Cybersecurity for medical practices
Protect your patients. Keep your practice moving.
Fractional CISO and HIPAA security advisory services for practices that need experienced guidance without hiring a full-time security executive.
I work with the owner, the practice administrator and your IT team or MSP to identify risks, prioritize improvements and strengthen your readiness.
What you get
Understand where you're exposed
A clear view of the risks to patient care, income and trust.
Know what to fix first
Improvements ranked by what matters most to the practice.
An advisor coordinating the work
One person keeping the plan moving with your team and IT.
The practice reality
Your day is full before cybersecurity enters the conversation.
Most practices I talk with are well run. Security just lands on people who already have full jobs. These are situations worth assessing, not signs that something is wrong:
The practice administrator also coordinates IT issues and compliance paperwork.
A departing employee's access spans several systems and vendors.
An insurance application asks questions the owner can't confidently answer.
A new location, EHR, telehealth service or AI scribe brings decisions nobody clearly owns.
Staff know backups exist but have never seen a recovery exercise.
What you get: coordinated guidance and a plan your administrator can actually manage.
Operational impact
A security incident can interrupt the entire practice day.
Care slows down
Charts, schedules, imaging or treatment information become unavailable.
Cash slows down
Claims, payments, eligibility checks and authorizations are delayed.
Staff get pulled away
Your team shifts to manual work and fielding patient calls.
Capacity is lost
Appointments are canceled and recovery adds costs.
Trust is tested
You face hard conversations about patient information.
80%
of responding practices lost revenue from unpaid claims after the 2024 Change Healthcare cyberattack.
85% had to commit additional staff time or resources to revenue cycle tasks. Most responses came from practices with fewer than 10 physicians. These practices weren't attacked themselves. The disruption came through a vendor.
The lesson: a practice can be seriously disrupted through a vendor, even when its own systems weren't attacked.
Common questions
Questions practice owners are right to ask.
“Our IT company handles security.”
IT providers often handle important protections. The question is who owns the practice-wide pieces: the risk assessment, policies, staff responsibilities, vendor oversight and incident decisions. My work complements the services your IT provider is contracted to deliver.
“We're too small to be affected.”
Size doesn't keep a practice off the list. See the example below.
“Our EHR vendor says it's HIPAA compliant.”
Your vendor is responsible for its systems. Your practice is still responsible for its workforce, accounts, devices, how patient information is handled and your other systems.
“We completed a risk assessment years ago.”
New vendors, locations, staff and technology change the picture. HHS expects risk analysis to be ongoing and updated as your practice changes.
“We have backups, so we can recover.”
Good start. Has recovery been tested, and do you know which services can keep running during an outage?
In February 2024, HHS announced a settlement with Green Ridge Behavioral Health, an outpatient mental health group practice, after a ransomware attack affecting more than 14,000 patients. The practice agreed to pay $40,000 and follow a three-year corrective action plan that includes risk analysis, risk management, updated policies, workforce training and review of system activity.
Source: HHS, Green Ridge Behavioral Health resolution agreement
Why work with me
Before I was a CISO, I was a CEO.
When I was a CEO, I made the calls on payroll, staffing, customer commitments and budgets, and I doubled revenue from $2.5 million to more than $5 million. I know what it's like to run a business with a full schedule and a limited budget.
Today I bring healthcare security leadership to practices like yours, and you work with me directly.
How I translate findings
The security finding
The business question
A billing system your practice depends on
What happens to cash flow if it goes down for a week?
A gap in who can access patient records
Is patient confidentiality at risk?
A recovery process that's never been tested
How many appointments would we have to cancel?
What you can expect
Fractional leadership
Security leadership that fits your practice.
A fractional CISO is an experienced security leader who works with your practice on an agreed part-time basis.
For owners
Business-focused advice on priorities, investment and open risks.
For administrators
A coordinated action plan, usable policies, organized documentation and help managing the work.
For clinical teams
Guidance that respects patient care and everyday workflows.
For IT or your MSP
Clear priorities, agreed responsibilities and coordinated implementation.
You can start with an assessment and add ongoing leadership when it makes sense. Scope and fees are agreed in writing, including any technical implementation costs that sit outside advisory fees.
Risk assessment and roadmap
Start with a clear picture of your practice's risks.
Map patient information
Where electronic patient information is created, stored, accessed and shared.
Review safeguards
Administrative, physical and technical safeguards, well beyond the EHR.
Document findings and a roadmap
Priorities, owners, timing and recommended actions for each finding.
Track follow-through
Findings only help if someone tracks them to completion.
Every roadmap item includes
My recommendation: a documented assessment and review every year, plus a reassessment after significant changes or an incident. HHS doesn't set a fixed schedule, but it expects risk analysis to be ongoing and updated as needed.
The benefit: owners can make informed investment decisions, and administrators can see what needs to happen next.
Source: HHS, Guidance on Risk Analysis
HIPAA Security Rule
Make HIPAA security part of how your practice operates.
The practical questions we answer together
Who is responsible for security?
Who can access patient information?
How are staff trained, and how are access changes managed?
How are devices and work areas protected?
How are system activity and incidents reviewed?
What happens when essential systems are unavailable?
Which vendors need business associate agreements?
Safeguards should reflect your practice's size, capabilities and risks. Every policy connects to a procedure staff can follow and documentation you can keep up.
HHS has proposed changes to the HIPAA Security Rule. I keep current requirements separate from proposed ones, so you know what applies today and what may be coming.
Care settings
Different care settings. Guidance built around your work.
Primary care
Plans for unavailable charts, prescription workflows, lab results and billing systems.
Dental
Practice-management software, digital imaging, shared workstations and vendor remote access.
Behavioral health
Telehealth, remote documentation, sensitive records and access that fits each staff role.
Pediatrics
Portal proxy access and workflows involving parents, guardians and adolescent confidentiality, with legal questions coordinated with your counsel.
Home health and hospice
Field devices, remote access, lost-device response, care coordination and access to essential information during outages.
Orthopedics and other specialties
Imaging, referral exchanges, connected systems and dependencies across locations.
These are examples of what an assessment looks at, not assumptions about any practice.
Sources: HHS, Personal Representatives guidance · HHS HC3, Mobile Device Security Checklist
Working with your IT team
Working alongside the people who support your practice.
A joint discussion with the owner, administrator and IT provider.
A review of existing services, documentation and protections.
Agreement on responsibilities and how evidence will be gathered.
Recommendations coordinated before changes are scheduled around clinical operations.
Implementation tracked and progress reported in plain language.
Example: planning for downtime
I help you define
Acceptable downtime and which systems to recover first.
Your IT team or MSP
Configures and tests the technical recovery arrangements.
Your administrator
Coordinates staff procedures and downtime exercises.
The benefit: the owner gets one coordinated plan with clear accountability.
Readiness and growth
Prepare for disruption and plan for what comes next.
Incident and ransomware readiness
Contacts, decision-making, escalation, communications and exercises.
Disaster recovery
Tested restoration priorities based on clinical and business needs.
Business continuity
Procedures for appointments, documentation, billing and patient communication during outages.
Insurance readiness
Accurate evidence and coordination with your broker before application or renewal.
AI governance
Evaluation of AI scribes and other tools, acceptable-use rules and a review of data handling.
Growth
A review of new locations, acquisitions, vendors and EHR changes before they're implemented.
The result: clearer decisions, better coordination, less uncertainty and a stronger ability to respond and recover.
Further reading
Practical guidance for practice owners and administrators.
Why therapy notes are a prime ransomware target
Sensitive records, risk assessments and response planning for small behavioral health practices.
Fractional CISO vs. full-time CISO for healthcare organizations
How the engagement model works and why it fits a practice's budget.
AI without the blind spots: a small business guide to governing and securing AI
How to set policies before your team adopts AI scribes and other tools.
FAQs
Questions practice owners ask before we start.
Do we need a fractional CISO if we already have an MSP?
Your MSP keeps systems running and protected day to day. I handle the practice-wide pieces, such as the risk assessment, policies, vendor oversight and incident planning, and coordinate the technical work with your MSP.
How often should we review our HIPAA risk assessment?
I recommend a documented review at least once a year, and again after significant changes such as a new location, a new EHR, a key vendor change or a security incident. HHS doesn't set a fixed schedule, but it expects risk analysis to be ongoing and updated as needed.
What happens after the assessment?
You get documented findings and a roadmap with priorities, owners, timing and recommended actions. Then we track follow-through, either as a defined project or through ongoing support.
How much staff time will this require?
It depends on scope. Your written proposal spells out the time needed from the owner, administrator and IT provider, and work is scheduled around clinical operations.
Can you help with multiple locations or clinicians working remotely?
Yes. The assessment covers each location, remote access, field devices and the vendors that connect them.
Can we start with a defined project?
Yes. You can start with a risk assessment and add ongoing leadership later if it makes sense.
What does ongoing support cost?
It depends on scope. Scope and fees are agreed in a written proposal before work starts. Technical implementation, such as new tools or IT provider work, may sit outside advisory fees, and I'll help you plan for it.
Next step
Know where your practice stands and what to do next.
In 30 minutes we'll talk about your practice, what concerns you right now and a sensible place to start.
