CX
Cobrix Solutions
Book Consultation(213) 214-1385

Healthcare IT & Cybersecurity

For California medical, dental and behavioral health practices where an IT failure is also a HIPAA failure.

The two failures that actually cause HIPAA findings

Practices rarely fail HIPAA because they lacked a firewall. They fail on two things: no documented risk analysis, and no record of which vendors touching patient data have signed a Business Associate Agreement.

Both are paperwork failures with technical roots. The risk analysis is explicitly required by the Security Rule at 45 CFR 164.308(a)(1)(ii)(A) and is among the most common findings in HHS Office for Civil Rights enforcement — not because practices are careless, but because nobody ever wrote it down. The BAA gap is quieter: a scheduling tool, a transcription service or a cloud drive quietly holding PHI with no agreement behind it.

The uncomfortable part is that both failures are invisible during normal operation. A practice can run for years with neither, and nothing will surface the gap until a breach, an audit, a cyber-insurance renewal, or a patient complaint forces the question.

What the HIPAA Security Rule actually asks for

The Security Rule splits into three safeguard categories. Vendors tend to sell against the technical column and ignore the other two, which is why so many practices own security products and still fail on documentation.

SafeguardWhat it coversWhere practices commonly fall short
AdministrativeRisk analysis, risk management, workforce training, sanction policy, contingency plan, BAAsThe risk analysis does not exist, or exists once from years ago and was never revisited after systems changed
PhysicalFacility access, workstation use and security, device and media disposalOld workstations and drives disposed of without documented sanitisation
TechnicalAccess control, audit controls, integrity, authentication, transmission securityAudit logging is available but switched off or retained too briefly to investigate anything

Note the word addressable in the Rule. It does not mean optional. It means you either implement the specification or document why an equivalent alternative is reasonable for your environment — and that documentation is itself the compliance artefact. Practices routinely read “addressable” as “skip”, which is the single most expensive misreading in the regulation.

What we configure in a practice

Cobrix runs Microsoft-native. Most practices already pay for Microsoft 365 Business Premium and use a fraction of it, so we start by turning on what you own before recommending anything you would have to buy.

1

Access control

Role-based permissions in Entra ID so front desk, clinical staff and billing see only what their role requires, with phishing-resistant MFA on every account. Minimum necessary access is a HIPAA principle, not just good practice.

2

Audit logging

Purview logging enabled with retention set deliberately, so that if PHI access is ever questioned you can answer with a record rather than an assumption. Default retention frequently expires before an investigation concludes.

3

Device control

Intune enforcing encryption, patching and configuration on every device that touches PHI, including staff laptops that leave the building and personal phones reading clinical email.

4

Email and PHI

Defender for Office 365 anti-phishing plus data-loss policy that catches PHI leaving by email before it goes, rather than after. Most PHI disclosures are accidental, not malicious.

Encryption deserves a specific note. It is an addressable specification, and the practical reason to implement it is the Breach Notification Rule’s safe harbour: PHI encrypted to HHS-specified standards and lost is generally not a reportable breach. A lost unencrypted laptop is a notification event with everything that follows. That asymmetry makes full-disk encryption one of the highest-return controls available, and it is included in the licensing most practices already hold.

Which tools can legally hold PHI

This is the question we get most, and the answer differs by tool and by plan tier. We maintain a plain-English verdict for each one — whether the vendor signs a BAA, which plan is required, and what has to be configured afterwards.

ToolCan it hold PHI?Condition
Microsoft 365YesCovered by Microsoft’s default BAA via the Data Protection Addendum; configuration still determines actual compliance
Microsoft TeamsYesSame default Microsoft BAA that covers Microsoft 365
Google WorkspaceConditionallyBusiness and Enterprise plans, once an admin accepts the BAA. Free Gmail never qualifies
DocusignConditionallyA BAA must be executed; free and basic tiers do not qualify
DropboxConditionallyBusiness and Education plans with a signed BAA. Personal and Basic accounts are not covered
ZoomConditionallyA BAA must be executed and the required protections enabled
SlackConditionallyHigher-tier plans only, with a signed BAA. A standard workspace cannot hold PHI
athenahealthConditionallyBuilt as a HIPAA-grade EHR, but a BAA must be executed before PHI is entered
HubSpotLimitedRequires the sensitive-data add-on and a signed BAA; a standard portal cannot hold PHI
CalendlyNoCalendly does not offer a BAA and its terms state customer data should not contain PHI
QuickBooks OnlineNoIntuit will not sign a BAA, so PHI does not belong in QuickBooks Online

The full set, with the reasoning behind each verdict, is at our HIPAA tool compliance guides.

The vendor inventory almost nobody has

Ask a practice to list every vendor that touches PHI and you will usually get the EHR, the billing company and the IT provider. The real list is longer and it is where BAA gaps live.

Building this inventory is unglamorous and it is the highest-return hour a practice manager can spend. It is also the artefact an investigator asks for first, because it reveals immediately whether a practice understands where its data actually is.

Practice types we work with

Independent primary care and specialty practices, dental groups, behavioral and mental health providers, and small multi-site clinics across California. These share a specific shape: enough regulatory exposure to need real controls, not enough headcount for an internal security function.

Behavioral and mental health carry an extra layer worth naming. Psychotherapy notes have heightened protection under HIPAA and California’s Confidentiality of Medical Information Act imposes its own duties that in places exceed the federal floor. Systems that segregate those records properly are a different configuration, not a stricter version of the same one.

We are not built for hospital systems or large health networks with existing security teams and enterprise EHR estates. If that is you, we will say so on the first call rather than three months in.

How to evaluate an IT provider for your firm

Most practices evaluate providers on price and response time. Those are the two things every provider claims and neither predicts the outcome. The questions below are harder to answer well, which is exactly why they are worth asking.

Ask for the answers in writing. A provider who will commit to them in an email is a different proposition from one who will only say them on a call.

What the first 90 days look like

Engagements fail most often in the transition, not the steady state — because nobody agreed who owned what while it was moving. This is the shape of a Cobrix onboarding.

1

Weeks 1-2: Assess

We inventory the environment: identities, devices, licences, data locations, vendor access and current configuration. Output is a written findings document with gaps ranked by exploitability, not by severity label. You keep it whether or not you continue.

2

Weeks 3-6: Stabilise

The high-exploitability items first — typically phishing-resistant MFA, removal of standing admin rights, audit logging with deliberate retention, and closing whatever access should have been revoked and was not.

3

Weeks 7-10: Document

The written programme, policies and risk analysis your obligations actually require as artefacts, reflecting your real environment rather than a template with your name inserted.

4

Weeks 11-13: Operate

Steady-state support, review cadence agreed, and the accepted-risk register written down with reasoning so the next audit or renewal has something honest to work from.

Nothing here requires you to replace working systems. Most of it is configuration of platforms you already own, which is why the first 90 days rarely involve capital expenditure.

Related services

For the day-to-day support side, see healthcare IT support. For the documented programme and risk analysis, see IT compliance services. Workforce training is a named HIPAA requirement — see security awareness training. If PHI may already be exposed, notification clocks start immediately: see incident response. For AI scribes and automation under HIPAA, see AI automation solutions.

Frequently asked questions

Does Microsoft 365 make our practice HIPAA compliant?

No. Microsoft extends a Business Associate Agreement covering eligible Microsoft 365 services, which is a prerequisite rather than an outcome. A default tenant is not compliant: audit logging and retention, access controls, MFA, encryption and data-loss policy all have to be configured, and the risk analysis and written policies still have to exist. The BAA covers Microsoft's obligations, not yours.

What is a HIPAA risk analysis and do we actually need one?

Yes — the Security Rule requires it explicitly at 45 CFR 164.308(a)(1)(ii)(A). It is a documented assessment of where PHI lives, what could compromise it, and what you have done about each risk. It is among the most common findings in HHS enforcement, usually because it was never written down rather than because the practice was insecure. It also needs revisiting whenever your systems change.

What does 'addressable' mean in the HIPAA Security Rule?

It does not mean optional. For an addressable specification you either implement it, or you document why it is not reasonable for your environment and implement an equivalent alternative. That written justification is itself the compliance artefact. Reading 'addressable' as 'skip' with no documentation is the most expensive misinterpretation in the regulation.

Do we need a BAA with our IT provider?

Yes. Any vendor that creates, receives, maintains or transmits PHI on your behalf is a Business Associate and requires an agreement. That includes your IT provider, and also tools you may not think of as clinical — cloud storage, transcription, appointment reminders, backup and disposal vendors. Cobrix signs a BAA as part of every healthcare engagement.

Is a lost laptop automatically a reportable breach?

Not if the device was encrypted to HHS-specified standards. The Breach Notification Rule provides a safe harbour for properly encrypted PHI, so an encrypted lost laptop is generally not a reportable event while an unencrypted one is. This asymmetry is why full-disk encryption is one of the highest-return controls available, and it is included in licensing most practices already hold.

Can we use AI scribes or transcription with patient data?

Only where the vendor will sign a BAA and their retention and training terms are acceptable. Many AI scribe tools have appeared inside practices without anyone approving them, which creates an unagreed disclosure of PHI. Before any AI tool touches clinical data, confirm three things: will they sign a BAA, do they train on your inputs, and how long do they retain them.

How long does it take to get a practice HIPAA-ready?

The technical controls usually move quickly, because most are settings inside a tenant you already own. What cannot be compressed honestly is evidence of operation — audit logging switched on today does not produce a year of history. We tell you what is genuinely achievable in your timeline and what has to be presented as in progress, which is a defensible position when documented.

Can you support our EHR system?

We support the environment your EHR runs in — identity, devices, network access, backup and the security controls around it — and we coordinate with your EHR vendor on integration and access. We do not represent ourselves as an administrator of any specific EHR platform; that expertise properly sits with the vendor, and a provider claiming deep expertise in every EHR is worth questioning.

Does California law add anything beyond HIPAA?

Yes. The Confidentiality of Medical Information Act imposes duties that in places exceed the federal floor, and California's breach notification statutes at Civil Code 1798.29 and 1798.82 run on their own timelines. A practice can meet HIPAA and still have a California obligation outstanding, which is why the two should be assessed together rather than sequentially.

Ready to Get Started?

Schedule a free consultation today.