Healthcare IT support in Los Angeles is ordinary managed IT with one addition: every decision has to be defensible under the HIPAA Security Rule, and the evidence has to exist before anyone asks for it. That means a current risk analysis, business associate agreements with every vendor that touches electronic protected health information, encryption you can prove, audit logs you retain, and a written record of the decisions you made and why.
We support medical practices, clinics, imaging centers, behavioral health providers, and the billing and administrative firms that work alongside them across Los Angeles County. We help you meet the requirements; we do not issue the certification itself, and we are not an official certifying body or auditor.
The Security Rule in three parts
The Security Rule lives at 45 CFR Part 164, Subpart C, and organizes into three groups of safeguards. Everything a vendor sells you maps back to one of them.
- Administrative safeguards (45 CFR 164.308). The security management process, including risk analysis and risk management, assigned security responsibility, workforce security and access management, security awareness and training, incident response procedures, contingency planning, evaluation, and the business associate contract requirement at 164.308(b).
- Physical safeguards (45 CFR 164.310). Facility access controls, workstation use and security, and device and media controls including disposal and reuse.
- Technical safeguards (45 CFR 164.312). Access control including unique user identification and emergency access, audit controls, integrity controls, person or entity authentication, and transmission security.
The rule marks each implementation specification as required or addressable. Addressable does not mean optional. It means you implement it, or you document why it is not reasonable and appropriate for your environment and implement an equivalent alternative. The documented decision is the part practices skip, and it is the part an investigator asks for.
Risk analysis: what it is and how often
The risk analysis at 45 CFR 164.308(a)(1)(ii)(A) is the foundation of the whole rule, and it is the most commonly cited deficiency in enforcement actions. It is an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of the ePHI your organization creates, receives, maintains, or transmits.
Two things it is not. It is not a vulnerability scan, though a scan can feed it. And it is not a one-time document. The rule requires it to be updated as needed, which in practice means annually and again on any material change: a new electronic health record system, a new location, a merger, a move to a new cloud platform, or a significant breach.
What a defensible risk analysis contains: an inventory of every system and location where ePHI lives including backups and mobile devices, the threats and vulnerabilities applicable to each, the current security measures, a likelihood and impact rating, the resulting risk level, and a dated record of who performed it. The remediation plan that follows it is risk management under 164.308(a)(1)(ii)(B), and it is a separate document.
Business associate agreements
Every vendor that creates, receives, maintains, or transmits ePHI on your behalf needs a business associate agreement before it touches the data, under 45 CFR 164.308(b) and 164.314(a). That includes your IT provider, your cloud backup vendor, your email host if it stores ePHI, your billing company, your transcription service, and any software vendor with support access into a system holding patient data.
The practical failures we find are consistent: an agreement that was signed once and never revisited when the service changed, a vendor that was added without one, subcontractor flow-down that was never confirmed, and no inventory of which agreements exist. Keep a list with the vendor, the service, the agreement date, and the renewal owner. Be Structured signs a business associate agreement with every healthcare client before onboarding begins.
Encryption
Encryption is addressable rather than required, at 45 CFR 164.312(a)(2)(iv) for data at rest and 164.312(e)(2)(ii) for data in transit, and it is still the control we would implement first. The reason is the breach notification safe harbor: if ePHI is encrypted in a manner consistent with HHS guidance so that it is rendered unusable, unreadable, or indecipherable to unauthorized persons, a loss of that data is not a breach requiring notification under 45 CFR 164.402. A stolen laptop becomes a property loss instead of a reportable event.
Where it has to be in place: full disk encryption on every workstation, laptop, and tablet; encryption of backups both in transit and at rest; TLS on email carrying ePHI, with a secure delivery mechanism for external recipients; encryption on any removable media; and mobile device management enforcing encryption on phones with mailbox access.
Audit logs
Audit controls at 45 CFR 164.312(b) require mechanisms that record and examine activity in systems containing ePHI. Recording is half of it. The other half, examining, is what most practices have never staffed, and a log nobody reviews satisfies the letter of the requirement badly.
What to log and review: access to the electronic health record by user and by patient record, administrative changes, authentication failures and successes, remote access sessions, and changes to the audit configuration itself. HIPAA sets a six year retention period for required documentation at 45 CFR 164.316(b)(2)(i), and many practices apply the same period to their security logs by policy. Set the retention deliberately rather than accepting a vendor default, because the default is usually 30 or 90 days and an investigation will ask for longer.
Where the 2025 to 2026 rulemaking stands
The Security Rule has not been substantially updated since 2013. On January 6, 2025 the HHS Office for Civil Rights published a notice of proposed rulemaking to modify it (90 FR 898), and the comment period closed on March 7, 2025.
Among other changes, the proposal would elevate technology asset inventory to a standard in its own right at 164.308(a)(1)(i), add a definition of multi-factor authentication, and require regulated entities to prioritize and remediate vulnerabilities found through vulnerability scanning and penetration testing. It also revisits the required versus addressable distinction that currently gives practices discretion over controls including encryption.
Status as of August 29, 2026: this is a proposed rule. No final rule has been published, and the Security Rule as it stands at 45 CFR Part 164 is what is enforceable today. Our advice to clients has not changed because of the proposal, for a simple reason: asset inventory, multi-factor authentication, encryption, and acting on scan findings are things a practice should already be doing, and a practice already doing them has nothing to do on the day a final rule appears.
What we do and what stays with the practice
| Work | Owned by |
|---|---|
| Technical safeguards: access control, authentication, encryption, audit logging, transmission security | Be Structured |
| Monitoring, patching, endpoint security, backup and recovery testing | Be Structured |
| Risk analysis facilitation and the technical findings within it | Joint |
| Risk management plan and the decision to accept or remediate a risk | Practice |
| Policies and procedures, and the documented addressable-specification decisions | Practice, with our input on technical content |
| Business associate agreements with your other vendors | Practice |
| Workforce training and sanction policy | Practice |
| Physical safeguards at your facility | Practice |
| Breach determination and patient notification | Practice, with counsel |
What healthcare IT support costs in Los Angeles
A Los Angeles medical practice generally pays in the same band as any other business of its size, between $125 and $300 per user per month, sitting toward the upper part of that band because the security tier, the logging retention, and the documentation work are all above baseline. The full breakdown of what moves the number is in our managed IT services pricing guide. Practices with imaging systems, on-premises servers running clinical applications, or multiple locations should expect project work alongside the monthly fee.
Related: HIPAA audit support for practices working through an assessment, and our managed security services for the monitoring side.
Contact Be Structured today to schedule a compliance assessment for your Los Angeles medical practice.
➤ Schedule Your Free IT Assessment
