Skip to content

For Anchorage medical, dental & legal practices

The compliance you sign for starts with the IT underneath.

HIPAA does not certify software; it asks your practice to protect patient data with reasonable safeguards and to document that you did. We build and run the IT side: the technical safeguards, the backups, the logging, and the records that hold up.

HIPAA Security Rule

Three safeguard categories

Administrative

Risk assessment, policies, workforce training, a named security contact.

Physical

Device control, workstation security, encrypted media, safe disposal.

Technical

Access controls, MFA, encryption, audit logging, tested backups.

We implement the technical safeguards and document all three. We do not issue HIPAA certifications, no IT company can.

What HIPAA actually requires of a small practice

HIPAA's Security Rule is not a checklist you buy. It asks covered entities, the dentist's office, the clinic, the therapy practice, to put in place administrative, physical, and technical safeguards appropriate to their size and risk, and to keep documentation proving they did. Most small Anchorage practices are far closer to compliant than they fear on the policy side, and farther than they think on the technical side.

The technical safeguards, the part that lives in your IT, are where we work: access controls, encryption, audit logging, malware protection, and contingency planning. The gaps we find most often are not exotic: no enforced MFA, laptops that were never encrypted, backups nobody has tested, and a missing Business Associate Agreement with a vendor.

The technical safeguards we implement

The six technical controls HIPAA's Security Rule expects.

Access controls

Unique logins per person, MFA on everything that touches patient data, role-based access so the front desk cannot open clinical records they do not need, and same-day account disabling when someone leaves.

Encryption, at rest and in transit

Full-disk encryption on every laptop and workstation (BitLocker, FileVault), encrypted email for anything containing PHI, and TLS on every connection. A lost-but-encrypted laptop is not a reportable breach.

Audit logging

Sign-in and access logging in Microsoft 365 or Google Workspace and in your practice management system, retained and reviewable, so you can answer "who accessed what, and when" if you ever have to.

Backup and contingency

Tested, encrypted, isolated backups of patient records, plus a written contingency plan so an outage or ransomware event does not become a patient-safety or reporting problem.

Malware and threat protection

Modern endpoint detection (Huntress EDR), email filtering, and patch management, because the most common cause of a HIPAA breach at a small practice is a phished account or ransomware, not a hacker.

Workforce safeguards

Security awareness training so your team can spot the phishing email that targets a clinic, plus documented policies for devices, passwords, and remote access.

What working with us covers

The IT half of HIPAA, handled.

We are your IT and security partner for the technical and documentation requirements. For clinical compliance, legal review, or formal certification, we coordinate with the right specialists.

Security risk assessment

A documented review of where PHI lives and how it is protected, the assessment HIPAA expects you to perform and keep current.

Business Associate Agreement

As your IT provider with potential access to systems holding PHI, we sign a BAA with you, and we help you confirm your other vendors have signed theirs.

Technical safeguards, implemented

MFA, encryption, EDR, logging, and tested backups configured and verified, not just recommended.

Documentation you can show

Policies, configurations, and assessment records kept current, because in HIPAA, if it is not documented, it did not happen.

An honest word on what we are, and aren't

We help you meet HIPAA's technical requirements. We do not certify HIPAA compliance, because no IT company truthfully can: HIPAA has no government certification, and compliance is a practice-wide responsibility that includes clinical, legal, and administrative pieces well outside IT. Anyone selling you a "HIPAA certified" guarantee is overstating it. What we deliver is real and documentable: the technical safeguards implemented and verified, a current risk assessment, a signed BAA, and the records to show your good-faith effort. For formal compliance attestation or legal sign-off, we will point you to a qualified partner.

Built for these practices

See where your practice stands.

The free 30-minute IT Health Check includes a look at the HIPAA technical safeguards: whether MFA is enforced, whether devices are encrypted, and whether your backups would actually restore. Real findings, no sales pitch.