Managed IT and HIPAA security for Maryland healthcare practices.
EDG.tech runs IT and security for independent medical, dental, and behavioral health practices across Gaithersburg, Rockville, Bethesda, Germantown, Washington, DC, and Frederick: encrypted devices and records, a signed business associate agreement, a documented HIPAA risk analysis, tested backups, and a 24/7 security operations center. EDG.tech Complete is $100 per user per month; Essentials is $45 per device per month.
Who this is for
For independent practices and small groups of roughly 5 to 80 staff: primary care, dental, specialty, behavioral health, physical therapy, and the labs and imaging centers that serve them. Hospital systems and practices owned by a health system with its own IT department are better served by that department, and we will tell you so.
What is at stake for a medical or dental practice?
Hacking is now almost the whole problem
In its report to Congress for 2024, the HHS Office for Civil Rights counted 663 large breaches of protected health information; 534 of them, 81%, were hacking or IT incidents, and those accounted for 99% of the roughly 243 million individuals affected. The lost laptop era is over. The way in is a login or an unpatched system.
Source: HHS OCR: Annual Report to Congress on Breaches, CY2024 (PDF)
The Security Rule is being rewritten around controls you may not have
The proposed HIPAA Security Rule update published December 27, 2024 would require multi-factor authentication, encryption of electronic health information at rest and in transit, an asset inventory and network map, vulnerability scans every six months, and written procedures to restore critical systems within 72 hours. The current rule still applies while the update is pending, and the controls are what examiners already ask about.
Source: HHS: HIPAA Security Rule NPRM fact sheet (Dec 27, 2024)
Ransomware investigations end in settlements, not sympathy
The HHS Office for Civil Rights has settled HIPAA investigations that began as ransomware attacks on providers, with payments and multi-year corrective action plans in each. The common finding is a missing or incomplete risk analysis, which is the one document a practice can finish before anything happens.
Source: HHS OCR: four HIPAA Security Rule ransomware settlements (Apr 23, 2026)
What does HIPAA ask of a small practice?
HIPAA's Security Rule requires a documented risk analysis, access controls, audit logs, encryption where reasonable, workforce training, and a business associate agreement with every vendor that touches patient information, including your IT provider. The Breach Notification Rule sets a 60-day outer limit for notifying patients and HHS. The proposed 2024 update would make multi-factor authentication, encryption, and 72-hour restoration explicit requirements. Maryland's Personal Information Protection Act applies to any personal data HIPAA does not cover, such as employee records. Your cyber-insurance carrier will ask for the same controls before renewal. EDG.tech signs a business associate agreement, builds the technical safeguards into the plan, and keeps the risk analysis, policies, and training records current. We do not certify HIPAA compliance, because nobody can; we make the safeguards real and documented.
How does EDG.tech serve healthcare practices?
A business associate agreement, signed before we touch anything
We sign your BAA on day one and work inside it: named staff with access, logged administrative sessions, encrypted remote tools, and a written record of every system that stores or moves patient information, which becomes the asset inventory the Security Rule wants.
Records that are encrypted everywhere they go
Laptops that leave the office, tablets at the front desk and in exam rooms, phones that receive patient messages, and the backups themselves are all encrypted, with multi-factor authentication on the practice management and EHR logins, so a lost device is a replacement cost and not a breach report.
The 72-hour restore, rehearsed
Scheduling, charting, imaging, and billing are backed up with versions and restore-tested on a calendar, so the practice can see patients again within three days of a ransomware event without paying. The drill is documented, which is what the proposed rule and your carrier both ask for.
Clinical devices on their own network
Imaging equipment, digital X-ray sensors, lab analyzers, and the vendor-managed boxes that cannot be patched sit on a segmented network away from the front desk and guest Wi-Fi, with default passwords removed and vendor remote access turned on only when a technician is actually connected.
Which plan fits a healthcare practice?
Enterprise-grade managed IT & cybersecurity, fully managed, 24/7.
See EDG.tech CompletePractices belong on Complete. Patient information lives on every clinician's and staff member's device and in their email, so per-user pricing matches the exposure, and the 24/7 security operations center is what turns a compromised login at 11 PM into a contained event instead of a reportable breach. Essentials fits a solo practitioner with a handful of devices who is building toward the full safeguards.
EDG.tech Essentials is $45 per device per month. Compare both plans
"Most practices that get hit never did the risk analysis. It is the first thing an investigator asks for and the first thing we do," says Duane Epperly, founder of EDG.tech.
Healthcare IT questions, answered
Will EDG.tech sign a business associate agreement?
Yes, before we access any system. As your IT provider we are a business associate under HIPAA, and the agreement sets out how we protect patient information, who on our team has access, how we report an incident to you, and what happens to data when the relationship ends. We also help you collect BAAs from your other vendors.
What does HIPAA compliant IT support cost for a small practice?
EDG.tech Complete is $100 per user per month and includes the safeguards HIPAA expects: encryption, multi-factor authentication, patching, backup, training, and 24/7 monitoring. A practice with 12 staff pays $1,200 per month. A formal risk analysis and policy set is a project quoted per client environment, usually once, then maintained inside the plan.
Can you do our HIPAA risk analysis?
We produce the technical risk analysis the Security Rule requires: an inventory of systems holding patient information, the threats to each, the safeguards in place, and the gaps with a remediation plan and dates. You keep it, update it annually with us, and hand it to an investigator or insurer when asked.
Do you support our EHR and practice management software?
Yes. We support the electronic health record, practice management, imaging, and billing systems you already use, whether cloud or on-premises, and we coordinate with the vendor's support when a problem is on their side. We do not resell clinical software, so our advice on moving to the cloud or staying put is only advice.
What happens if our practice is hit by ransomware?
The security operations center isolates the affected devices within minutes, we restore charting, scheduling, and billing from versioned backups, and we work the notification decision with you and your counsel: what was accessed, whether it is a reportable breach, and the 60-day HIPAA clock. Practices on Complete have the restore rehearsed in advance.
Sources
- HHS OCR: Annual Report to Congress on Breaches, CY2024 (PDF)
- HHS: HIPAA Security Rule NPRM fact sheet (Dec 27, 2024)
- HHS OCR: four HIPAA Security Rule ransomware settlements (Apr 23, 2026)
- HHS: HIPAA Breach Notification Rule
- HHS: Business associate contracts
- Maryland Attorney General: PIPA guidelines for businesses
Last reviewed: October 10, 2026
Ready for IT you never have to worry about?
Book a free 30-minute consultation, or start with a free security assessment. You get a fixed price within two business days. No pressure, no jargon.