"We've never had a problem." It's the most common thing we hear on a first visit, and it's usually said with real confidence. The practice has antivirus. There's a backup drive humming away under a desk. The software is from a name they trust. On the surface, everything looks handled. The trouble is that "looks handled" and "is handled" are two very different things — and the gap between them stays invisible right up until the day it isn't.
The three silent gaps
Underneath a practice that feels fine, we tend to find the same three holes:
- A backup that has never been tested. A backup you've never actually restored from is a hope, not a safety net. Drives fill up, jobs quietly fail, and a reassuring "backup complete" keeps showing while nothing usable is really being saved. Nobody finds out until they need it — the worst possible moment to learn.
- Nobody watching, and nothing recorded. No audit logging means no record of who signed in, what was opened, or what left the building. It feels harmless right up until there's an incident and you can't answer a single question about it.
- A risk assessment that was never done. HIPAA requires a written security risk assessment, and most practices have simply never had one. Without it, nobody has ever actually gone looking for the holes — which is exactly why everything feels fine.
What a breach looks like when you're not ready
Here's the part that surprises people. The ransom note or the locked screen isn't the worst of it. The worst of it is the silence afterward. HIPAA — and your cyber-insurance carrier — will ask hard questions: What was accessed? When? Whose records were involved? Can you prove it wasn't more? A practice with no logs and no tested backup can't answer any of them. And when you can't prove what was and wasn't taken, you're often forced to assume the worst and report the worst. The gap doesn't just cause the breach — it makes the breach far more expensive.
A practice that looked buttoned-up (and wasn't)
One office we took over is a good example — and we'll keep it anonymous, because the details aren't the point. On paper they were fine: paid antivirus, a backup appliance under the counter, staff who'd been there for years. When we ran the risk assessment, the picture changed fast. The backup hadn't completed a successful job in months — it had quietly failed and no one was ever alerted. The whole front desk shared a single login, so the system had no idea who was who. There was no multi-factor authentication anywhere, and no logging at all. Nothing had gone wrong yet. But if it had, they'd have been completely blind: no clean backup to restore, and no way to tell what happened.
We didn't scare them into a giant project. We worked the list in order of what removed the most risk fastest — got a real backup running and boot-tested it, gave every person their own login, switched on multi-factor and encryption, and turned on logging so there'd finally be a record. Then we put it in writing: the assessment, the incident-response steps, the recovery plan — so they had something solid to stand behind.
How we close the gap
"HIPAA-grade" isn't a product you buy; it's a set of technical safeguards you stand up and then keep maintained. On the technical side that means a written risk assessment you could hand to an auditor, backups that are encrypted and boot-tested on a schedule, multi-factor everywhere, full-disk encryption on every machine, audit logging that's actually kept, and written incident-response and disaster-recovery plans. The practice still owns its compliance program — the staff training, the policies, the vendor agreements — but the technical foundation underneath it is finally solid, monitored, and provable.
Three questions worth asking tonight
You don't need an audit to find out whether you have this gap. Ask:
- When did our backup last restore successfully — not "run," but actually restore?
- If we were breached tonight, could we tell exactly what was accessed?
- When was our last written security risk assessment?
If the honest answers are "I'm not sure," you've found the gap. The good news: it's fixable — and it's a lot cheaper to close before a breach than after one.
