Medical & dental practices · Massachusetts
Elecrics manages the technology behind practices across the South Shore and greater Massachusetts — the technical safeguards HIPAA actually asks of your IT, handled by people who answer the phone before your first patient.
Monday–Friday, 8:00 AM–5:00 PM ET · Braintree, MA
What we will and won’t claim
No IT company can make a practice “HIPAA compliant” — compliance covers training, policies, physical security and processes we don’t control. What we do is sign a BAA and take responsibility for the technical safeguards: access, audit, encryption, authentication and transmission. Anyone promising you the whole of HIPAA is selling something they can’t deliver.
Sound familiar?
Free security check
Each maps to the HIPAA Security Rule clause it serves, so you can check our work rather than take our word for it.
Who can reach patient data, and from which devices
§164.312(a) Access control
Whether access is logged, and whether anyone ever reads the logs
§164.312(b) Audit controls
Laptop and workstation encryption, including anything taken home
§164.312(a)(2)(iv) Encryption
Email: whether PHI leaves unencrypted, and who it reaches
§164.312(e) Transmission security
Backups — existence, frequency, and whether a restore was ever tested
§164.308(a)(7) Contingency plan
Staff accounts for people who have left
§164.308(a)(3)(ii)(C) Termination procedures
Multi-factor authentication on email and remote access
§164.312(d) Person or entity authentication
Operating systems and software still receiving security updates
§164.308(a)(5)(ii)(B) Protection from malicious software
Which vendors touch PHI, and whether each has a signed BAA
§164.308(b) Business associate contracts
What actually happens in the first hour of a suspected breach
§164.308(a)(6) Security incident procedures
We send you the findings whether or not you become a client. If everything is in order, we’ll tell you that too.
Business Associate Agreement
If a vendor can reach systems holding protected health information, HIPAA requires a Business Associate Agreement — and that vendor becomes directly liable under the rule, not just contractually. We sign one as a matter of course, before onboarding starts.
It is worth asking your current provider for theirs. A provider who hesitates is telling you something useful.
What a BAA actually commits us to
Twenty minutes on the phone, then a written summary of what we found. No cost, and no obligation to go further.
Prefer the full picture first? See everything we manage · Book an IT Fit Call