Yes. We put the technical HIPAA safeguards in place, keep them working, and keep the documentation that shows it. HIPAA compliance is something a practice maintains every day, and we handle the IT side of that work with you.
Most practices we talk to already have some HIPAA pieces in place: antivirus, maybe an encrypted email tool, maybe a password policy nobody enforces. What's usually missing is a consistent routine that keeps all of it working, documented and ready for review year-round. That's where healthcare-focused IT support comes in. We don't certify anyone (no one can, as explained below), but we make sure the technical side of your environment does what the HIPAA Security Rule asks of it.
The Security Rule sets out three groups of safeguards: administrative, physical and technical. The technical safeguards are where IT lives:
Several administrative safeguards also touch IT directly: risk analysis, security awareness training, contingency planning (backup and disaster recovery) and managing business associates. We handle the technical side and help with the administrative pieces that overlap with IT.
One update to watch: in January 2025, HHS proposed changes to the Security Rule that would make encryption and multi-factor authentication explicit requirements and remove the "addressable" category for most safeguards. As of this writing it is a proposal, not a final rule. We already treat encryption and MFA as standard for our healthcare clients, so the practices we support are in a good position either way.
Before we handle any PHI, we sign a Business Associate Agreement with your practice. HIPAA requires one with any IT vendor that handles protected health information. If a vendor won't sign a BAA, that's a strong signal it shouldn't be working with PHI.
HIPAA requires an accurate and thorough risk analysis, reviewed as your environment changes. We run vulnerability scans, document gaps and give you a prioritized list of what to fix first. The result is the written record a reviewer expects to see.
We encrypt workstations, laptops and mobile devices at rest, email and file transfers in transit, and backups. If PHI lives on a device or moves between two places, our standard is to encrypt it.
Role-based access means the hygienist isn't pulling billing data and the front desk isn't reading chart notes. Audit logging records access to systems holding PHI, which HIPAA's audit controls standard calls for and which matters a great deal if you ever have to investigate an incident.
PHI in personal Gmail or Outlook is a breach waiting to happen. We deploy encrypted email, plus our Email Privacy Suite for larger files such as charts, lab results and imaging. The details are in our article on transferring large medical files.
HIPAA's security awareness and training standard is required for your workforce, which in practice means nearly everyone on staff. Security awareness training and phishing simulations are a standard part of our cybersecurity plans. We track completion and keep the records. More on that in security awareness training and compliance.
HIPAA's contingency plan standard means you need to be able to recover from ransomware, hardware failure or a storm that knocks the office offline. Our backup and disaster recovery service uses immutable (write-once) backup storage designed so backups can't be altered or deleted by an attacker, tests restores, and documents the recovery plan.
Endpoint detection and response runs on every workstation that touches PHI. When something looks suspicious, it can isolate the device automatically while a technician investigates.
HIPAA requires that your HIPAA documentation (policies, procedures, risk analyses and similar records) be kept for six years. Medical record retention is a separate question set by state law and licensing board rules: in Florida, physicians generally must keep patient records for at least five years after the last patient contact, and some specialties and payer contracts require longer. We configure retention policies to match what your practice tells us it needs, using tamper-resistant storage where it counts.
Much of a HIPAA review comes down to records. We keep the technical documentation you'll need, including risk assessments, access logs, training records, incident logs, policy reviews and BAAs with downstream vendors, so it's organized before anyone asks for it.
We are not a HIPAA certification body, and neither is anyone else. HHS doesn't certify practices or vendors as "HIPAA compliant," so any vendor offering to certify your practice is selling something that doesn't exist. What a reviewer looks at is whether your administrative, physical and technical safeguards are real and documented. We make the technical ones real and document them.
We also don't replace your privacy or security officer, your attorney or your auditor. They own the parts of HIPAA that aren't IT, such as clinical policy and legal interpretation. We work alongside them.
Breaches happen to small practices and large hospital systems alike. OCR enforcement often involves the same preventable gaps: unencrypted laptops, missing BAAs, no risk analysis on file and staff emailing PHI to personal accounts. HIPAA penalties are tiered and adjusted for inflation each year.
If an incident happens at a client practice, we isolate affected systems, preserve evidence, restore from clean backups and document what happened. As your business associate, we notify you of a breach involving PHI we handle, as our BAA requires. You, as the covered entity, then notify affected individuals without unreasonable delay and no later than 60 days after discovery, and we help you gather the facts you need to do that. We can't promise an incident will never happen. We can make sure you're prepared when it does.
NerdSquad is not a law firm; confirm your obligations with your compliance counsel.
Every covered entity needs this discipline (see our overview of compliance frameworks), and it matters most for:
We work with practices across Southwest Florida, including Naples, Fort Myers, Cape Coral and Bonita Springs. If you're in the Naples area, see our page on HIPAA compliance support in Naples.
If you've never had a formal HIPAA risk analysis, or you aren't sure your current setup would hold up to a review, it's worth a conversation. We'll walk through your environment and tell you plainly what's in good shape, what isn't and what to fix first.
Already a client? Call (239) 465-0079 or submit a ticket. If something is down, call so we can start right away.
Not a client yet? NerdSquad Managed IT Services is a Managed Service Provider (MSP) based in Naples, Florida. We support businesses onsite across Southwest Florida and remotely nationwide. Book a discovery call or call (239) 465-0079.