{"id":3968,"date":"2025-11-16T22:48:19","date_gmt":"2025-11-16T22:48:19","guid":{"rendered":"https:\/\/medindex.am\/accounts\/?page_id=3968"},"modified":"2025-11-16T22:51:10","modified_gmt":"2025-11-16T22:51:10","slug":"hipaa-requirements-if-medical-website-is-only-inside-the-office-and-not-accessible-from-the-public-internet","status":"publish","type":"page","link":"https:\/\/medindex.am\/accounts\/hipaa-requirements-if-medical-website-is-only-inside-the-office-and-not-accessible-from-the-public-internet\/","title":{"rendered":"HIPAA requirements if medical website is only inside the office and not accessible from the public Internet"},"content":{"rendered":"\n<p>If your <strong>OpenEMR (or medical website\/software)<\/strong> is <strong>ONLY inside your office<\/strong>, <strong>not accessible from the public Internet<\/strong>, and <strong>does not transmit PHI outside the clinic<\/strong>, then your HIPAA requirements are <em>much simpler<\/em> \u2014 <strong>but still real<\/strong>.<\/p>\n\n\n\n<p>Below is the <strong>correct<\/strong> and <strong>practical<\/strong> HIPAA requirements list for an <em>on-premise, office-only EMR system<\/em>.<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h6 class=\"wp-block-heading\">\u2705 <strong>If your system is only on an office computer (no Internet access for PHI)<\/strong><\/h6>\n\n\n\n<p>You <strong>still<\/strong> must follow HIPAA <strong>Security Rule<\/strong> requirements because PHI is stored electronically (ePHI).<br>BUT you <strong>do NOT need HIPAA-compliant web hosting<\/strong> or external BAA.<\/p>\n\n\n\n<p>You must secure:<\/p>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>1. Physical Safeguards (Required)<\/strong><\/h4>\n\n\n\n<p>These protect access to the physical computer.<\/p>\n\n\n\n<h6 class=\"wp-block-heading\">\u2714 Locked office &amp; controlled access<\/h6>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Only authorized staff can enter rooms with PHI computers.<\/li>\n<\/ul>\n\n\n\n<h6 class=\"wp-block-heading\">\u2714 Secure workstation placement<\/h6>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Computer screens cannot face patients or public areas.<\/li>\n<\/ul>\n\n\n\n<h6 class=\"wp-block-heading\">\u2714 A backup process<\/h6>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Local encrypted backup (USB, external HDD, NAS).<\/li>\n\n\n\n<li>Device must be locked up when not in use.<\/li>\n<\/ul>\n\n\n\n<h6 class=\"wp-block-heading\">\u2714 Device disposal<\/h6>\n\n\n\n<ul class=\"wp-block-list\">\n<li>If old PCs\/HDDs are replaced, drives must be wiped with secure erase.<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>2. Technical Safeguards (Required)<\/strong><\/h4>\n\n\n\n<p>These protect PHI on the device.<\/p>\n\n\n\n<h6 class=\"wp-block-heading\">\u2714 Full-disk encryption<\/h6>\n\n\n\n<p>Use <strong>BitLocker (Windows)<\/strong> or <strong>FileVault (Mac)<\/strong>.<br>HIPAA <strong>requires encryption or documented justification<\/strong>.<\/p>\n\n\n\n<h6 class=\"wp-block-heading\">\u2714 User authentication &amp; access control<\/h6>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Each staff member must have their <strong>own login<\/strong> (Windows + OpenEMR).<\/li>\n\n\n\n<li><strong>Strong passwords<\/strong> required.<\/li>\n\n\n\n<li><strong>Automatic logout<\/strong> after inactivity.<\/li>\n<\/ul>\n\n\n\n<h6 class=\"wp-block-heading\">\u2714 Audit logs<\/h6>\n\n\n\n<p>OpenEMR already provides this.<br>You must keep logs for access and changes to PHI.<\/p>\n\n\n\n<h6 class=\"wp-block-heading\">\u2714 Role-based access<\/h6>\n\n\n\n<p>Receptionist \u2260 Doctor \u2260 Biller<\/p>\n\n\n\n<h6 class=\"wp-block-heading\">\u2714 Network isolation<\/h6>\n\n\n\n<p>If your EMR computer is on the same LAN as Wi-Fi, ensure:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Wi-Fi is <strong>secure WPA3 or WPA2-Enterprise<\/strong><\/li>\n\n\n\n<li>Guest Wi-Fi is <strong>separate<\/strong><\/li>\n\n\n\n<li>No port forwarding \/ no remote access<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h4 class=\"wp-block-heading\"><strong>3. Administrative Safeguards (Required)<\/strong><\/h4>\n\n\n\n<p>Policies and procedures you must follow.<\/p>\n\n\n\n<h6 class=\"wp-block-heading\">\u2714 HIPAA training for staff<\/h6>\n\n\n\n<p>Every employee must get yearly HIPAA training.<\/p>\n\n\n\n<h6 class=\"wp-block-heading\">\u2714 Risk assessment (simple version)<\/h6>\n\n\n\n<p>You must document:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Where PHI is stored<\/li>\n\n\n\n<li>Who uses the system<\/li>\n\n\n\n<li>What risks exist (theft, power outage, virus, etc.)<\/li>\n\n\n\n<li>What measures you take to reduce these risks<\/li>\n<\/ul>\n\n\n\n<h6 class=\"wp-block-heading\">\u2714 Incident response plan<\/h6>\n\n\n\n<p>Write down:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>What you do if a computer is stolen<\/li>\n\n\n\n<li>What you do if a virus hits<\/li>\n\n\n\n<li>Who is contacted<\/li>\n<\/ul>\n\n\n\n<h6 class=\"wp-block-heading\">\u2714 Backup &amp; recovery plan<\/h6>\n\n\n\n<ul class=\"wp-block-list\">\n<li>At least one <strong>encrypted<\/strong> backup<\/li>\n\n\n\n<li>Verify backups monthly<\/li>\n\n\n\n<li>A way to restore OpenEMR within reasonable time<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h6 class=\"wp-block-heading\">\ud83d\uded1 <strong>NO HIPAA REQUIRED<\/strong> for things you are NOT doing<\/h6>\n\n\n\n<p>Because the system is <strong>not on the Internet<\/strong>, you do <strong>NOT<\/strong> need:<\/p>\n\n\n\n<h6 class=\"wp-block-heading\">\u274c HIPAA hosting<\/h6>\n\n\n\n<h6 class=\"wp-block-heading\">\u274c A Business Associate Agreement (unless 3rd-party IT has access)<\/h6>\n\n\n\n<h6 class=\"wp-block-heading\">\u274c SSL certificates (for public access)<\/h6>\n\n\n\n<h6 class=\"wp-block-heading\">\u274c Cloud storage<\/h6>\n\n\n\n<h6 class=\"wp-block-heading\">\u274c External server hardening<\/h6>\n\n\n\n<h6 class=\"wp-block-heading\">\u274c Public website security compliance for PHI<\/h6>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h6 class=\"wp-block-heading\">\u26a0 BUT\u2026 You still need BAA with your IT company<\/h6>\n\n\n\n<p>If any IT person or maintenance provider can access the system or see PHI, they are a <strong>Business Associate<\/strong> and must sign a <strong>BAA<\/strong>.<\/p>\n\n\n\n<p>Examples needing a BAA:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>Managed IT company<\/li>\n\n\n\n<li>Remote tech support<\/li>\n\n\n\n<li>Contracted system administrator<\/li>\n\n\n\n<li>Cloud backup vendors (if used)<\/li>\n<\/ul>\n\n\n\n<hr class=\"wp-block-separator has-alpha-channel-opacity\"\/>\n\n\n\n<h6 class=\"wp-block-heading\">\ud83d\udc68\u200d\u2695\ufe0f If your setup is like this, you are OK<\/h6>\n\n\n\n<p>Example safe setup:<\/p>\n\n\n\n<ul class=\"wp-block-list\">\n<li>OpenEMR installed on office desktop\/server<\/li>\n\n\n\n<li>PHI\/Data only accessible inside the office<\/li>\n\n\n\n<li>No remote access<\/li>\n\n\n\n<li>Staff use the office LAN only<\/li>\n\n\n\n<li>Daily encrypted local backup<\/li>\n\n\n\n<li>BitLocker enabled<\/li>\n\n\n\n<li>Password-protected logins<\/li>\n\n\n\n<li>Staff trained in HIPAA basics<\/li>\n<\/ul>\n\n\n\n<p>This is <strong>completely compliant<\/strong> for a 1\u20135 doctor practice if maintained properly.<\/p>\n\n\n\n<p><\/p>\n","protected":false},"excerpt":{"rendered":"<p>If your OpenEMR (or medical website\/software) is ONLY inside your office, not accessible from the public Internet, and does not transmit PHI outside the clinic, then your HIPAA requirements are much simpler \u2014 but still real. Below is the correct and practical HIPAA requirements list for an on-premise, office-only EMR system. \u2705 If your system [&hellip;]<\/p>\n","protected":false},"author":1,"featured_media":0,"parent":0,"menu_order":0,"comment_status":"closed","ping_status":"closed","template":"","meta":{"slim_seo":{"title":"HIPAA requirements if medical website is only inside the office and not accessible from the public Internet - Medindex","description":"If your OpenEMR (or medical website\/software) is ONLY inside your office , not accessible from the public Internet , and does not transmit PHI outside the clini"},"footnotes":""},"class_list":["post-3968","page","type-page","status-publish","hentry"],"_hostinger_reach_plugin_has_subscription_block":false,"_hostinger_reach_plugin_is_elementor":false,"_links":{"self":[{"href":"https:\/\/medindex.am\/accounts\/wp-json\/wp\/v2\/pages\/3968","targetHints":{"allow":["GET"]}}],"collection":[{"href":"https:\/\/medindex.am\/accounts\/wp-json\/wp\/v2\/pages"}],"about":[{"href":"https:\/\/medindex.am\/accounts\/wp-json\/wp\/v2\/types\/page"}],"author":[{"embeddable":true,"href":"https:\/\/medindex.am\/accounts\/wp-json\/wp\/v2\/users\/1"}],"replies":[{"embeddable":true,"href":"https:\/\/medindex.am\/accounts\/wp-json\/wp\/v2\/comments?post=3968"}],"version-history":[{"count":0,"href":"https:\/\/medindex.am\/accounts\/wp-json\/wp\/v2\/pages\/3968\/revisions"}],"wp:attachment":[{"href":"https:\/\/medindex.am\/accounts\/wp-json\/wp\/v2\/media?parent=3968"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}