Healthcare

How should a healthcare organization evaluate an IT partner under HIPAA?

Start with the business associate agreement and who signs it, then move to the operational questions: how access is granted and removed, what audit evidence they can produce, how change windows work around patient care, and what happens during downtime. A partner who has worked in clinical settings answers those from experience rather than from the regulation.

Start with the business associate agreement

Any vendor whose staff can reach protected health information is a business associate, and that includes an IT provider with administrative access to your systems. The agreement is not a formality to be handled at signature.

Ask who signs it, whether their subcontractors are covered, how breach notification timelines are stated, and what happens to your data and documentation when the relationship ends. A partner who cannot answer the offboarding question has not thought about the part that matters most to you.

The questions worth asking, and what a good answer sounds like

Evaluating a healthcare IT partner

AskA good answer sounds like
How does someone get access to our systems, and how do they lose it?Named accounts, multi-factor, least privilege, and a documented offboarding step that runs the same day. Not a shared administrator password
What can you produce if we are audited?Access logs, patch reports, backup and restore records, and a current inventory. Produced from the tooling, not reconstructed afterwards
When do you patch and reboot?Windows agreed against clinical schedules, with a named person who can stop a change. Not a blanket maintenance window that assumes nights are quiet
What happens when the EHR is unreachable?A downtime procedure that has been walked through with clinical staff, including how documentation catches up afterwards
Who is our contact, and who covers them?A named owner and a named backup, both of whom already know the environment
Have you worked in a clinical environment?Specifics: which systems, what went wrong, what changed as a result

What the regulation does not tell you

HIPAA sets the requirements. It does not tell you what it means to work around a schedule where a delayed reboot affects a person waiting in a room, or how to handle shared workstations where clinical staff need speed and the security team needs attribution.

Those tensions are where healthcare IT is actually decided, and they are resolved by working with clinical leadership rather than by pointing at policy. A partner who has only read the rule tends to solve for the audit and create friction for the people delivering care.

Where we stand on this

We are HIPAA-compliant and we work in HIPAA-regulated environments. Day to day that shows up as access controls with real offboarding, patch and backup evidence you can hand to an auditor, and change windows agreed with the people running the schedule. Ongoing work is Managed IT; where spend, risk, and vendor decisions need an executive owner, that is Fractional CIO/CISO.

The healthcare brief in full sits on Healthcare, including the systems we see most often and how practices differ from hospital departments.

Questions we hear first

Does a HIPAA certification exist for IT vendors?

There is no official government certification for HIPAA compliance, which is why the word appears on so many vendor sites without much behind it. Judge the controls and the evidence instead: how access is managed, what logs exist, and whether they can produce records without scrambling.

Do we need a business associate agreement with our IT provider?

If their staff can reach systems that hold protected health information, yes. Administrative access counts even when nobody intends to look at patient records. Get it signed before access is granted, not after.

Our practice is small. Is this proportionate?

The obligations do not scale down with headcount, though the implementation does. A ten-person practice needs the same access discipline and the same breach procedures as a department, delivered with far less machinery. That is a normal engagement rather than an enterprise program.

How do you handle change windows around patient care?

By agreeing them with whoever owns the schedule, and by giving that person the ability to stop a change. Most friction in clinical IT comes from maintenance planned against a calendar rather than against the actual day.

Can you work alongside our EHR vendor?

Yes, and that is usually the arrangement. The EHR vendor owns the application; we own the environment it runs in, the identity around it, and the escalation path when the two need to talk to each other. Start at Become a Client.

Cincinnati skyline and Ohio River bridge at dusk

Let's talk about the work.

One conversation covers IT, marketing, or both. We use it to work through goals and what belongs in the first engagement.

Mailing address

6809 Main St · Cincinnati, OH 45244

Email

[email protected]