Practical guidance for dental and medical practices in Nashville and Middle Tennessee — written for office managers and practice owners, not IT departments.
Every practice that calls us asks some version of the same question: do I need the one-time audit, or the ongoing service? Here's the honest answer, based on what actually determines the right fit — not just budget.
A patient calls asking for a copy of their chart, or a new dentist's office faxes over a records request. It sounds routine — but HIPAA's Right of Access rule has a strict clock attached to it, and it's become one of OCR's favorite things to enforce.
Most practices installed Google Analytics or a Facebook pixel years ago and never thought about it again. HHS now treats certain uses of that same tracking code as a reportable breach of patient data — here's what changed and how to check your own site.
A resignation, a termination, a seasonal hire who moves on — every time someone leaves your practice, they leave behind a trail of logins, badges, and app access. Here's what actually has to happen on their way out, and why "we'll get to it" is how breaches happen.
Appointment reminders, a quick photo of a shade guide, a follow-up question after a procedure — front desks text and email patients constantly. Here's where HIPAA actually draws the line, and where practices get it wrong without realizing it.
Nearly every dental practice has software vendors, a billing company, maybe an IT contractor — and HIPAA requires a signed agreement with every one of them. Here's what a BAA actually covers, who most practices forget, and what happens when one is missing.
A laptop left in a car, a phone that never made it home from lunch — lost devices are one of the most common ways practices end up reporting a breach. Here's what determines whether it's a paperwork headache or a six-figure problem.
Ransomware doesn't start with a ransom note — it starts with a normal Tuesday. Here's what actually happens to a dental or medical practice from the first sign of trouble to the final bill.
An OCR audit notice can arrive with little warning. Here's exactly what happens next, what OCR will ask for, and how to respond without making things worse.
What dental and medical practices across Middle Tennessee need to know about the 2026 HIPAA Security Rule update — and how to get ready without hiring a full IT department.
Pricing for HIPAA risk assessments varies widely. Here's what actually drives the cost and what a fair price looks like for a single-location practice.
Getting — or keeping — a cyber insurance policy now requires proof of specific security controls. Here's what carriers are checking for before they'll cover a dental or medical practice.
The biggest HIPAA Security Rule update since 2003 is here. Here's what actually changed and the concrete steps practices need to take to stay compliant.