Support Center | ☎︎ Call us: (845) 440-5000 | info@vjnetworks.com
HIPAA Security Rule · Rockland · Westchester · Bergen

Cybersecurity for healthcare practices in NY and NJ.

Cybersecurity for a healthcare practice means implementing the administrative, physical, and technical safeguards the HIPAA Security Rule actually requires, then documenting them. VJNetworks has managed systems touching protected health information since 2008.

97%
Client Retention
2008
Protecting PHI Since
15min
Response Standard
Healthcare practice manager holding patient records beside a locked records cabinet in a medical clinic corridor
BAA
Signed with every
healthcare client
The problem

HIPAA is a security regulation. Most practices treat it as paperwork.

A practice buys HIPAA compliance and receives a binder. Policies, a training slide deck, a signed acknowledgment from every employee. Into a drawer it goes. Nobody opens it again until something goes wrong, and by that point the questions being asked are about what was running on the machines rather than what the binder said should have been.

None of that is worthless. It is simply not what the rule asks for. The HIPAA Security Rule requires implemented administrative, physical, and technical safeguards protecting electronic protected health information. Actually running, not written down as an intention.

That gap is where small practices sit. The policy says workstations lock after fifteen minutes. Nobody checked whether the setting was ever pushed to the machines, whether it survived the last Windows feature update, or whether the two laptops that live at the satellite office were ever enrolled at all. This page is about closing that gap, and it sits alongside our broader HIPAA-compliant IT for healthcare work.

The requirement

What the Security Rule actually asks for.

Three categories of safeguard, set out at 45 CFR Part 164. Every practice is responsible for all three, scaled to its size and complexity.

Administrative

Risk analysis, workforce training, access management, contingency planning, and the sanction policy nobody enjoys writing. This is the category most often missing from small practices, and the risk analysis sitting at the top of it is the single item OCR asks about first.

Physical

Who can physically reach your systems. Locked server closets, workstation placement, screen angles at the front desk, and a documented process for disposing of old drives. Unglamorous. Still required.

Technical

Access controls, unique user IDs, audit logging, integrity controls, and encryption of ePHI at rest and in transit. The part people assume their IT provider already handles. Worth confirming.

HHS and ONC publish a free Security Risk Assessment Tool built specifically for small and medium practices. If you have never done a formal risk analysis, start there. You do not need us to run it.
The gaps

Where practices are actually exposed.

No current risk analysis

Not a checklist a vendor filled in three years ago. Start here. A documented assessment of where ePHI lives, what could reach it, and what you decided to do about each finding.

Vendors nobody vetted

The billing service, the transcription tool, the answering service, the IT provider. Every one that touches ePHI needs a Business Associate Agreement on file. Most practices cannot produce the full list when asked, because nobody has ever been given the job of keeping it, and the agreements that do exist were signed by someone who left two years ago.

Access that only ever grew

Staff change roles and pick up permissions. Almost nobody loses them. Nobody subtracts. The front desk ends up able to open records it has no reason to see, and the audit log nobody reads is the only trace.

Backups nobody has restored

Has anyone tried it? A backup that has never been restored is a claim rather than a control. Contingency planning is an explicit Security Rule requirement, and a restore you have never rehearsed is where that requirement quietly fails.

The work

Seven pieces of work, scoped to a practice.

Security risk analysis

Where ePHI lives, who reaches it, what threatens it, and a ranked register you can hand to an investigator.

Access control and MFA

Unique logins, role-based permissions, multi-factor on anything reaching records, and an offboarding step that actually runs the day somebody leaves rather than the week the auditor asks whether it does.

Email and phishing defense

Filtering, encrypted send for anything carrying ePHI, and training built from your own inbox rather than stock examples.

Endpoint protection

Detection on every workstation and server, with anomalies terminated and rolled back rather than logged for somebody to read on Monday.

Backup and recovery

Encrypted, off-site, and restore-tested on a schedule. Covered in more depth on our backup and disaster recovery page.

Vendor and BAA review

Every vendor touching ePHI listed, every agreement located or chased, and the gaps written down instead of assumed.

Your EHR is part of the security perimeter, not an exception to it.

VJNetworks has experience supporting healthcare platforms including PointClickCare and AccuCare, keeping access to patient and operational systems both secure and available. Controls that ignore the software your staff actually spend the day inside are controls that get worked around by Friday, so we tune them against real clinical workflow rather than against a generic hardening checklist.

Fit

Is this the right fit for your practice?

Built for

Independent practices, specialty clinics, dental and behavioral health offices, and multi-site groups in Rockland, Westchester, and Bergen with roughly 5 to 60 people per location. Small enough to know everyone.

Practices with no internal IT security staff. Or one office manager who inherited the responsibility along with everything else, and has been quietly hoping it never gets tested.

Probably not for

Hospital systems and large provider networks with an internal security team and their own compliance office. Different problem. That is a different engagement than the one described here.

Organizations that need their vendor to hold SOC 2 certification as a procurement condition. Better to say so now than at the end of a proposal.

Track record

Numbers worth checking before you take our word for it.

97%
Client retention, held for over 20 years across every service line we run.
2008
The year we started managing systems that touch protected health information.
22yrs
In operation since 2004, headquartered in Garnerville, New York.
15min
Response standard, from someone who already knows your environment.
Process

Four steps from unsure to documented.

1

Scoping call

Thirty minutes. What software you run, how many locations, who currently handles IT, and what prompted the call. Usually something did.

2

Assessment

We map where ePHI actually lives, test the controls you believe are in place, and list the vendors touching it.

3

Ranked findings

A gap register in priority order, with what each finding would cost to close. Yours either way. You keep it whether you hire us or not.

4

Remediate and maintain

We close the gaps in order and sign a BAA. Then the documentation stays current, reviewed on a schedule instead of aging quietly in a drawer until the next time somebody needs it in a hurry.

Questions

About cybersecurity for healthcare practices.

We already passed a HIPAA audit. Doesn’t that cover us?

Two different things, and the gap between them is where practices get caught. A compliance review checks whether you have policies. A security assessment checks whether the controls those policies describe are actually running on your machines today. It happens constantly. Plenty of practices pass the first and fail the second without ever knowing it, usually because the two reviews were bought from different people who never compared notes.

Does our IT company need to sign a BAA?

Yes, and it is not optional for either side. Any vendor that creates, receives, maintains, or transmits ePHI on your behalf is a business associate under HIPAA. No exceptions. VJNetworks signs a Business Associate Agreement with every healthcare client before touching anything. If your current provider has not, both of you are exposed.

How often does the risk analysis actually need redoing?

Annually is the working answer for most practices, plus any time something material changes. A new location, a new EHR, a new billing vendor, a merger. Ask what changed. The rule asks for accuracy rather than a fixed calendar, so an assessment that predates your current software is not a current assessment.

There’s a new HIPAA Security Rule coming. Do we need to act now?

Not yet, and do not wait for it either. HHS published a proposed update on January 6, 2025 that would make several currently addressable safeguards required. It has not been finalized, so the 2013 rule is what applies today. Nearly everything in the proposal is standard practice already, so a practice that gets current now is not doing the work twice.

We run PointClickCare. Is that something you support?

PointClickCare and AccuCare are both platforms we have experience supporting. The brand matters less than you would think. What matters is whether whoever manages your security understands how clinical staff actually use the system, because controls that make the software unusable get worked around within a week.

What actually happens if we do have a breach?

The clock starts immediately, and your documentation decides how bad it gets. Move fast. HIPAA sets notification obligations to affected individuals and to HHS, with tighter timelines for larger incidents. What can you actually produce? Practices that can produce a current risk analysis and evidence of implemented safeguards sit in a materially different position from practices that are reconstructing what they had in place while the notification clock is already running.

How is this different from the managed IT you already offer?

Same team, different scope. Our healthcare IT work covers the whole environment, from help desk to hardware. This is the security layer specifically, and it can run as its own engagement if you already have an IT provider you like. Our general cybersecurity services page covers the same discipline outside a clinical setting.

If you want the longer version of what the rule expects from a vendor, we wrote that up separately in what HIPAA actually requires from your IT provider. A formal security risk and vulnerability assessment is usually the first concrete step.

Find out what your risk analysis would actually find.

A free security assessment maps where your practice keeps ePHI, which controls are genuinely in place, and which vendors are missing an agreement. You keep the findings whether you hire us or not.

Get Your Free Security Assessment →

Or call (845) 440-5000