What HIPAA Requires for Your IT Systems
The Health Insurance Portability and Accountability Act applies to any organization that creates, receives, stores, or transmits protected health information (PHI). This includes medical practices, dental offices, physical therapy clinics, pharmacies, and any business associate that handles health data on their behalf — billing companies, IT providers, cloud hosting vendors, and even shredding services.
HIPAA's Security Rule specifies three categories of safeguards that covered entities must implement:
Administrative safeguards include conducting a formal risk assessment, designating a security officer, developing policies for workforce access to PHI, and training employees on security awareness. These are not optional — the risk assessment alone is the most commonly cited deficiency in HIPAA audits.
Physical safeguards address facility access controls, workstation security, and device disposal. Server rooms must be locked. Workstations displaying PHI should not be visible to unauthorized individuals. When computers or hard drives are retired, data must be destroyed — not just deleted, but wiped or physically destroyed.
Technical safeguards are where IT plays the biggest role: unique user identification (no shared logins), automatic logoff after inactivity, encryption of PHI at rest and in transit, audit controls that log who accessed what and when, and integrity controls that prevent unauthorized modification of records.
Common mistake: Many small medical practices in Buffalo assume that using a HIPAA-compliant EHR system means they are fully compliant. It does not. HIPAA applies to your entire IT environment — email, file shares, backups, mobile devices, and even fax machines. The EHR is one piece of a much larger compliance picture.
PCI-DSS Basics for Businesses Accepting Cards
The Payment Card Industry Data Security Standard applies to every business that accepts, processes, stores, or transmits credit card data — from a single-register retail shop to a multi-location restaurant chain. If you take credit cards, PCI-DSS applies to you, regardless of your size.
PCI-DSS has 12 core requirements organized into six categories:
| Category | Requirements |
|---|---|
| Build and maintain a secure network | Install and maintain firewalls; change default vendor passwords |
| Protect cardholder data | Encrypt stored data; encrypt transmission across open networks |
| Maintain a vulnerability management program | Use and update antivirus software; develop secure systems and apps |
| Implement strong access control | Restrict access on a need-to-know basis; assign unique IDs; restrict physical access |
| Monitor and test networks | Track and monitor all access to network resources and cardholder data; test security systems regularly |
| Maintain an information security policy | Document and enforce a security policy for all personnel |
For most small Buffalo businesses, the simplest path to PCI compliance is to minimize your cardholder data environment. Use a point-to-point encrypted (P2PE) terminal that sends card data directly to the processor without it ever touching your network. If card numbers never enter your systems, the scope of your PCI obligations shrinks dramatically.
We help Erie County businesses assess their PCI scope, select compliant payment hardware, segment their networks to isolate payment systems, and complete the annual Self-Assessment Questionnaire (SAQ) that their payment processor requires.
NYS SHIELD Act: What Buffalo Businesses Need to Know
New York's Stop Hacks and Improve Electronic Data Security (SHIELD) Act, effective since March 2020, expanded data breach notification requirements and imposed new data security obligations on any business that holds private information about New York residents — even if the business is located outside New York.
The SHIELD Act requires businesses to implement "reasonable safeguards" across three areas that mirror HIPAA's structure:
The definition of "private information" under the SHIELD Act is broad: Social Security numbers, driver's license numbers, financial account numbers, biometric data, email addresses combined with passwords, and more. For most Buffalo businesses, this means you almost certainly hold data covered by the law.
Penalties for SHIELD Act violations can reach $5,000 per violation for failure to notify affected individuals of a breach, with no cap. The Attorney General can also seek injunctive relief and civil penalties. Small businesses receive some leniency if they can demonstrate that their security program was reasonable relative to their size and complexity.
Risk Assessments: Where Compliance Starts
Every major compliance framework — HIPAA, PCI-DSS, SHIELD Act — begins with a risk assessment. This is a systematic review of your IT environment to identify where sensitive data lives, how it is protected, and what threats and vulnerabilities could lead to a breach.
A proper risk assessment is not a checkbox exercise. It involves inventorying all systems that store or process regulated data, mapping data flows (where data enters, where it moves, where it is stored, and how it leaves), evaluating the effectiveness of existing security controls, and rating risks based on likelihood and potential impact.
For a Buffalo medical practice, this might reveal that patient records are being emailed to a referring physician using unencrypted email — a clear HIPAA violation. For a retail business, it might uncover that credit card terminals are on the same network segment as employee workstations — a PCI-DSS gap.
Driram Group conducts risk assessments tailored to the compliance frameworks relevant to your business. We deliver a prioritized findings report with specific, actionable remediation steps — not a 200-page document that sits on a shelf.
Data Encryption and Access Controls
Encryption and access control are the two technical pillars of every compliance framework. Encryption protects data if it is stolen — encrypted data is useless to an attacker without the decryption key. Access controls ensure that only authorized individuals can reach the data in the first place.
For encryption, compliance requirements are straightforward: encrypt sensitive data at rest (on hard drives, in databases, in backups) and in transit (over email, between servers, across the internet). Windows BitLocker provides full-disk encryption for workstations and laptops at no additional cost. For email, Microsoft 365's built-in message encryption or a third-party solution like Virtru can encrypt messages containing PHI or financial data.
Access controls follow the principle of least privilege — every user should have access only to the data they need to do their job, and nothing more. This means no shared logins, role-based permissions on file shares and applications, and regular access reviews to remove permissions for employees who have changed roles or left the company.
Audit logging is not optional. HIPAA, PCI-DSS, and the SHIELD Act all require the ability to track who accessed what data and when. Windows Event Logging, combined with a log management solution, creates the audit trail that regulators and auditors expect to see. We configure centralized logging so that records are tamper-resistant and retained for the required period.
Penalties for Non-Compliance
Compliance is not just about avoiding fines — it is about protecting your business, your customers, and your reputation. But the penalties are worth understanding because they underscore how seriously regulators take these requirements.
| Regulation | Penalty Range | Who Enforces |
|---|---|---|
| HIPAA | $141 to $2,134,831 per violation category per year; criminal penalties up to $250,000 and imprisonment | HHS Office for Civil Rights (OCR) |
| PCI-DSS | $5,000 to $100,000 per month of non-compliance; card brands may revoke processing ability | Payment card brands (Visa, Mastercard) via acquiring banks |
| NYS SHIELD Act | Up to $5,000 per violation for breach notification failures; $20/failure for late notices (capped at $250,000) | NY Attorney General |
Beyond formal penalties, a data breach brings indirect costs: forensic investigation, legal fees, customer notification, credit monitoring services, lost business, and reputational damage. For small businesses, a serious breach can be an existential event. The Ponemon Institute estimates the average cost of a data breach for small businesses at over $150,000 — enough to close many Erie County small businesses permanently.
How a Local IT Provider Helps with Compliance
Compliance is an ongoing obligation, not a one-time project. Regulations change, threats evolve, and your IT environment shifts as you add employees, adopt new tools, and grow your business. A local IT provider like Driram Group serves as your compliance partner — handling the technical requirements so you can focus on running your business.
We provide risk assessments to identify gaps, implement technical controls (encryption, access controls, audit logging, network segmentation), manage ongoing patch management and security monitoring, conduct employee security awareness training, assist with documentation and policy development, and support you during audits or breach investigations.
Working with a local provider in the Buffalo area offers a practical advantage: we understand the regulatory landscape that affects Erie County businesses specifically, from the healthcare practices along Main Street to the retail shops in the Eastern Hills Mall area. We can be on-site the same day if a compliance issue requires hands-on attention.
IT Service Areas — Erie County
Driram Group provides IT compliance consulting, implementation, and ongoing support for businesses across Erie County. We work with medical practices, dental offices, retail businesses, professional services firms, and any organization that handles regulated data.