Live webinar · Free · 45 minutes
Cybersecurity for Small Medical Practices: palmiq Webinar what HIPAA requires today, what's only proposed, and what's worth doing either way
A 45-minute working session for practice managers and owners of small medical, dental and behavioral health offices, led by palmiq. You'll leave able to sort every security control on your list into three buckets — required now, proposed but not final, and expected by cyber insurers and hospital business associate agreements regardless — and you'll see what each one looks like at small-practice scale.
- A three-column control mapencryption, MFA, asset inventory, vulnerability scanning, penetration testing, incident response and incident notification, each sorted into required today, proposed and not final, or expected by insurers and BAAs anyway.
- A straight answer on timingreporting indicates the proposed HIPAA Security Rule overhaul is still not final, with OMB targeting July 2027 for final action and OCR not confirming a firm date. We treat that as a multi-year planning horizon — a budgeting suggestion, not a deadline anyone has published — instead of pretending a compliance date exists.
- The small-practice version of each controlwhat the proposed items look like implemented in a 12-person office rather than a hospital system, including where the honest answer is "not yet."
- A verification procedure you can hand to your front deskpractical steps for phone and email requests to change payment details, release records or approve a transfer, built for impersonation attempts that look and sound legitimate.
- Clarity on the Security Risk Analysiswhat this existing obligation actually covers, what documentation holds up when someone asks to see it, and how a low-key gap assessment conversation with palmiq picks up where the session ends for practices that want one.
Reserve your seat
Free · 45 minutes · 12 seats per session
No sales sequence. One reminder before the session, and the recording after.
What we actually cover
What people bring to this session.
Do we have to encrypt ePHI and turn on MFA right now?
Today these sit inside the existing Security Rule's risk analysis requirement rather than as flat mandates. The NPRM proposes making them explicit by removing the "addressable" designation — proposed, not law. We walk both paths and explain why most practices land on doing it anyway.
We don't have a hospital's budget. Is anyone listening to that?
Yes. Per published reporting, CHIME and a coalition of 100+ hospital and provider groups have formally asked HHS to withdraw the proposed rule, largely on cost and feasibility grounds. We take that objection seriously and talk through proportionate spending instead of dismissing it.
Our staff is trained to spot suspicious emails. Isn't that enough?
IBM's 2025 Cost of a Data Breach Report, as summarized by All Covered, found roughly 1 in 6 breaches involved attackers using AI — most commonly phishing (37%) and deepfake impersonation (35%). We cover why a written verification procedure now does the work that "the email looked off" used to do.
Where does security spending actually reduce what a breach costs?
Per the same All Covered summary of IBM's report, healthcare remained the costliest sector at an average $7.42 million, down from $9.77 million the prior year, while the global average fell from $4.88 million to $4.44 million — the first drop in five years, attributed largely to faster detection and containment. That points at detection-and-response time, which is the practical case for monitoring and managed detection and response (MDR) rather than buying more prevention tools. We spend real time on it.
Before you register
Common questions
- Does our IT provider need a business associate agreement?
- If a provider creates, receives, maintains or transmits ePHI on your behalf, it is a business associate and a signed BAA is required. We cover what belongs in one and what to ask for.
- Will attending make our practice HIPAA compliant?
- No, and no vendor or software can. There is no HHS certification program for either. Compliance is organizational: policies, training, documentation and the Security Risk Analysis. This session is education.
- How current is the material?
- The slides carry an "accurate as of" date. The rulemaking is open and we say so plainly. Breach figures cited come from a secondary summary of IBM's 2025 report, and rulemaking details from published reporting; primary sources are listed on the closing slide so you can check them.
- Who should attend?
- Practice managers, owners, office administrators and billing leads at small medical, dental and behavioral health practices. No technical background assumed.
Rather talk it through first? Call 703-336-9700, or see the other sessions.