Industries

The network, the schedule and the chart all fail together.

In most businesses an IT outage is an inconvenience. In a practice it is a waiting room of people who took the morning off, a schedule that cannot be rebuilt, and clinical information nobody can reach. Iconium runs the safeguards the HIPAA Security Rule expects, and keeps the evidence that they were running.

60 days
Breach notification deadline
24/7
Threat monitoring
Under 2 hrs
First response, business hours
$0
Trip charges

What actually goes wrong in a practice

Healthcare has a failure mode most industries do not: the thing that breaks is often the thing that proves what you did.

The clinical day stops

  • The practice management or EHR system unreachable with a full waiting room
  • Imaging or lab interfaces silently failing, so results stop arriving and nobody notices until someone asks
  • A single workstation in an operatory or exam room down, which in a small practice is a whole provider idle

The disclosure problem

  • Ransomware on a server holding ePHI, which is a security incident and a notification question at the same time
  • Staff sharing one login, so the access log cannot tell you who saw what
  • A stolen laptop with unencrypted patient data, where encryption would have made it a non-event

What the Security Rule actually requires

The HIPAA Security Rule requires covered entities and business associates to implement appropriate administrative, physical and technical safeguards to ensure the confidentiality, integrity and availability of electronic protected health information. It is deliberately flexible about how, and entirely inflexible about whether.

What that means in practice

  • A risk analysis you can produce, not one you intended to do
  • Access controls with unique user identification, so the log means something
  • Audit controls that record activity in systems holding ePHI
  • Encryption of ePHI in transit and at rest
  • Contingency planning: backup, disaster recovery and emergency mode operation
  • Workforce training and sanctions

If it does go wrong

The Breach Notification Rule requires notice to affected individuals without unreasonable delay and no later than 60 days after discovery. Breaches affecting 500 or more individuals go to the Secretary on the same 60-day clock, with media notice as well; smaller breaches may be reported annually, within 60 days of the year end.

Sixty days sounds generous until you are trying to establish what was actually reachable. That determination is a technical question, and it is much faster when the logging was already in place.

A proposed update to the Security Rule was published in January 2025 and remains a proposal. We are tracking it. We will not sell you anything on the strength of a rule that has not been finalised, and you should be wary of anyone who does.

The safeguards we run

All part of the standard monthly rate, grouped by the safeguard category they answer to.

Technical

  • Encryption in transit and at rest
  • Multi-factor authentication and identity hardening
  • Access controls and unique user identification, reviewed rather than set once
  • Application allow-listing, DNS and web content filtering
  • Email security and quarantine

Administrative

  • Security awareness training and simulated phishing
  • Vendor management across your clinical and billing systems
  • Quarterly technology planning, so the risk picture has a review date
  • Audit evidence collection

Detection and response

  • Managed detection and response, 24/7, independent of our support hours
  • Patch and vulnerability management
  • Dark web credential monitoring

Contingency

  • Backup verification and recovery testing, not just backup
  • Onsite support when remote will not do it, included in the rate
  • Unlimited help desk, under two hours to first response in business hours

Where our responsibility stops

  • Any provider with access to your ePHI is a business associate under HIPAA, and the business associate agreement belongs in place before that access begins, not afterwards. If a provider you are evaluating treats that as paperwork to sort out later, it tells you how they think about the rest of it.
  • We operate safeguards and produce evidence. We do not make the determination of whether an incident is a reportable breach, and we do not make the notification. Those are decisions for the practice, usually with counsel.
  • There is no such thing as HIPAA certification. No agency issues one. A vendor selling you a compliance seal is selling you a graphic.
  • Your EHR, practice management and billing vendors keep their own support obligations. We manage the environment they run in and coordinate with them.

What it costs

The same published rates: $163 per user, $19 per computer, $100 per server, $17 per mailbox and $179 per additional location, per month. A fully equipped seat is $199 all in. No minimum, no setup fee, no automatic annual escalator. The pricing page shows the lot, with no form in front of it.

We cover practices across Northeast Ohio and the Greater Houston area, including multi-location practices where each site is charged per location rather than per device in it.

Questions practices ask us

It is not optional, so the answer for any provider worth using is yes. Under HIPAA, a provider with access to electronic protected health information is a business associate, and the agreement belongs in place before access begins. It sets out what we may do with ePHI, what safeguards we maintain and what happens if there is an incident. Ask to see it rather than taking anyone’s word for it, ours included.

No, and nobody can. There is no HIPAA certification and no agency that issues one; compliance is a state your practice maintains, not a product you buy. What we do is operate the technical and administrative safeguards the Security Rule expects, and keep the evidence that they were running. The policies, the training records, the risk analysis decisions and the notification calls remain the practice’s, usually with counsel.

We manage the environment it depends on: the workstations, the servers or the connection to the hosted platform, the identities, the network and the backups. Where the vendor supports the application itself we coordinate with them rather than displacing them, and we handle the parts they will not touch. Tell us what you run on the first call and we will be specific about where the line sits.

Detection and response run 24/7, so containment does not wait for business hours. Recovery depends on whether the backups actually restore, which we test rather than assume. The part specific to healthcare is the third question: what was reachable. That determination drives whether you have a reportable breach and a 60-day clock, and it is far faster to answer when the logging and access controls were already in place.

The Security Rule does not scale down with headcount, and neither do the people attacking small practices — they target them precisely because the defences are usually thinner. There is no seat minimum and no monthly minimum here, so a small practice pays for what it has. What changes with size is the implementation, not the obligation.

Yes, and it is one of the most common findings we see. The Security Rule expects unique user identification, and the practical reason is simple: a shared login means your audit log cannot tell you who accessed a record. On an ordinary day that is untidy. On the day you need to establish what a specific person saw, it is the difference between a clear answer and an assumption.

We plan for a clean handover and never withhold data or client intellectual property. For a practice that also means returning or destroying ePHI as the business associate agreement specifies, and documenting that we did. Onboarding in the other direction typically takes about a week, with terms of twelve, twenty-four or thirty-six months and no setup fee.

Yes. Macs are covered at the same per-computer rate as anything else, and mixed environments are normal. Tablets and other shared clinical devices need a little more thought around identity and screen locking, which is a conversation rather than a surcharge.

Want to know what a risk analysis would actually turn up?

Call (440) 991-9980 or book a thirty minute call. We will tell you plainly which safeguards are already in place and which are not, including the ones that cost nothing to fix.

See also: every industry we serve and our written answers.