Written findings · 30/60/90 · Not a legal opinion
HIPAA IT Review for Central PA Medical Practices
HIPAA is not a PDF in a drawer, and it is not a badge on an MSP homepage. It is whether identity, email, backups, access, and audit trails would survive a serious question from your insurer, a business associate, or OCR. Most Central PA practices that ask us for help are not reckless. They inherited a Microsoft tenant, a closet, and a vendor who said “we’re HIPAA compliant.”
InTech Network Solutions is a healthcare-first MSP founded in 2013. We work orthopedic, GI, and other specialty practices, plus 25–500 employee organizations that handle regulated data. This page is a scoped review: written findings and a 30/60/90. It is not a legal opinion, not an audit letter you can wave at a regulator, and not “HIPAA/HITECH certification.” Those certifications are not a thing we can honestly sell.
Call 814-264-2444. Automated attendant. Leave a message or use the request button. We return business-hours requests. We do not claim a human answers every inbound call.
Who should request this
- A practice administrator or compliance lead who has an insurance cybersecurity questionnaire on the desk and no one who can answer it with evidence.
- An IT director or internal IT person who knows the gaps (shared logins, no MFA on email, backups never restored) and needs a document the physicians will fund. Often the follow-on is co-managed IT, not a firing.
- A multi-site specialty group with an Altoona or State College hub and satellites in Tyrone, Huntingdon, Lewistown, or Johnstown — different closets, one tenant, uneven controls.
- A practice whose current MSP talks HIPAA and cannot show the work. Pair this with an MSP second opinion if the issue is the provider, not only the checklist.
Geography we actually work: Altoona, Hollidaysburg, State College, Bellefonte, Huntingdon, Johnstown, Bedford, Lewistown, Clearfield, Tyrone. Service-area business — no street address. On-site when the evidence is physical; remote when it lives in Entra ID and the backup console.
What we inspect
We inspect the IT you run, not your clinical protocols. Counsel still owns legal interpretation. We will say that in the PDF.
Identity and access
Who can reach ePHI. Unique IDs versus shared clinical logins. Privileged roles in Microsoft 365 and on the servers. Joiner/mover/leaver: does billing still have an account three months after they left the 12th Avenue office. MFA coverage — including the exceptions that quietly disable it for “the doctor who hates phones.”
Email and collaboration
Exchange Online and any leftover on-prem mail. Forwarding rules to personal Gmail. Shared front-desk mailboxes. Guest links on SharePoint and OneDrive that turn a visit note into a public URL. This is the same pile as the Microsoft 365 security and licensing review; the HIPAA review cares about ePHI paths, not only license waste.
Endpoints and the network
Workstations at the front desk, imaging PCs, provider laptops that go home to College Township or Logan Township. Encryption at rest where the device holds ePHI. Local admin sprawl. Whether guest Wi-Fi can see clinical VLANs. Cybersecurity is the deeper service line; the review is the snapshot.
Backup, restore, and downtime
Where ePHI copies live. Encryption. Who can delete the backups (ransomware’s favorite feature). Date and scope of the last restore test. Backup and disaster recovery is how we operate this after the review; the review asks whether you could recover a clinic in Altoona or a suite off Atherton without hoping.
Audit logs and admin trails
Whether you could answer “who accessed what, when” for a mailbox, a file share, or an EHR workstation — not theoretically, with the log retention you actually have.
BAAs and vendors
A list of who touches ePHI: EHR vendor, imaging, billing, backup, MSP, copier, patient-comms. We are not your lawyer. We will tell you which vendors look like business associates and whether a BAA is on file if you give us the file. Missing paperwork is a finding. We will not fabricate a BAA inventory.
Policies versus the network
If you have written access-control and incident procedures, we check whether the tenant matches them. If you do not, that is a finding — we can point at compliance and risk work to draft and maintain them. The review itself does not pretend to be a full administrative-safeguard engagement unless we scope that separately.
What you get
- Written findings. What we saw, where we saw it, why it matters for a covered entity or business associate. Plain language. No fear stats we cannot defend.
- A 30/60/90. Thirty days: the items that should not wait (MFA holes, exposed sharing, backups with no restore). Sixty: identity cleanup, logging, endpoint gaps. Ninety: the projects (network splits, Intune, replacing a closet that cannot be made honest).
- An evidence appendix. Screenshots and exports you already own, so you are not trusting a slide.
- A conversation about next steps you control: fix with current IT / MSP, hire InTech for managed IT or healthcare IT, or do nothing. Doing nothing is allowed. You will at least know.
We do not issue a “HIPAA compliant” certificate at the end. Anyone who does is selling theater. Help desk and monitoring are how gaps stay closed after you choose an operator; they are not the review.
What this is not
- Not a legal opinion. Have counsel review anything you submit to a regulator, payer, or board.
- Not an official OCR audit. We are not the government.
- Not HITECH/HIPAA certification of InTech or of your practice.
- Not a live-answer hotline. Automated attendant. Monday–Friday, 8:00 a.m.–5:00 p.m. Eastern on contact.
- Not a requirement to switch MSPs. If you want the no-blame provider review, that is MSP second opinion.
Owner: Lance Schreffler. Phone 814-264-2444. Email contact@intechns.com. Local context: Altoona managed IT, State College MSP.
No testimonials or review counts on this page. Ask for a peer conversation after you have the findings if you need one.
InTech is a service-area business. No public street address. Automated attendant on inbound calls. This review is technical findings and a recommended 30/60/90. It is not legal advice.
