IT and security support for New York City medical and professional practices
Small practices carry the same obligations as large health systems with none of the staff. There’s no IT department, no security officer, and no time between patients to think about any of it. DriveTech handles the technology side: the network, the email, the workstations, the backups, and the documentation.
What we find most often
Patient information moving through free personal email.
The most common finding and the easiest to correct.
DriveTech signs Business Associate Agreements with the medical practices we support.
No multi-factor authentication on Microsoft 365.
Email is where practices get compromised. MFA is the single highest-value control on this list and usually the fastest to turn on.
A risk analysis nobody has updated.
Under the HIPAA Security Rule already in force, an incomplete or stale risk analysis is the deficiency federal regulators cite most frequently in enforcement actions. It’s also the first document anyone asks for.
One flat network.
Front desk, clinical systems, imaging, and patient Wi-Fi all sharing a single network with nothing separating them.
Backups nobody has ever restored from.
An untested backup is a hope, not a control.
No asset inventory.
Nobody can list every system that touches patient information — which makes every other control impossible to verify.
About the proposed HIPAA Security Rule changes
You may be getting emails claiming your practice is out of compliance with “new HIPAA security rules.” Here is the accurate picture as of August 2026.
The overhaul proposed in January 2025 — which would make encryption, multi-factor authentication, annual risk analysis, network segmentation, and asset inventories explicitly required rather than “addressable” — is still a proposed rule. It has not been finalized. Federal regulators have moved final action to a long-term agenda with a July 2027 target, and that timing could shift again.
That does not mean nothing applies. The existing HIPAA Security Rule is fully in force and actively enforced, and inadequate risk analysis remains the most-cited deficiency in enforcement actions. The work that would prepare a practice for the proposed rule is the same work the current rule already expects: a current documented risk analysis, an accurate inventory of systems touching patient information, multi-factor authentication on remote and privileged access, tested backups, and current business associate agreements.
DriveTech does the technical side of that work. We are not attorneys and don’t provide legal interpretation of your obligations — for that, use your counsel or compliance advisor.
Regulatory status current to August 2026. Re-verify annually and immediately if a final rule is published.
What DriveTech handles
Secure email and messaging platforms · Microsoft 365 hardening and multi-factor authentication · Network separation for clinical, administrative, and guest traffic · FortiGate firewall deployment · Workstation setup, migration, and endpoint protection · Backup coverage and restore testing · Staff security awareness training · Written documentation for insurers, auditors, and business associate requirements
Also for law firms and professional offices
Law firms and professional practices face the same underlying problems with different labels — client security questionnaires instead of BAAs, wire fraud on closings instead of patient data, matter confidentiality instead of PHI. The work is largely the same.
If your office is licensed by the New York Department of Financial Services — insurance brokers, lenders, investment advisers — note that all requirements of the amended Part 500 have been in full effect since November 1, 2025, including near-universal multi-factor authentication and a documented asset inventory program, with annual certification due each April 15.
