Protect patient information without running an IT department
Dental, medical, therapy and specialty practices carry serious responsibility for patient information. We help small practices meet it in plain English.
Patients trust your office, and so do the people who would fake it
-
HIPAA applies at any size
Federal HIPAA rules require every covered practice, whatever its size, to have a documented security risk analysis. Many small practices have one that is out of date, or never got written. -
Fake emails that look like yours
Many small offices never finish the setup that tells other mail servers to reject messages faking their domain. A patient could get an email that looks like it came from your office, asking them to update their insurance information. -
Equipment and outside vendors
Practice software, imaging equipment and patient-form vendors all touch your network. Someone should know what is connected and who supports it.
What cyber insurers increasingly ask about
-
Sign-in protection
Multi-factor sign-in on email and remote access. -
Current, supported software
Every computer patched, and nothing running that its maker has stopped supporting. -
Backups that work
Copies kept separate from your network, and a restore that has actually been tested. -
Staff awareness
Training and practice spotting fake emails. -
A plan for a bad day
Who does what if something goes wrong.
Cyber insurance applications increasingly ask about these controls. We help you answer honestly, and close the gaps.
Plain answers, in plain English
The assessment gives you a clear, plain-English starting point for the written security risk analysis HIPAA asks for. Before we look at any system that holds patient information, we put a Business Associate Agreement in place.
Computers and software
Which machines are patched, which software is out of date or unsupported, and where the real risk sits.
Email and sign-in
Whether your domain can be faked, how mailboxes are protected, and whether multi-factor sign-in is on where it matters.
Backups and recovery
Whether you could get back to work after ransomware or a failed server, and whether anyone has ever tested a restore.
PineLinx provides technology services, not legal advice.
Find out where your practice stands
A free, no-obligation assessment with a plain-English report. Nothing is installed or scanned without your written OK.