Your clinic can't wait
for a callback.
Managed IT, HIPAA compliance, phones, and fiber for Utah clinics, specialty groups, and urgent care, from a team that keeps the EHR up, the devices segmented, and the evidence ready.
The clinic is a network of things that cannot all be patched.
An EHR server, imaging workstations, an EKG cart, the lab analyzer, and a fax gateway that has not been updated since it was installed. The risk analysis starts with this list, and so does our work: what network each device lives on, who patches it, and what happens if it dies tonight.
| Device | Network | Patching | Backup | What we watch |
|---|---|---|---|---|
| EHR and practice management | Clinical | Monthly, planned window | Nightly, restore-tested | The whole clinic depends on it. Backups verified quarterly by restoring a chart. |
| Imaging workstations | Isolated | Vendor-approved only | Studies replicated | The vendor said not to touch it, so it gets its own network and a window the vendor agrees to. |
| EKG, spirometry, ultrasound carts | Isolated | Vendor-managed | Config only | Cannot run endpoint protection, so they cannot reach anything but the EHR interface. |
| Lab analyzer and interface PC | Isolated | Vendor-approved only | Config only | Results flow one way into the EHR. Nothing flows back. |
| Fax and e-fax gateway | Isolated | Replaced when unpatchable | n/a | Usually the oldest thing in the building and the most exposed. We replace it or wall it off. |
| Front desk, billing, admin PCs | Office | Weekly | Cloud files | MFA on every login, named accounts, no shared front-desk password. |
| Telehealth carts and tablets | Clinical | Weekly, managed | n/a | Managed devices only. Personal phones do not get the EHR app without a policy. |
Compliance you can hand to an auditor.
We run the HIPAA program, not just the servers. Every element below is part of the service, kept current on a schedule, and written down where you can find it.
Every item is documented and evidence-backed, so an auditor, an insurer, or a patient gets a file, not a scramble.
- Annual risk analysis current current
- Business associate agreements tracked to renewal current
- Workforce HIPAA training every hire, every year current
- MFA on EHR, email, and remote access enforced current
- Connected devices on their own network segmented current
- EHR and imaging backup restore test scheduled scheduled
- Breach response playbook rehearsed current
- Cyber-insurance attestation ready current
The written assessment HIPAA requires, refreshed every year and after any big change.
A policy set tailored to the clinic, approved by the physician owner or administrator, acknowledged by staff.
Every vendor that touches PHI, billing company included, on file and tracked to renewal.
At hire and every year, with completion records and phishing tests that look like your payer portals.
PHI encrypted in transit; multi-factor on the EHR, email, and every remote-access path.
Immutable offsite copies of the EHR, imaging, and file servers, restore-tested on a schedule.
Who calls whom, what gets preserved, and the notification clock, rehearsed before you need it.
The MFA, backup, EDR, and training questions on your renewal, answered with evidence.
Day one: what we usually find.
An inventory, not a pitch. These are the conditions we walk into at most clinics, in the order we find them.
- EHR downtime with no plan
The EHR is the clinic. When it stops, the waiting room fills. Nobody has written down what happens next or tested a restore.
- Medical devices on the office network
Ultrasound carts, EKGs, and lab analyzers running old Windows, reachable from the same network as the front desk and the guest Wi-Fi.
- Fax and scanning held together with hope
Referrals and records still move by fax. The fax-to-email box is unmanaged and nobody knows where the PDFs land.
- Shared logins and no MFA
A nurse station account everyone knows, remote access for the billing company with a password that never changed.
- IT that goes quiet during clinic hours
Tickets answered after 5. Patients seen from 8.
- A HIPAA binder nobody can find
Policies from the last consultant, a risk analysis from years ago, BAAs missing for the newest vendors.
Ambient scribes, patient chatbots, and the note someone pasted into ChatGPT.
Providers want the scribe. The front desk wants the chatbot to answer portal messages. Billing wants prior authorizations drafted. Each of those is a business associate handling PHI, and each needs a contract, a data boundary, and a person who signs the output.
- An ambient scribe on a provider’s phone, trialed on a personal account
- AI features switched on inside the EHR by the vendor
- Portal-message and prior-auth drafting in a free chatbot
- Staff summarizing referrals with whatever tool was open
Scribes, chatbots, and EHR copilots sign a business associate agreement and get reviewed like any other vendor before a single visit is recorded.
Patients hear that the visit is being recorded and why, and the recording lives where the BAA says, for as long as the policy says.
AI drafts the encounter, the provider reads and signs it. The chart shows what was generated and who approved it.
Front desk, clinical, and billing each get a short list of tools that are allowed, with the rule for each, taught in the yearly HIPAA session.
- PHI in free chatbots or personal accounts
- Visit recordings on a personal phone
- Referrals or labs pasted into unknown AI sites
- Any AI vendor without a BAA
The AI use policy is written into the HIPAA program and reviewed in the annual risk analysis, so it never becomes its own project.
What changes for the people in the building.
The front desk, the providers, and the administrator each feel it differently. This is what each of them gets.
Check-in that does not stall.
- The EHR and scheduling up when the doors open.
- Phones and the nurse line routed to people who can answer.
- Scans and faxes that land where they are supposed to.
The chart is there when you walk in.
- EHR, imaging, and devices up in every exam room.
- Secure access from home and from the hospital.
- Telehealth that connects on the first try.
Compliance you can show.
- Risk analysis, training, and BAAs current and findable.
- The billing company connected safely, with a named account.
- One bill and one number to call.
We already know your stack.
EHR and practice management, imaging and connected devices, and the office systems around them.
- Cloud EHRs such as athenahealth, eClinicalWorks, NextGen, and Tebra
- On-prem EHR servers while you need them
- E-prescribing and patient portals
- Billing-company remote access, done safely
- DICOM imaging and PACS workstations
- Ultrasound, EKG, and lab devices on their own network
- Patched in vendor-approved windows
- Backed up and inventoried
- Windows workstations in every exam room
- Microsoft 365, fax-to-email, label and badge printers
- Patient Wi-Fi kept off the clinical network
- Telehealth that works on the first try
We prefer cloud EHR when it fits the practice, and we run and back up the on-prem server properly until you get there.
Most clinics land on Hardened.
Same plans as every SeriousIT client, no medical surcharge. The compliance pack is what a clinic with patient data needs.
One team for the whole clinic.
Front-desk phones, internet, and the cabling and cameras for a new suite or a second location, from the same people who run your IT.
Front-desk phones
Hosted phones with call routing for a busy front desk, nurse-line queues, mobile apps for providers, and after-hours handling that works.
Business phonesBusiness fiber
UTOPIA Fiber for the clinic, supported by the team that runs your network, so the cloud EHR and imaging uploads stop waiting.
Business fiberBuildouts and second locations
Structured cabling, cameras, and door access for new suites and expansion, managed after install.
InfrastructureStraight answers.
Do you support cloud EHRs, or just on-prem?
Both. We prefer cloud EHR when it fits the practice, and we run and back up the on-prem server properly until then.
Can you do our HIPAA risk analysis?
Yes. The annual risk analysis, the policy set, workforce training, BAAs, and the breach playbook are part of the Hardened plan, kept current on a schedule.
What about medical devices the vendor will not let us patch?
We put them on their own network, patch in the window the vendor agrees to, and back them up. An unpatched device on the same network as the EHR is the most common way we see clinics get hit.
Our billing company needs remote access. Is that safe?
It can be. Named accounts, MFA, access limited to what they need, and a BAA on file. We set it up and review it.
Will you be reachable during clinic hours?
That is the point. Business-hours support with real response times, and no after-hours or per-ticket surcharges on any plan.
Do you work with multi-site groups?
Yes. Standardized builds per location, one help desk, and compliance evidence rolled up across sites.
Start with a HIPAA gap check.
Send us your current bills and your last risk analysis, if you have one. We come back with what is exposed, what it would take to fix, and what consolidating would cost.