Upper East Side · Manhattan

Cybersecurity for NYC medical offices

Cybersecurity for NYC medical offices.

This page is for medical offices and practices (doctors’ offices). It is not walk-in computer repair and not for consumers. Law firms and other professional offices may use the same review.

DriveTech provides IT and security for NYC practices and offices.

Call 212-249-4091 · backup: help@drivetechpc.com

What we find most often

  • Personal email for patient information. The most common finding and the easiest to correct. DriveTech signs Business Associate Agreements (BAAs) with the medical practices we support.
  • No multi-factor authentication on Microsoft 365. Email is where practices get compromised. MFA is usually the fastest high-value control to turn on.
  • A stale HIPAA risk analysis. Under the HIPAA Security Rule already in force, an incomplete or outdated risk analysis is the deficiency federal regulators cite most often.
  • One flat network. Front desk, clinical systems, imaging, and guest Wi-Fi sharing a single network with nothing separating them.
  • Untested backups. An untested backup is a hope, not a control.
  • No asset inventory. Nobody can list every system that touches patient information, which makes other controls hard to verify.

DriveTech does technical work for medical offices. We do not claim that this work makes an office HIPAA-compliant or fully secure. We are not attorneys and do not provide legal advice.

HIPAA Security Rule — accurate status as of August 2026

The overhaul proposed in January 2025 has not been finalized. The existing HIPAA Security Rule remains in force. DriveTech does the technical side of that work (risk-analysis support, inventory, MFA, backups, documentation). Legal interpretation of your obligations belongs with your counsel or compliance advisor.

What a medical office security review covers

  • FortiGate firewall with UTP / network separation so front desk, clinical systems, and guest Wi-Fi are not one flat network
  • Secure email and Microsoft 365 MFA (Google Workspace MFA where used)
  • Office phone and VoIP, any provider
  • Endpoints: post-incident hardening, workstation setup, migration, and protection
  • Backup coverage and restore testing
  • Written documentation for insurers, auditors, and business-associate requirements
  • Privacy and website compliance
  • Monthly network monitoring

How it works

Call 212-249-4091. DriveTech reviews what the office actually runs, then you get a written list of gaps and what it would take to close them. Nothing is authorized until you say so.

Who this is for

Medical offices and practices (doctors’ offices) on the Upper East Side and nearby Manhattan. Law firms and other professional offices can use the same review. Licensed NYDFS Part 500 firms (insurance brokers, lenders, investment advisers) often need the same MFA and asset-inventory work; DriveTech can do the technical pieces. This page is not for consumers and not walk-in computer repair.

Request a medical office security review

Call 212-249-4091 or use the form. You can also email help@drivetechpc.com.

    Call (212) 249-4091, or use this short form and we will follow up during business hours.









    This simple check and the hidden honeypot help block automated spam.

    351 East 82nd Street, New York, NY 10028