Industries
In most businesses an IT outage is an inconvenience. In a practice it is a waiting room of people who took the morning off, a schedule that cannot be rebuilt, and clinical information nobody can reach. Iconium runs the safeguards the HIPAA Security Rule expects, and keeps the evidence that they were running.
Healthcare has a failure mode most industries do not: the thing that breaks is often the thing that proves what you did.
The HIPAA Security Rule requires covered entities and business associates to implement appropriate administrative, physical and technical safeguards to ensure the confidentiality, integrity and availability of electronic protected health information. It is deliberately flexible about how, and entirely inflexible about whether.
The Breach Notification Rule requires notice to affected individuals without unreasonable delay and no later than 60 days after discovery. Breaches affecting 500 or more individuals go to the Secretary on the same 60-day clock, with media notice as well; smaller breaches may be reported annually, within 60 days of the year end.
Sixty days sounds generous until you are trying to establish what was actually reachable. That determination is a technical question, and it is much faster when the logging was already in place.
A proposed update to the Security Rule was published in January 2025 and remains a proposal. We are tracking it. We will not sell you anything on the strength of a rule that has not been finalised, and you should be wary of anyone who does.
All part of the standard monthly rate, grouped by the safeguard category they answer to.
The same published rates: $163 per user, $19 per computer, $100 per server, $17 per mailbox and $179 per additional location, per month. A fully equipped seat is $199 all in. No minimum, no setup fee, no automatic annual escalator. The pricing page shows the lot, with no form in front of it.
We cover practices across Northeast Ohio and the Greater Houston area, including multi-location practices where each site is charged per location rather than per device in it.
It is not optional, so the answer for any provider worth using is yes. Under HIPAA, a provider with access to electronic protected health information is a business associate, and the agreement belongs in place before access begins. It sets out what we may do with ePHI, what safeguards we maintain and what happens if there is an incident. Ask to see it rather than taking anyone’s word for it, ours included.
No, and nobody can. There is no HIPAA certification and no agency that issues one; compliance is a state your practice maintains, not a product you buy. What we do is operate the technical and administrative safeguards the Security Rule expects, and keep the evidence that they were running. The policies, the training records, the risk analysis decisions and the notification calls remain the practice’s, usually with counsel.
We manage the environment it depends on: the workstations, the servers or the connection to the hosted platform, the identities, the network and the backups. Where the vendor supports the application itself we coordinate with them rather than displacing them, and we handle the parts they will not touch. Tell us what you run on the first call and we will be specific about where the line sits.
Detection and response run 24/7, so containment does not wait for business hours. Recovery depends on whether the backups actually restore, which we test rather than assume. The part specific to healthcare is the third question: what was reachable. That determination drives whether you have a reportable breach and a 60-day clock, and it is far faster to answer when the logging and access controls were already in place.
The Security Rule does not scale down with headcount, and neither do the people attacking small practices — they target them precisely because the defences are usually thinner. There is no seat minimum and no monthly minimum here, so a small practice pays for what it has. What changes with size is the implementation, not the obligation.
Yes, and it is one of the most common findings we see. The Security Rule expects unique user identification, and the practical reason is simple: a shared login means your audit log cannot tell you who accessed a record. On an ordinary day that is untidy. On the day you need to establish what a specific person saw, it is the difference between a clear answer and an assumption.
We plan for a clean handover and never withhold data or client intellectual property. For a practice that also means returning or destroying ePHI as the business associate agreement specifies, and documenting that we did. Onboarding in the other direction typically takes about a week, with terms of twelve, twenty-four or thirty-six months and no setup fee.
Yes. Macs are covered at the same per-computer rate as anything else, and mixed environments are normal. Tablets and other shared clinical devices need a little more thought around identity and screen locking, which is a conversation rather than a surcharge.
Call (440) 991-9980 or book a thirty minute call. We will tell you plainly which safeguards are already in place and which are not, including the ones that cost nothing to fix.
See also: every industry we serve and our written answers.