Industry
The schedule, the images, and a signed agreement before any of it.
Dental offices and similar small clinics lose days of care when ransomware locks the front desk, and they hold patient information that US health privacy law treats differently from a law firm’s files. We can describe the service clearly. We will not connect to a practice, or store its logs, until a business associate agreement is in place. That agreement does not exist yet.
Why the work shows up
- A dental practice that stores electronic patient information is generally a covered entity under HIPAA. A vendor that handles that information for the practice is a business associate and needs a business associate agreement. This is a description of the usual shape of the rule, not legal advice to a specific practice.
- Cyber insurers ask clinics about backups, MFA, and endpoint detection for the same reason they ask law firms. The questionnaire is not a finding that the practice is safe.
- The practice-management system and the imaging workstations are the business. If they are down on a Monday, the loss is the day’s schedule, not an abstract record count.
- Many offices already have an IT vendor tied to the practice-management system. We are not proposing to throw that vendor out.
What we would actually do
- After a signed business associate agreement: endpoint monitoring on front-desk and imaging PCs that can run an agent, identity monitoring on the mail tenant, and a monthly letter the owner-dentist or office manager can read.
- Agree who may isolate a workstation during clinic hours. Locking the imaging PC at 9 a.m. is a clinical decision as much as a security one.
- Keep simulations off patient names, insurer portals, and real referral sources.
What we will not take on
- We will not take on a dental or other healthcare client before counsel has produced a business associate agreement and Ed has signed it.
- We will not claim to be HIPAA certified. That is not a status this company holds, and it is not a status we will print on a proposal.
- We will not monitor a device that cannot run an agent, including a machine a vendor contract forbids us to touch.
- We will not notify patients. Breach notification is the practice’s obligation, with its own counsel.
The bundles and the hours are the same ones on the pricing page. A profession does not get a secret package.