Email and account security
Require MFA, monitor suspicious sign-ins, disable inactive accounts, and train staff on phishing.
Use separate accounts for shared roles instead of shared passwords whenever possible.
EMR and billing systems
Review user roles, remove former staff, confirm audit logs, protect exports, and limit broad access to patient records.
Make sure front desk, billing, clinicians, and administrators have access aligned to job needs.
Devices and workstations
Encrypt laptops, require screen locks, patch systems, run endpoint protection, and keep an inventory.
For shared workstations, use fast user switching or individual logins rather than generic shared accounts.
Wi-Fi and network
Separate guest Wi-Fi from internal systems. Segment cameras, IoT devices, and business systems where possible.
Do not let unmanaged devices sit on the same network as systems that access patient data.
Backups and downtime
Know how the practice operates if the EMR, internet, phones, or scheduling system is down. Test restores and document downtime workflows.
Staff training
Use short, recurring training: phishing, secure texting, screenshots, portable devices, patient identity verification, and incident reporting.
Owner review checklist
Can we identify every system with ePHI? Can we name every admin? Are backups tested? Are BAAs organized? Do we have a written incident response process?
Schedule now
