consumer file sharing. Encryption is technically 'addressable' under HIPAA, but if an unencrypted laptop with PHI is stolen, it's a reportable breach; if it was encrypted, it generally isn't. That asymmetry decides it.

An audit trail someone can actually produce

When something goes wrong, you'll be asked who accessed what, when. That means unified audit logging turned on in M365, EHR access logs retained, and IT changes (access grants, offboarding, security changes) recorded somewhere you can export. 'We think we disabled it' is not an answer an investigator accepts.

Backups you have restored at least once

Ransomware turns backup policy into existential fact. You need automatic backups of practice data, at least one copy the attacker can't encrypt (offline or immutable), and a restore you've actually rehearsed. A backup that has never been test-restored is a hope, not a control.

The documentation layer

A current risk assessment, written policies that match reality, BAAs with every vendor touching PHI (including your IT provider), and security awareness training with attendance records. This is the part auditors read first — and the part busy practices skip.

ClinicOps runs these controls as a managed service — MFA and device-compliance scoring, automated offboarding with audit trail, and a BAA as standard. Our portal shows your posture as a live score, not a binder on a shelf.

Want this handled for your practice?

Book a free 30-minute IT assessment — you keep the 30/60/90-day roadmap either way.