HIPAA Technical Safeguards — Network Layer

Your patient records
and your waiting room WiFi
should never share a network.

Most medical and dental offices are running networks that were set up by the ISP installer and never touched again. That's a HIPAA violation waiting to happen — and a single breach can mean six-figure fines. We fix the network and keep it that way.

🏥 Medical offices 🦷 Dental practices 👁 Optometry 🧪 Lab & diagnostics 💆 Mental health practices 🏃 Physical therapy
The problems we see

What's wrong with most
medical office networks.

These aren't edge cases. We see every one of these in the majority of small practices we assess.

⚠️
No network segmentation

Your EHR workstations, medical devices, front desk computers, and patient waiting room WiFi are all on the same flat network. Any device can reach any other device. This is a HIPAA Technical Safeguard failure.

"The IT guy who set this up said it was fine. It's not fine."
🔓
Patient WiFi touches everything

If a patient in your waiting room is on the same WiFi as your EHR server, they can potentially reach protected health information. One curious person with a scanning tool is a breach.

"We just give patients the office WiFi password. Everyone does that."
🖨️
Medical devices on the main LAN

Imaging equipment, diagnostic devices, and connected medical hardware often run outdated firmware that can't be patched. These should never be exposed to general office traffic or patient networks.

"Our X-ray machine is just on the network with everything else."
📵
EHR goes down, appointments stop

When the internet drops, your cloud-based EHR goes with it — Epic, Athenahealth, Dentrix Ascend, all of them. No failover means turning patients away or reverting to paper.

"We had to reschedule eight patients last month because of an outage."
📋
No documentation for audits

A HIPAA audit or cyber insurance assessment will ask for network diagrams, access logs, and documentation of your technical safeguards. Most practices have nothing to show.

"Our cyber insurance renewal asked for a network diagram and we didn't have one."
🏢
Multi-provider, no IT oversight

Group practices with multiple providers and locations often have inconsistent setups — each location configured differently, no central monitoring, and no one responsible when something goes wrong.

"Location 2 has completely different equipment. Nobody knows who set it up."
HIPAA & your network

What HIPAA actually
requires of your network.

The HIPAA Security Rule Technical Safeguards are not optional suggestions. Here's what applies to your network infrastructure specifically.

What the rules require

The HIPAA Security Rule (45 CFR §164.312) mandates technical safeguards for any system that creates, receives, maintains, or transmits electronic protected health information (ePHI).

  • Access controls — only authorized systems can reach ePHI
  • Transmission security — ePHI must be encrypted in transit
  • Audit controls — systems must log access to ePHI
  • Integrity controls — ePHI must be protected from improper alteration
  • Network segmentation — PHI systems must be isolated from general access
  • Automatic logoff — sessions must terminate after inactivity
What we provide

We design your network to satisfy the Technical Safeguards section of the Security Rule — proper segmentation, encrypted traffic paths, and documented architecture you can show to auditors or cyber insurance underwriters.

What a breach actually costs

HIPAA penalties are tiered by level of negligence. Networks with no segmentation and default configurations fall into the higher tiers.

  • Tier 1 (unknowing violation) — $100 to $50,000 per violation
  • Tier 2 (reasonable cause) — $1,000 to $50,000 per violation
  • Tier 3 (willful neglect, corrected) — $10,000 to $50,000
  • Tier 4 (willful neglect, not corrected) — $50,000 per violation, up to $1.9M annually
  • State AG penalties — additional fines on top of federal
  • Breach notification costs — legal, notification, credit monitoring
The real risk for small practices

A flat network with patient WiFi sharing a subnet with EHR workstations is a documented, willful-neglect-level violation once it's been brought to your attention. The cost of the managed network is a fraction of one incident.

By practice type

What we set up for
your specific practice.

Medical, dental, optometry, and therapy practices all have different systems and workflows. Here's what a properly segmented network looks like for each.

Medical offices

Primary care, urgent care, specialists — most run cloud-based EHRs, have connected diagnostic equipment, and a front desk workflow that can't tolerate downtime. Network reliability is directly tied to patient throughput.

  • EHR workstation network isolation — Epic, Athenahealth, eClinicalWorks, Kareo
  • Medical device VLAN — imaging, diagnostic, connected equipment
  • Front desk and billing network — separate from clinical systems
  • Patient waiting room WiFi — fully isolated, bandwidth managed
  • Telehealth platform connectivity and quality of service (QoS) prioritization
  • LTE failover — EHR access maintained if primary circuit fails
  • Encrypted DNS and traffic inspection at the firewall
  • Network documentation package for HIPAA audit readiness
BAA note
We execute a Business Associate Agreement (BAA) with every medical practice client. This is required under HIPAA when a vendor has access to systems that process ePHI. Most IT vendors either don't offer this or don't know what it is.
Network layout — medical office
Clinical / EHRPHI ZONE
EHR workstations · clinical tablets · printers
VLAN 10 · 192.168.10.x
Medical DevicesPHI ZONE
Imaging · diagnostic equipment · connected devices
VLAN 20 · 192.168.20.x
Front Desk / AdminRESTRICTED
Scheduling · billing · phone system
VLAN 30 · 192.168.30.x
VoIP / PhonesQoS PRIORITY
IP desk phones · softphones · fax
VLAN 40 · 192.168.40.x
Patient WiFiFULLY ISOLATED
Waiting room devices — zero access to all other VLANs
VLAN 50 · 192.168.50.x
↑ Firewall enforces inter-VLAN rules. PHI zones cannot be reached from patient WiFi or front desk segments. All inter-VLAN traffic logged.

Dental practices

Dental offices have some of the most complex network requirements of any small medical practice — digital X-ray and CBCT imaging systems, intraoral cameras, practice management software, and patient check-in kiosks all on one network. Most are seriously misconfigured.

  • Practice management software isolation — Dentrix, Eaglesoft, Open Dental, Curve
  • Digital imaging network — X-ray, CBCT, intraoral camera VLANs
  • Imaging workstation high-bandwidth prioritization
  • Patient check-in kiosk isolation
  • Sterilization and operatory device connectivity
  • Patient entertainment / display network
  • Front desk scheduling and billing isolation
  • LTE failover — cloud-based practice management stays up
Imaging note
CBCT and digital X-ray systems produce large files and need high-bandwidth LAN paths to workstations. We configure QoS and routing so imaging traffic doesn't compete with general office traffic — and imaging systems are never exposed to patient networks.
Network layout — dental practice
Practice ManagementPHI ZONE
Dentrix/Eaglesoft workstations · server
VLAN 10 · 192.168.10.x
Imaging SystemsPHI ZONE
X-ray · CBCT · intraoral cameras · imaging workstations
VLAN 20 · 192.168.20.x
Front Desk / AdminRESTRICTED
Scheduling · billing · check-in kiosks
VLAN 30 · 192.168.30.x
Patient EntertainmentISOLATED
Operatory TVs · ceiling displays · patient tablets
VLAN 40 · 192.168.40.x
Patient WiFiFULLY ISOLATED
Waiting room devices — zero clinical access
VLAN 50 · 192.168.50.x
↑ Imaging VLAN has dedicated high-bandwidth path. PHI zones never accessible from patient-facing segments.

Optometry practices

Optometry offices run diagnostic equipment — autorefractors, OCT machines, visual field analyzers — alongside practice management software, optical retail POS, and patient-facing waiting room systems. Each needs its own network zone.

  • Practice management isolation — Revolution EHR, Eyefinity, OfficeMate
  • Diagnostic equipment VLAN — OCT, autorefractor, visual field
  • Optical retail POS isolation and PCI compliance
  • Patient waiting room WiFi isolation
  • Remote access for after-hours chart review
  • Integrated lens ordering system connectivity
  • HIPAA-compliant network documentation
Dual-purpose note
Optometry practices often combine healthcare (HIPAA) and retail (PCI) compliance requirements on the same network. We design for both simultaneously — clinical systems stay HIPAA-compliant, optical retail stays PCI-compliant, and the two segments never share a path.
Network layout — optometry
Clinical / EHRPHI ZONE
EHR workstations · exam room systems
VLAN 10 · 192.168.10.x
Diagnostic EquipmentPHI ZONE
OCT · autorefractor · visual field analyzers
VLAN 20 · 192.168.20.x
Optical Retail POSPCI ZONE
Frame sales terminals · card readers · ordering
VLAN 30 · 192.168.30.x
Patient WiFiFULLY ISOLATED
Waiting room — no clinical or retail access
VLAN 40 · 192.168.40.x
↑ Dual HIPAA + PCI compliance satisfied. Clinical and retail segments cannot communicate directly.

Mental health & therapy practices

Therapy, counseling, and mental health practices handle some of the most sensitive PHI that exists. The network requirements are simpler than a medical office, but the stakes for a breach are extremely high — and telehealth reliability is critical.

  • EHR and notes system isolation — SimplePractice, TherapyNotes, Luminare
  • Telehealth platform prioritization — Zoom, Doxy.me, VSee bandwidth QoS
  • Waiting room WiFi completely isolated from session systems
  • Sound masking system network integration if applicable
  • Secure remote access for providers working from multiple locations
  • HIPAA documentation for credentialing and insurance audits
  • Encrypted DNS — prevents DNS-level snooping on session traffic
Telehealth note
Telehealth sessions require stable, low-latency connectivity. We configure QoS rules that prioritize video session traffic over general office traffic — so a file download in the waiting room doesn't degrade a session in progress.
Network layout — therapy practice
Clinical / EHRPHI ZONE
EHR workstations · provider laptops · session systems
VLAN 10 · 192.168.10.x
Admin / BillingRESTRICTED
Scheduling · billing · insurance systems
VLAN 20 · 192.168.20.x
VoIP / TelehealthQoS PRIORITY
IP phones · video session systems — bandwidth guaranteed
VLAN 30 · 192.168.30.x
Patient WiFiFULLY ISOLATED
Waiting room — zero clinical access
VLAN 40 · 192.168.40.x
↑ Telehealth VLAN has guaranteed bandwidth. PHI never accessible from patient WiFi or waiting room systems.
What you get

Everything your practice
network needs.

Flat monthly pricing. HIPAA-compliant from day one. One point of contact for everything network-related.

01
HIPAA-Compliant Firewall

Properly configured firewall with VLAN segmentation enforced at the hardware level. PHI zones isolated, inter-VLAN traffic logged, encrypted DNS enabled.

Included in monthly rate
02
Managed WiFi

Separate SSIDs for clinical staff, admin, and patient waiting room. Patient network is client-isolated — devices can reach the internet but nothing on your LAN.

Included in monthly rate
03
Internet Brokerage

Best circuit for your location across all SoCal carriers. We manage the carrier relationship — you reach out to us, not AT&T, when it's down.

Free — we earn from the carrier
04
LTE Failover

Automatic cellular backup when your primary circuit fails. Cloud EHR access and telehealth sessions keep working. No staff action required.

Add-on — ask about pricing
05
Proactive Monitoring

We monitor your network 24/7. Most issues are caught and resolved remotely before your staff notices anything is wrong.

Included in monthly rate
06
HIPAA Documentation Package

Network diagram, VLAN documentation, and a written technical safeguards summary — ready for a HIPAA audit, cyber insurance application, or credentialing review.

Included at setup
💬
Pricing based on your practice environment. Provider count, locations, EHR platform, imaging systems, and compliance requirements all factor in. You'll get an exact monthly number after a free 30-minute assessment — not a range, not a "starting at" that balloons after you sign.
Business Associate Agreement (BAA)
Under HIPAA, any vendor with access to systems that process electronic protected health information must sign a BAA with your practice. We sign a BAA with every medical client. This is non-negotiable for compliance — and most IT vendors don't offer it or don't understand why it's required. Ask any vendor you're evaluating whether they'll sign one.
Process

HIPAA-compliant and running
in less than a week.

We've done this in medical and dental offices enough times that the process is tight. Here's what to expect.

01
Free assessment

30 minutes, remote. We review your current network, EHR and device list, and identify specific HIPAA exposure. You get a written summary.

02
Flat quote + BAA

Specific monthly number, scope of work, and a Business Associate Agreement ready to sign. No open-ended estimates.

03
Off-hours install

We schedule installation before your office opens or after it closes. Patient care is never interrupted. Most single-location setups take 3–5 hours.

04
Documentation delivered

You receive a complete network diagram and HIPAA technical safeguards summary within 48 hours of installation. Audit-ready from day one.

Questions

Things practice managers
ask before they reach out.

Plain answers. No upsell.

Almost certainly not. EHR vendors support the software — they don't own, configure, or monitor your network infrastructure. Your Athenahealth or Dentrix support team cannot tell you whether your firewall is segmenting your PHI zone from your patient WiFi. That's a separate discipline, and it's what we do.
Yes — every time, no exceptions. A BAA is a required component of any HIPAA-compliant vendor relationship where the vendor has access to systems that touch ePHI. We include it in the onboarding process. If a vendor tells you they don't need to sign a BAA because they "don't touch patient data," ask them to explain that in writing.
If your practice creates, receives, maintains, or transmits electronic protected health information — which any practice using an EHR does — then yes, the HIPAA Security Rule Technical Safeguards apply to your network. This is not optional and it's not just for large health systems. Solo practices and small group practices are regularly audited and fined.
With LTE failover enabled, your firewall automatically switches to a cellular backup connection when the primary circuit fails — usually within 30 to 60 seconds. Cloud-based EHR access, telehealth sessions, and scheduling systems keep working. For practices that cannot tolerate any downtime, we can also configure dual-circuit failover with two wired connections from different carriers.
Yes. Multi-location is where a managed service relationship adds the most value — consistent architecture at every site, central monitoring, one invoice, one BAA covering both locations. We design both sites identically so there's no confusion about which location has which configuration.
Yes — this is standard. We schedule all installation work before your office opens or after it closes. Most practices give us a Saturday morning or an early weekday slot. Patient care is never interrupted. Ongoing support issues are handled remotely without any on-site disruption.
Get started

Let's assess your
practice network.

Free 30-minute assessment. We'll identify exactly where your network falls short of HIPAA Technical Safeguards requirements and tell you what it costs to fix it.

Free assessment — written findings included
BAA included with every medical client
Off-hours installation — no patient disruption