If you run a medical practice, “HIPAA compliant” gets thrown around a lot, usually by vendors selling something. Underneath the label, HIPAA’s Security Rule is pretty specific about what your IT actually has to do. Here’s the practical version, without the legal reading.
What the Security Rule expects from your systems
Access controls. Not everyone on staff needs access to every record. HIPAA expects role-based access, unique logins for every user, and a way to shut off access immediately when someone leaves.
Encryption. Patient data should be encrypted both at rest (sitting on a server or drive) and in transit (moving through email, a patient portal, or between systems). If a laptop gets stolen and the drive was encrypted, that’s a very different conversation with regulators than an unencrypted one.
Audit logs. You need a record of who accessed what patient data, and when. Not because you assume staff are doing something wrong, but because if a breach happens, you need to know exactly what was touched and by whom.
Backup and recovery. A practice needs a tested plan for restoring patient data after a ransomware attack, a hardware failure, or plain human error. “We have backups” only counts if you’ve actually confirmed they restore correctly.
Breach response. If patient data is exposed, HIPAA has specific notification timelines and requirements. Having a plan before an incident happens is the difference between a controlled response and a scramble.
None of this is exotic. It’s the baseline most healthcare IT should already be doing. The gap, in our experience, isn’t usually the concept. It’s whether it’s actually been implemented, tested, and documented, versus just assumed.
How this plays out for practices in San Marcos and Hays County
At safemode IT, we support medical practices across Hays County, and San Marcos specifically has more healthcare-focused competition in the IT space than it used to. That’s a good thing for practices shopping around, but it also means “we do HIPAA compliance” isn’t a differentiator on its own anymore. What matters is whether a provider can show you the access logs, the backup test results, and the incident response plan, not just tell you they exist.
We recently walked a San Marcos medical practice through exactly this after a business email compromise knocked out their patient communications for part of a day. We wrote up what happened and how it got resolved in a separate post. The technical response mattered, but so did having a plan already in place for what to do next.
Where TAC 202 overlaps with HIPAA
If your practice also does any work with a Texas state entity, a university health system, or a county appraisal district, you may run into TAC 202 as well. It’s a separate requirement from HIPAA, aimed at Texas state agencies and their vendors rather than healthcare specifically, but the overlap is real: multi-factor authentication, documented risk assessments, incident response planning, and annual security training show up in both. Practices that get one right are usually most of the way to the other.
What to do next
If you manage a medical practice and you’re not sure whether your current IT setup would hold up under a real HIPAA audit, or under a breach, that’s worth a straight answer, not a sales pitch.
We put together a HIPAA compliance checklist built for practice managers, not compliance attorneys. It’s free to download. Or if you’d rather have someone walk your systems directly, we offer a free assessment for medical practices in San Marcos and Hays County.
Frequently asked questions
What does HIPAA require from a medical practice’s IT?
The HIPAA Security Rule requires administrative, physical, and technical safeguards. In practice, that means role-based access controls, encryption of patient data at rest and in transit, audit logs of who accessed what, a tested backup and recovery plan, and a documented breach response process.
Is TAC 202 the same thing as HIPAA?
No. TAC 202 is a separate Texas state requirement aimed at state agencies, universities, and their vendors, including county appraisal districts. It doesn’t apply to every medical practice. But the security controls it requires, like multi-factor authentication and documented risk assessments, overlap heavily with what HIPAA already expects.
Is the HIPAA Security Rule changing?
A stricter update has been proposed at the federal level, including mandatory multi-factor authentication and tighter encryption requirements, but as of this writing it’s still a proposed rule, not final law. Worth watching, not yet something to build a compliance plan around.
This post describes current, settled HIPAA Security Rule requirements. It is not legal advice; a healthcare compliance attorney should review your specific situation.