If your business touches patient health information in any way, HIPAA is the federal law that governs how you handle, store and share it. It applies to medical and dental practices, and also to the vendors who work with them, including IT providers.
HIPAA dates to 1996, which makes it ancient in tech years. It is still the main privacy and security law in U.S. healthcare, regulators still enforce it, and its Security Rule is in the middle of a proposed update. If you run a practice or work with one, here is what HIPAA actually asks of your IT.
Health Insurance Portability and Accountability Act. The "portability" part was originally about letting people keep health coverage between jobs. The "accountability" part is where IT lives: rules about how health information is protected, who can access it and what happens when it is breached.
Picture every piece of patient information as certified mail. HIPAA sets the rules for who may open it, how it must be sealed, who is responsible if it goes missing and what happens if it lands in the wrong hands. Those rules apply not only to the practice but to everyone who handles the mail on its behalf: IT companies, billing services, cloud storage vendors and more.
The Privacy Rule defines protected health information (PHI) and who may use or disclose it. PHI is health information linked to anything that could identify a patient: name, dates, address, Social Security number, account numbers and similar details.
The Security Rule sets the administrative, physical and technical safeguards for electronic PHI (ePHI). Encryption, access controls, audit logs, backup and recovery, device management and workforce training all flow from here.
The Breach Notification Rule says who you must notify, how quickly and what to document when unsecured PHI is compromised.
Covered entities are healthcare providers that bill electronically (doctors, dentists, clinics, hospitals), health plans and healthcare clearinghouses.
Business associates are vendors that create, receive, maintain or transmit PHI for a covered entity. A Managed Service Provider (MSP) that manages systems holding ePHI is a business associate, and HIPAA applies to it directly.
Covered entities and business associates must sign a Business Associate Agreement (BAA), a contract that spells out each party's responsibilities for protecting PHI. Sharing PHI with a vendor without a BAA is itself a compliance problem, before anything else goes wrong.
The Security Rule groups safeguards into three buckets:
HIPAA describes outcomes rather than specific products. That gives you flexibility, but it also means you can't buy one tool and declare yourself done. Implementation and documentation both count, and HIPAA documentation must be kept for 6 years.
In January 2025, HHS published a proposed rule to update the Security Rule. Among other changes, it would make MFA and encryption explicit requirements and remove the "addressable" distinction for most specifications. As of this writing it is a proposal, not a final rule, so treat it as a strong signal of where expectations are heading rather than current law.
There is no such thing as "HIPAA certified." No government agency or private body issues an official HIPAA certification. The Office for Civil Rights (OCR) at HHS investigates complaints and breaches and enforces the rules, but there is no exam and no seal. A vendor that says it is "HIPAA certified" usually means it completed a third-party review or training program, which can be useful but isn't the same thing. What matters is whether you can show your safeguards and documentation.
OCR can impose civil money penalties, which are tiered by level of culpability (from "did not know" up to uncorrected willful neglect) and adjusted for inflation each year. Many cases end in resolution agreements with multi-year corrective action plans. Criminal penalties are possible for knowing misuse of PHI, and state attorneys general can also enforce HIPAA.
Florida's breach law, the Florida Information Protection Act (FIPA), can also apply to the same incident.
An IT provider working with a healthcare client is a business associate with legal obligations. In practice that means:
Retention also shapes your IT. HIPAA requires its own documentation to be kept for 6 years, and Florida has separate medical and dental record retention rules that vary by profession. Check with your licensing board or counsel for the period that applies to your records. Either way, backup and disaster recovery systems need to handle long retention windows, and immutable storage (such as WORM storage) helps protect retained records from tampering.
NerdSquad helps practices put these controls and the supporting documentation in place. Practices in Collier County can see our approach to HIPAA compliance support in Naples.
NerdSquad is not a law firm; confirm your obligations with your compliance counsel.
Already a client? Call (239) 465-0079 or submit a ticket. If something is down, call so we can start right away.
Not a client yet? NerdSquad Managed IT Services is a Managed Service Provider (MSP) based in Naples, Florida. We support businesses onsite across Southwest Florida and remotely nationwide. Book a discovery call or call (239) 465-0079.