HIPAA security for small practices

Train your staff. Watch your exposure. Prove all of it.

Three managed security services for medical, dental, and behavioral health practices — staff phishing defense, dark web credential monitoring, and a monthly audit report written in English instead of jargon. One retainer, one point of contact, and a documented paper trail that builds every single month.

Three services, one monthly retainer

Hospitals hire a security team to do these three things. A ten-person practice can't — so nobody does them, and the gap sits there until something goes wrong. We run all three on a fixed monthly rhythm and hand you the evidence each time.

01

Staff Phishing Defense

The training service

Almost every breach at a small practice starts the same way — not with a firewall failing, but with someone at a front desk opening a message that looked exactly like the fifty legitimate ones they handled that morning. A fake refund request. A spoofed lab result. An urgent text that appears to come from the doctor.

We send your staff realistic simulated phishing built around how your kind of practice actually gets targeted — dental billing looks nothing like a therapy intake. Anyone who clicks gets a short, blame-free lesson at the moment it lands, which is the only moment the lesson sticks. Everything runs with your written authorization, against your own team. We measure readiness; we never attack.

What you get

  • Monthly simulated phishing, tailored to your practice type
  • Point-of-click micro-training for anyone who falls for it
  • Click and report rates tracked over time
  • Per-employee completion records for your training file
02

Dark Web Credential Monitoring

The alert service

Your office manager uses the same password for the practice management system and for a shopping site. The shopping site gets breached. Now a working set of credentials for your practice is circulating in a database anyone can buy — and nobody at your office has any idea.

We monitor breach corpora continuously for credentials tied to your practice's domain and alert you when one surfaces, with the specific step to take: which account, who owns it, what to reset first. We work exclusively from established breach-intelligence sources. We never purchase, broker, or handle stolen data, and we never ask you for a password.

What you get

  • Continuous monitoring of your practice domain
  • Alerts naming the account and the remediation steps
  • Historical exposure baseline at onboarding
  • Every alert and resolution logged and dated
03

Device & Vulnerability Audit

The report service

HIPAA requires every practice to conduct a security risk analysis and to act on what it finds. The exposure isn't only for being breached — it's for being unable to show you were ever looking. Most small practices have genuinely never produced that documentation, because nobody ever told them what it should look like.

Each month we scan the devices on your network for unpatched software, unsupported operating systems, open services, and misconfigurations — then translate the raw technical output into a plain-English report a practice owner can actually read and act on: what changed, what matters, what to fix first, and what we already handled.

What you get

  • Monthly device and network vulnerability scan
  • Plain-English PDF report, dated and retained
  • A prioritized fix list — not a 200-page CVE dump
  • Technical findings that feed your risk analysis file

Why this is required, in plain English

The HIPAA Security Rule doesn't suggest that you train your workforce and assess your risk. It requires it — of every covered entity and every business associate, from a 200-bed hospital to a two-chair dental office.

45 CFR § 164.308(a)(5) — Administrative Safeguards
"Implement a security awareness and training program for all members of its workforce, including management."

That standard is required. Under it sit four implementation specifications — and "addressable" does not mean optional. It means you either implement it, or document in writing why it isn't reasonable for your practice and put an equivalent safeguard in its place:

  • Security reminders — periodic updates, not a one-time onboarding video.
  • Protection from malicious software — how your staff recognizes and reports it.
  • Log-in monitoring — noticing and reporting failed or unusual access attempts.
  • Password management — creating, changing, and safeguarding credentials.

Separately, § 164.308(a)(1)(ii)(A) requires an accurate and thorough risk analysis covering all electronic protected health information your practice holds — and § 164.308(a)(1)(ii)(B) requires you to actually act on what it finds.

What a month looks like

Security fails at small practices because it's a project nobody has time to start. So we made it a rhythm instead of a project — it runs whether or not anyone at your office remembers it's running.

Built for the practices nobody sells to

Enterprise security vendors price and scope for hospital systems. We're built for the offices that handle just as much protected health information with a fraction of the support.

Straight answers

This market is full of vendors implying more than they can deliver. Here's where we draw the lines, up front.

Does this make my practice "HIPAA certified"?
No — and neither does anything else. HHS does not certify or endorse any security vendor, and a company telling you otherwise is selling something that doesn't exist. We help you meet specific requirements and prove it. That's a real, valuable thing, and it isn't the same as compliance.
Is your monthly scan my HIPAA risk analysis?
No. A risk analysis is broader than a technical scan — it covers administrative, physical, and technical safeguards across everywhere your ePHI lives. Our audit produces the technical evidence that feeds it and keeps it current. We'll always tell you plainly what it does and doesn't cover.
Do you need access to patient records?
No, and we don't want it. We work with staff email addresses, device inventories, and scan results. Please never send us protected health information.
Do you go onto the dark web for me?
No. We work from established breach-intelligence sources and never purchase, broker, or handle stolen data. Defense only — we teach and monitor protection, never intrusion.