Elecrics logoElecricsManaged IT Services
ServicesIndustriesHealthcare ITHow It WorksAboutClient Support
Call (617) 982-2325(617) 982-2325Book an IT Fit CallSign in
Elecrics logoElecrics

The complete outsourced IT department for growing Massachusetts businesses.

530 West St, Braintree, MA 02184

Mon–Fri, 8 AM–5 PM ET

(617) 982-2325support@elecrics.com

Services

Complete Managed ITHelpdesk & Employee SupportMicrosoft 365 & Google WorkspaceCybersecurity & Data ProtectionDevice & Endpoint ManagementNetworks & Workplace TechnologyDevice Procurement & LifecycleIT Projects & Deployments

Company

How It WorksIndustriesProperty Management ITIT Insights (Blog)About ElecricsContactClient Support

Get Started

A free 20-minute call to see whether Elecrics is the right IT department for your team.

Book an IT Fit Call

Windows · Mac · Chromebook · Microsoft 365 · Google Workspace

© 2026 Elecrics LLC. All rights reserved.

Terms of ServicePrivacy PolicyCCPA/CPRA

    Medical & dental practices · Massachusetts

    HIPAA IT support that will sign a BAA and pick up at 8 AM

    Elecrics manages the technology behind practices across the South Shore and greater Massachusetts — the technical safeguards HIPAA actually asks of your IT, handled by people who answer the phone before your first patient.

    Get the free security check (617) 982-2325

    Monday–Friday, 8:00 AM–5:00 PM ET · Braintree, MA

    What we will and won’t claim

    No IT company can make a practice “HIPAA compliant” — compliance covers training, policies, physical security and processes we don’t control. What we do is sign a BAA and take responsibility for the technical safeguards: access, audit, encryption, authentication and transmission. Anyone promising you the whole of HIPAA is selling something they can’t deliver.

    Free 10-point security check

    No cost, no obligation. We review the ten points below and send you what we find — in plain English, whether or not you hire us.

    Or call (617) 982-2325 · Mon–Fri, 8 AM–5 PM ET

    Sound familiar?

    The things practices call us about

    • Your practice management system goes down mid-morning and nobody answers the phone until 10.
    • You are not certain whether your backups would restore, because nobody has tried.
    • A staff member left months ago and you suspect their login still works.
    • Your current IT company will not sign a BAA, or has never been asked.
    • You were told you are "HIPAA compliant" but nobody can show you what that covered.

    Free security check

    Ten things we look at

    Each maps to the HIPAA Security Rule clause it serves, so you can check our work rather than take our word for it.

    1. 1

      Who can reach patient data, and from which devices

      §164.312(a) Access control

    2. 2

      Whether access is logged, and whether anyone ever reads the logs

      §164.312(b) Audit controls

    3. 3

      Laptop and workstation encryption, including anything taken home

      §164.312(a)(2)(iv) Encryption

    4. 4

      Email: whether PHI leaves unencrypted, and who it reaches

      §164.312(e) Transmission security

    5. 5

      Backups — existence, frequency, and whether a restore was ever tested

      §164.308(a)(7) Contingency plan

    6. 6

      Staff accounts for people who have left

      §164.308(a)(3)(ii)(C) Termination procedures

    7. 7

      Multi-factor authentication on email and remote access

      §164.312(d) Person or entity authentication

    8. 8

      Operating systems and software still receiving security updates

      §164.308(a)(5)(ii)(B) Protection from malicious software

    9. 9

      Which vendors touch PHI, and whether each has a signed BAA

      §164.308(b) Business associate contracts

    10. 10

      What actually happens in the first hour of a suspected breach

      §164.308(a)(6) Security incident procedures

    We send you the findings whether or not you become a client. If everything is in order, we’ll tell you that too.

    Business Associate Agreement

    We sign a BAA before we touch anything

    If a vendor can reach systems holding protected health information, HIPAA requires a Business Associate Agreement — and that vendor becomes directly liable under the rule, not just contractually. We sign one as a matter of course, before onboarding starts.

    It is worth asking your current provider for theirs. A provider who hesitates is telling you something useful.

    What a BAA actually commits us to

    • Safeguard PHI we can reach, under the Security Rule
    • Report any security incident affecting it, to you
    • Bind any subcontractor we use to the same terms
    • Return or destroy PHI when we stop working together
    It does not cover your staff training, your physical premises, or your policies — those stay yours, and we’ll tell you where the line falls.

    Start with the free check

    Twenty minutes on the phone, then a written summary of what we found. No cost, and no obligation to go further.

    Book the check (617) 982-2325

    Prefer the full picture first? See everything we manage · Book an IT Fit Call