Skip to main content
Updates

Notes from the field.

Short, plain-language posts on what's shifting in HIPAA, OCR, and cyber-insurer expectations for small clinical practices.

May 2026

What the Change Healthcare breach means for small practices

When a clearinghouse breach takes the practice's claims pipeline offline for weeks, the BAA, the cyber policy's business-interruption rider, and your downtime billing posture all get tested at once.

Most small practices touched Change Healthcare without realizing it — through their clearinghouse, their EHR's billing module, or a pharmacy benefit lookup buried in e-prescribing. When the platform went dark in early 2024, claims pipelines stalled for weeks. Cash flow, not PHI exposure, was the first crisis.

The lesson for small practices is that vendor concentration is a quiet risk. The fix is not paranoia — it is documentation. Know which BA touches which workflow, and what your BAA says about downtime credits and breach notification timing.

If your clearinghouse is down again tomorrow: file the BI claim within 72 hours, keep a written downtime log with timestamps, and switch to manual eligibility for high-cost services. Your cyber policy almost certainly covers vendor outage if you document it.

What this means for your practice: Run our triage if your billing pipeline goes dark — it points to the EHR-vendor-compromise playbook with the right first-hour actions.
Apr 2026

How OCR picks who to investigate

Public Wall-of-Shame entries, complaints from former staff, and patterns flagged in MIPS audits are the three doors. Here is what a small practice can do to stay out of all three.

OCR is not a random auditor. Investigations almost always begin from one of three signals: a breach the practice self-reported (the Wall of Shame), a complaint from a patient or former employee, or a referral from CMS after a MIPS Promoting Interoperability audit flagged a missing Security Risk Analysis.

Self-reports you cannot avoid — the law requires them. But complaint-driven investigations correlate strongly with how staff are off-boarded. A disgruntled biller who knows there is no documented sanction policy and no training records is a high-percentage complainant.

MIPS-referred investigations are the most preventable. The Security Risk Analysis is one document. Filing it annually closes the most common door OCR uses to find small practices.

What this means for your practice: Take the 5-minute self-check to see whether your SRA, sanction policy, and training records would survive an information request.
Mar 2026

The one HIPAA document that blocks 70% of fines

Most small-practice OCR fines on record trace back to a missing or stale Security Risk Analysis. Here is what a defensible SRA actually looks like at 1–25 providers.

Pull the OCR resolution agreements for any small practice fine over the last decade and one finding shows up over and over: no current Security Risk Analysis on file. The settlement letter often calls this out by name as the proximate failure.

A defensible SRA for a small practice is not a 100-page binder. It is an inventory of the systems that touch PHI, a written analysis of the threats to each, a documented mitigation for each material risk, and a date. The NIST 800-66r2 outline and the HHS SRA Tool are both free.

The single most expensive mistake is doing one once, three years ago. The Security Rule requires it to be ongoing — read that as annual at minimum, plus after any material change (new EHR, new location, new MSP, a real incident).

What this means for your practice: If you do not have a current SRA, the Practice tier ships with an annual SRA checklist designed for 1–25 providers.
Built by

Travis R. Barlow.

25+ years in incident response. 580+ engagements. Founder of AtlSecCon, one of Canada's longest-running security conferences. No SDR, no junior associate — you talk to the person who has run this incident before.

25+
years IR
580+
engagements
1–25
provider ICP
Scenarios we have walked practices through

Illustrative composites drawn from practitioner conversations. No patient or practice identifiers.

  • Ransomware · Friday afternoon

    Walked the office manager of an 8-provider primary-care clinic through the first three hours — who to call, what not to touch, and what the 60-day HIPAA clock meant.

  • Cyber-insurer renewal

    A 3-provider dermatology clinic pulled the playbooks, customized two pages, and the underwriter accepted the plan — instead of a $9,000 consulting engagement.

  • BEC wire-fraud attempt

    A 5-provider OB/GYN group had read the Front-Desk Email Compromise playbook the week before. Their dual-approval rule caught the wire and prevented the loss.

  • MSP handoff to physician-owner

    The HIPAA self-check produced a one-page gap list an MSP could hand to a physician-owner — no jargon translation required.

Upgrade — vCISO

Your MIPS-ready SRA — and a named owner for the 60-day clock.

Training gets your people ready and advisory is there when something breaks. When you need someone to own the program — the HIPAA Security Rule, your annual SRA, and 405(d) “reasonable security” — and be the name your OCR, cyber insurer, EHR/clearinghouse business associates, and (in Canada) your provincial health privacy commissioner can point to, that’s the HackFirstAid vCISO: a security leader on retainer. Built for the EHR/vendor ransomware event mid-clinic-day, where the breach clock starts before the schedule clears.

We own your program

Strategy, risk register, roadmap, governance, cadenced reviews, and the OCR, cyber-insurer, EHR/clearinghouse BA, and provincial privacy commissioner conversations.

Independent partners execute

DFIR, SOC, pen-testing, tooling, legal, brokerage — coordinated by your vCISO, never sold by us.

Small Practice
CA$1,800/mo
Solo & the smallest offices — quarterly cadence
Foundations
CA$3,000/mo
Managed
CA$6,500/mo
Most chosen
Embedded
CA$12,000/mo

Billed annually. Every tier includes a named vCISO, a 90-day on-ramp, and household coverage.