Cybersecurity
HIPAA Compliant IT Services in NJ: What the Rule Actually Requires
Most of what medical practices are told about HIPAA and technology is fear marketing. Here is what the Security Rule actually asks of your IT, in plain terms, and what a provider claiming to offer HIPAA compliant IT services should actually be doing.
5 min read
read
·

Most of what small medical practices hear about HIPAA and technology arrives wrapped in fear. A vendor mentions six-figure fines, waves at "compliance," and the practice signs something without ever learning what the regulation actually asks of its computers.
So here is the unusual version: what the HIPAA Security Rule actually requires from your IT, what it does not require, and how to tell whether an IT provider advertising HIPAA compliant services knows the difference.
First, the Honest Boundary
No IT company can make you HIPAA compliant, and no IT company can certify you. There is no such thing as a HIPAA certification recognized by the federal government. Compliance belongs to your practice as a whole: your policies, your training, your business associate agreements, and your technology together.
What an IT provider can legitimately do is put the technical safeguards in place, keep them running, and hand you the documentation that proves it. That is the part we do. Anyone promising more than that is telling you something useful about how carefully they read regulations.
What the Security Rule Actually Asks For
The Security Rule divides its requirements into administrative, physical, and technical safeguards. The technical safeguards are where your IT provider lives, and they come down to a short list of plain questions.
Who can see patient data, and how do you know? Every user needs a unique login. Shared accounts, one password for the whole front desk, a generic "reception" user: all of these fail the access control requirement, and all of them are still common in small practices. Role-based access follows from the same principle. The billing person does not need what the physician needs.
Would you know if someone looked? Audit controls mean your systems record who accessed what and when. In practice this is logging on your EHR, your file shares, and your network, retained long enough to answer a question months later. A practice that cannot answer "who opened this chart in March" does not have audit controls, whatever its policy binder says.
Is the data unreadable if stolen? Encryption, both for data sitting on drives and data moving across networks. The word "addressable" in the rule has convinced some vendors this is optional. It is not optional in any meaningful sense. If a laptop with an unencrypted drive leaves your office in the wrong bag, that is a reportable breach. If the drive was encrypted, in most cases it is a lost laptop.
Can you get the data back? A contingency plan: backups, a disaster recovery process, and a way to keep operating during an outage. A backup and a recovery plan are not the same thing, and the difference is exactly what an auditor asks about.
Can the data walk out? Transmission security and device controls. Email that carries patient information needs encryption. Texting patient details on personal phones is one of the most common violations in small practices, and no firewall fixes a workflow problem.
That is the substance of it. Not mysterious, not proprietary, and not something that requires a compliance-branded appliance with a monthly fee attached.
What HIPAA Does Not Require
This list matters just as much, because the gap between the two lists is where practices overspend.
HIPAA does not name products. It does not require any particular firewall brand, any specific EHR, or any vendor's "HIPAA package." It does not require your server to live in your office, and it does not forbid the cloud; it requires that wherever patient data lives, the safeguards above apply and a business associate agreement exists with whoever holds it. Microsoft 365, properly configured under a BAA, can be part of a compliant environment. Improperly configured, the same subscription is a liability. The product was never the point. The configuration is.
HIPAA also does not require perfection. It requires reasonable and appropriate safeguards, documented decisions, and a risk analysis that shows you looked. A four-provider practice is not held to the infrastructure of a hospital system. It is held to having thought it through.
The Risk Analysis Is Where Everything Starts
If your practice has never had a formal security risk analysis, that is the first gap, and it is the one enforcement actions cite most often. Not because a firewall was missing, but because nobody could produce the document showing the practice had assessed where its patient data lives and what threatens it.
This is also where a competent IT provider earns its fee: walking the environment, finding where PHI actually is (it is never only in the EHR; it is in scans, in email, in the shared drive named "Old Server"), and producing the written analysis your policies build on. Every engagement we take starts with an assessment for exactly this reason.
What a HIPAA Compliant IT Provider Should Be Doing for You
If you are paying someone for HIPAA compliant IT services in New Jersey, these are fair things to expect and fair questions to ask at your next review.
They should sign a business associate agreement without being asked twice. An IT provider with access to your systems is a business associate under the rule, and one that hesitates to sign a BAA is disqualifying itself.
They should be able to show you the state of the safeguards on demand: who has access to what, when patches went in, whether every drive is encrypted, when the backups last ran and where they go. Not promise it. Show it.
They should keep the boring machinery running: patching on schedule, endpoint protection current, EHR and practice systems monitored, backups configured and watched rather than assumed. And if your organization touches patient data without being a practice, a billing company, a claims processor, a transcription service, the same Security Rule obligations apply to you as a business associate, which surprises more organizations than it should.
And they should tell you plainly where their responsibility ends and yours begins. Training your staff, maintaining your policies, and deciding your risk tolerances are yours. The technical controls and the evidence trail are theirs.
Where NJ Practices Usually Stand
The pattern across small and mid-sized practices in New Jersey is consistent: the EHR vendor handled its own slice properly, and everything around it grew informally. The Wi-Fi the front desk uses is the same network patients join. Old workstations share one login. Email is standard-issue with no encryption and no BAA. Backups exist but nobody watches them.
None of that is negligence. It is what happens when a practice grows and nobody owns the technical layer. It is also all fixable, usually without drama, and fixing it costs considerably less than the first hour of a breach response.
Frequently Asked Questions
Can an IT company make my practice HIPAA compliant? No, and be wary of one that says yes. Compliance covers your policies, training, agreements, and technology together. An IT provider puts the technical safeguards in place and documents them. That is a large piece, but it is a piece.
Is there such a thing as HIPAA certification? Not from the government. Third parties sell certificates, and they can be useful as internal evidence of effort, but no certificate changes your obligations or protects you in an investigation.
Does HIPAA require specific products or brands? No. It requires outcomes: controlled access, audit trails, encryption, backups, and secure transmission. Any well-configured professional stack can meet them. Any badly configured one fails them.
Is cloud email like Microsoft 365 allowed under HIPAA? Yes, with a business associate agreement in place and the right configuration: encryption, access controls, and logging enabled. The subscription alone is not the compliance. The configuration is.
What is the most common gap you find in NJ practices? The missing or outdated risk analysis, followed closely by shared logins and unencrypted devices. All three are ordinary to fix. All three are the first things an investigator asks about.
How much does HIPAA compliant IT support cost for a small practice? It is structured like any managed IT agreement: a monthly rate based on users, devices, and scope, with the healthcare-specific controls built in rather than bolted on. The plans are here, and an assessment gives you an exact number.


