FAQs




HEALTHCARE FAQ

Frequently asked questions tailored for healthcare clients, including HIPAA compliance considerations, PHI protection, and clinical continuity.

Signs include unusual system behavior, unexpected account lockouts, staff receiving strange emails, or patients reporting suspicious contact. Under HIPAA, you are required to report a confirmed breach within 72 hours of discovery. If you suspect anything, contact your IT provider immediately — do not investigate on your own.

Yes. HIPAA's Security Rule requires layered technical safeguards — not just antivirus. That includes endpoint detection, encrypted communications, access controls, and audit logging. Antivirus alone does not satisfy your compliance obligations.

HIPAA does not explicitly mandate MFA by name, but it requires access controls and authentication measures that reasonably protect PHI. MFA is the industry-accepted standard for meeting that requirement and is what we enforce on all systems handling patient data.

Only if those devices are enrolled in your Mobile Device Management (MDM) platform, encrypted, and governed by your HIPAA security policies. Unmanaged personal devices accessing PHI is a compliance violation and a significant liability.

Every 3–5 years. Older hardware may not support current encryption standards or receive operating system security patches — both of which are HIPAA requirements. We track your hardware lifecycle and flag devices before they become a compliance risk.

Microsoft 365 can be configured to support HIPAA compliance, but out of the box it is not. A Business Associate Agreement (BAA) must be signed with Microsoft, and specific security settings must be enabled and maintained. We handle this as part of your managed environment.

Yes, but only within a properly configured and BAA-covered Microsoft 365 environment. Files must be encrypted, access must be role-based, and sharing settings must be locked down. We configure and audit this for you.

Yes. The HIPAA Security Rule explicitly requires a data backup plan as part of your contingency planning. Backups must be encrypted, tested regularly, and stored in a way that allows timely recovery in the event of a disaster or system failure.

Your business continuity plan should include a documented downtime procedure — a manual or offline process for continuing patient care when your EHR is unavailable. We work with your team to ensure your backup and recovery strategy supports your clinical workflow, not just your data.

Yes. As a vendor with access to systems that may contain PHI, we are required to sign a BAA with every healthcare client. This is a non-negotiable part of our engagement and is in place before we touch any system.

We follow a defined incident response process — contain the threat, preserve evidence, assess scope, and notify your leadership immediately so your HIPAA Privacy Officer can initiate the required breach notification process. We do not communicate breach details to patients or regulators — that is your organization's responsibility with our full support.