Medical & dental practices

Cybersecurity built around the practice that has to open tomorrow morning

Medical and dental practices lose money to security incidents in a specific way: the schedule stops, the phones still ring, and the notification clock starts. PikeShield works on the five failures that actually cause that, for practices in Florida and across the US.

BAA signed before access Read-only assessment under NDA No patient data in reports
Digital shield representing protection of practice systems and patient data.▸ PRACTICE SHIELD // READY
Fit

Built for practices where one bad morning stops the schedule

Dental and orthodontic practices

One to five locations, practice management software on site or hosted, front desk handling insurance attachments all day.

Primary care and specialty clinics

Small clinical teams, an outside IT provider, and a billing company that touches patient data.

Behavioral health practices

Telehealth in the mix, remote clinicians, and records that carry more sensitivity than most.

Practices that just had a scare

A phishing email that someone clicked, a vendor breach notice, or an audit question nobody could answer.

01Access granted
02Daily operations
03Exposure accumulates
04Incident
05Notification duty
06Recovery
07Evidence
Diagnosis

Five failures, and none of them are exotic

These are the ones that actually close practices for a day, not the ones that make headlines.

LEAK 01

Access outlives the person

Hygienists, temps, associates and front desk staff rotate, and practice management logins are shared to keep the day moving. Access is granted verbally and almost never removed, so the list of people who can open a chart is longer than the payroll.

LEAK 02

The front desk is the attack surface

Reception opens insurance attachments, referral PDFs and imaging links from strangers as a core job function. That is exactly the behaviour phishing depends on, and MFA is often enabled but not enforced on the accounts that matter most.

LEAK 03

Vendors touch the data and nobody checked them

Billing company, IT provider, imaging cloud, transcription, recall service. Each one reaches patient data, each one needs a signed BAA on file, and in most practices nobody can produce the list, let alone the agreements.

LEAK 04

Backups exist but have never been restored

The backup job reports success for years. Nobody has ever run a test restore, so the first real test happens on the worst morning, and the recovery time is discovered rather than planned.

LEAK 05

Nobody knows what the first hour looks like

The HIPAA Breach Notification Rule sets obligations and deadlines, but the practice has no written incident plan, no escalation list, and no agreed answer to who calls counsel, the carrier and the affected patients.

The system

Organized around outcomes. Not a menu of tactics.

Each capability answers one failure above, in the same order.

FIX 01

Know who can reach what

Access inventory across practice management, email, imaging and finance, least-privilege roles, and an offboarding runbook that can be tested rather than remembered.

FIX 02

Make the front desk hard to phish

MFA enforced tenant-wide including the legacy paths that bypass it, plus ongoing phishing simulations aimed at the workflows reception really handles.

FIX 03

Put the vendor list on paper

Inventory of every third party touching patient data, which agreements exist, which are missing, and what each vendor can actually reach.

FIX 04

Prove the recovery works

Test restores with a measured recovery time, so the practice knows in advance how long a bad morning lasts.

FIX 05

Rehearse the first hour

Written incident response plan, escalation path with names and numbers, and a tabletop exercise so the plan has been used once before it matters.

Reframe

Preventing the breach is only half the work

Most practices buy prevention and skip recovery. The two are different jobs and only one of them is tested on the day it matters.

Prevention decides how likely the incident is. Recovery decides how expensive it is: how many hours the schedule is down, whether the notification clock starts, and whether anyone can prove what was and was not reached. A practice with average prevention and rehearsed recovery loses a morning. A practice with good prevention and untested backups loses a week.

Analyst reviewing monitoring dashboards for a healthcare environment.
AssessHardenMonitorRespond
How we work

No case studies here, on purpose

Security work for practices is confidential by nature. Instead of borrowed logos, here is how the engagement behaves.

Read-only first, always under NDA

The assessment phase changes nothing. Access is read-only and scoped, and the scope is agreed in writing before it starts.

No patient data in our deliverables

Findings describe systems, settings and exposure. Patient information is not copied, exported or pasted into a report.

Plain language, ranked by business risk

A finding that stops the schedule outranks a high severity score on a system nobody uses. Both the practice owner and the IT provider get a version they can act on.

The runbook is yours to keep

Documentation is written so another provider could pick it up. A security posture that depends on us being reachable is a weak posture.

01Assessment requested
02Scope and BAA in place
03Findings delivered and ranked
04Priority controls implemented
05Verified re-check

A finding is an event. A verified re-check is a result. What the exact model looks like depends on your practice management system, your IT provider and the boundaries your compliance officer sets, so it is agreed during scoping rather than assumed.

Guardrails

How patient data is handled during the engagement

A BAA is signed before access

Where an engagement involves systems that contain protected health information, a business associate agreement is executed before any access is granted.

The assessment is read-only and scoped

Under NDA, with the systems in scope named in writing. Nothing is modified during assessment.

No patient information in this form

The form on this page is for practice contact details only. Do not include patient names, records or clinical detail.

Framework references are context, not legal advice

Findings map to HIPAA Security Rule safeguards and NIST CSF so your compliance officer and counsel can act on them. The compliance determination is theirs, not ours.

FAQ

The questions practices actually ask

Do you need access to patient records?
No. The assessment looks at systems, settings, accounts and access, not at clinical content. Where a system in scope contains protected health information, a business associate agreement is signed first and access stays read-only during assessment.
Do you sign a BAA?
Yes. Where the engagement involves systems containing protected health information, a business associate agreement is executed before access is granted.
We already have an IT company. Do we need you as well?
Usually they are different jobs. An IT provider keeps the practice running day to day. A security engagement asks what would happen if an account were taken over tonight, and hands the remediation runbook to whoever maintains the environment, including your existing provider.
Does this make our practice HIPAA compliant?
No engagement can promise that, and any vendor who does is selling something. This work reduces technical risk and documents the safeguards you have in place so your compliance officer and counsel can make the compliance determination.
How much does it cost?
PikeShield scopes each engagement to your environment, team size, and risk profile, so pricing is tailored rather than one-size-fits-all. The first step is a free security assessment, after which PikeShield outlines priorities and recommended next steps.
What happens in the first call?
A 30 minute working conversation about how the practice runs, who touches patient data, and what already worries you. It ends with a scoped next step or an honest answer that we are not the right fit.
Get started

A 30 minute working conversation

What it is: a scoped look at how your practice runs and where the exposure sits. What it is not: a generic sales deck. What you leave with: a clear next step, or an honest answer that we are not the right fit.