If your office WiFi was set up by your internet provider and has never had a professional review, there's a good chance it falls short of what HIPAA expects, even if everything seems to work. The seven checks below will tell you where you stand.
WiFi is one of the most overlooked weak spots in a medical or dental practice. Many owners assume that if the internet works and the router has a password, they're covered. Usually they aren't. The HIPAA Security Rule requires practices to assess risks to electronic protected health information (ePHI) and put reasonable safeguards in place for how it is transmitted, stored and accessed. The rule is technology-neutral and doesn't name specific products or settings, but a default router from your internet provider rarely meets that bar out of the box. (A proposed update to the Security Rule, published in January 2025, would make requirements such as encryption and multi-factor authentication more explicit; it was still a proposal at the time of writing.)
In this episode of NerdSquad Tech Tips, our CEO walks through the checklist we use when reviewing a practice's wireless network. It's fast, practical and written for practice owners and office managers, not IT staff.
No wireless network is perfectly secure. Where you can, run workstations that handle patient data over wired connections rather than WiFi. That isn't always practical, since modern practices depend on wireless, but it's the stronger option and worth building toward.
Default router logins are publicly documented and easy to exploit. If your router still uses its factory admin password, or a default address such as 192.168.0.1, fix that first. Use a strong, unique admin password stored in a password manager, not on a sticky note in the network closet.
Your wireless network should use WPA2 at minimum, and WPA3 where your equipment supports it. For the staff network, enterprise authentication (WPA2-Enterprise or WPA3-Enterprise, which gives each person their own login) is stronger than one shared password. If you see WEP or an open, unencrypted network anywhere, data sent over it is exposed and needs fixing now.
Some practices hide the name (SSID) of the staff network so it doesn't show up in the list on every patient's phone. That's fine as a tidy-up, but it isn't a security control: hidden networks are easy to find with free tools, and HIPAA doesn't require it. Give the staff network a name that doesn't identify the practice or its purpose, and rely on strong encryption, individual logins and network separation for the actual protection.
This is one of the most common gaps we find. Patients, vendors and visitors should never be on the same network as your clinical systems. Use separate networks, ideally with separate VLANs and firewall rules, so a guest device has no path to your EHR, imaging or practice management software. Our article on firewalls and network security explains how that separation works.
The Security Rule requires audit controls: the ability to record and examine activity in systems that contain or use ePHI. Your network equipment should keep access logs, and those logs should be reviewed or sent to a monitoring system that flags unusual activity. If your router can't log at all, it's time to replace it with business-class equipment.
Routers, switches and access points belong in a locked location, not in the waiting room or on an open shelf behind the front desk. Physical access to network hardware can bypass your software controls. Keep firmware updated on all of it.
Move away from passwords alone wherever you can. Multi-factor authentication (MFA) through an authenticator app, or passwordless sign-in, greatly reduces the risk of someone getting into systems that hold patient data.
This episode is for medical and dental practice owners and office managers running out-of-the-box network setups without a dedicated IT team. If that's you and you haven't had a professional network assessment, this checklist is a good place to start.
NerdSquad provides IT support for medical and dental practices across Southwest Florida, including HIPAA compliance support in Naples. We assess existing networks, find the gaps and put the technical safeguards and documentation in place that support your HIPAA compliance program. NerdSquad is not a law firm; confirm your obligations with your compliance counsel.
More short videos are collected in NerdSquad Tech Tips, and our blog has a companion post: Is my WiFi HIPAA compliant?
Already a client? Call (239) 465-0079 or submit a ticket. If something is down, call so we can start right away.
Not a client yet? NerdSquad Managed IT Services is a Managed Service Provider (MSP) based in Naples, Florida. We support businesses onsite across Southwest Florida and remotely nationwide. Book a discovery call or call (239) 465-0079.