top of page
  • Youtube
  • Facebook
  • X
  • LinkedIn

Healthcare IT Services & HIPAA Security for Lubbock Practices

Your schedule, charts, imaging and billing all run on technology. When the EHR is slow, a workstation won't sign in, or a suspicious email lands in the front-desk inbox, patients wait and your staff scrambles. Double Technologies provides managed IT and cybersecurity for medical, dental, chiropractic, physical therapy, optometry and behavioral health practices in Lubbock and across West Texas.

We keep your systems running, help you meet the HIPAA Security Rule's technical requirements, and give you the documentation to show the work. We sign a Business Associate Agreement, we explain things in plain English, and we're right here in West Texas. Call (806) 319-8521 to talk with our team.

Who We Help

We work with the small and mid-sized practices that make up most of healthcare on the South Plains: family medicine and specialty clinics, dental offices, chiropractors, physical and occupational therapy clinics, optometrists, and behavioral health and counseling practices, and home health agencies.

 

Veterinary clinics aren't covered by HIPAA, but they run on the same kind of practice software, take card payments and live in email, so we protect them the same way.

IT Challenges Lubbock Practices Face

Most practices we talk to don't have an IT department. The office manager or a provider who's "good with computers" ends up handling it between patients. The problems tend to look the same:

  • Everything depends on one system. If the EHR or practice-management software goes down, check-in, charting, scheduling and billing stop with it.

  • Email is the front door for attacks. Fake invoices, fake records requests and "password expired" messages aimed at busy front-desk staff are how many breaches start.

  • The HIPAA paperwork never quite gets done. The Security Rule requires a risk analysis, but many small practices have never completed one, or haven't updated it since they changed systems or moved offices.

  • Shared logins and aging equipment. One password for the whole front desk, an old server in a closet, and Wi-Fi that patients and staff share.

  • Too many vendors. The EHR vendor, internet provider, imaging company and phone vendor each point at someone else when something breaks.

What's Included in Our Healthcare IT Services

HIPAA-Aligned Managed IT

​

Help desk support for your staff, proactive monitoring, patch management, user onboarding and offboarding, and an up-to-date inventory of the devices that touch patient data. It's delivered at a predictable flat monthly fee, so you aren't paying by the emergency. Learn more about our managed IT services in Lubbock.

​

The HIPAA Security Rule's Technical Safeguards, in Plain English

​

The Security Rule (45 CFR 164.312) lists five technical safeguards for electronic protected health information (ePHI). Here's what each one means and how we help:

  • Access control: Each person has their own login and sees only what their job requires. How we help: Unique accounts, role-based permissions, MFA, automatic screen lock.

  • Audit controls: You can see who accessed what, and when. How we help: Logging and alerting across Microsoft 365, servers and firewalls.

  • Integrity: Patient data isn't changed or destroyed improperly. How we help: Endpoint protection, patching, protected backups.

  • Person or entity authentication: Users prove they are who they say they are. How we help: Multi-factor authentication and strong password policies.

  • Transmission security: ePHI is protected when it moves. How we help: Encrypted email, VPN, managed firewall, secured Wi-Fi.

HIPAA also requires administrative and physical safeguards. We support the IT side of those, like security training, device inventories and the risk analysis. Your practice keeps ownership of its privacy policies, its designated privacy and security officers, and staff procedures. We'll be clear about who handles what.

​

HIPAA Security Risk Assessment

​

A security risk assessment looks at where your patient data lives, who can reach it, and what could go wrong. We review workstations, servers, Microsoft 365, the network, backups and the vendors who touch your data. You receive a written report that ranks the risks, an inventory of systems that store ePHI, and a prioritized remediation plan, plus documentation to keep on file if an auditor, insurer or the Office for Civil Rights asks. Risk assessments are priced separately and are not included in our managed plans.

​

Encrypted Backup & Disaster Recovery

Ransomware and failed hardware are the two fastest ways to lose a day of patients. We set up encrypted, monitored backups with offsite cloud copies and immutable storage, back up Microsoft 365, and test restores so you know they work. We also help you write down a downtime plan: how long you can be without the EHR, and how the front desk keeps working until systems are back. See our backup and disaster recovery services.

​

Microsoft 365 Secured for Patient Data

Microsoft offers a HIPAA Business Associate Agreement for its core Microsoft 365 services, but the settings still have to be right. We configure multi-factor authentication, conditional access, Microsoft Defender, data loss prevention and encrypted email so staff can send PHI to patients and referring providers safely. Read more about Microsoft 365 management.

​

Endpoint Protection, EDR & 24/7 Monitoring

Every workstation, laptop and server gets endpoint protection with detection and response (EDR), and we monitor around the clock for suspicious activity. If something gets through, we move quickly to contain it. Our cybersecurity services in Lubbock cover the full security stack. 

​

Phishing & Security Awareness Training

Your staff is your best defense. We provide short security awareness training and phishing awareness so front-desk, billing and clinical staff learn to spot fake messages before they click. Training records also help document HIPAA's security awareness requirement.

​

EHR & Practice-Management Software Support

We keep the computers, printers, scanners, network and user access around your EHR working, and we deal directly with your software vendor on troubleshooting, updates and escalations, so you don't have to sit on hold. 

​

Network, Firewall & Wi-Fi

A managed firewall, a separate guest Wi-Fi for patients, secure VPN access for providers charting from home, and monitoring that catches outages early. Multi-location practices get one consistent setup across every office. More on network management.

 

Business Associate Agreement

Because we may access systems that store PHI, we sign a Business Associate Agreement (BAA) before work begins, and we help you keep track of BAAs with your other IT vendors.

How Working Together Goes

​

  1. A conversation. Tell us about your practice, your systems and what's frustrating you. No jargon.

  2. Assessment. We review your environment and complete or update your security risk assessment.

  3. Onboarding. We sign the BAA, deploy our tools, and schedule changes like the MFA rollout around clinic hours, not during them.

  4. Ongoing support. Day-to-day help desk, monitoring, patching and backups, with regular reviews and updated documentation as your practice changes.

​

Why Practices Choose a Local Lubbock IT Team

  • We're nearby. When something needs hands on a machine, we can come to your office. 

  • Plain English. Our technicians explain what's happening and why, so you can make informed decisions.

  • Security first. Every setup we build starts with protecting patient data, not bolting security on later.

  • Predictable pricing. Flat monthly fees mean no surprise invoices after a bad week.

​​

​

Areas We Serve

We support practices in Lubbock, Wolfforth, Levelland, Brownfield, Littlefield, Post, Plainview, Amarillo, Abilene and throughout West Texas.

​

Frequently Asked Questions

​

Do you sign a Business Associate Agreement (BAA)?

Yes. Because our team may access systems that store patient information, we sign a BAA before any work begins. We can also help you inventory the BAAs you have with other IT and software vendors.

​

Can you make our practice "HIPAA certified"?

No one can. There is no official HIPAA certification, and HHS doesn't certify practices or vendors. Compliance is ongoing and remains your practice's responsibility. We help you meet the Security Rule's technical requirements, complete a security risk assessment, and keep documentation ready for audits.

​

What's included in a HIPAA security risk assessment?

We review where patient data is stored, who can access it, and how it's protected across workstations, servers, Microsoft 365, the network, backups and vendors. You get a written report of ranked risks, an inventory of systems holding ePHI, and a prioritized plan to fix the gaps.

​

Can you work with our EHR or practice-management vendor?

Yes. We support the computers, network and user access your EHR depends on, and we coordinate directly with your software vendor on troubleshooting, updates and escalations.

​

How long does onboarding take?

It depends on the size of your practice and what's already in place. We start with an assessment, sign the BAA, then roll out changes on a schedule that works around patient hours.

​

Do you support practices outside Lubbock?

Yes. We work with practices in Wolfforth, Levelland, Brownfield, Littlefield, Post, Plainview, Amarillo, Abilene and across West Texas, with remote support every day and on-site visits when needed.

​

Talk With a Lubbock Healthcare IT Team

Whether you need a risk assessment, help securing Microsoft 365, or an IT partner who answers the phone, we're ready to help. Call (806) 319-8521 or contact our team to schedule a free HIPAA IT review.

Locations. Lubbock, Texas

                 Brownfield, Texas

                 Littlefield, Texas

                 Levelland, Texas

                 Amarillo, Texas

                 Abilene, Texas

                 Post, Texas

              All of West Texas

                

Tel. (806) 319-8521

© 2022 by Double Technologies 

Privacy Policy

Cisco Partner
Fortigate Partner
bottom of page