SeriousIT
Medical practices

Your clinic can't wait
for a callback.

Managed IT, HIPAA compliance, phones, and fiber for Utah clinics, specialty groups, and urgent care, from a team that keeps the EHR up, the devices segmented, and the evidence ready.

Two clinicians reviewing a scan on computer monitors
Exam room, chart up, nothing waiting
Every device has a row

The clinic is a network of things that cannot all be patched.

An EHR server, imaging workstations, an EKG cart, the lab analyzer, and a fax gateway that has not been updated since it was installed. The risk analysis starts with this list, and so does our work: what network each device lives on, who patches it, and what happens if it dies tonight.

DeviceNetworkPatchingBackupWhat we watch
EHR and practice management Clinical Monthly, planned window Nightly, restore-tested The whole clinic depends on it. Backups verified quarterly by restoring a chart.
Imaging workstations Isolated Vendor-approved only Studies replicated The vendor said not to touch it, so it gets its own network and a window the vendor agrees to.
EKG, spirometry, ultrasound carts Isolated Vendor-managed Config only Cannot run endpoint protection, so they cannot reach anything but the EHR interface.
Lab analyzer and interface PC Isolated Vendor-approved only Config only Results flow one way into the EHR. Nothing flows back.
Fax and e-fax gateway Isolated Replaced when unpatchable n/a Usually the oldest thing in the building and the most exposed. We replace it or wall it off.
Front desk, billing, admin PCs Office Weekly Cloud files MFA on every login, named accounts, no shared front-desk password.
Telehealth carts and tablets Clinical Weekly, managed n/a Managed devices only. Personal phones do not get the EHR app without a policy.
Office front desk, billing, admin Clinical EHR and exam rooms Isolated devices we cannot patch ourselves This register is the inventory a HIPAA risk analysis is built from. We keep it current and it becomes the first page of yours.
HIPAA, delivered

Compliance you can hand to an auditor.

We run the HIPAA program, not just the servers. Every element below is part of the service, kept current on a schedule, and written down where you can find it.

Every item is documented and evidence-backed, so an auditor, an insurer, or a patient gets a file, not a scramble.

What a covered clinic looks like
The HIPAA items we keep current for every medical client
  • Annual risk analysis current current
  • Business associate agreements tracked to renewal current
  • Workforce HIPAA training every hire, every year current
  • MFA on EHR, email, and remote access enforced current
  • Connected devices on their own network segmented current
  • EHR and imaging backup restore test scheduled scheduled
  • Breach response playbook rehearsed current
  • Cyber-insurance attestation ready current
Every line is documented and evidence-backed, so when an auditor, an insurer, or a patient asks, the answer is a file, not a scramble.
The HIPAA year, item by item
A year of the program, item by item. Dots are the months we act; bars run all year.
Annual risk analysis

The written assessment HIPAA requires, refreshed every year and after any big change.

Policies and procedures

A policy set tailored to the clinic, approved by the physician owner or administrator, acknowledged by staff.

Business associate agreements

Every vendor that touches PHI, billing company included, on file and tracked to renewal.

Workforce training

At hire and every year, with completion records and phishing tests that look like your payer portals.

Encrypted email and MFA

PHI encrypted in transit; multi-factor on the EHR, email, and every remote-access path.

Backups with tested restores

Immutable offsite copies of the EHR, imaging, and file servers, restore-tested on a schedule.

Breach response playbook

Who calls whom, what gets preserved, and the notification clock, rehearsed before you need it.

Cyber-insurance attestation

The MFA, backup, EDR, and training questions on your renewal, answered with evidence.

A clinic office with a desk and computer
Day one

Day one: what we usually find.

An inventory, not a pitch. These are the conditions we walk into at most clinics, in the order we find them.

  1. EHR downtime with no plan

    The EHR is the clinic. When it stops, the waiting room fills. Nobody has written down what happens next or tested a restore.

  2. Medical devices on the office network

    Ultrasound carts, EKGs, and lab analyzers running old Windows, reachable from the same network as the front desk and the guest Wi-Fi.

  3. Fax and scanning held together with hope

    Referrals and records still move by fax. The fax-to-email box is unmanaged and nobody knows where the PDFs land.

  4. Shared logins and no MFA

    A nurse station account everyone knows, remote access for the billing company with a password that never changed.

  5. IT that goes quiet during clinic hours

    Tickets answered after 5. Patients seen from 8.

  6. A HIPAA binder nobody can find

    Policies from the last consultant, a risk analysis from years ago, BAAs missing for the newest vendors.

AI, done right

Ambient scribes, patient chatbots, and the note someone pasted into ChatGPT.

Providers want the scribe. The front desk wants the chatbot to answer portal messages. Billing wants prior authorizations drafted. Each of those is a business associate handling PHI, and each needs a contract, a data boundary, and a person who signs the output.

Already happening on your network
  • An ambient scribe on a provider’s phone, trialed on a personal account
  • AI features switched on inside the EHR by the vendor
  • Portal-message and prior-auth drafting in a free chatbot
  • Staff summarizing referrals with whatever tool was open
Nobody meant to create a risk. They wanted the work done faster. The fix is a short list and a few settings, not a ban.
BAA, then data, in that order

Scribes, chatbots, and EHR copilots sign a business associate agreement and get reviewed like any other vendor before a single visit is recorded.

Scribes with a consent script

Patients hear that the visit is being recorded and why, and the recording lives where the BAA says, for as long as the policy says.

The provider signs the note

AI drafts the encounter, the provider reads and signs it. The chart shows what was generated and who approved it.

Approved tools, per role

Front desk, clinical, and billing each get a short list of tools that are allowed, with the rule for each, taught in the yearly HIPAA session.

Never leaves the building
  • PHI in free chatbots or personal accounts
  • Visit recordings on a personal phone
  • Referrals or labs pasted into unknown AI sites
  • Any AI vendor without a BAA

The AI use policy is written into the HIPAA program and reviewed in the annual risk analysis, so it never becomes its own project.

After go-live

What changes for the people in the building.

The front desk, the providers, and the administrator each feel it differently. This is what each of them gets.

Front desk

Check-in that does not stall.

  • The EHR and scheduling up when the doors open.
  • Phones and the nurse line routed to people who can answer.
  • Scans and faxes that land where they are supposed to.
Providers

The chart is there when you walk in.

  • EHR, imaging, and devices up in every exam room.
  • Secure access from home and from the hospital.
  • Telehealth that connects on the first try.
Administrator

Compliance you can show.

  • Risk analysis, training, and BAAs current and findable.
  • The billing company connected safely, with a named account.
  • One bill and one number to call.
The systems we live in

We already know your stack.

EHR and practice management, imaging and connected devices, and the office systems around them.

EHR and practice management
  • Cloud EHRs such as athenahealth, eClinicalWorks, NextGen, and Tebra
  • On-prem EHR servers while you need them
  • E-prescribing and patient portals
  • Billing-company remote access, done safely
Imaging and devices
  • DICOM imaging and PACS workstations
  • Ultrasound, EKG, and lab devices on their own network
  • Patched in vendor-approved windows
  • Backed up and inventoried
The rest of the clinic
  • Windows workstations in every exam room
  • Microsoft 365, fax-to-email, label and badge printers
  • Patient Wi-Fi kept off the clinical network
  • Telehealth that works on the first try

We prefer cloud EHR when it fits the practice, and we run and back up the on-prem server properly until you get there.

Which plan

Most clinics land on Hardened.

Same plans as every SeriousIT client, no medical surcharge. The compliance pack is what a clinic with patient data needs.

Hardenedmost common
The HIPAA program above, 24/7 detection and response, log retention, and the compliance evidence your insurer and auditor ask for.
Secured
Small single-provider offices that want the security baseline with EDR, email security, and tested backups, and handle their own HIPAA paperwork.
Managed
Rarely the right fit for a practice with patient data. We will tell you if it is.
Questions we get

Straight answers.

Do you support cloud EHRs, or just on-prem?

Both. We prefer cloud EHR when it fits the practice, and we run and back up the on-prem server properly until then.

Can you do our HIPAA risk analysis?

Yes. The annual risk analysis, the policy set, workforce training, BAAs, and the breach playbook are part of the Hardened plan, kept current on a schedule.

What about medical devices the vendor will not let us patch?

We put them on their own network, patch in the window the vendor agrees to, and back them up. An unpatched device on the same network as the EHR is the most common way we see clinics get hit.

Our billing company needs remote access. Is that safe?

It can be. Named accounts, MFA, access limited to what they need, and a BAA on file. We set it up and review it.

Will you be reachable during clinic hours?

That is the point. Business-hours support with real response times, and no after-hours or per-ticket surcharges on any plan.

Do you work with multi-site groups?

Yes. Standardized builds per location, one help desk, and compliance evidence rolled up across sites.

A clinician working at two medical monitors

Start with a HIPAA gap check.

Send us your current bills and your last risk analysis, if you have one. We come back with what is exposed, what it would take to fix, and what consolidating would cost.