For California medical, dental and behavioral health practices where an IT failure is also a HIPAA failure.
Practices rarely fail HIPAA because they lacked a firewall. They fail on two things: no documented risk analysis, and no record of which vendors touching patient data have signed a Business Associate Agreement.
Both are paperwork failures with technical roots. The risk analysis is explicitly required by the Security Rule at 45 CFR 164.308(a)(1)(ii)(A) and is among the most common findings in HHS Office for Civil Rights enforcement — not because practices are careless, but because nobody ever wrote it down. The BAA gap is quieter: a scheduling tool, a transcription service or a cloud drive quietly holding PHI with no agreement behind it.
The uncomfortable part is that both failures are invisible during normal operation. A practice can run for years with neither, and nothing will surface the gap until a breach, an audit, a cyber-insurance renewal, or a patient complaint forces the question.
The Security Rule splits into three safeguard categories. Vendors tend to sell against the technical column and ignore the other two, which is why so many practices own security products and still fail on documentation.
| Safeguard | What it covers | Where practices commonly fall short |
|---|---|---|
| Administrative | Risk analysis, risk management, workforce training, sanction policy, contingency plan, BAAs | The risk analysis does not exist, or exists once from years ago and was never revisited after systems changed |
| Physical | Facility access, workstation use and security, device and media disposal | Old workstations and drives disposed of without documented sanitisation |
| Technical | Access control, audit controls, integrity, authentication, transmission security | Audit logging is available but switched off or retained too briefly to investigate anything |
Note the word addressable in the Rule. It does not mean optional. It means you either implement the specification or document why an equivalent alternative is reasonable for your environment — and that documentation is itself the compliance artefact. Practices routinely read “addressable” as “skip”, which is the single most expensive misreading in the regulation.
Cobrix runs Microsoft-native. Most practices already pay for Microsoft 365 Business Premium and use a fraction of it, so we start by turning on what you own before recommending anything you would have to buy.
Role-based permissions in Entra ID so front desk, clinical staff and billing see only what their role requires, with phishing-resistant MFA on every account. Minimum necessary access is a HIPAA principle, not just good practice.
Purview logging enabled with retention set deliberately, so that if PHI access is ever questioned you can answer with a record rather than an assumption. Default retention frequently expires before an investigation concludes.
Intune enforcing encryption, patching and configuration on every device that touches PHI, including staff laptops that leave the building and personal phones reading clinical email.
Defender for Office 365 anti-phishing plus data-loss policy that catches PHI leaving by email before it goes, rather than after. Most PHI disclosures are accidental, not malicious.
Encryption deserves a specific note. It is an addressable specification, and the practical reason to implement it is the Breach Notification Rule’s safe harbour: PHI encrypted to HHS-specified standards and lost is generally not a reportable breach. A lost unencrypted laptop is a notification event with everything that follows. That asymmetry makes full-disk encryption one of the highest-return controls available, and it is included in the licensing most practices already hold.
This is the question we get most, and the answer differs by tool and by plan tier. We maintain a plain-English verdict for each one — whether the vendor signs a BAA, which plan is required, and what has to be configured afterwards.
| Tool | Can it hold PHI? | Condition |
|---|---|---|
| Microsoft 365 | Yes | Covered by Microsoft’s default BAA via the Data Protection Addendum; configuration still determines actual compliance |
| Microsoft Teams | Yes | Same default Microsoft BAA that covers Microsoft 365 |
| Google Workspace | Conditionally | Business and Enterprise plans, once an admin accepts the BAA. Free Gmail never qualifies |
| Docusign | Conditionally | A BAA must be executed; free and basic tiers do not qualify |
| Dropbox | Conditionally | Business and Education plans with a signed BAA. Personal and Basic accounts are not covered |
| Zoom | Conditionally | A BAA must be executed and the required protections enabled |
| Slack | Conditionally | Higher-tier plans only, with a signed BAA. A standard workspace cannot hold PHI |
| athenahealth | Conditionally | Built as a HIPAA-grade EHR, but a BAA must be executed before PHI is entered |
| HubSpot | Limited | Requires the sensitive-data add-on and a signed BAA; a standard portal cannot hold PHI |
| Calendly | No | Calendly does not offer a BAA and its terms state customer data should not contain PHI |
| QuickBooks Online | No | Intuit will not sign a BAA, so PHI does not belong in QuickBooks Online |
The full set, with the reasoning behind each verdict, is at our HIPAA tool compliance guides.
Ask a practice to list every vendor that touches PHI and you will usually get the EHR, the billing company and the IT provider. The real list is longer and it is where BAA gaps live.
Building this inventory is unglamorous and it is the highest-return hour a practice manager can spend. It is also the artefact an investigator asks for first, because it reveals immediately whether a practice understands where its data actually is.
Independent primary care and specialty practices, dental groups, behavioral and mental health providers, and small multi-site clinics across California. These share a specific shape: enough regulatory exposure to need real controls, not enough headcount for an internal security function.
Behavioral and mental health carry an extra layer worth naming. Psychotherapy notes have heightened protection under HIPAA and California’s Confidentiality of Medical Information Act imposes its own duties that in places exceed the federal floor. Systems that segregate those records properly are a different configuration, not a stricter version of the same one.
We are not built for hospital systems or large health networks with existing security teams and enterprise EHR estates. If that is you, we will say so on the first call rather than three months in.
Most practices evaluate providers on price and response time. Those are the two things every provider claims and neither predicts the outcome. The questions below are harder to answer well, which is exactly why they are worth asking.
Ask for the answers in writing. A provider who will commit to them in an email is a different proposition from one who will only say them on a call.
Engagements fail most often in the transition, not the steady state — because nobody agreed who owned what while it was moving. This is the shape of a Cobrix onboarding.
We inventory the environment: identities, devices, licences, data locations, vendor access and current configuration. Output is a written findings document with gaps ranked by exploitability, not by severity label. You keep it whether or not you continue.
The high-exploitability items first — typically phishing-resistant MFA, removal of standing admin rights, audit logging with deliberate retention, and closing whatever access should have been revoked and was not.
The written programme, policies and risk analysis your obligations actually require as artefacts, reflecting your real environment rather than a template with your name inserted.
Steady-state support, review cadence agreed, and the accepted-risk register written down with reasoning so the next audit or renewal has something honest to work from.
Nothing here requires you to replace working systems. Most of it is configuration of platforms you already own, which is why the first 90 days rarely involve capital expenditure.
For the day-to-day support side, see healthcare IT support. For the documented programme and risk analysis, see IT compliance services. Workforce training is a named HIPAA requirement — see security awareness training. If PHI may already be exposed, notification clocks start immediately: see incident response. For AI scribes and automation under HIPAA, see AI automation solutions.
No. Microsoft extends a Business Associate Agreement covering eligible Microsoft 365 services, which is a prerequisite rather than an outcome. A default tenant is not compliant: audit logging and retention, access controls, MFA, encryption and data-loss policy all have to be configured, and the risk analysis and written policies still have to exist. The BAA covers Microsoft's obligations, not yours.
Yes — the Security Rule requires it explicitly at 45 CFR 164.308(a)(1)(ii)(A). It is a documented assessment of where PHI lives, what could compromise it, and what you have done about each risk. It is among the most common findings in HHS enforcement, usually because it was never written down rather than because the practice was insecure. It also needs revisiting whenever your systems change.
It does not mean optional. For an addressable specification you either implement it, or you document why it is not reasonable for your environment and implement an equivalent alternative. That written justification is itself the compliance artefact. Reading 'addressable' as 'skip' with no documentation is the most expensive misinterpretation in the regulation.
Yes. Any vendor that creates, receives, maintains or transmits PHI on your behalf is a Business Associate and requires an agreement. That includes your IT provider, and also tools you may not think of as clinical — cloud storage, transcription, appointment reminders, backup and disposal vendors. Cobrix signs a BAA as part of every healthcare engagement.
Not if the device was encrypted to HHS-specified standards. The Breach Notification Rule provides a safe harbour for properly encrypted PHI, so an encrypted lost laptop is generally not a reportable event while an unencrypted one is. This asymmetry is why full-disk encryption is one of the highest-return controls available, and it is included in licensing most practices already hold.
Only where the vendor will sign a BAA and their retention and training terms are acceptable. Many AI scribe tools have appeared inside practices without anyone approving them, which creates an unagreed disclosure of PHI. Before any AI tool touches clinical data, confirm three things: will they sign a BAA, do they train on your inputs, and how long do they retain them.
The technical controls usually move quickly, because most are settings inside a tenant you already own. What cannot be compressed honestly is evidence of operation — audit logging switched on today does not produce a year of history. We tell you what is genuinely achievable in your timeline and what has to be presented as in progress, which is a defensible position when documented.
We support the environment your EHR runs in — identity, devices, network access, backup and the security controls around it — and we coordinate with your EHR vendor on integration and access. We do not represent ourselves as an administrator of any specific EHR platform; that expertise properly sits with the vendor, and a provider claiming deep expertise in every EHR is worth questioning.
Yes. The Confidentiality of Medical Information Act imposes duties that in places exceed the federal floor, and California's breach notification statutes at Civil Code 1798.29 and 1798.82 run on their own timelines. A practice can meet HIPAA and still have a California obligation outstanding, which is why the two should be assessed together rather than sequentially.
Schedule a free consultation today.