← All Resources

Medical Practices

Your Cloud EHR Doesn't Make Your Medical Practice HIPAA Compliant

A reputable cloud EHR can protect the application and data it hosts, but it cannot secure every device, account, workflow and decision in the medical practice that uses it.

Short answer

No cloud EHR makes an entire medical practice HIPAA compliant. The vendor is responsible for its part of the environment; the practice remains responsible for its own risk analysis, workforce, devices, identities, networks, email, remote access, policies, contingency planning and use of the platform.

Cloud hosting changes the environment, not the responsibility

HHS permits covered entities and business associates to use cloud services for electronic protected health information when the arrangement complies with the HIPAA Rules, including an appropriate Business Associate Agreement when the provider creates, receives, maintains or transmits ePHI on the organization’s behalf.

That arrangement is shared responsibility. The vendor protects its hosted platform according to its obligations and agreement. The practice still must understand the service, conduct its own risk analysis, manage how people access it and implement reasonable and appropriate safeguards around the rest of the environment.

A signed BAA is necessary in many vendor relationships, but it is not a certificate that the practice or product is “HIPAA compliant.” It documents responsibilities and permitted activity. The practice still needs to understand what the agreement covers, configure the service appropriately, limit user access and address any systems or workflows outside the vendor’s scope.

The EHR ends where many practice risks begin

A secure application can still be accessed from a compromised laptop, through a stolen password or by a former employee whose account was never disabled. Information may also leave the EHR through email, downloads, scanned documents, billing exports, interfaces, patient communications, backups or vendor support workflows.

The practice’s environment therefore includes more than the EHR: workstations, servers, mobile devices, Microsoft 365 or Google Workspace, wireless networks, remote access, identity systems, printers and scanners, local folders, voice or messaging systems and every vendor that creates, receives, maintains or transmits ePHI.

Technical safeguards are only one layer

Practical safeguards may include unique user accounts, multi-factor authentication where appropriate, device encryption, endpoint protection, patching, secure remote access, network segmentation, protected backups and logging. Which measures are reasonable and appropriate should be informed by the practice’s risk analysis and the systems involved.

Those technical controls do not replace administrative and physical safeguards. The practice still needs assigned security responsibility, workforce authorization, training, policies, incident procedures, vendor management, facility and workstation protections, contingency planning and documentation of important decisions.

The risk analysis must follow the information

HHS guidance says the risk analysis must consider all ePHI an organization creates, receives, maintains or transmits. A review limited to the EHR’s security questionnaire will miss the endpoints, integrations, email workflows, vendors and local data that surround the application.

Map where ePHI enters the practice, where it can be viewed or stored, how it is transmitted and which people and vendors can reach it. Then identify threats and vulnerabilities, assess existing safeguards and document remediation priorities. This is the foundation for deciding which protections the practice needs—not a product-comparison exercise.

Current rule and proposed changes

HHS has proposed substantial updates to the HIPAA Security Rule. HHS continues to describe that update as a proposed rule and states that the current Security Rule remains in effect while rulemaking continues. This article describes the current shared-responsibility and risk-analysis requirements; proposed provisions should not be presented as current requirements.

Practices can still use the proposal as a signal of regulatory direction and modern security expectations, but legal and compliance decisions should be based on the rule in effect and advice specific to the organization.

What this means for your practice

Ask the EHR vendor good questions about its safeguards, BAA, availability, backup and recovery, incident reporting and data return. Then turn the same attention inward. Can the practice identify every user, device, integration and vendor with access? Are former users removed promptly? Are local downloads protected? Can the practice restore critical operations if the platform or Internet connection is unavailable?

The right conclusion is not that cloud EHRs are unsafe. They can be an important and well-protected part of the environment. The conclusion is that the practice needs a security program around the platform, with clear ownership and documentation.

Related support

GO InfoTek can help medical practices evaluate the complete technology environment around the EHR, implement and manage appropriate safeguards, and connect that work to the practice’s Security Risk Analysis and written program.

Medical practice IT & HIPAA supportHIPAA Security Risk AnalysisManaged IT services

This article provides general information to support technology, cybersecurity and compliance discussions. It is not legal advice and does not replace review of your organization’s specific obligations with qualified legal or compliance professionals.

Sources and Further Reading

A practical next step

Discuss Your Environment with GO InfoTek

Start with the systems, safeguards, documentation and questions your organization has today.

Schedule a Conversation