HIPAA compliance for small practices in Montana. Your EHR isn’t where the risk is.
Your EHR vendor’s BAA covers their platform. It doesn’t cover the scans folder, the shared inbox, or the old server nobody turned off. Our IT support is run by GIAC certified forensic analysts, so we start there.
The first assessment is free, and the findings are yours either way.

Vetted, tested, and in writing.
Every certified practice is assessed by a third party risk assessor and keeps the required controls in place. The Big Sky Guarantee and Service Warranty put that standard in writing.
Containment, forensics, eradication, recovery, and rebuilding if needed, at no additional cost, within defined service limits.
The Big Sky Guarantee is not an insurance policy. It’s our commitment to do the response work ourselves.
Eligible payments made directly to the organization, up to $500,000 per covered incident, depending on plan.
The Big Sky Service Warranty is not an insurance policy and does not replace cyber insurance.
For certified clients on Professional, Enterprise, or co-managed plans, with required controls in place. Eligibility requirements, service limits, and exclusions apply. Full terms are provided for your review before you sign. See which plans qualify
“Our EHR company handles that.”
They handle their platform, and their BAA says where that ends. In a 5 to 15 person practice, this is what’s on your side of the line.
The scans folder
Insurance cards, IDs, and intake forms scanned to a desktop, uploaded to the chart, then left there for years.
The shared inbox
Faxes arriving as PDFs, referrals, and prior auth threads, checked from three phones with one shared password.
The old EHR server
Still powered on, still on the network, still full of records, and no longer getting security updates.
The devices that leave
The laptop that goes home, the phone with the inbox on it, and the USB drive still in a drawer.
None of that is in your EHR contract, and all of it is your obligation. After an incident, the question is what they accessed. If nobody can answer that, the safe answer is to notify every patient. Whether you can answer it is decided by logging set up before anything happened.
Three things we often find in small practices
These show up in many assessments, whatever EHR the practice runs.
Nobody has been designated
The Security Rule requires a named security official at the practice. Ask who that is and you’ll usually get a pause.
The person who left in March
Their EHR account got disabled. The email, fax portal, payer sites, and shared drive usually didn’t. Nobody kept a list.
One shared login at check in
Every audit log entry it produces is useless, because it can’t show who viewed a chart. That’s OCR’s first question.
“Great company to work with. Any issues we have had they have addressed quickly.”
Find out where your patient data actually ends up before an auditor does.
The assessment is free. About 20 minutes at your practice, at a time you pick, and the findings are yours either way.
An eye care practice is a clinic and a retail store under one roof.
Patient records, diagnostic imaging, and an optical counter taking card payments all share one small network, and usually one IT budget. That’s two kinds of compliance in the same building.
The imaging devices
OCT scanners and retinal cameras often run older operating systems the vendor won’t let you update, with patient images on your network.
The practice system
Crystal PM and Compulink each draw their line of responsibility in a different place. Everything on your side of it is yours to secure.
The optical counter
Frame and lens sales take card payments, putting PCI requirements on the same network as patient records and vision plan portals.
If you run an eye care practice, the assessment covers the clinical side and the optical counter in the same conversation.
Running a dental office? See dental IT. Need managed IT across a larger clinic? See healthcare managed IT.

Times you should call someone else
We’d rather tell you now than six months in. We’re probably not the right call if:
You’re solo on a cloud EHR
No server, three laptops. You need MFA, a password manager, and encrypted email, not a contract. We’ll tell you which, free.
You need someone onsite daily
We serve Great Falls, Helena, and Billings, with same day onsite for contract clients. If someone has to be at a desk every morning, hire them, and we’ll back them up with co-managed IT.
You want the cheapest number
We’re not it. Our price includes the monitoring, logging, and risk analysis that make a breach answerable.

Around your patients, not in the way of them.
What working inside a small practice looks like, written as what we do.
So we secure your systems the way attackers probe them.
HIPAA for small practices: common questions
The questions practices ask before the first conversation. If something isn’t here, the phone is answered in Montana.
Isn’t our EHR vendor responsible for HIPAA?
For their platform. You remain responsible for everything on your side: workstations, email, devices, access, and the risk analysis covering all of it.
We’re a four provider clinic with no IT staff. Does that make us less of a target?
It makes you an easier one. Attackers scan for exposed remote access and reuse credentials from old breach dumps, and a clinic without dedicated IT is more likely to have an unpatched portal or a shared login still working. Nobody chose your practice, and that’s the point.
Who has to be our security official?
Someone at the practice. It can’t be outsourced to us or to any vendor. We support that person and do the technical work; the designation stays with you.
Our office manager handles IT alongside billing and scheduling. What changes for them?
They stop being the last line of defense. We take the security, backup, and compliance layer and become the number staff call, so credentialing and prior authorizations get their attention back. They stay the decision maker on anything that affects the schedule.
How much of our staff’s time does onboarding cost?
A few short sessions with your office manager over about two weeks, plus a quick MFA setup at each workstation. Anything disruptive is scheduled outside clinic hours.
If patient records are exposed, who determines what we have to report?
Scoping does, and that depends on your logs. Contract clients get same day onsite; we establish what was actually accessed rather than what might have been, and give your compliance officer and counsel something defensible to base notification decisions on. Incident work carries no emergency surcharge, and for certified clients the response comes under The Big Sky Guarantee, within defined service limits.
What does it cost?
Managed IT starts at $75 per device per month on Essentials and $95 on Professional, plus a per user charge. Every price is on our pricing page, and you get a written scope before you sign.
How long does switching providers take?
About two weeks from signature to fully managed. We document everything first and run alongside your current provider, so you’re never without support.
Here’s what happens when you call.
Twenty minutes, a straight answer, and nothing to sign.
