Who I Help · Medical Practices

Cybersecurity for medical practices

Protect your patients. Keep your practice moving.

Fractional CISO and HIPAA security advisory services for practices that need experienced guidance without hiring a full-time security executive.

I work with the owner, the practice administrator and your IT team or MSP to identify risks, prioritize improvements and strengthen your readiness.

What you get

Understand where you're exposed

A clear view of the risks to patient care, income and trust.

Know what to fix first

Improvements ranked by what matters most to the practice.

An advisor coordinating the work

One person keeping the plan moving with your team and IT.

The practice reality

Your day is full before cybersecurity enters the conversation.

Most practices I talk with are well run. Security just lands on people who already have full jobs. These are situations worth assessing, not signs that something is wrong:

The practice administrator also coordinates IT issues and compliance paperwork.

A departing employee's access spans several systems and vendors.

An insurance application asks questions the owner can't confidently answer.

A new location, EHR, telehealth service or AI scribe brings decisions nobody clearly owns.

Staff know backups exist but have never seen a recovery exercise.

What you get: coordinated guidance and a plan your administrator can actually manage.

Operational impact

A security incident can interrupt the entire practice day.

Care slows down

Charts, schedules, imaging or treatment information become unavailable.

Cash slows down

Claims, payments, eligibility checks and authorizations are delayed.

Staff get pulled away

Your team shifts to manual work and fielding patient calls.

Capacity is lost

Appointments are canceled and recovery adds costs.

Trust is tested

You face hard conversations about patient information.

80%

of responding practices lost revenue from unpaid claims after the 2024 Change Healthcare cyberattack.

85% had to commit additional staff time or resources to revenue cycle tasks. Most responses came from practices with fewer than 10 physicians. These practices weren't attacked themselves. The disruption came through a vendor.

Source: American Medical Association, informal survey of more than 1,400 respondents, March 26 to April 3, 2024; percentages are among those who answered each question

The lesson: a practice can be seriously disrupted through a vendor, even when its own systems weren't attacked.

Common questions

Questions practice owners are right to ask.

“Our IT company handles security.”

IT providers often handle important protections. The question is who owns the practice-wide pieces: the risk assessment, policies, staff responsibilities, vendor oversight and incident decisions. My work complements the services your IT provider is contracted to deliver.

“We're too small to be affected.”

Size doesn't keep a practice off the list. See the example below.

“Our EHR vendor says it's HIPAA compliant.”

Your vendor is responsible for its systems. Your practice is still responsible for its workforce, accounts, devices, how patient information is handled and your other systems.

“We completed a risk assessment years ago.”

New vendors, locations, staff and technology change the picture. HHS expects risk analysis to be ongoing and updated as your practice changes.

“We have backups, so we can recover.”

Good start. Has recovery been tested, and do you know which services can keep running during an outage?

In February 2024, HHS announced a settlement with Green Ridge Behavioral Health, an outpatient mental health group practice, after a ransomware attack affecting more than 14,000 patients. The practice agreed to pay $40,000 and follow a three-year corrective action plan that includes risk analysis, risk management, updated policies, workforce training and review of system activity.

Source: HHS, Green Ridge Behavioral Health resolution agreement

Why work with me

Before I was a CISO, I was a CEO.

When I was a CEO, I made the calls on payroll, staffing, customer commitments and budgets, and I doubled revenue from $2.5 million to more than $5 million. I know what it's like to run a business with a full schedule and a limited budget.

Today I bring healthcare security leadership to practices like yours, and you work with me directly.

How I translate findings

The security finding

The business question

A billing system your practice depends on

What happens to cash flow if it goes down for a week?

A gap in who can access patient records

Is patient confidentiality at risk?

A recovery process that's never been tested

How many appointments would we have to cancel?

What you can expect

Practical explanations
Prioritized recommendations
Follow-through

More about Melissa

Fractional leadership

Security leadership that fits your practice.

A fractional CISO is an experienced security leader who works with your practice on an agreed part-time basis.

For owners

Business-focused advice on priorities, investment and open risks.

For administrators

A coordinated action plan, usable policies, organized documentation and help managing the work.

For clinical teams

Guidance that respects patient care and everyday workflows.

For IT or your MSP

Clear priorities, agreed responsibilities and coordinated implementation.

You can start with an assessment and add ongoing leadership when it makes sense. Scope and fees are agreed in writing, including any technical implementation costs that sit outside advisory fees.

Risk assessment and roadmap

Start with a clear picture of your practice's risks.

1

Map patient information

Where electronic patient information is created, stored, accessed and shared.

2

Review safeguards

Administrative, physical and technical safeguards, well beyond the EHR.

3

Document findings and a roadmap

Priorities, owners, timing and recommended actions for each finding.

4

Track follow-through

Findings only help if someone tracks them to completion.

Every roadmap item includes

Priority
Owner
Timing
Recommended action

My recommendation: a documented assessment and review every year, plus a reassessment after significant changes or an incident. HHS doesn't set a fixed schedule, but it expects risk analysis to be ongoing and updated as needed.

The benefit: owners can make informed investment decisions, and administrators can see what needs to happen next.

Source: HHS, Guidance on Risk Analysis

HIPAA Security Rule

Make HIPAA security part of how your practice operates.

The practical questions we answer together

?

Who is responsible for security?

?

Who can access patient information?

?

How are staff trained, and how are access changes managed?

?

How are devices and work areas protected?

?

How are system activity and incidents reviewed?

?

What happens when essential systems are unavailable?

?

Which vendors need business associate agreements?

Safeguards should reflect your practice's size, capabilities and risks. Every policy connects to a procedure staff can follow and documentation you can keep up.

HHS has proposed changes to the HIPAA Security Rule. I keep current requirements separate from proposed ones, so you know what applies today and what may be coming.

Source: HHS, Summary of the HIPAA Security Rule

Care settings

Different care settings. Guidance built around your work.

Primary care

Plans for unavailable charts, prescription workflows, lab results and billing systems.

Dental

Practice-management software, digital imaging, shared workstations and vendor remote access.

Behavioral health

Telehealth, remote documentation, sensitive records and access that fits each staff role.

Pediatrics

Portal proxy access and workflows involving parents, guardians and adolescent confidentiality, with legal questions coordinated with your counsel.

Home health and hospice

Field devices, remote access, lost-device response, care coordination and access to essential information during outages.

Orthopedics and other specialties

Imaging, referral exchanges, connected systems and dependencies across locations.

These are examples of what an assessment looks at, not assumptions about any practice.

Sources: HHS, Personal Representatives guidance · HHS HC3, Mobile Device Security Checklist

Working with your IT team

Working alongside the people who support your practice.

1

A joint discussion with the owner, administrator and IT provider.

2

A review of existing services, documentation and protections.

3

Agreement on responsibilities and how evidence will be gathered.

4

Recommendations coordinated before changes are scheduled around clinical operations.

5

Implementation tracked and progress reported in plain language.

Example: planning for downtime

I help you define

Acceptable downtime and which systems to recover first.

Your IT team or MSP

Configures and tests the technical recovery arrangements.

Your administrator

Coordinates staff procedures and downtime exercises.

The benefit: the owner gets one coordinated plan with clear accountability.

Readiness and growth

Prepare for disruption and plan for what comes next.

Incident and ransomware readiness

Contacts, decision-making, escalation, communications and exercises.

Disaster recovery

Tested restoration priorities based on clinical and business needs.

Business continuity

Procedures for appointments, documentation, billing and patient communication during outages.

Insurance readiness

Accurate evidence and coordination with your broker before application or renewal.

AI governance

Evaluation of AI scribes and other tools, acceptable-use rules and a review of data handling.

Growth

A review of new locations, acquisitions, vendors and EHR changes before they're implemented.

The result: clearer decisions, better coordination, less uncertainty and a stronger ability to respond and recover.

FAQs

Questions practice owners ask before we start.

Do we need a fractional CISO if we already have an MSP?

Your MSP keeps systems running and protected day to day. I handle the practice-wide pieces, such as the risk assessment, policies, vendor oversight and incident planning, and coordinate the technical work with your MSP.

How often should we review our HIPAA risk assessment?

I recommend a documented review at least once a year, and again after significant changes such as a new location, a new EHR, a key vendor change or a security incident. HHS doesn't set a fixed schedule, but it expects risk analysis to be ongoing and updated as needed.

What happens after the assessment?

You get documented findings and a roadmap with priorities, owners, timing and recommended actions. Then we track follow-through, either as a defined project or through ongoing support.

How much staff time will this require?

It depends on scope. Your written proposal spells out the time needed from the owner, administrator and IT provider, and work is scheduled around clinical operations.

Can you help with multiple locations or clinicians working remotely?

Yes. The assessment covers each location, remote access, field devices and the vendors that connect them.

Can we start with a defined project?

Yes. You can start with a risk assessment and add ongoing leadership later if it makes sense.

What does ongoing support cost?

It depends on scope. Scope and fees are agreed in a written proposal before work starts. Technical implementation, such as new tools or IT provider work, may sit outside advisory fees, and I'll help you plan for it.

Next step

Know where your practice stands and what to do next.

In 30 minutes we'll talk about your practice, what concerns you right now and a sensible place to start.