Who this is for
Independent and small-group practices in Louisiana: family medicine, specialists, chiropractic, physical therapy, urgent care, med spas and behavioral health, typically 5 to 50 staff across one or a few locations. You hold protected health information (PHI) in an EHR, imaging, billing and email. You need IT and security that satisfy HIPAA, keep the schedule moving, and do not require a full-time IT employee.
Pain points specific to Louisiana medical practices
- The HIPAA risk analysis is required and usually missing. The Security Rule requires an accurate and thorough risk analysis, reviewed and updated as the practice changes. Most small practices have never documented one, and it is the first thing an auditor or breach investigator asks for.
- EHR downtime stops revenue. Whether you run a cloud EHR or a server in a closet, the workstations, network and internet around it are your responsibility, and an outage at 9am on Monday is a waiting room full of patients.
- PHI is on more devices than you think. Front-desk PCs, the provider's laptop, the billing manager's home computer, phones with email, the scanner. Unencrypted devices are a reportable breach waiting to happen.
- Ransomware in a clinic is a patient-safety event. No EHR means no charts, no e-prescribing, no schedule. Recovery time is measured in cancelled appointments.
- Email is the front door for attackers. Phishing against a busy front desk works. A compromised mailbox with patient communications in it is a breach, not just an inconvenience.
- Hurricane season is a HIPAA event. Losing records to a flood without tested, off-site backups is a breach of the Security Rule's contingency requirements, not just bad luck.
- Vendors point at each other. The EHR vendor blames the network, the phone vendor blames the firewall, and nobody owns the problem.
What we deliver
- HIPAA security risk analysis documented to the standard HHS expects, with each finding tied to a specific fix in your environment and a plan for review as the practice changes.
- Technical safeguards implemented, not just listed: access control, audit logging, integrity controls, authentication and transmission security.
- Endpoint encryption on every workstation and laptop that touches PHI, so a stolen laptop is a police report rather than a breach notification.
- Multi-factor authentication on email, the EHR, remote access and any portal that touches patient data.
- Network segmentation separating guest Wi-Fi, clinical workstations, imaging and medical devices, and administrative staff.
- Microsoft 365 or Google Workspace hardening with conditional access, audit logging and a business associate agreement in place for the platform.
- Endpoint detection and response on every device, with 24x7 managed detection and response through our Huntress SOC partnership.
- EHR and imaging environment support: the servers, workstations and integrations your clinical software depends on, with vendor coordination so you are not stuck in the middle.
- Encrypted, off-site, immutable backups tested on a schedule, with the option to stand up your environment in our Mandeville facility if the clinic floods.
- Business associate agreements, including for our own engagement.
- Staff security training that fits in a lunch break and covers the phishing your front desk will actually see.
- Breach-response runbook drafted before you need it: containment, counsel, the 60-day federal notification clock and Louisiana's breach notification requirements.
How we work
We start with a HIPAA-grounded assessment of your practice. From there, we scope an engagement that fits your provider count, your EHR, your locations and your risk tolerance. You get one point of contact who knows your environment.
- Scoped engagement based on what your practice actually needs, not a tier menu.
- Flat monthly rate after the initial assessment, with maintenance scheduled outside clinic hours.
- Full client environment isolation. Your data is never on shared infrastructure with another practice.
Why us, in plain terms
We are owner-led and local, with a 24x7 security operations layer through Huntress behind every endpoint we protect. Our own operations run on a private AI platform we built, which means less manual toil and more time on your environment. We are based in Mandeville, we know the Louisiana market, and we understand how clinical workflow and HIPAA obligations collide on a Tuesday morning.
Free 30-minute assessment
If your current setup leaves you guessing whether you would pass a HIPAA audit, or whether your backups would actually restore, we will tell you in 30 minutes. No pressure, no proposal pushed across the table at the end of the call. Just an honest read on what you have, what is working, and what we would do differently.