Skip to main content
Almost all of our client information is electronic: the practice management system, email, the care portal, telehealth. The Security Rule requires us to protect it with administrative, physical, and technical safeguards. Here’s what that means day to day.

Where ePHI lives

Client information lives in these systems and nowhere else:
  • PracticeOS (GoHighLevel): the client record, scheduling, communication, notes
  • The care portal: intake and client-facing documents
  • Google Workspace (Gmail, Drive, Calendar) under a signed business associate agreement, for internal work only
  • Stedi: eligibility and claims
  • Gusto: employee (not client) data
If client information is somewhere else (a personal note app, a text thread, a downloaded spreadsheet, a photo on your phone), it’s in the wrong place. Move it or delete it and tell the practice manager.

Administrative safeguards

  • Every workforce member signs a confidentiality agreement and completes security training before access.
  • Access is granted by role and limited to what the role needs. Clinicians see their own caseload. See Getting access.
  • Access is reviewed when roles change and revoked the day someone leaves.
  • The practice conducts a periodic risk analysis and keeps security policies for at least six years, as the rule requires.

Physical safeguards

  • Lock your screen when you step away, even for a minute. Set auto-lock to five minutes or less.
  • Position screens so clients and visitors can’t read them.
  • Paper with client information, which should be rare, goes in a locked drawer, never left on a desk, and is shredded when no longer needed.
  • Office keys and access are controlled. See Office and facility.

Technical safeguards

  • Unique login for every person, on every system. See Passwords and user accounts.
  • Two-factor authentication on every system that offers it, which is all of ours.
  • Encryption at rest on every device that touches ePHI (FileVault on Mac, BitLocker on Windows, default encryption on modern phones).
  • Automatic updates turned on.
  • Remote wipe enrollment for any mobile device with practice apps. See Devices, mobile, and texting.

Phishing and social engineering

Most breaches start with a message that looks legitimate. Before you click a link, open an attachment, or enter a password:
  • Check the sender’s actual address, not just the display name.
  • Be suspicious of urgency, unexpected invoices, password reset requests you didn’t initiate, and anyone asking for credentials.
  • When in doubt, don’t click. Forward it to Zack and ask.
Nobody at the practice will ever ask for your password. Not Zack, not Helen, not a vendor.

Your responsibilities, in one list

  1. Unique credentials, never shared.
  2. Two-factor on everything.
  3. Encrypted, updated, auto-locking devices.
  4. Client information only in practice systems.
  5. Report anything odd immediately.
Why. The Security Rule sounds technical, but nearly all of it comes down to these five habits. Do them and you’ve done most of the work.