Flyght
← Back to Blog
Healthcare

HIPAA-Compliant IT for Toledo Dental Practices and Medical Offices

Flyght TeamMay 3, 20267 min read

Toledo's healthcare sector includes major regional employers like ProMedica and Mercy Health, but the majority of patient care happens in smaller settings: private dental practices, independent medical offices, and specialty clinics. These practices handle the same protected health information (PHI) as large hospital systems, face the same federal compliance requirements, and carry the same legal liability when something goes wrong.

HIPAA enforcement is real. The Department of Health and Human Services' Office for Civil Rights (OCR) has collected over $130 million in penalties. Fines reach up to $1.9 million per violation category per year. A 2024 OCR audit initiative now specifically targets small and mid-sized covered entities — which means private practices and dental offices are in the crosshairs whether they've had an incident or not.

Here's what your practice actually needs to know about HIPAA-compliant IT — and how to know if you're genuinely protected.

What HIPAA's Security Rule Requires From Your IT

The HIPAA Security Rule — codified at 45 CFR Part 164, Subpart C — establishes enforceable technical safeguard requirements for covered entities and their business associates. Under 45 CFR §164.312, four primary categories apply directly to your IT environment:

Access Controls (§164.312(a)(1))

Each user must have a unique login. Role-based access must limit what staff can view or modify. Emergency access procedures must be documented, and automatic session timeouts must be configured on all workstations and EHR terminals accessing patient records.

Audit Controls (§164.312(b))

Your systems must generate and maintain logs of who accessed PHI, when, and what they did with it. If your EHR doesn't produce audit logs — or nobody reviews them — that's an enforceable compliance gap that OCR investigators will find.

Transmission Security (§164.312(e)(1))

Any PHI transmitted over a network — email, EHR data syncs, remote access connections — must be encrypted. Sending patient information via standard unencrypted email is a HIPAA violation regardless of whether the data was actually intercepted.

Contingency Planning (§164.308(a)(7))

Practices must maintain a documented data backup plan, disaster recovery plan, and emergency mode operation plan. 'We have a backup' is not a compliant answer. The plan must be written, tested, and updated whenever significant changes occur to your systems.

The OCR Audit Process: What Triggers an Investigation

OCR investigations start in one of three ways: a patient or employee complaint, a mandatory breach report, or selection through the agency's proactive audit program. The third category is new — it means your practice doesn't need to have experienced a breach to receive an audit notice.

When investigators arrive, they will ask for your risk assessment documentation, your policies and procedures, your audit logs, and your Business Associate Agreements with every technology vendor. Practices that cannot produce a signed BAA from their IT company typically receive corrective action plans that include mandatory compliance oversight for years.

The 5 Most Common HIPAA IT Violations in Dental and Medical Offices

In working with healthcare practices across Northwest Ohio, we see the same compliance failures consistently. Here are the five most common — and most consequential:

1. No Business Associate Agreement With Your IT Provider

If your IT company has access to systems that store or transmit PHI — and they almost certainly do — they are a Business Associate under HIPAA. Without a signed BAA, every interaction that company has with your environment is a potential violation. Most general IT providers have never heard of a Business Associate Agreement.

2. Shared Workstation Logins

In busy dental offices, multiple staff members commonly share a single Windows login. This directly violates the unique user identification requirement under §164.312(a)(2)(i). It also makes your audit logs useless — you cannot prove who accessed patient records, which is the first thing OCR investigators check.

3. Unencrypted PHI on Laptops and Mobile Devices

A stolen laptop containing unencrypted patient records is a reportable HIPAA breach — regardless of whether the data was actually accessed. If providers or front desk staff use devices that access your practice management system without full-disk encryption, you have an active compliance exposure.

4. No Formal Risk Assessment

The Security Rule requires a documented risk analysis under §164.308(a)(1), conducted regularly — not just once at setup. OCR's first request in any investigation is the risk assessment. 'We don't have one' is the fastest path to a corrective action plan and civil monetary penalties.

5. Inadequate Backup and No Tested Recovery Plan

Practices that rely on a single local backup — or no backup — fail the contingency planning standard. If ransomware encrypts your EHR database and you cannot restore patient records, you have both a HIPAA breach and a practice shutdown happening simultaneously. Recovery time objectives must be documented and actually tested.

Why a Standard IT Company Is Not Enough: The Business Associate Agreement

A Business Associate Agreement is a legally binding contract HIPAA requires before any vendor can access, store, or transmit PHI on your behalf. Your EHR vendor has one. Your billing clearinghouse has one. Your IT company must have one.

A valid BAA defines what PHI the business associate can access, requires appropriate safeguards, establishes breach reporting obligations, and specifies what happens to PHI when the relationship ends. It also establishes shared liability if a breach occurs due to IT provider negligence.

Most general IT companies have no HIPAA-specific policies and have never signed a BAA. At Flyght, every healthcare and dental client relationship begins with one — before any work touches your environment.

EHR and Practice Management Software Security

Platforms like Dentrix and Eaglesoft for dental offices, and Athenahealth, Epic, and eClinicalWorks for medical practices, are the core of your PHI environment. Securing them requires more than the vendor's default configuration.

Dentrix and Eaglesoft are predominantly on-premise systems running on local servers within your practice. Your network security, backup strategy, and workstation configurations directly affect the security of patient records. A compromised workstation with Dentrix access is a direct path into your patient database.

Cloud-based platforms like Athenahealth shift some security responsibility to the vendor — but your staff credentials, your network, and your endpoint protection remain entirely your responsibility. MFA should be enabled on all cloud-based EHR accounts, and remote access must use encrypted connections.

Ransomware's Unique Impact on Healthcare Practices

Healthcare is the number one ransomware target in the United States, and dental practices are not exempt. Practices cannot see patients without their records, downtime is lost revenue, and attackers know practices pay quickly to restore access.

What many managers don't realize: a ransomware attack on a healthcare provider is automatically a HIPAA breach. OCR treats encryption of PHI as an unauthorized disclosure unless you can prove — with logged evidence — that data was not exfiltrated. That's a difficult case to make without proper audit infrastructure.

The 2024 Change Healthcare attack disrupted revenue cycles for practices across Northwest Ohio for weeks, exposing exactly how vulnerable smaller practices are to third-party vendor outages and direct attacks alike.

What a HIPAA-Compliant MSP Relationship Looks Like

A HIPAA-compliant managed IT relationship differs from standard IT support in several concrete ways. At minimum, look for: a signed BAA before any work begins — non-negotiable with any vendor that accesses your systems; formal HIPAA risk assessment support that meets OCR requirements; documented policies covering access management, incident response, breach notification, and device disposal; ongoing monitoring and audit log review; and workforce security training that covers HIPAA-specific obligations, not just generic phishing awareness.

Flyght provides all of these for dental practices and medical offices across Toledo and Northwest Ohio. Our team understands that your staff needs to focus on patient care — not on deciphering 45 CFR §164. That's our job.

Request a HIPAA IT Compliance Assessment

If your practice is operating without a BAA from your IT provider, without a documented risk assessment, or without confidence that your systems meet the Security Rule's technical safeguard requirements — the time to address that is before an OCR complaint or a ransomware event, not after.

Flyght offers a no-obligation HIPAA IT Compliance Assessment for dental practices and medical offices in Toledo and Northwest Ohio. We'll evaluate your current technical safeguards, identify compliance gaps, review your BAA status with all technology vendors, and give you a clear picture of where your practice stands — and what it would take to get fully compliant.

ProMedica and Mercy Health have enterprise security teams. Your practice deserves the same level of protection, right-sized for your environment and your budget.

Contact us at (419) 670-7100 or fill out the contact form to schedule your assessment.

Ready to talk?

If this article hit close to home, let's have a conversation. No pitch, no pressure — just an honest look at where your IT stands today.

Get Your Free IT Assessment