Mar 11, 2025

News

5 Signs Your Medical Practice's Network Isn't HIPAA-Ready

Woman in white sweater sitting before a vintage desktop computer.

Most practice owners assume their IT is "fine" until something breaks, or worse, until a breach forces the question. HIPAA doesn't require perfect security, but it does require you to be able to demonstrate reasonable safeguards and ongoing risk management. Here are five signs your network has gaps that could turn into real compliance and financial exposure.

1. Staff share logins and passwords. If your front desk logs in with one shared username and password "because it's easier," you have no way to prove who accessed which patient record and when. HIPAA's access control and audit requirements assume individual accountability, a shared login makes that impossible from day one.
2. You don't know when your backups were last tested. Almost every practice has some backup running. Far fewer have ever actually tried restoring from it. A backup that's never been tested is a backup you're assuming works, and ransomware recovery is the worst possible time to find out it doesn't.
3. Workstations are old and unpatched but still run your patient software. It's common for practices to keep an aging PC running because it's the only one the scheduling or EHR software still works on. Unpatched systems are the easiest entry point for ransomware and malware, and an outdated OS that no longer receives security updates is a documented, known risk under HIPAA's Security Rule.
4. You've never signed a Business Associate Agreement with your IT provider. If a vendor touches, stores, or has access to patient data, including your MSP, HIPAA requires a signed BAA with them. No BAA means no documented accountability if something goes wrong on their end, and it's one of the first things an auditor or a breach investigator will ask for.
5. There's no documented incident-response plan. If a laptop is stolen or a phishing email compromises an account tomorrow, does your staff know what to do in the first hour? HIPAA expects you to have a plan, not just good intentions, knowing who to call, what to shut down, and how to notify patients if required.
Self-check: if you nodded along to two or more of the above, your practice likely has real HIPAA exposure that's still fixable, none of these are hard to correct once someone actually goes through them with you.
UpsiteGroup runs this exact check for South Florida medical offices every day. If you want a straight answer on where your practice stands, we'll walk through all five with you at no cost.
Get your free HIPAA network assessment →

Get expert clarity

Frequently asked questions

Can my staff use the free version of ChatGPT or Claude at work?

Yes, for tasks with no patient information at all, like drafting a generic handout or a job posting. Never for anything touching a patient’s chart or PHI, per both companies’ own consumer terms.

What is a BAA and why does it matter for AI tools?

A Business Associate Agreement is a signed contract required under HIPAA before any vendor can touch PHI on your behalf. Anthropic and OpenAI only offer BAAs on business-tier or API plans, and it must be separately executed, not assumed from a paid subscription.

Does paying for ChatGPT Plus or Claude Pro make it HIPAA-compliant?

No. Both companies state that even paid individual consumer accounts (Plus, Pro, Max) are not covered by a BAA and PHI should not be entered into them.

What should our practice do before letting staff use AI with patient information?

Confirm a business-tier account is provisioned with an executed BAA, set a written policy distinguishing PHI from non-PHI use cases, and fold AI access into your existing audit-logging and access-review process.

How does UpsiteGroup help with this?

We confirm which AI tools your staff can access, verify a BAA is actually on file (not just technically available), and manage AI access controls alongside your EHR’s existing security configuration.

Faded abstract map pattern behind the closing call to action

Build smarter systems and grow with confidence

Faded abstract map pattern behind the closing call to action

Build smarter systems and grow with confidence