"We've never had a problem." It's the most common thing we hear on a first visit, and it's usually said with real confidence. The practice has antivirus. There's a backup drive humming away under a desk. The software is from a name they trust. On the surface, everything looks handled. The trouble is that "looks handled" and "is handled" are two very different things — and the gap between them stays invisible right up until the day it isn't.

The three silent gaps

Underneath a practice that feels fine, we tend to find the same three holes:

What a breach looks like when you're not ready

Here's the part that surprises people. The ransom note or the locked screen isn't the worst of it. The worst of it is the silence afterward. HIPAA — and your cyber-insurance carrier — will ask hard questions: What was accessed? When? Whose records were involved? Can you prove it wasn't more? A practice with no logs and no tested backup can't answer any of them. And when you can't prove what was and wasn't taken, you're often forced to assume the worst and report the worst. The gap doesn't just cause the breach — it makes the breach far more expensive.

A practice that looked buttoned-up (and wasn't)

One office we took over is a good example — and we'll keep it anonymous, because the details aren't the point. On paper they were fine: paid antivirus, a backup appliance under the counter, staff who'd been there for years. When we ran the risk assessment, the picture changed fast. The backup hadn't completed a successful job in months — it had quietly failed and no one was ever alerted. The whole front desk shared a single login, so the system had no idea who was who. There was no multi-factor authentication anywhere, and no logging at all. Nothing had gone wrong yet. But if it had, they'd have been completely blind: no clean backup to restore, and no way to tell what happened.

We didn't scare them into a giant project. We worked the list in order of what removed the most risk fastest — got a real backup running and boot-tested it, gave every person their own login, switched on multi-factor and encryption, and turned on logging so there'd finally be a record. Then we put it in writing: the assessment, the incident-response steps, the recovery plan — so they had something solid to stand behind.

How we close the gap

"HIPAA-grade" isn't a product you buy; it's a set of technical safeguards you stand up and then keep maintained. On the technical side that means a written risk assessment you could hand to an auditor, backups that are encrypted and boot-tested on a schedule, multi-factor everywhere, full-disk encryption on every machine, audit logging that's actually kept, and written incident-response and disaster-recovery plans. The practice still owns its compliance program — the staff training, the policies, the vendor agreements — but the technical foundation underneath it is finally solid, monitored, and provable.

Three questions worth asking tonight

You don't need an audit to find out whether you have this gap. Ask:

  1. When did our backup last restore successfully — not "run," but actually restore?
  2. If we were breached tonight, could we tell exactly what was accessed?
  3. When was our last written security risk assessment?

If the honest answers are "I'm not sure," you've found the gap. The good news: it's fixable — and it's a lot cheaper to close before a breach than after one.