HIPAA-aligned managed IT for California medical practices — including the documentation an audit asks for.
Most IT providers can keep workstations running. A medical practice needs that plus a second thing: evidence. When an auditor, an insurer or the Office for Civil Rights asks how PHI is protected, the answer has to be documented, not asserted.
That is the practical difference between general IT support and healthcare IT support, and it is where most practices discover their provider was never set up to help.
Cobrix signs a Business Associate Agreement with every healthcare client, as HIPAA requires of any vendor handling PHI on your behalf. It is part of the standard service agreement, not an add-on.
Microsoft extends a HIPAA BAA to eligible tenants by default — but a default tenant is not compliant. Access controls, audit logging, encryption and data-loss prevention have to be configured and kept that way.
Every workstation, laptop and mobile device that touches PHI enrolled under policy through Microsoft Intune, with encryption enforced and the ability to wipe a lost device remotely.
Phishing-resistant multi-factor authentication, unique credentials per workforce member, and role-based access so staff reach only the records their role requires.
Configured so that sending patient information to a referring provider or a patient does not become the breach, including handling for the cases where the recipient has no secure mail.
Tested restores rather than assumed ones, sized against how long your practice can actually operate without its records.
Your clinical systems are usually vendor-hosted. We handle the connectivity, workstation configuration, printing and integration issues around them, and coordinate with the vendor when the problem is on their side.
The Security Risk Analysis, access reviews and control evidence that HIPAA expects you to be able to produce, maintained as you go rather than assembled in a panic.
The Security Rule is specific about the technical safeguards. In practice it comes down to:
The Security Risk Analysis is the one practices most often skip and the one investigators most reliably ask for. It is not a scan or a checklist a tool produces — it is a documented assessment of your specific environment.
These are not exotic failures. They are the same handful of gaps, in roughly this order:
Before you commit to a provider, ask which tools in your practice hold PHI and whether each vendor will sign a BAA. It is a short question and the answer tells you a great deal.
Our HIPAA tool compliance guides give the verdict for the tools most practices already use, including Microsoft 365, Google Workspace, Calendly and Docusign.
A signed Business Associate Agreement with the provider, unique credentials and role-based access for every workforce member, multi-factor authentication, encryption of PHI in transit and at rest, audit logging with deliberate retention, managed and encrypted devices, tested backups, and a documented annual Security Risk Analysis. The BAA alone is not compliance; configuration and documentation are what an investigator examines.
Yes. Any vendor that creates, receives, maintains or transmits PHI on your behalf is a business associate under HIPAA and must execute a BAA. If a prospective IT provider hesitates on this, that is the answer to your question about whether they work with medical practices.
No. Microsoft extends a HIPAA BAA to eligible tenants through its Data Protection Addendum, which is necessary but not sufficient. Compliance depends on how the tenant is configured: access controls, audit logging, encryption, device management and data-loss prevention all have to be set and maintained.
It is a documented assessment of the threats and vulnerabilities affecting PHI in your specific environment, together with the controls addressing them. HIPAA requires it, it is expected to be current rather than one-time, and it is among the first artefacts requested in an investigation.
Cobrix prices managed IT on a flat monthly per-seat or per-device basis with no overage charges, so the cost scales with your headcount rather than with how many things break. What a specific practice pays depends on seat count, device count and which compliance work is in scope.
Schedule a free consultation today.