For healthcare practices

Protect patient information without running an IT department

Dental, medical, therapy and specialty practices carry serious responsibility for patient information. We help small practices meet it in plain English.

What's at stake

Patients trust your office, and so do the people who would fake it

  • HIPAA applies at any size
    Federal HIPAA rules require every covered practice, whatever its size, to have a documented security risk analysis. Many small practices have one that is out of date, or never got written.
  • Fake emails that look like yours
    Many small offices never finish the setup that tells other mail servers to reject messages faking their domain. A patient could get an email that looks like it came from your office, asking them to update their insurance information.
  • Equipment and outside vendors
    Practice software, imaging equipment and patient-form vendors all touch your network. Someone should know what is connected and who supports it.
At renewal time

What cyber insurers increasingly ask about

  • Sign-in protection
    Multi-factor sign-in on email and remote access.
  • Current, supported software
    Every computer patched, and nothing running that its maker has stopped supporting.
  • Backups that work
    Copies kept separate from your network, and a restore that has actually been tested.
  • Staff awareness
    Training and practice spotting fake emails.
  • A plan for a bad day
    Who does what if something goes wrong.

Cyber insurance applications increasingly ask about these controls. We help you answer honestly, and close the gaps.

What the free assessment looks at

Plain answers, in plain English

The assessment gives you a clear, plain-English starting point for the written security risk analysis HIPAA asks for. Before we look at any system that holds patient information, we put a Business Associate Agreement in place.

Your computers

Computers and software

Which machines are patched, which software is out of date or unsupported, and where the real risk sits.

Your email

Email and sign-in

Whether your domain can be faked, how mailboxes are protected, and whether multi-factor sign-in is on where it matters.

Your backups

Backups and recovery

Whether you could get back to work after ransomware or a failed server, and whether anyone has ever tested a restore.

PineLinx provides technology services, not legal advice.

Find out where your practice stands

A free, no-obligation assessment with a plain-English report. Nothing is installed or scanned without your written OK.