Healthcare IT support in Los Angeles is ordinary managed IT with one addition: every decision has to be defensible under the HIPAA Security Rule, and the evidence has to exist before anyone asks for it. That means a current risk analysis, business associate agreements with every vendor that touches electronic protected health information, encryption you can prove, audit logs you retain, and a written record of the decisions you made and why.

We support medical practices, clinics, imaging centers, behavioral health providers, and the billing and administrative firms that work alongside them across Los Angeles County. We help you meet the requirements; we do not issue the certification itself, and we are not an official certifying body or auditor.

The Security Rule in three parts

The Security Rule lives at 45 CFR Part 164, Subpart C, and organizes into three groups of safeguards. Everything a vendor sells you maps back to one of them.

  • Administrative safeguards (45 CFR 164.308). The security management process, including risk analysis and risk management, assigned security responsibility, workforce security and access management, security awareness and training, incident response procedures, contingency planning, evaluation, and the business associate contract requirement at 164.308(b).
  • Physical safeguards (45 CFR 164.310). Facility access controls, workstation use and security, and device and media controls including disposal and reuse.
  • Technical safeguards (45 CFR 164.312). Access control including unique user identification and emergency access, audit controls, integrity controls, person or entity authentication, and transmission security.

The rule marks each implementation specification as required or addressable. Addressable does not mean optional. It means you implement it, or you document why it is not reasonable and appropriate for your environment and implement an equivalent alternative. The documented decision is the part practices skip, and it is the part an investigator asks for.

Risk analysis: what it is and how often

The risk analysis at 45 CFR 164.308(a)(1)(ii)(A) is the foundation of the whole rule, and it is the most commonly cited deficiency in enforcement actions. It is an accurate and thorough assessment of the potential risks and vulnerabilities to the confidentiality, integrity, and availability of the ePHI your organization creates, receives, maintains, or transmits.

Two things it is not. It is not a vulnerability scan, though a scan can feed it. And it is not a one-time document. The rule requires it to be updated as needed, which in practice means annually and again on any material change: a new electronic health record system, a new location, a merger, a move to a new cloud platform, or a significant breach.

What a defensible risk analysis contains: an inventory of every system and location where ePHI lives including backups and mobile devices, the threats and vulnerabilities applicable to each, the current security measures, a likelihood and impact rating, the resulting risk level, and a dated record of who performed it. The remediation plan that follows it is risk management under 164.308(a)(1)(ii)(B), and it is a separate document.

Business associate agreements

Every vendor that creates, receives, maintains, or transmits ePHI on your behalf needs a business associate agreement before it touches the data, under 45 CFR 164.308(b) and 164.314(a). That includes your IT provider, your cloud backup vendor, your email host if it stores ePHI, your billing company, your transcription service, and any software vendor with support access into a system holding patient data.

The practical failures we find are consistent: an agreement that was signed once and never revisited when the service changed, a vendor that was added without one, subcontractor flow-down that was never confirmed, and no inventory of which agreements exist. Keep a list with the vendor, the service, the agreement date, and the renewal owner. Be Structured signs a business associate agreement with every healthcare client before onboarding begins.

Encryption

Encryption is addressable rather than required, at 45 CFR 164.312(a)(2)(iv) for data at rest and 164.312(e)(2)(ii) for data in transit, and it is still the control we would implement first. The reason is the breach notification safe harbor: if ePHI is encrypted in a manner consistent with HHS guidance so that it is rendered unusable, unreadable, or indecipherable to unauthorized persons, a loss of that data is not a breach requiring notification under 45 CFR 164.402. A stolen laptop becomes a property loss instead of a reportable event.

Where it has to be in place: full disk encryption on every workstation, laptop, and tablet; encryption of backups both in transit and at rest; TLS on email carrying ePHI, with a secure delivery mechanism for external recipients; encryption on any removable media; and mobile device management enforcing encryption on phones with mailbox access.

Audit logs

Audit controls at 45 CFR 164.312(b) require mechanisms that record and examine activity in systems containing ePHI. Recording is half of it. The other half, examining, is what most practices have never staffed, and a log nobody reviews satisfies the letter of the requirement badly.

What to log and review: access to the electronic health record by user and by patient record, administrative changes, authentication failures and successes, remote access sessions, and changes to the audit configuration itself. HIPAA sets a six year retention period for required documentation at 45 CFR 164.316(b)(2)(i), and many practices apply the same period to their security logs by policy. Set the retention deliberately rather than accepting a vendor default, because the default is usually 30 or 90 days and an investigation will ask for longer.

Where the 2025 to 2026 rulemaking stands

The Security Rule has not been substantially updated since 2013. On January 6, 2025 the HHS Office for Civil Rights published a notice of proposed rulemaking to modify it (90 FR 898), and the comment period closed on March 7, 2025.

Among other changes, the proposal would elevate technology asset inventory to a standard in its own right at 164.308(a)(1)(i), add a definition of multi-factor authentication, and require regulated entities to prioritize and remediate vulnerabilities found through vulnerability scanning and penetration testing. It also revisits the required versus addressable distinction that currently gives practices discretion over controls including encryption.

Status as of August 29, 2026: this is a proposed rule. No final rule has been published, and the Security Rule as it stands at 45 CFR Part 164 is what is enforceable today. Our advice to clients has not changed because of the proposal, for a simple reason: asset inventory, multi-factor authentication, encryption, and acting on scan findings are things a practice should already be doing, and a practice already doing them has nothing to do on the day a final rule appears.

What we do and what stays with the practice

Work Owned by
Technical safeguards: access control, authentication, encryption, audit logging, transmission security Be Structured
Monitoring, patching, endpoint security, backup and recovery testing Be Structured
Risk analysis facilitation and the technical findings within it Joint
Risk management plan and the decision to accept or remediate a risk Practice
Policies and procedures, and the documented addressable-specification decisions Practice, with our input on technical content
Business associate agreements with your other vendors Practice
Workforce training and sanction policy Practice
Physical safeguards at your facility Practice
Breach determination and patient notification Practice, with counsel

What healthcare IT support costs in Los Angeles

A Los Angeles medical practice generally pays in the same band as any other business of its size, between $125 and $300 per user per month, sitting toward the upper part of that band because the security tier, the logging retention, and the documentation work are all above baseline. The full breakdown of what moves the number is in our managed IT services pricing guide. Practices with imaging systems, on-premises servers running clinical applications, or multiple locations should expect project work alongside the monthly fee.

Related: HIPAA audit support for practices working through an assessment, and our managed security services for the monitoring side.

Contact Be Structured today to schedule a compliance assessment for your Los Angeles medical practice.

➤ Schedule Your Free IT Assessment

Frequently Asked Questions About Healthcare IT and HIPAA

What does HIPAA-compliant IT support actually mean?

It means the technical safeguards in 45 CFR 164.312 are implemented and evidenced, your IT provider has signed a business associate agreement, and the decisions behind each addressable specification are documented. There is no HIPAA certification for an IT provider and no product that makes a practice compliant. What exists is a set of safeguards, a current risk analysis, and a documented record of what you decided and why. Be wary of any provider selling compliance as a product.

How often does a HIPAA risk analysis need to be done?

The rule at 45 CFR 164.308(a)(1)(ii)(A) requires an accurate and thorough assessment and requires it to be updated as needed rather than naming an interval. In practice that means annually, and again on any material change: a new electronic health record system, a new location, a merger, a cloud migration, or a security incident. Risk analysis is the most commonly cited deficiency in enforcement actions, and the reason is usually that the practice did one once and never revisited it.

Is encryption required under HIPAA?

Encryption is addressable rather than required, at 45 CFR 164.312(a)(2)(iv) for data at rest and 164.312(e)(2)(ii) for data in transit. Addressable means you implement it or document why it is not reasonable and appropriate and put an equivalent alternative in place. We recommend implementing it in almost every case because of the breach notification safe harbor: properly encrypted ePHI that is lost or stolen is not a breach requiring notification under 45 CFR 164.402, which turns a stolen laptop into a property loss rather than a reportable event.

Who needs to sign a business associate agreement?

Every vendor that creates, receives, maintains, or transmits electronic protected health information on your behalf, under 45 CFR 164.308(b) and 164.314(a). That includes your IT provider, cloud backup vendor, email host if it stores ePHI, billing company, transcription service, and any software vendor with support access into a system holding patient data. Keep an inventory with the vendor, the service, the agreement date, and an owner for renewal, because the failure we find most often is not a missing clause but a vendor nobody remembered to paper.

How long do we have to keep HIPAA audit logs?

HIPAA requires documentation to be retained for six years from the date of creation or the date it was last in effect, whichever is later, at 45 CFR 164.316(b)(2)(i). Security logs are not named explicitly, so many practices apply the same six year period by policy. What matters practically is that you set the retention deliberately rather than inheriting a vendor default of 30 or 90 days, because an investigation or an insurance claim will ask for a period longer than that.

What is the status of the proposed HIPAA Security Rule update?

It is still a proposed rule. The HHS Office for Civil Rights published the notice of proposed rulemaking on January 6, 2025 at 90 FR 898, and the comment period closed on March 7, 2025. As of August 29, 2026 no final rule has been published, so the Security Rule as it currently stands at 45 CFR Part 164 is what is enforceable. The proposal would elevate technology asset inventory to a standard, add a definition of multi-factor authentication, require remediation of vulnerabilities found by scanning and penetration testing, and revisit the required versus addressable distinction.

Should we prepare now for the proposed Security Rule changes?

Prepare for the substance, not for the rule. Asset inventory, multi-factor authentication everywhere, encryption at rest and in transit, vulnerability scanning with actual remediation, and reviewed audit logs are all things a practice should be doing under the current rule and under any reasonable reading of what a final rule would require. A practice that has those in place has nothing to do on publication day. A practice waiting for a final rule before starting will be starting from behind, on someone else timeline.

How much does IT support for a medical practice cost in Los Angeles?

Generally between $125 and $300 per user per month, in the same band as any business of similar size but usually toward the upper part of it, because the security tier, log retention, and documentation work sit above baseline. Practices with imaging systems, on-premises clinical application servers, or multiple locations should expect project work alongside the monthly fee. Our managed IT services pricing guide breaks down the variables that move the number.