Every few months a medical practice calls us after getting a quote from another technology company. The quote is for a security package. The package is real, the products are real, and the number is somewhere between two and four times what a practice that size should be spending.
When we ask what drove it, the answer is almost always the same: HIPAA.
HIPAA gets used as a blank check in our industry. It is treated as a bar so high and so vague that any amount of spending can be justified by pointing at it. That is not what the rule says, and it is worth understanding why, because it will save you money and probably make you more compliant at the same time.
The Security Rule asks you to implement safeguards that are appropriate to the size, complexity, and capabilities of your organization. That language is in the regulation itself. It is not an interpretation and it is not a loophole.
A six-provider family practice is not held to the same implementation as a regional hospital system. Both have to protect patient data. They are not expected to do it with the same tools, the same staffing, or the same budget.
This is genuinely good news, and it is the part most practices never hear. HIPAA is a scaling framework. It expects your safeguards to grow as your practice grows, your patient volume increases, and the amount of data you hold expands. It does not expect a fifteen-person office to operate like a health system on day one.
So the useful question is not "are we HIPAA compliant," which is unanswerable in the abstract. The useful question is: what is appropriate for a practice our size, and can we prove we are doing it?
We organize security into three tiers. Where a practice belongs depends on size, patient volume, and how much data it holds.
Firewall, multi-factor authentication everywhere, endpoint protection on every device, offsite backup that has actually been restored from, and email security. Then a written security risk assessment and a signed Business Associate Agreement with whoever touches your systems.
That is a defensible position. A practice this size with those things in place and documented is in far better shape than a practice with a monitoring platform and no risk assessment.
At this size you almost certainly carry cyber insurance, and your carrier has opinions. Security awareness training with completion records. A password manager, because at twenty people the shared-password workarounds have already started. Managed detection and response. Advanced email protection.
Your floor is no longer your own judgment. It is the application you signed.
Now you have enough staff, enough access to manage, and enough patient volume that centralized logging, twenty-four-hour monitoring, and formal policy governance are proportionate rather than theatrical. At this size someone can actually act on an alert at 2 a.m., which is the thing that makes monitoring worth paying for.
Two products come up over and over in quotes to small practices, and they are almost always premature.
Twenty-four-hour security operations center monitoring at ten people. Monitoring produces alerts. Alerts require somebody positioned to respond to them. If a small practice has no after-hours response capability and no plan for what happens when the alert fires, you are paying for a notification you cannot act on. The product is real and eventually you will want it. At ten people it usually is not the next dollar you should spend.
Enterprise governance and compliance platforms. These are built for organizations with a compliance officer whose job is to feed them. A practice without that role ends up with an expensive dashboard nobody updates, which is worse than a spreadsheet somebody actually maintains.
There is a third, quieter waste: paying for empty seats. Security licensing is usually per user. Practices have turnover, and nobody reconciles the count. We routinely find practices paying to protect people who left months ago.
Here is the pattern we see most, and it has nothing to do with spending more.
Practices generally have more controls than they think. What they do not have is proof.
Multi-factor authentication is on, but there is no dated record showing it is enforced. Backups run every night, but nobody has restored from them in two years, so nobody actually knows if they work. Staff were told about phishing at a lunch meeting, but there are no completion records. The risk assessment exists somewhere, from 2021.
In an audit, an undocumented control counts as no control. The same is true on an insurance claim. You can have done everything right and still be exposed, because you cannot demonstrate any of it.
The fix is not more software. It is a provider who produces documentation as part of the work instead of scrambling for it when a notice arrives.
"Do we have a Business Associate Agreement on file, and can you send me a copy today?"
If your technology company touches systems containing patient data, you need one. If nobody can produce it in an afternoon, that is your answer.
"When was our last restore test, and what did it show?"
Not "are we backed up." Anyone can say yes to that. Restoring is a different question, and the date of the last test tells you almost everything about how your provider works.
You cannot evaluate what you cannot see.
Most practices get a single bundled line on their invoice that says something like "security and compliance." That number goes up occasionally and nobody can explain why, because nobody can see inside it. You cannot tell which tier you are paying for, whether you are paying for two products that do the same job, or whether the user count still matches your staff.
We itemize every component with a monthly report behind it. Not as a favor. Because a practice that can see what it is buying makes better decisions, and a practice that cannot is just approving a number and hoping.
If your provider cannot produce a line-item breakdown of your security stack within a day, you have learned something important, and you did not need to know anything about firewalls to learn it.
We can take a practice all the way through HIPAA, and we do it regularly. We can also build far past it if you want that. We are not going to talk anyone out of being secure.
What we will do is tell you when something is premature. We would rather have a practice at the right tier, spending appropriately, with clean documentation and a roadmap for when things should change, than a practice overspending on tools it cannot use while missing the restore test that would have actually mattered.
That is the whole argument. Right-size it, document it, and grow it as the practice grows.
No. The HIPAA Security Rule is deliberately technology-neutral. It requires administrative, physical, and technical safeguards appropriate to the size, complexity, and capabilities of your organization, and it requires you to document the reasoning behind your choices. Any vendor claiming a specific product is required by HIPAA is selling, not advising.
The Security Rule requires a risk analysis and expects it to be reviewed and updated periodically, which in practice means annually and after any significant change to your systems, staffing, or locations. A risk assessment from three years ago is generally treated as no risk assessment at all. This is the first document typically requested in an inquiry.
Yes, if they create, receive, maintain, or transmit protected health information on your behalf, which nearly every technology company managing a practice's systems does. Without a signed BAA, the compliance gap is on your side. Ask your provider for a copy today. If it takes more than an afternoon to produce, you have a problem.
Usually not right away. Around-the-clock monitoring produces alerts, and alerts only create value when someone is positioned to act on them. Practices under roughly forty people typically get more protection per dollar from the fundamentals, documented processes, and tested backups. Monitoring becomes proportionate as staff, patient volume, and data holdings grow.
Functionally, the same thing that happens with no controls. Auditors and insurance carriers evaluate evidence, not intent. An enforced MFA policy with no dated record, a backup with no restore test, and training with no completion records are all difficult to defend. Documentation is not paperwork for its own sake. It is the only form the protection takes when someone outside your practice asks.
Ninety-second version: take the three-question self-check. No email required to see your result.
Longer version: send us your cyber policy or your most recent renewal application, whichever you have handy. We will tell you which of those controls your practice can actually prove today, which ones you cannot, and which tier you are genuinely operating at. Send your IT invoice along with it if you want us to check whether your spend matches your tier, though that part is optional.
No charge. No meeting required. Five business days.
Request a Security Stack Review
Four Winds IT is a technology company serving 300+ businesses across Southwest Florida, headquartered right here in Sarasota. Call us at (941) 315-2380 and an engineer picks up.