Small Manassas Medical Practice’s HIPAA Cybersecurity Checklist: What Your EHR Vendor Isn’t Covering

HIPAA-cybersecurity-checklist-for-small-Manassas-medical-practices

Ask a Manassas practice manager who handles HIPAA compliance for their office, and the answer is usually the same. The EHR vendor or billing platform, whichever software company sends the biggest invoice. That answer is wrong, and it is the single most expensive misunderstanding in small healthcare cybersecurity today. 

In April 2025, attackers spent nearly a month inside the network of a specialty practice group headquartered just across the Potomac in Maryland. By the time it was contained, the protected health information of 1.9 million patients had been exposed, including Social Security numbers, financial account information, and health insurance details. This was one of many small and mid-size healthcare breaches in 2025, a year in which the total number of individuals affected by healthcare data breaches crossed 20 million by mid-year alone.

The HHS Office for Civil Rights closed out 152 HIPAA enforcement actions between 2021 and 2024, and the majority hit small and mid-size providers, not large hospital systems. In 2024, the healthcare industry averaged $9.77 million per data breach, according to IBM’s Cost of a Data Breach Report, the highest of any sector for the fourteenth year running. Small practices carry the same obligations as those larger providers, but with fewer resources and, in most cases, a false sense of security about what their vendor is actually doing.

Here is the checklist a small Manassas medical practice should be working through this year, and the specific places where your EHR vendor’s coverage stops and your responsibility begins.

What your EHR vendor actually covers

Modern EHR platforms handle a specific slice of HIPAA compliance. They encrypt patient records at rest inside their environment and maintain access logs for who touched what inside the platform. They sign a Business Associate Agreement with you, which formally makes them accountable for the pieces they handle.

That is where the coverage stops.

Your EHR vendor does not: 

  • secure your office network
  • train your staff
  • manage the laptops your team uses to log in
  • encrypt the email your front desk sends
  • back up the data you keep outside the platform
  • tell you when a workstation is compromised
  • respond when something goes wrong.

The onus of every one of those falls on the practice. And every one of them shows up in HIPAA enforcement actions.
HIPAA-enforcement-actions-managed-it-service-in-nova-south

1. Written HIPAA Security Risk Analysis

The Security Rule requires every covered entity to conduct a documented cybersecurity risk assessment in Manassas and update it whenever the environment changes. The absence of one is the most common finding in OCR investigations, cited in more than 70 percent of settlement resolutions. Your EHR vendor does not do this for you. It has to cover your entire environment, not just the software they provide.

2. Multi-factor authentication on every access point

MFA on the EHR is a start. MFA on email, remote access, VPN, cloud storage, and every administrative account is the requirement. Verizon’s 2024 Data Breach Investigations Report attributes the majority of healthcare breaches to stolen credentials. MFA closes that door.

3. Endpoint protection and 24/7 monitoring

Every laptop, workstation, and mobile device that accesses patient data needs endpoint detection and response, actively monitored. Antivirus alone does not meet the standard anymore. Ransomware attacks on small clinics increased sharply in the last three years, and the average recovery cost for a small healthcare practice runs well into six figures once downtime, notification, and remediation are combined.

4. Encrypted email and secure patient communication

Regular email is not HIPAA-compliant when it carries PHI. A secure patient portal or an encrypted email gateway is required for any exchange of patient information with patients, referring providers, or vendors. Attachments sent over standard email are a breach in progress.

5. Tested backups outside the EHR environment

Your EHR vendor backs up their platform for their own operational continuity. That is not the same as a backup you control, encrypted, stored offsite, and restored on a tested schedule. If your EHR vendor goes down, gets breached, or drops your account, an untested backup is not a backup.

6. Written policies and staff training

HIPAA requires documented policies covering access, incident response, sanctions, breach notification, and workforce training. Training has to happen at hire and at least annually thereafter, with documentation of who attended and when. OCR asks for the training log first in nearly every audit.

7. Business Associate Agreements with every vendor touching PHI

The EHR vendor is one. Your IT provider is another. So is your cloud backup service, your billing service, your transcription vendor, and any consultant with system access. Missing BAAs are a common enforcement finding and one of the easiest to fix before it becomes a problem.

8. Documented incident response plan

If a workstation is compromised at 6 pm on a Friday, who does the practice manager call? What gets isolated? What gets logged? Who notifies OCR, and when? The Security Rule requires a written plan, tested at least annually. Most small practices do not have one.

9. Physical safeguards

Locked server rooms or wiring closets, screen privacy filters at the front desk, workstation timeouts, and a written policy for device disposal. The Security Rule’s physical safeguards section is short, but it is enforced, and small practices are often out of compliance without realizing it.

10. Ongoing compliance documentation

HIPAA is not a one-time project. Documentation of policies, training, risk analysis, incident response tests, and vendor management has to be maintained continuously and produced on request. If a breach happens, the difference between a small fine and a large one is usually the quality of the documentation.

What this looks like in practice

Most Manassas practices we walk through this checklist can honestly check off two or three items. The rest are either partially in place, undocumented, or assumed to be handled by the EHR vendor.

That gap is where enforcement lives. OCR does not send warning letters to small practices. It sends corrective action plans, and those come with monitoring periods, mandatory remediation, and settlement amounts that regularly exceed a full year of managed IT spend.

The checklist above does not require an enterprise budget. It requires a coordinated approach across your EHR, your IT provider, your staff, and your written policies, with one person accountable for making sure all four are working together.

Working with a local partner

Most small Manassas practices need an accountable partner who can look at the checklist above, tell them honestly which items are covered and which are not, and close the gaps without turning it into a six-month consulting engagement.

We play that role for healthcare clients across Manassas City and the surrounding counties. Somu Valliappan, our Managing Partner, spent 20+ years in enterprise IT and security across commercial and federal environments before opening CMIT Solutions of NOVA South, and the HIPAA-aligned stack we run for practices is built on that background rather than a generic MSP template.

With 300+ locations across North America, CMIT Solutions is one of the largest managed IT and cybersecurity providers serving independent medical and dental practices in the US. The result is that practices get enterprise-grade protection against ransomware, business email compromise, and vendor breaches without the enterprise price tag. 

If you want a straight read on where your practice actually stands against this checklist, call (571) 720-9555 or book a call with Somu. He will walk you through what is in place, what is missing, and what it would take to close the distance before OCR does it for you.

Frequently Asked Questions

Does my EHR vendor cover HIPAA compliance for my practice?

Partially. Your EHR vendor covers the pieces of HIPAA that apply inside their platform. Your network, staff, devices, email, backups, and policies are your responsibility.

What is a HIPAA Security Risk Analysis, and do I need one?

Yes, every covered entity is required to conduct and document one, and update it when the environment changes. It is the single most common finding in OCR enforcement actions.

What happens if a small practice has a HIPAA breach?

The practice is required to notify affected patients, HHS, and in some cases the media. Fines range from a few thousand dollars to seven figures depending on severity, documentation quality, and cooperation with investigators.

Is regular email HIPAA-compliant if I only send PHI to trusted people?

No. Regular email is not HIPAA-compliant regardless of the recipient. A secure portal or encrypted email gateway is required.

Do I need a Business Associate Agreement with my IT provider?

Yes. Any vendor with access to systems that store or transmit PHI needs a signed BAA. That includes your IT provider, your cloud backup service, and any consultant with system access.

How often does HIPAA training need to happen?

At hire, and at least annually after that, with documentation of who attended and when. Training logs are one of the first things OCR asks for in an audit.

Can a small practice be HIPAA-compliant with cloud-based software?

Yes, if the software vendor signs a BAA, the practice enforces MFA and access controls, and the practice maintains its own tested backup outside the vendor’s environment.

How do I know if my practice is actually HIPAA-compliant?

Work through the checklist above. If you cannot produce documentation for each item, you are not fully compliant, regardless of what your EHR vendor claims.

Back to Blog

Share:

Related Posts

Managed-Cybersecurity-Actually-Costs-a-Small-Business-in-Northern-Virginia

What Managed Cybersecurity Actually Costs a Small to Mid-Size Business in Northern Virginia

Managed cybersecurity services in Northern Virginia typically run ~$100 per user per…

Read More
What-Manassas-City-Small-Businesses-Should-Expect

What Manassas City Small Businesses Should Expect From a Local Managed IT Provider in 2026

If you own a business in Manassas City, the toughest conversation you…

Read More