{"id":694,"date":"2026-08-18T08:20:03","date_gmt":"2026-08-18T13:20:03","guid":{"rendered":"https:\/\/cmitsolutions.com\/novasouth-va-1254\/?p=694"},"modified":"2026-08-18T08:20:03","modified_gmt":"2026-08-18T13:20:03","slug":"hipaa-cybersecurity-checklist-manassas-medical-practices","status":"publish","type":"post","link":"https:\/\/cmitsolutions.com\/novasouth-va-1254\/blog\/hipaa-cybersecurity-checklist-manassas-medical-practices\/","title":{"rendered":"Small Manassas Medical Practice&#8217;s HIPAA Cybersecurity Checklist: What Your EHR Vendor Isn&#8217;t Covering"},"content":{"rendered":"<p><span style=\"font-weight: 400\">Ask a Manassas practice manager who handles HIPAA compliance for their office, and the answer is usually the same. The EHR vendor or billing platform, whichever software company sends the biggest invoice.\u00a0<\/span><span style=\"font-weight: 400\">That answer is wrong, and it is the single most expensive misunderstanding in small healthcare cybersecurity today.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400\">In April 2025, attackers spent nearly a month inside the <\/span><span style=\"font-weight: 400\">network of a specialty practice group<\/span><span style=\"font-weight: 400\"> headquartered just across the Potomac in Maryland.<\/span><span style=\"font-weight: 400\"> By the time it was contained, the protected health information of 1.9 million patients had been exposed, including Social Security numbers, financial account information, and health insurance details. This was one of <a href=\"https:\/\/cmitsolutions.com\/novasouth-va-1254\/blog\/managed-it-services-manassas-2026\/\">many small and mid-size<\/a> healthcare breaches in 2025, a year in which the total number of individuals affected by healthcare data breaches crossed 20 million by mid-year alone.<\/span><\/p>\n<p><span style=\"font-weight: 400\">The<\/span><a href=\"https:\/\/www.hhs.gov\/hipaa\/for-professionals\/compliance-enforcement\/data\/enforcement-highlights\/index.html\"> <span style=\"font-weight: 400\">HHS Office for Civil Rights<\/span><\/a><span style=\"font-weight: 400\"> closed out 152 HIPAA enforcement actions between 2021 and 2024, and the majority hit small and mid-size providers, not large hospital systems.<\/span><span style=\"font-weight: 400\"> In 2024, the healthcare industry averaged $9.77 million per data breach, according to<\/span><a href=\"https:\/\/newsroom.ibm.com\/2024-07-30-ibm-report-escalating-data-breach-disruption-pushes-costs-to-new-highs\"> <span style=\"font-weight: 400\">IBM&#8217;s Cost of a Data Breach Report<\/span><\/a><span style=\"font-weight: 400\">, the highest of any sector for the fourteenth year running. Small practices carry the same obligations as those larger providers, but with fewer resources and, in most cases, a false sense of security about what their vendor is actually doing.<\/span><\/p>\n<p><span style=\"font-weight: 400\">Here is the checklist a small Manassas medical practice should be working through this year, and the specific places where your EHR vendor&#8217;s coverage stops and your responsibility begins.<\/span><\/p>\n<h3><b>What your EHR vendor actually covers<\/b><\/h3>\n<p><span style=\"font-weight: 400\">Modern EHR platforms handle a specific slice of HIPAA compliance. They encrypt patient records at rest inside their environment and maintain access logs for who touched what inside the platform. They sign a Business Associate Agreement with you, which formally makes them accountable for the pieces they handle.<\/span><\/p>\n<p><span style=\"font-weight: 400\">That is where the coverage stops.<\/span><\/p>\n<p><span style=\"font-weight: 400\">Your EHR vendor does not:\u00a0<\/span><\/p>\n<ul>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">secure your office network<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">train your staff<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">manage the laptops your team uses to log in<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">encrypt the email your front desk sends<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">back up the data you keep outside the platform<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">tell you when a workstation is compromised<\/span><\/li>\n<li style=\"font-weight: 400\"><span style=\"font-weight: 400\">respond when something goes wrong.<\/span><\/li>\n<\/ul>\n<p><span style=\"font-weight: 400\">The onus of every one of those falls on the practice. And every one of them shows up in HIPAA enforcement actions.<br \/>\n<\/span><b><img decoding=\"async\" class=\"aligncenter wp-image-696 size-full\" src=\"https:\/\/cmitsolutions.com\/novasouth-va-1254\/wp-content\/uploads\/sites\/272\/2026\/08\/opt-3.png\" alt=\"HIPAA-enforcement-actions-managed-it-service-in-nova-south\" width=\"2240\" height=\"1260\" srcset=\"https:\/\/cmitsolutions.com\/novasouth-va-1254\/wp-content\/uploads\/sites\/272\/2026\/08\/opt-3.png 2240w, https:\/\/cmitsolutions.com\/novasouth-va-1254\/wp-content\/uploads\/sites\/272\/2026\/08\/opt-3-300x169.png 300w, https:\/\/cmitsolutions.com\/novasouth-va-1254\/wp-content\/uploads\/sites\/272\/2026\/08\/opt-3-1024x576.png 1024w, https:\/\/cmitsolutions.com\/novasouth-va-1254\/wp-content\/uploads\/sites\/272\/2026\/08\/opt-3-768x432.png 768w, https:\/\/cmitsolutions.com\/novasouth-va-1254\/wp-content\/uploads\/sites\/272\/2026\/08\/opt-3-1536x864.png 1536w, https:\/\/cmitsolutions.com\/novasouth-va-1254\/wp-content\/uploads\/sites\/272\/2026\/08\/opt-3-2048x1152.png 2048w, https:\/\/cmitsolutions.com\/novasouth-va-1254\/wp-content\/uploads\/sites\/272\/2026\/08\/opt-3-1920x1080.png 1920w\" sizes=\"(max-width: 2240px) 100vw, 2240px\" \/><\/b><\/p>\n<h3><b>1. Written HIPAA Security Risk Analysis<\/b><\/h3>\n<p><span style=\"font-weight: 400\">The Security Rule requires every covered entity to conduct a documented <a href=\"https:\/\/cmitsolutions.com\/novasouth-va-1254\/\"><strong>cybersecurity risk assessment in Manassas<\/strong><\/a> and update it whenever the environment changes. The absence of one is the most common finding in OCR investigations, cited in more than 70 percent of settlement resolutions. Your EHR vendor does not do this for you. It has to cover your entire environment, not just the software they provide.<\/span><\/p>\n<h3><b>2. Multi-factor authentication on every access point<\/b><\/h3>\n<p><span style=\"font-weight: 400\">MFA on the EHR is a start. MFA on email, remote access, VPN, cloud storage, and every administrative account is the requirement. Verizon&#8217;s 2024 Data Breach Investigations Report attributes the majority of healthcare breaches to stolen credentials. MFA closes that door.<\/span><\/p>\n<h3><b>3. Endpoint protection and 24\/7 monitoring<\/b><\/h3>\n<p><span style=\"font-weight: 400\">Every laptop, workstation, and mobile device that accesses patient data needs endpoint detection and response, actively monitored. Antivirus alone does not meet the standard anymore. Ransomware attacks on small clinics increased sharply in the last three years, and the average recovery cost for a small healthcare practice runs well into six figures once downtime, notification, and remediation are combined.<\/span><\/p>\n<h3><b>4. Encrypted email and secure patient communication<\/b><\/h3>\n<p><span style=\"font-weight: 400\">Regular email is not HIPAA-compliant when it carries PHI. A secure patient portal or an encrypted email gateway is required for any exchange of patient information with patients, referring providers, or vendors. Attachments sent over standard email are a breach in progress.<\/span><\/p>\n<h3><b>5. Tested backups outside the EHR environment<\/b><\/h3>\n<p><span style=\"font-weight: 400\">Your EHR vendor backs up their platform for their own operational continuity. That is not the same as a backup you control, encrypted, stored offsite, and restored on a tested schedule. If your EHR vendor goes down, gets breached, or drops your account, an untested backup is not a backup.<\/span><\/p>\n<h3><b>6. Written policies and staff training<\/b><\/h3>\n<p><span style=\"font-weight: 400\">HIPAA requires documented policies covering access, incident response, sanctions, breach notification, and workforce training. Training has to happen at hire and at least annually thereafter, with documentation of who attended and when. OCR asks for the training log first in nearly every audit.<\/span><\/p>\n<h3><b>7. Business Associate Agreements with every vendor touching PHI<\/b><\/h3>\n<p><span style=\"font-weight: 400\">The EHR vendor is one. Your IT provider is another. So is your cloud backup service, your billing service, your transcription vendor, and any consultant with system access. Missing BAAs are a common enforcement finding and one of the easiest to fix before it becomes a problem.<\/span><\/p>\n<h3><b>8. Documented incident response plan<\/b><\/h3>\n<p><span style=\"font-weight: 400\">If a workstation is compromised at 6 pm on a Friday, who does the practice manager call? What gets isolated? What gets logged? Who notifies OCR, and when? The Security Rule requires a written plan, tested at least annually. Most small practices do not have one.<\/span><\/p>\n<h3><b>9. Physical safeguards<\/b><\/h3>\n<p><span style=\"font-weight: 400\">Locked server rooms or wiring closets, screen privacy filters at the front desk, workstation timeouts, and a written policy for device disposal. The Security Rule&#8217;s physical safeguards section is short, but it is enforced, and small practices are often out of compliance without realizing it.<\/span><\/p>\n<h3><b>10. Ongoing compliance documentation<\/b><\/h3>\n<p><span style=\"font-weight: 400\">HIPAA is not a one-time project. Documentation of policies, training, risk analysis, incident response tests, and vendor management has to be maintained continuously and produced on request. If a breach happens, the difference between a small fine and a large one is usually the quality of the documentation.<\/span><\/p>\n<h2><b>What this looks like in practice<\/b><\/h2>\n<p><span style=\"font-weight: 400\">Most Manassas practices we walk through this checklist can honestly check off two or three items. The rest are either partially in place, undocumented, or assumed to be handled by the EHR vendor.<\/span><\/p>\n<p><span style=\"font-weight: 400\">That gap is where enforcement lives. OCR does not send warning letters to small practices. It sends corrective action plans, and those come with monitoring periods, mandatory remediation, and settlement amounts that regularly exceed a full year of managed IT spend.<\/span><\/p>\n<p><span style=\"font-weight: 400\">The checklist above does not require an enterprise budget. It requires a coordinated approach across your EHR, your IT provider, your staff, and your written policies, with one person accountable for making sure all four are working together.<\/span><\/p>\n<h2><b>Working with a local partner<\/b><\/h2>\n<p><span style=\"font-weight: 400\">Most small Manassas practices need an accountable partner who can look at the checklist above, tell them honestly which items are covered and which are not, and close the gaps without turning it into a six-month consulting engagement.<\/span><\/p>\n<p><span style=\"font-weight: 400\">We play that role for healthcare clients across Manassas City and the surrounding counties. Somu Valliappan, our Managing Partner, spent 20+ years in enterprise IT and security across commercial and federal environments before opening CMIT Solutions of NOVA South, and the HIPAA-aligned stack we run for practices is built on that background rather than a generic MSP template.<\/span><\/p>\n<p><span style=\"font-weight: 400\">With 300+ locations across North America, CMIT Solutions is one of the largest managed IT and cybersecurity providers serving independent medical and dental practices in the US. The result is that practices get enterprise-grade protection against ransomware, business email compromise, and vendor breaches without the enterprise price tag.\u00a0<\/span><\/p>\n<p><span style=\"font-weight: 400\">If you want a straight read on where your practice actually stands against this checklist, call (571) 720-9555 or <a href=\"https:\/\/meetings.hubspot.com\/somu-valliappan\/discovery?__hstc=36040575.7259eff40091fb610868daa57c79d722.1785332691180.1787051350774.1787059044517.26&amp;__hssc=36040575.2.1787059044517&amp;__hsfp=cf51673c1f34f9b4f209ca04c3a158fe\"><strong>book a call with Somu<\/strong><\/a>. He will walk you through what is in place, what is missing, and what it would take to close the distance before OCR does it for you.<\/span><\/p>\n<h2><b>Frequently Asked Questions<\/b><\/h2>\n<p><b>Does my EHR vendor cover HIPAA compliance for my practice?<br \/>\n<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400\"> Partially. Your EHR vendor covers the pieces of HIPAA that apply inside their platform. Your network, staff, devices, email, backups, and policies are your responsibility.<\/span><\/p>\n<p><b>What is a HIPAA Security Risk Analysis, and do I need one?<br \/>\n<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400\"> Yes, every covered entity is required to conduct and document one, and update it when the environment changes. It is the single most common finding in OCR enforcement actions.<\/span><\/p>\n<p><b>What happens if a small practice has a HIPAA breach?<br \/>\n<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400\"> The practice is required to notify affected patients, HHS, and in some cases the media. Fines range from a few thousand dollars to seven figures depending on severity, documentation quality, and cooperation with investigators.<\/span><\/p>\n<p><b>Is regular email HIPAA-compliant if I only send PHI to trusted people?<br \/>\n<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400\"> No. Regular email is not HIPAA-compliant regardless of the recipient. A secure portal or encrypted email gateway is required.<\/span><\/p>\n<p><b>Do I need a Business Associate Agreement with my IT provider?<br \/>\n<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400\"> Yes. Any vendor with access to systems that store or transmit PHI needs a signed BAA. That includes your IT provider, your cloud backup service, and any consultant with system access.<\/span><\/p>\n<p><b>How often does HIPAA training need to happen?<br \/>\n<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400\"> At hire, and at least annually after that, with documentation of who attended and when. Training logs are one of the first things OCR asks for in an audit.<\/span><\/p>\n<p><b>Can a small practice be HIPAA-compliant with cloud-based software?<br \/>\n<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400\"> Yes, if the software vendor signs a BAA, the practice enforces MFA and access controls, and the practice maintains its own tested backup outside the vendor&#8217;s environment.<\/span><\/p>\n<p><b>How do I know if my practice is actually HIPAA-compliant?<br \/>\n<\/b><b><br \/>\n<\/b><span style=\"font-weight: 400\"> Work through the checklist above. If you cannot produce documentation for each item, you are not fully compliant, regardless of what your EHR vendor claims.<\/span><\/p>\n","protected":false},"excerpt":{"rendered":"<p>Ask a Manassas practice manager who handles HIPAA compliance for their office,&#8230;<\/p>\n","protected":false},"author":1074,"featured_media":695,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"footnotes":""},"categories":[1],"tags":[],"class_list":["post-694","post","type-post","status-publish","format-standard","has-post-thumbnail","hentry","category-local-it"],"aioseo_notices":[],"aioseo_head":"\n\t\t<!-- All in One SEO Pro 5.0.1.1 - aioseo.com -->\n\t<meta name=\"description\" content=\"Ask a Manassas practice manager who handles HIPAA compliance for their office, and the answer is usually the same. The EHR vendor or billing platform, whichever software company sends the biggest invoice. That answer is wrong, and it is the single most expensive misunderstanding in small healthcare cybersecurity today. In April 2025, attackers spent nearly a\" \/>\n\t<meta name=\"robots\" content=\"max-image-preview:large\" \/>\n\t<meta name=\"author\" content=\"agroie\"\/>\n\t<meta name=\"google-site-verification\" content=\"3lRCz6OHh_cx7XgCiFFswLnNZ6ChXgx3IxZKpTa69yA\" \/>\n\t<link rel=\"canonical\" href=\"https:\/\/cmitsolutions.com\/novasouth-va-1254\/blog\/hipaa-cybersecurity-checklist-manassas-medical-practices\/\" \/>\n\t<meta name=\"generator\" content=\"All in One SEO Pro (AIOSEO) 5.0.1.1\" \/>\n\t\t<meta property=\"og:locale\" content=\"en_US\" \/>\n\t\t<meta property=\"og:site_name\" content=\"NOVA South, VA 1254 | CMIT Solutions\" \/>\n\t\t<meta property=\"og:type\" content=\"article\" \/>\n\t\t<meta property=\"og:title\" content=\"Small Manassas Medical Practice\u2019s HIPAA Cybersecurity Checklist: What Your EHR Vendor Isn\u2019t Covering | CMIT Solutions NOVA South\" \/>\n\t\t<meta property=\"og:description\" content=\"Ask a Manassas practice manager who handles HIPAA compliance for their office, and the answer is usually the same. The EHR vendor or billing platform, whichever software company sends the biggest invoice. That answer is wrong, and it is the single most expensive misunderstanding in small healthcare cybersecurity today. In April 2025, attackers spent nearly a\" \/>\n\t\t<meta property=\"og:url\" content=\"https:\/\/cmitsolutions.com\/novasouth-va-1254\/blog\/hipaa-cybersecurity-checklist-manassas-medical-practices\/\" \/>\n\t\t<meta property=\"article:published_time\" content=\"2026-08-18T13:20:03+00:00\" \/>\n\t\t<meta property=\"article:modified_time\" content=\"2026-08-18T13:20:03+00:00\" \/>\n\t\t<meta name=\"twitter:card\" content=\"summary_large_image\" \/>\n\t\t<meta name=\"twitter:title\" content=\"Small Manassas Medical Practice\u2019s HIPAA Cybersecurity Checklist: What Your EHR Vendor Isn\u2019t Covering | CMIT Solutions NOVA South\" \/>\n\t\t<meta name=\"twitter:description\" content=\"Ask a Manassas practice manager who handles HIPAA compliance for their office, and the answer is usually the same. The EHR vendor or billing platform, whichever software company sends the biggest invoice. That answer is wrong, and it is the single most expensive misunderstanding in small healthcare cybersecurity today. In April 2025, attackers spent nearly a\" \/>\n\t\t<script type=\"application\/ld+json\" class=\"aioseo-schema\">\n\t\t\t{\"@context\":\"https:\\\/\\\/schema.org\",\"@graph\":[{\"@type\":\"BlogPosting\",\"@id\":\"https:\\\/\\\/cmitsolutions.com\\\/novasouth-va-1254\\\/blog\\\/hipaa-cybersecurity-checklist-manassas-medical-practices\\\/#blogposting\",\"name\":\"Small Manassas Medical Practice\\u2019s HIPAA Cybersecurity Checklist: What Your EHR Vendor Isn\\u2019t Covering | CMIT Solutions NOVA South\",\"headline\":\"Small Manassas Medical Practice&#8217;s HIPAA Cybersecurity Checklist: What Your EHR Vendor Isn&#8217;t Covering\",\"author\":{\"@id\":\"https:\\\/\\\/cmitsolutions.com\\\/novasouth-va-1254\\\/blog\\\/author\\\/agroie\\\/#author\"},\"publisher\":{\"@id\":\"https:\\\/\\\/cmitsolutions.com\\\/novasouth-va-1254\\\/#organization\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/cmitsolutions.com\\\/novasouth-va-1254\\\/wp-content\\\/uploads\\\/sites\\\/272\\\/2026\\\/08\\\/Small-Manassas-Medical-Practices-HIPAA.png\",\"width\":2240,\"height\":1260,\"caption\":\"HIPAA-cybersecurity-checklist-for-small-Manassas-medical-practices\"},\"datePublished\":\"2026-08-18T08:20:03-05:00\",\"dateModified\":\"2026-08-18T08:20:03-05:00\",\"inLanguage\":\"en-US\",\"mainEntityOfPage\":{\"@id\":\"https:\\\/\\\/cmitsolutions.com\\\/novasouth-va-1254\\\/blog\\\/hipaa-cybersecurity-checklist-manassas-medical-practices\\\/#webpage\"},\"isPartOf\":{\"@id\":\"https:\\\/\\\/cmitsolutions.com\\\/novasouth-va-1254\\\/blog\\\/hipaa-cybersecurity-checklist-manassas-medical-practices\\\/#webpage\"},\"articleSection\":\"Local IT\"},{\"@type\":\"BreadcrumbList\",\"@id\":\"https:\\\/\\\/cmitsolutions.com\\\/novasouth-va-1254\\\/blog\\\/hipaa-cybersecurity-checklist-manassas-medical-practices\\\/#breadcrumblist\",\"itemListElement\":[{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/cmitsolutions.com\\\/novasouth-va-1254#listItem\",\"position\":1,\"name\":\"Home\",\"item\":\"https:\\\/\\\/cmitsolutions.com\\\/novasouth-va-1254\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/cmitsolutions.com\\\/novasouth-va-1254\\\/blog\\\/category\\\/local-it\\\/#listItem\",\"name\":\"Local IT\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/cmitsolutions.com\\\/novasouth-va-1254\\\/blog\\\/category\\\/local-it\\\/#listItem\",\"position\":2,\"name\":\"Local IT\",\"item\":\"https:\\\/\\\/cmitsolutions.com\\\/novasouth-va-1254\\\/blog\\\/category\\\/local-it\\\/\",\"nextItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/cmitsolutions.com\\\/novasouth-va-1254\\\/blog\\\/hipaa-cybersecurity-checklist-manassas-medical-practices\\\/#listItem\",\"name\":\"Small Manassas Medical Practice&#8217;s HIPAA Cybersecurity Checklist: What Your EHR Vendor Isn&#8217;t Covering\"},\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/cmitsolutions.com\\\/novasouth-va-1254#listItem\",\"name\":\"Home\"}},{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/cmitsolutions.com\\\/novasouth-va-1254\\\/blog\\\/hipaa-cybersecurity-checklist-manassas-medical-practices\\\/#listItem\",\"position\":3,\"name\":\"Small Manassas Medical Practice&#8217;s HIPAA Cybersecurity Checklist: What Your EHR Vendor Isn&#8217;t Covering\",\"previousItem\":{\"@type\":\"ListItem\",\"@id\":\"https:\\\/\\\/cmitsolutions.com\\\/novasouth-va-1254\\\/blog\\\/category\\\/local-it\\\/#listItem\",\"name\":\"Local IT\"}}]},{\"@type\":\"Organization\",\"@id\":\"https:\\\/\\\/cmitsolutions.com\\\/novasouth-va-1254\\\/#organization\",\"name\":\"CMIT Solutions NOVA South\",\"description\":\"CMIT Solutions\",\"url\":\"https:\\\/\\\/cmitsolutions.com\\\/novasouth-va-1254\\\/\",\"logo\":{\"@type\":\"ImageObject\",\"url\":\"http:\\\/\\\/cmitsolutions.com\\\/template\\\/wp-content\\\/uploads\\\/sites\\\/2\\\/2022\\\/09\\\/CMMIT-Solutions-Logo.png\",\"@id\":\"https:\\\/\\\/cmitsolutions.com\\\/novasouth-va-1254\\\/blog\\\/hipaa-cybersecurity-checklist-manassas-medical-practices\\\/#organizationLogo\"},\"image\":{\"@id\":\"https:\\\/\\\/cmitsolutions.com\\\/novasouth-va-1254\\\/blog\\\/hipaa-cybersecurity-checklist-manassas-medical-practices\\\/#organizationLogo\"}},{\"@type\":\"Person\",\"@id\":\"https:\\\/\\\/cmitsolutions.com\\\/novasouth-va-1254\\\/blog\\\/author\\\/agroie\\\/#author\",\"url\":\"https:\\\/\\\/cmitsolutions.com\\\/novasouth-va-1254\\\/blog\\\/author\\\/agroie\\\/\",\"name\":\"agroie\",\"image\":{\"@type\":\"ImageObject\",\"@id\":\"https:\\\/\\\/cmitsolutions.com\\\/novasouth-va-1254\\\/blog\\\/hipaa-cybersecurity-checklist-manassas-medical-practices\\\/#authorImage\",\"url\":\"https:\\\/\\\/secure.gravatar.com\\\/avatar\\\/15f590642c85e746d631881d4dc18d411e6ea60edb6270af56bfec6a8a16269d?s=96&d=mm&r=g\",\"width\":96,\"height\":96,\"caption\":\"agroie\"}},{\"@type\":\"WebPage\",\"@id\":\"https:\\\/\\\/cmitsolutions.com\\\/novasouth-va-1254\\\/blog\\\/hipaa-cybersecurity-checklist-manassas-medical-practices\\\/#webpage\",\"url\":\"https:\\\/\\\/cmitsolutions.com\\\/novasouth-va-1254\\\/blog\\\/hipaa-cybersecurity-checklist-manassas-medical-practices\\\/\",\"name\":\"Small Manassas Medical Practice\\u2019s HIPAA Cybersecurity Checklist: What Your EHR Vendor Isn\\u2019t Covering | CMIT Solutions NOVA South\",\"description\":\"Ask a Manassas practice manager who handles HIPAA compliance for their office, and the answer is usually the same. The EHR vendor or billing platform, whichever software company sends the biggest invoice. That answer is wrong, and it is the single most expensive misunderstanding in small healthcare cybersecurity today. In April 2025, attackers spent nearly a\",\"inLanguage\":\"en-US\",\"isPartOf\":{\"@id\":\"https:\\\/\\\/cmitsolutions.com\\\/novasouth-va-1254\\\/#website\"},\"breadcrumb\":{\"@id\":\"https:\\\/\\\/cmitsolutions.com\\\/novasouth-va-1254\\\/blog\\\/hipaa-cybersecurity-checklist-manassas-medical-practices\\\/#breadcrumblist\"},\"author\":{\"@id\":\"https:\\\/\\\/cmitsolutions.com\\\/novasouth-va-1254\\\/blog\\\/author\\\/agroie\\\/#author\"},\"creator\":{\"@id\":\"https:\\\/\\\/cmitsolutions.com\\\/novasouth-va-1254\\\/blog\\\/author\\\/agroie\\\/#author\"},\"image\":{\"@type\":\"ImageObject\",\"url\":\"https:\\\/\\\/cmitsolutions.com\\\/novasouth-va-1254\\\/wp-content\\\/uploads\\\/sites\\\/272\\\/2026\\\/08\\\/Small-Manassas-Medical-Practices-HIPAA.png\",\"@id\":\"https:\\\/\\\/cmitsolutions.com\\\/novasouth-va-1254\\\/blog\\\/hipaa-cybersecurity-checklist-manassas-medical-practices\\\/#mainImage\",\"width\":2240,\"height\":1260,\"caption\":\"HIPAA-cybersecurity-checklist-for-small-Manassas-medical-practices\"},\"primaryImageOfPage\":{\"@id\":\"https:\\\/\\\/cmitsolutions.com\\\/novasouth-va-1254\\\/blog\\\/hipaa-cybersecurity-checklist-manassas-medical-practices\\\/#mainImage\"},\"datePublished\":\"2026-08-18T08:20:03-05:00\",\"dateModified\":\"2026-08-18T08:20:03-05:00\"},{\"@type\":\"WebSite\",\"@id\":\"https:\\\/\\\/cmitsolutions.com\\\/novasouth-va-1254\\\/#website\",\"url\":\"https:\\\/\\\/cmitsolutions.com\\\/novasouth-va-1254\\\/\",\"name\":\"CMIT Solutions NOVA South\",\"description\":\"CMIT Solutions\",\"inLanguage\":\"en-US\",\"publisher\":{\"@id\":\"https:\\\/\\\/cmitsolutions.com\\\/novasouth-va-1254\\\/#organization\"}}]}\n\t\t<\/script>\n\t\t<script type=\"text\/javascript\">\n\t\t\t(function(c,l,a,r,i,t,y){\n\t\t\tc[a]=c[a]||function(){(c[a].q=c[a].q||[]).push(arguments)};t=l.createElement(r);t.async=1;\n\t\t\tt.src=\"https:\/\/www.clarity.ms\/tag\/\"+i+\"?ref=aioseo\";y=l.getElementsByTagName(r)[0];y.parentNode.insertBefore(t,y);\n\t\t})(window, document, \"clarity\", \"script\", \"xp9jgeq79n\");\n\t\t<\/script>\n\t\t<script>(function(w,d,s,l,i){w[l]=w[l]||[];w[l].push({'gtm.start': new Date().getTime(),event:'gtm.js'});var f=d.getElementsByTagName(s)[0], j=d.createElement(s),dl=l!='dataLayer'?'&l='+l:'';j.async=true;j.src='https:\/\/www.googletagmanager.com\/gtm.js?id='+i+dl;f.parentNode.insertBefore(j,f);})(window,document,'script','dataLayer',\"GTM-N223FQ8T\");<\/script>\n\t\t<!-- All in One SEO Pro -->\r\n\t\t<title>Small Manassas Medical Practice\u2019s HIPAA Cybersecurity Checklist: What Your EHR Vendor Isn\u2019t Covering | CMIT Solutions NOVA South<\/title>\n\n","aioseo_head_json":{"title":"Small Manassas Medical Practice\u2019s HIPAA Cybersecurity Checklist: What Your EHR Vendor Isn\u2019t Covering | CMIT Solutions NOVA South","description":"Ask a Manassas practice manager who handles HIPAA compliance for their office, and the answer is usually the same. The EHR vendor or billing platform, whichever software company sends the biggest invoice. That answer is wrong, and it is the single most expensive misunderstanding in small healthcare cybersecurity today. In April 2025, attackers spent nearly a","canonical_url":"https:\/\/cmitsolutions.com\/novasouth-va-1254\/blog\/hipaa-cybersecurity-checklist-manassas-medical-practices\/","robots":"max-image-preview:large","keywords":"","webmasterTools":{"google-site-verification":"3lRCz6OHh_cx7XgCiFFswLnNZ6ChXgx3IxZKpTa69yA","miscellaneous":""},"schema":{"@context":"https:\/\/schema.org","@graph":[{"@type":"BlogPosting","@id":"https:\/\/cmitsolutions.com\/novasouth-va-1254\/blog\/hipaa-cybersecurity-checklist-manassas-medical-practices\/#blogposting","name":"Small Manassas Medical Practice\u2019s HIPAA Cybersecurity Checklist: What Your EHR Vendor Isn\u2019t Covering | CMIT Solutions NOVA South","headline":"Small Manassas Medical Practice&#8217;s HIPAA Cybersecurity Checklist: What Your EHR Vendor Isn&#8217;t Covering","author":{"@id":"https:\/\/cmitsolutions.com\/novasouth-va-1254\/blog\/author\/agroie\/#author"},"publisher":{"@id":"https:\/\/cmitsolutions.com\/novasouth-va-1254\/#organization"},"image":{"@type":"ImageObject","url":"https:\/\/cmitsolutions.com\/novasouth-va-1254\/wp-content\/uploads\/sites\/272\/2026\/08\/Small-Manassas-Medical-Practices-HIPAA.png","width":2240,"height":1260,"caption":"HIPAA-cybersecurity-checklist-for-small-Manassas-medical-practices"},"datePublished":"2026-08-18T08:20:03-05:00","dateModified":"2026-08-18T08:20:03-05:00","inLanguage":"en-US","mainEntityOfPage":{"@id":"https:\/\/cmitsolutions.com\/novasouth-va-1254\/blog\/hipaa-cybersecurity-checklist-manassas-medical-practices\/#webpage"},"isPartOf":{"@id":"https:\/\/cmitsolutions.com\/novasouth-va-1254\/blog\/hipaa-cybersecurity-checklist-manassas-medical-practices\/#webpage"},"articleSection":"Local IT"},{"@type":"BreadcrumbList","@id":"https:\/\/cmitsolutions.com\/novasouth-va-1254\/blog\/hipaa-cybersecurity-checklist-manassas-medical-practices\/#breadcrumblist","itemListElement":[{"@type":"ListItem","@id":"https:\/\/cmitsolutions.com\/novasouth-va-1254#listItem","position":1,"name":"Home","item":"https:\/\/cmitsolutions.com\/novasouth-va-1254","nextItem":{"@type":"ListItem","@id":"https:\/\/cmitsolutions.com\/novasouth-va-1254\/blog\/category\/local-it\/#listItem","name":"Local IT"}},{"@type":"ListItem","@id":"https:\/\/cmitsolutions.com\/novasouth-va-1254\/blog\/category\/local-it\/#listItem","position":2,"name":"Local IT","item":"https:\/\/cmitsolutions.com\/novasouth-va-1254\/blog\/category\/local-it\/","nextItem":{"@type":"ListItem","@id":"https:\/\/cmitsolutions.com\/novasouth-va-1254\/blog\/hipaa-cybersecurity-checklist-manassas-medical-practices\/#listItem","name":"Small Manassas Medical Practice&#8217;s HIPAA Cybersecurity Checklist: What Your EHR Vendor Isn&#8217;t Covering"},"previousItem":{"@type":"ListItem","@id":"https:\/\/cmitsolutions.com\/novasouth-va-1254#listItem","name":"Home"}},{"@type":"ListItem","@id":"https:\/\/cmitsolutions.com\/novasouth-va-1254\/blog\/hipaa-cybersecurity-checklist-manassas-medical-practices\/#listItem","position":3,"name":"Small Manassas Medical Practice&#8217;s HIPAA Cybersecurity Checklist: What Your EHR Vendor Isn&#8217;t Covering","previousItem":{"@type":"ListItem","@id":"https:\/\/cmitsolutions.com\/novasouth-va-1254\/blog\/category\/local-it\/#listItem","name":"Local IT"}}]},{"@type":"Organization","@id":"https:\/\/cmitsolutions.com\/novasouth-va-1254\/#organization","name":"CMIT Solutions NOVA South","description":"CMIT Solutions","url":"https:\/\/cmitsolutions.com\/novasouth-va-1254\/","logo":{"@type":"ImageObject","url":"http:\/\/cmitsolutions.com\/template\/wp-content\/uploads\/sites\/2\/2022\/09\/CMMIT-Solutions-Logo.png","@id":"https:\/\/cmitsolutions.com\/novasouth-va-1254\/blog\/hipaa-cybersecurity-checklist-manassas-medical-practices\/#organizationLogo"},"image":{"@id":"https:\/\/cmitsolutions.com\/novasouth-va-1254\/blog\/hipaa-cybersecurity-checklist-manassas-medical-practices\/#organizationLogo"}},{"@type":"Person","@id":"https:\/\/cmitsolutions.com\/novasouth-va-1254\/blog\/author\/agroie\/#author","url":"https:\/\/cmitsolutions.com\/novasouth-va-1254\/blog\/author\/agroie\/","name":"agroie","image":{"@type":"ImageObject","@id":"https:\/\/cmitsolutions.com\/novasouth-va-1254\/blog\/hipaa-cybersecurity-checklist-manassas-medical-practices\/#authorImage","url":"https:\/\/secure.gravatar.com\/avatar\/15f590642c85e746d631881d4dc18d411e6ea60edb6270af56bfec6a8a16269d?s=96&d=mm&r=g","width":96,"height":96,"caption":"agroie"}},{"@type":"WebPage","@id":"https:\/\/cmitsolutions.com\/novasouth-va-1254\/blog\/hipaa-cybersecurity-checklist-manassas-medical-practices\/#webpage","url":"https:\/\/cmitsolutions.com\/novasouth-va-1254\/blog\/hipaa-cybersecurity-checklist-manassas-medical-practices\/","name":"Small Manassas Medical Practice\u2019s HIPAA Cybersecurity Checklist: What Your EHR Vendor Isn\u2019t Covering | CMIT Solutions NOVA South","description":"Ask a Manassas practice manager who handles HIPAA compliance for their office, and the answer is usually the same. The EHR vendor or billing platform, whichever software company sends the biggest invoice. That answer is wrong, and it is the single most expensive misunderstanding in small healthcare cybersecurity today. In April 2025, attackers spent nearly a","inLanguage":"en-US","isPartOf":{"@id":"https:\/\/cmitsolutions.com\/novasouth-va-1254\/#website"},"breadcrumb":{"@id":"https:\/\/cmitsolutions.com\/novasouth-va-1254\/blog\/hipaa-cybersecurity-checklist-manassas-medical-practices\/#breadcrumblist"},"author":{"@id":"https:\/\/cmitsolutions.com\/novasouth-va-1254\/blog\/author\/agroie\/#author"},"creator":{"@id":"https:\/\/cmitsolutions.com\/novasouth-va-1254\/blog\/author\/agroie\/#author"},"image":{"@type":"ImageObject","url":"https:\/\/cmitsolutions.com\/novasouth-va-1254\/wp-content\/uploads\/sites\/272\/2026\/08\/Small-Manassas-Medical-Practices-HIPAA.png","@id":"https:\/\/cmitsolutions.com\/novasouth-va-1254\/blog\/hipaa-cybersecurity-checklist-manassas-medical-practices\/#mainImage","width":2240,"height":1260,"caption":"HIPAA-cybersecurity-checklist-for-small-Manassas-medical-practices"},"primaryImageOfPage":{"@id":"https:\/\/cmitsolutions.com\/novasouth-va-1254\/blog\/hipaa-cybersecurity-checklist-manassas-medical-practices\/#mainImage"},"datePublished":"2026-08-18T08:20:03-05:00","dateModified":"2026-08-18T08:20:03-05:00"},{"@type":"WebSite","@id":"https:\/\/cmitsolutions.com\/novasouth-va-1254\/#website","url":"https:\/\/cmitsolutions.com\/novasouth-va-1254\/","name":"CMIT Solutions NOVA South","description":"CMIT Solutions","inLanguage":"en-US","publisher":{"@id":"https:\/\/cmitsolutions.com\/novasouth-va-1254\/#organization"}}]},"og:locale":"en_US","og:site_name":"NOVA South, VA 1254 | CMIT Solutions","og:type":"article","og:title":"Small Manassas Medical Practice\u2019s HIPAA Cybersecurity Checklist: What Your EHR Vendor Isn\u2019t Covering | CMIT Solutions NOVA South","og:description":"Ask a Manassas practice manager who handles HIPAA compliance for their office, and the answer is usually the same. The EHR vendor or billing platform, whichever software company sends the biggest invoice. That answer is wrong, and it is the single most expensive misunderstanding in small healthcare cybersecurity today. In April 2025, attackers spent nearly a","og:url":"https:\/\/cmitsolutions.com\/novasouth-va-1254\/blog\/hipaa-cybersecurity-checklist-manassas-medical-practices\/","article:published_time":"2026-08-18T13:20:03+00:00","article:modified_time":"2026-08-18T13:20:03+00:00","twitter:card":"summary_large_image","twitter:title":"Small Manassas Medical Practice\u2019s HIPAA Cybersecurity Checklist: What Your EHR Vendor Isn\u2019t Covering | CMIT Solutions NOVA South","twitter:description":"Ask a Manassas practice manager who handles HIPAA compliance for their office, and the answer is usually the same. The EHR vendor or billing platform, whichever software company sends the biggest invoice. That answer is wrong, and it is the single most expensive misunderstanding in small healthcare cybersecurity today. In April 2025, attackers spent nearly a"},"aioseo_meta_data":{"post_id":"694","title":null,"description":null,"keywords":null,"keyphrases":{"focus":{"keyphrase":"","score":0,"analysis":{"keyphraseInTitle":{"score":0,"maxScore":9,"error":1}}},"additional":[]},"primary_term":null,"canonical_url":null,"og_title":null,"og_description":null,"og_object_type":"default","og_image_type":"default","og_image_url":null,"og_image_width":null,"og_image_height":null,"og_image_custom_url":null,"og_image_custom_fields":null,"og_video":"","og_custom_url":null,"og_article_section":null,"og_article_tags":null,"twitter_use_og":false,"twitter_card":"default","twitter_image_type":"default","twitter_image_url":null,"twitter_image_custom_url":null,"twitter_image_custom_fields":null,"twitter_title":null,"twitter_description":null,"schema":{"blockGraphs":[],"customGraphs":[],"default":{"data":{"Article":[],"Course":[],"Dataset":[],"FAQPage":[],"Movie":[],"Person":[],"Product":[],"ProductReview":[],"Car":[],"Recipe":[],"Service":[],"SoftwareApplication":[],"WebPage":[]},"graphName":"BlogPosting","isEnabled":true},"graphs":[]},"schema_type":"default","schema_type_options":null,"pillar_content":false,"robots_default":true,"robots_noindex":false,"robots_noarchive":false,"robots_nosnippet":false,"robots_nofollow":false,"robots_noimageindex":false,"robots_noodp":false,"robots_notranslate":false,"robots_max_snippet":"-1","robots_max_videopreview":"-1","robots_max_imagepreview":"large","priority":null,"frequency":"default","local_seo":null,"breadcrumb_settings":null,"limit_modified_date":false,"open_ai":null,"ai":{"faqs":[],"keyPoints":[],"schemas":[],"titles":[],"descriptions":[],"socialPosts":{"email":{"subject":"","preview":"","content":""},"linkedin":[],"twitter":[],"facebook":[],"instagram":[]}},"created":"2026-08-18 13:01:54","updated":"2026-08-18 15:37:07","seo_analyzer_scan_date":"2026-08-18 13:23:02","focus_keyword":null,"additional_keywords":null,"truseo_locale":null},"aioseo_breadcrumb":"<div class=\"aioseo-breadcrumbs\"><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/cmitsolutions.com\/novasouth-va-1254\" title=\"Home\">Home<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">\u00bb<\/span><span class=\"aioseo-breadcrumb\">\n\t<a href=\"https:\/\/cmitsolutions.com\/novasouth-va-1254\/blog\/category\/local-it\/\" title=\"Local IT\">Local IT<\/a>\n<\/span><span class=\"aioseo-breadcrumb-separator\">\u00bb<\/span><span class=\"aioseo-breadcrumb\">\n\tSmall Manassas Medical Practice\u2019s HIPAA Cybersecurity Checklist: What Your EHR Vendor Isn\u2019t Covering\n<\/span><\/div>","aioseo_breadcrumb_json":[{"label":"Home","link":"https:\/\/cmitsolutions.com\/novasouth-va-1254"},{"label":"Local IT","link":"https:\/\/cmitsolutions.com\/novasouth-va-1254\/blog\/category\/local-it\/"},{"label":"Small Manassas Medical Practice&#8217;s HIPAA Cybersecurity Checklist: What Your EHR Vendor Isn&#8217;t Covering","link":"https:\/\/cmitsolutions.com\/novasouth-va-1254\/blog\/hipaa-cybersecurity-checklist-manassas-medical-practices\/"}],"_links":{"self":[{"href":"https:\/\/cmitsolutions.com\/novasouth-va-1254\/wp-json\/wp\/v2\/posts\/694","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/cmitsolutions.com\/novasouth-va-1254\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"https:\/\/cmitsolutions.com\/novasouth-va-1254\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"https:\/\/cmitsolutions.com\/novasouth-va-1254\/wp-json\/wp\/v2\/users\/1074"}],"replies":[{"embeddable":true,"href":"https:\/\/cmitsolutions.com\/novasouth-va-1254\/wp-json\/wp\/v2\/comments?post=694"}],"version-history":[{"count":0,"href":"https:\/\/cmitsolutions.com\/novasouth-va-1254\/wp-json\/wp\/v2\/posts\/694\/revisions"}],"wp:featuredmedia":[{"embeddable":true,"href":"https:\/\/cmitsolutions.com\/novasouth-va-1254\/wp-json\/wp\/v2\/media\/695"}],"wp:attachment":[{"href":"https:\/\/cmitsolutions.com\/novasouth-va-1254\/wp-json\/wp\/v2\/media?parent=694"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"https:\/\/cmitsolutions.com\/novasouth-va-1254\/wp-json\/wp\/v2\/categories?post=694"},{"taxonomy":"post_tag","embeddable":true,"href":"https:\/\/cmitsolutions.com\/novasouth-va-1254\/wp-json\/wp\/v2\/tags?post=694"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}