We follow a defined incident response process — contain the threat, preserve evidence, assess scope, and notify your leadership immediately so your HIPAA Privacy Officer can initiate the required breach notification process. We do not communicate breach details to patients or regulators — that is your organization's responsibility with our full support.
Working with RAM-Tech — How do you handle a suspected HIPAA breach on our behalf?
Working with RAM-Tech — Does RAM-Tech sign a Business Associate Agreement (BAA)?
Yes. As a vendor with access to systems that may contain PHI, we are required to sign a BAA with every healthcare client. This is a non-negotiable part of our engagement and is in place before we touch any system.
Backup & Recovery — What happens if our EHR system goes down?
Your business continuity plan should include a documented downtime procedure — a manual or offline process for continuing patient care when your EHR is unavailable. We work with your team to ensure your backup and recovery strategy supports your clinical workflow, not just your data.
Backup & Recovery — Does HIPAA require us to back up our data?
Yes. The HIPAA Security Rule explicitly requires a data backup plan as part of your contingency planning. Backups must be encrypted, tested regularly, and stored in a way that allows timely recovery in the event of a disaster or system failure.
Cloud & M365 — Can we store patient records in OneDrive or SharePoint?
Yes, but only within a properly configured and BAA-covered Microsoft 365 environment. Files must be encrypted, access must be role-based, and sharing settings must be locked down. We configure and audit this for you.
Cloud & M365 — Is Microsoft 365 HIPAA compliant?
Microsoft 365 can be configured to support HIPAA compliance, but out of the box it is not. A Business Associate Agreement (BAA) must be signed with Microsoft, and specific security settings must be enabled and maintained. We handle this as part of your managed environment.
General IT — How often should we replace our clinical workstations?
Every 3–5 years. Older hardware may not support current encryption standards or receive operating system security patches — both of which are HIPAA requirements. We track your hardware lifecycle and flag devices before they become a compliance risk.
General IT — Can staff access patient records from personal devices?
Only if those devices are enrolled in your Mobile Device Management (MDM) platform, encrypted, and governed by your HIPAA security policies. Unmanaged personal devices accessing PHI is a compliance violation and a significant liability.
Security — Is MFA required under HIPAA?
HIPAA does not explicitly mandate MFA by name, but it requires access controls and authentication measures that reasonably protect PHI. MFA is the industry-accepted standard for meeting that requirement and is what we enforce on all systems handling patient data.
Security — Do we need more than antivirus to protect patient data?
Yes. HIPAA's Security Rule requires layered technical safeguards — not just antivirus. That includes endpoint detection, encrypted communications, access controls, and audit logging. Antivirus alone does not satisfy your compliance obligations.
- 1
- 2
