That last part is the whole reason this article exists. Most practices are not one purchase away from being secure. They are one architecture decision away from being able to be secure, and they find that out at the worst possible moment.
The account everybody gets backwards
When we take over a practice, we look at who has what. Almost every time, the owner and the practice administrator have the most relaxed security settings in the organization. No forced re-authentication. Exempted from the multifactor rollout because it was slowing them down. Sometimes a shared password with a spouse who helps with billing.
The logic is understandable. They are the boss. The controls are annoying. Somebody made an exception once and it stuck.
But an attacker does not care about the org chart the way you do. They care about which account can approve a wire, sign into the EHR with the widest permissions, email every employee without raising an eyebrow, and reset other people's passwords. That is the owner. That is the administrator. Those two accounts should carry the strictest controls in the building, not the loosest.
We say this out loud to owners and it does not always land well. Nobody enjoys being told their own convenience is the vulnerability. But the accounts with the most authority carry the most risk, and the person who holds them sets the security culture for everyone else. If staff see the owner skipping the login prompt, the policy is already dead.
What we find when we walk into a practice for the first time
We support roughly 17 medical practices across dental, primary care, specialty, behavioral health, and PT ranging from 5 to 65 users. The same five things come up over and over:
1. Reused and insecure passwords.
The same password across the EHR, the email, and the imaging portal. Often written somewhere at the front desk.
2. No network segmentation.
The scheduling machine, the imaging equipment, the guest Wi-Fi, and the server all live in the same flat network. Anything that gets in can reach everything.
3. No clear owner for any responsibility.
Not just who administers the server. Who is accountable for the processes that keep running after the person who invented them leaves.
4. Generic shared accounts with no audit trail.
A "frontdesk" login that four people use. When something happens, there is no way to answer the only question that matters, which is who did this.
5. Every workstation managed individually.
No domain controller, no Intune, no MDM. Each machine is its own island with its own settings and its own local admin.
There is also a labor argument, and it is usually the one that lands with a practice administrator. Pushing a single piece of software to a practice with no central management means touching every machine by hand. That runs hours depending on device count, and it interrupts staff while it happens. The same deployment through Active Directory, Intune, or an MDM platform takes under 15 minutes and nobody notices it happened. Now multiply that difference by every patch, every configuration change, and every new hire.
Your EHR vendor is not your compliance department
The most common misunderstanding we run into is the belief that signing a Business Associate Agreement is the end of the conversation. Sign it, file it, move on.
A BAA is a contract, not a control. It establishes who is responsible for what. It does not tell you whether your vendor is actually doing any of it.
These are the questions worth asking your EHR vendor, your billing service,
and anyone else touching patient data:
Where is our data physically stored, and who else has access to that environment?
How is it protected at rest and in transit?
If you get hit with an incident, what is your recovery process and how long does it take?
Do you adhere to a recognized security framework? Are you SOC 2 certified?
What kind of multifactor authentication do you support? Is it app based or hardware based, or is it SMS and email codes?
Does your login enforce inactivity timeouts? If not, why not?
None of this is because EHR companies are careless. They build clinical software. They are experts in medical workflow, not in modern identity security, and they generally will not raise these issues on their own. Somebody on your side of the table has to ask.
The two most valuable fixes cost nothing
Write down your policies.
They are also not optional in the way most practices assume. Written policies are a standard requirement on cyber insurance applications, they sit inside HIPAA's administrative safeguards, and they appear in every major security framework, including NIST, ISO 27001, and CIS. Exactly which policies are required varies a little between them. Disaster recovery and business continuity plans show up on nearly all of them at minimum.
Turn on multifactor authentication everywhere.
Still overlooked, still free on most platforms, still worth doing on day one.
Now the honest caveat, because you deserve one. MFA is no longer the wall it was five years ago. Attackers steal session tokens, run device code phishing, and walk around it in ways that did not exist when it became the standard recommendation.
Any consultant who tells you MFA alone makes you safe is selling you something. What it still does reliably is stop the enormous volume of automated credential stuffing and bot driven brute force attempts, which is most of what is thrown at a small practice. It is a floor, not a ceiling. Build the floor.
What conditional access actually stops.
The number a practice administrator will actually want is the difference. Business Premium runs roughly $7 more per user per month than Business Standard, the tier below it. For a twelve-person practice, that is about $84 a month to close the gap that MFA alone leaves open.
What OCR is actually penalizing practices for.
For scale, the current civil monetary penalty tiers run from a $145 minimum per violation where an entity genuinely did not know, up to $2,190,294 for willful neglect left uncorrected, following the inflation adjustment effective January 28, 2026.
A risk analysis is not a scan, and it is not a certificate you buy. It is a documented assessment of where electronic patient data lives, how it moves through your systems, what could go wrong at each point, and what you are doing about each of those risks. It has to be accurate, thorough, and kept current. If you cannot produce yours right now, that is the first thing to fix.
The Security Rule overhaul, and why July 2027 is not a real deadline
So we are not going to tell you a deadline is coming. What we will tell you is that every requirement in that proposal is something a well-run practice should already be doing, and OCR is enforcing the existing rule right now without waiting for the new one. Treating July 2027 as a due date is how you end up doing the same work later, under pressure, with less room to plan it.
One Virginia thing practices get wrong
The nuance worth knowing is that patient data is not the only sensitive data you hold. Employee records, payroll, and tax identification numbers sit outside HIPAA, and a breach touching those can trigger Virginia's general notification law even when the patient side is handled federally. If your practice also does contract work with a state entity, separate reporting obligations may attach through that relationship.
We are an IT company, not a law firm. If you are working through an actual incident, your attorney and your insurance carrier drive the notification decisions. This is context so you know which questions to ask them.
If you only do Four Things
Tighten the owner and administrator accounts.
Whatever the strictest policy in your practice is, those accounts get it. No exceptions, starting with the person who signs the checks.
Produce a current risk analysis.
If you cannot hand one to a regulator today, this is your largest exposure, and the one OCR is most actively enforcing.
Write the policies down.
Incident response, offboarding, acceptable use, backup and recovery. Free, boring, and the thing you will be judged on.
Get every workstation under central management.
Until that exists, every other control is applied by hand and will drift.
And one question to take to your next renewal meeting: do you carry cyber insurance, and have you read what your carrier requires you to have in place? In the incident we opened with, insurance covered the majority of an incident response engagement that came to just shy of $10,000, before any remediation work. Carriers are also increasingly specific about the controls they expect, and finding out at claim time that you did not meet them is a bad afternoon.
Not sure where your practice stands?
Top Notch Computers has supported Virginia businesses since 1999, with offices in Charlottesville, Richmond, and Falls Church. We currently support around 16 medical practices across the Commonwealth. Start with a conversation, not a contract.

Frequently asked questions
Here are some common questions about this topic and from medical practices like yours.
The current Security Rule does not name multifactor authentication as a required control. It requires reasonable and appropriate safeguards, and MFA is what a reasonable safeguard looks like in 2026, which is why it shows up in nearly every OCR corrective action plan. The proposed Security Rule update would make it explicitly mandatory for systems accessing electronic patient data, though that rule is not final and is currently projected for July 2027 at the earliest.
No. A compliant EHR covers the EHR. Your practice is still responsible for the workstations, the network, the email system, the accounts, the physical access, the training, the documented policies, and the risk analysis covering all of it. Vendor compliance is one input, not the answer.
It depends heavily on size, insurance, and how long the intrusion went undetected. For a concrete floor, one of our clients faced an incident response engagement just shy of $10,000 from a single compromised email account, before remediation costs, with insurance covering the majority of it. On the regulatory side, recent OCR settlements with practices comparable to a typical Virginia office have ranged from $25,000 to $250,000, alongside two years of monitored corrective action.
Generally no, if you are a HIPAA covered entity. Virginia Code § 32.1-127.1:05 expressly exempts covered entities and business associates subject to federal breach notification requirements, so a private practice reports under the federal HIPAA Breach Notification Rule instead. Breaches involving employee or payroll data rather than patient data can fall under Virginia's general notification statute, so confirm the scope of any incident with your attorney.
Yes, and not because anyone picked you specifically. Most of what reaches a small practice is automated and indiscriminate, looking for reused credentials and unpatched systems. Both of the OCR settlements referenced above involved single site practices. Being small is not cover.
Sources
HHS Office for Civil Rights, settlement with Comprehensive Neurology, PC, April 25, 2025 · HHS Office for Civil Rights, settlement with Syracuse ASC, LLC, July 23, 2025 · HHS Office for Civil Rights, Notice of Proposed Rulemaking on the HIPAA Security Rule, published January 6, 2025 · OMB Unified Agenda, RIN 0945-AA22, final action projected July 2027 · HHS civil monetary penalty inflation adjustment, effective January 28, 2026 · Code of Virginia § 32.1-127.1:05 and § 18.2-186.6