A DubLow Digital brandIT · Cybersecurity · Digital Marketing · Eagle County, CO

HIPAA Compliance IT for Vail Valley Practices

HIPAA compliance for a small practice means protecting electronic patient information (ePHI) with documented administrative, physical and technical safeguards. Vail Valley IT helps Eagle County medical, dental, therapy and wellness practices run the required security risk analysis, put the technical controls in place, train staff, and keep the evidence an OCR investigator or auditor would ask for.

Reviewed by Todd Whitelow · Updated October 2026 · General information, not legal advice

Regulatory update

In December 2024, HHS proposed the first major update to the HIPAA Security Rule since 2013. The proposal would make several practices explicitly mandatory, including vulnerability scanning at least every six months, penetration testing at least every 12 months, encryption of ePHI, MFA and a written asset inventory. As of this page’s last review, a final rule had not been published. Most of the proposed controls are already expected practice, and we implement them now so the final rule is a formality.

Who HIPAA applies to

  • Covered entities: medical, dental, chiropractic, physical therapy, behavioral health, med-spa and other providers that bill electronically
  • Health plans and clearinghouses
  • Business associates: vendors that create, receive, maintain or transmit ePHI for a covered entity, including IT providers, billing companies and many software vendors

What HIPAA means for a small business

The HIPAA Security Rule (45 CFR Part 164, Subpart C) does not prescribe specific products. It requires you to assess your own risks and implement “reasonable and appropriate” safeguards, then document what you did and why. In practice, OCR investigations most often cite the same failure: no accurate, current risk analysis.

That makes the risk analysis the foundation. Everything else, from encryption and MFA to training and backups, flows from it and should be traceable back to it.

HIPAA requirements and how we meet them

RequirementHow Vail Valley IT handles it
Security risk analysis and risk management§164.308(a)(1)Documented risk analysis of every system touching ePHI, a prioritized remediation plan, and an annual review. Cybersecurity Risk Assessment
Security awareness and training§164.308(a)(5)Onboarding and recurring training with phishing simulations and completion records for every workforce member. Security Awareness Training
Access control and unique user IDs§164.312(a)Individual accounts, MFA, least-privilege access and same-day offboarding. Managed IT Services
Audit controls§164.312(b)Sign-in and activity logging in Microsoft 365 and endpoints, retained and reviewed. Compliance & Cybersecurity
Transmission and device security§164.312(e), §164.310(d)Encrypted email options, full-disk encryption on laptops and phones, and secure disposal of old devices. Hardware Upgrades
Contingency plan and backups§164.308(a)(7)Immutable, tested backups and a written disaster recovery and emergency mode plan. IT & Data Protection
Evaluation and technical testing§164.308(a)(8)Vulnerability scanning and penetration testing to verify safeguards work as intended. Penetration Testing & Vulnerability Scanning
Business associate agreements§164.308(b)We sign a BAA and help you track BAAs with other vendors that touch ePHI.

Common HIPAA gaps we find in valley businesses

  • A risk analysis that is years old, a generic template, or missing entirely
  • Staff sharing logins to the EHR or front-desk computer
  • Laptops and phones with patient data that are not encrypted
  • No MFA on email, which is where most patient data leaks start
  • Backups that have never been test-restored
  • No record that staff completed security training

Evidence to keep on file

  • Current security risk analysis and remediation plan
  • Written policies and procedures
  • Training completion records
  • Vulnerability scan and penetration test reports
  • Backup and restore test logs
  • Signed business associate agreements
  • Incident response plan and breach log

How we get you there

  1. Gap assessment

    We compare your current setup to HIPAA and list what is missing.

  2. Remediation plan

    Prioritized fixes with a flat price, in plain language.

  3. Implement & train

    Controls, policies and staff training put in place.

  4. Test & document

    Scans, pen tests and an evidence file you can hand to an auditor.

Not sure where you stand?Take the free 2-minute security check.
Take the check

Frequently asked questions

Does a small medical or dental practice need to comply with HIPAA?

Yes. HIPAA applies to covered entities of every size, including solo and small practices. The Security Rule scales its expectations to your size and resources, but the risk analysis, safeguards and documentation are still required.

Is penetration testing required for HIPAA?

The current rule requires a risk analysis and periodic technical evaluation but does not name penetration testing explicitly. HHS’s proposed update would require penetration testing at least every 12 months and vulnerability scanning at least every six months. Many practices adopt both now because they are the clearest evidence that safeguards work.

Is HIPAA security training required every year?

HIPAA requires a security awareness and training program for the workforce but does not set a specific frequency in the current rule. Annual training plus periodic reminders and phishing tests is the common standard, and it is what auditors and insurers expect to see documented.

What happens if a small practice has a HIPAA breach?

Breaches of unsecured PHI must be reported to affected individuals, to HHS, and in larger cases to the media, within set deadlines. OCR may investigate, and penalties depend on the level of negligence. Encryption can change whether an incident is a reportable breach at all.

This page summarizes public regulations for general information and is not legal advice. Confirm obligations with your attorney or compliance advisor.

Get HIPAA-ready without the guesswork

Start with a free cybersecurity assessment. You get written findings and a flat price to close the gaps.