Clinical Security
HIPAA security for small practices
HIPAA security for small practices
Train your staff. Watch your exposure. Prove all of it.
Three managed security services for medical, dental, and behavioral health practices — staff
phishing defense, dark web credential monitoring, and a monthly audit report written in
English instead of jargon. One retainer, one point of contact, and a documented paper trail
that builds every single month.
Three services, one monthly retainer
Hospitals hire a security team to do these three things. A ten-person practice can't — so
nobody does them, and the gap sits there until something goes wrong. We run all three on a
fixed monthly rhythm and hand you the evidence each time.
01
Staff Phishing Defense
The training service
Almost every breach at a small practice starts the same way — not with a firewall
failing, but with someone at a front desk opening a message that looked exactly like
the fifty legitimate ones they handled that morning. A fake refund request. A spoofed
lab result. An urgent text that appears to come from the doctor.
We send your staff realistic simulated phishing built around how your kind of
practice actually gets targeted — dental billing looks nothing like a therapy intake.
Anyone who clicks gets a short, blame-free lesson at the moment it lands, which is the
only moment the lesson sticks. Everything runs with your written authorization,
against your own team. We measure readiness; we never attack.
What you get
Monthly simulated phishing, tailored to your practice type
Point-of-click micro-training for anyone who falls for it
Click and report rates tracked over time
Per-employee completion records for your training file
02
Dark Web Credential Monitoring
The alert service
Your office manager uses the same password for the practice management system and for
a shopping site. The shopping site gets breached. Now a working set of credentials for
your practice is circulating in a database anyone can buy — and nobody at your office
has any idea.
We monitor breach corpora continuously for credentials tied to your practice's domain
and alert you when one surfaces, with the specific step to take: which account, who
owns it, what to reset first. We work exclusively from established breach-intelligence
sources. We never purchase, broker, or handle stolen data, and we never ask you for a
password.
What you get
Continuous monitoring of your practice domain
Alerts naming the account and the remediation steps
Historical exposure baseline at onboarding
Every alert and resolution logged and dated
03
Device & Vulnerability Audit
The report service
HIPAA requires every practice to conduct a security risk analysis and to act on what it
finds. The exposure isn't only for being breached — it's for being unable to show you
were ever looking. Most small practices have genuinely never produced that
documentation, because nobody ever told them what it should look like.
Each month we scan the devices on your network for unpatched software, unsupported
operating systems, open services, and misconfigurations — then translate the raw
technical output into a plain-English report a practice owner can actually read and
act on: what changed, what matters, what to fix first, and what we already handled.
What you get
Monthly device and network vulnerability scan
Plain-English PDF report, dated and retained
A prioritized fix list — not a 200-page CVE dump
Technical findings that feed your risk analysis file
Why this is required, in plain English
The HIPAA Security Rule doesn't suggest that you train your workforce and assess your risk. It
requires it — of every covered entity and every business associate, from a 200-bed hospital to
a two-chair dental office.
"Implement a security awareness and training program for all members of its workforce,
including management."
That standard is required. Under it sit four implementation
specifications — and "addressable" does not mean optional. It means you either implement
it, or document in writing why it isn't reasonable for your practice and put an equivalent
safeguard in its place:
Security reminders — periodic updates, not a one-time onboarding video.
Protection from malicious software — how your staff recognizes and reports it.
Log-in monitoring — noticing and reporting failed or unusual access attempts.
Password management — creating, changing, and safeguarding credentials.
Separately, § 164.308(a)(1)(ii)(A) requires an accurate and thorough risk
analysis covering all electronic protected health information your practice holds — and
§ 164.308(a)(1)(ii)(B) requires you to actually act on what it finds.
What a month looks like
Security fails at small practices because it's a project nobody has time to start. So we made
it a rhythm instead of a project — it runs whether or not anyone at your office remembers it's
running.
Onboarding
Baseline exposure check, staff roster, and your first full audit — so you can see exactly
where you're starting from.
Every month
A phishing simulation goes out to your team, with instant coaching for anyone who clicks.
Continuously
Credential monitoring runs in the background. If something surfaces you hear from us — not
months later in a breach notice.
Month end
Your audit report lands: what we scanned, what we found, what to fix, what's already
handled. Filed and retained automatically.
Built for the practices nobody sells to
Enterprise security vendors price and scope for hospital systems. We're built for the offices
that handle just as much protected health information with a fraction of the support.
Medical practices Solo, family, and specialty clinics
Dental offices One chair to a multi-location group
Behavioral health Therapists, counselors, group practices
Business associates Billing, transcription, IT, and MSPs
Straight answers
This market is full of vendors implying more than they can deliver. Here's where we draw the
lines, up front.
Does this make my practice "HIPAA certified"?
No — and neither does anything else. HHS does not certify or endorse any security vendor,
and a company telling you otherwise is selling something that doesn't exist. We help you
meet specific requirements and prove it. That's a real, valuable thing, and it isn't the
same as compliance.
Is your monthly scan my HIPAA risk analysis?
No. A risk analysis is broader than a technical scan — it covers administrative, physical,
and technical safeguards across everywhere your ePHI lives. Our audit produces the
technical evidence that feeds it and keeps it current. We'll always tell you plainly what
it does and doesn't cover.
Do you need access to patient records?
No, and we don't want it. We work with staff email addresses, device inventories, and scan
results. Please never send us protected health information.
Do you go onto the dark web for me?
No. We work from established breach-intelligence sources and never purchase, broker, or
handle stolen data. Defense only — we teach and monitor protection, never intrusion.