Where ePHI lives
Client information lives in these systems and nowhere else:- PracticeOS (GoHighLevel): the client record, scheduling, communication, notes
- The care portal: intake and client-facing documents
- Google Workspace (Gmail, Drive, Calendar) under a signed business associate agreement, for internal work only
- Stedi: eligibility and claims
- Gusto: employee (not client) data
Administrative safeguards
- Every workforce member signs a confidentiality agreement and completes security training before access.
- Access is granted by role and limited to what the role needs. Clinicians see their own caseload. See Getting access.
- Access is reviewed when roles change and revoked the day someone leaves.
- The practice conducts a periodic risk analysis and keeps security policies for at least six years, as the rule requires.
Physical safeguards
- Lock your screen when you step away, even for a minute. Set auto-lock to five minutes or less.
- Position screens so clients and visitors can’t read them.
- Paper with client information, which should be rare, goes in a locked drawer, never left on a desk, and is shredded when no longer needed.
- Office keys and access are controlled. See Office and facility.
Technical safeguards
- Unique login for every person, on every system. See Passwords and user accounts.
- Two-factor authentication on every system that offers it, which is all of ours.
- Encryption at rest on every device that touches ePHI (FileVault on Mac, BitLocker on Windows, default encryption on modern phones).
- Automatic updates turned on.
- Remote wipe enrollment for any mobile device with practice apps. See Devices, mobile, and texting.
Phishing and social engineering
Most breaches start with a message that looks legitimate. Before you click a link, open an attachment, or enter a password:- Check the sender’s actual address, not just the display name.
- Be suspicious of urgency, unexpected invoices, password reset requests you didn’t initiate, and anyone asking for credentials.
- When in doubt, don’t click. Forward it to Zack and ask.
Your responsibilities, in one list
- Unique credentials, never shared.
- Two-factor on everything.
- Encrypted, updated, auto-locking devices.
- Client information only in practice systems.
- Report anything odd immediately.
Why. The Security Rule sounds technical, but nearly all of it comes down to these five habits. Do them and you’ve done most of the work.