Endpoint protection for medical and dental practices
The Security Rule asks for protection against malicious software and for a risk analysis that justifies your choices. Both are easier when every machine reports to one console.
Industries summary
Where this usually goes wrong
- 1 Practice management software runs on machines nobody has audited since they were installed.
- 2 Protection exists on the front-desk computers but nobody is certain about the machines in the treatment rooms.
- 3 The risk analysis is out of date, or was never written down at all.
- 4 A vendor or a health plan has sent a security questionnaire and the endpoint questions cannot be answered from evidence.
- 5 Licences were bought at retail and there is no console, so lapsed protection goes unnoticed.
What Corelink does
- License business endpoint protection with a central console, so protection status on every workstation is visible in one place.
- Count every device that stores or touches patient information, including servers and imaging workstations, before quoting.
- Deliver licences in the practice's own name, so whoever holds your security responsibilities can see the estate directly.
- Align renewal dates so coverage cannot lapse on a machine nobody is watching.
- State plainly which parts of the Security Rule software cannot address.
What the obligation is
The HIPAA Security Rule sets standards for protecting electronic protected health information. It is deliberately technology-neutral: it describes what must be achieved and leaves covered entities to decide how, in proportion to their size, complexity and resources. A ten-person dental practice is not expected to build what a hospital system builds, but it is expected to have thought the question through and written down the result.
Two parts of the rule matter most for this page. The first is risk analysis: a covered entity is required to assess the risks to electronic protected health information across its environment, and that assessment is what justifies every other decision. The second is protection from malicious software, which appears among the rule’s implementation specifications rather than as an absolute instruction to install a named product.
That structure is worth understanding, because it explains why no purchase can make a practice compliant. The rule asks you to reach a defensible judgement and to document it. Software is what you buy after the judgement, not instead of it.
We are not a law firm and nothing here is legal advice. A practice should confirm its own obligations with its counsel or compliance advisor. What follows is only the software part.
Where endpoint protection fits
A small practice’s computers are unusually varied for their number. There is a server running the practice management system, or a cloud service reached from a browser. There are front-desk machines handling scheduling and insurance. There are workstations in treatment rooms, frequently older, frequently running whatever the equipment vendor validated years ago. There may be an imaging workstation nobody is allowed to touch.
Three things follow. Coverage is hard to state confidently, because the machines are not all in one place and not all installed at the same time. Currency is hard to verify, because nobody is logging in to a treatment-room computer to check whether its subscription expired. And the older machines, which are the ones most likely to be running something out of support, are exactly the ones a practice is most reluctant to change.
A central console does not solve the last problem, but it does make the first two into questions with answers. It lists the machines, shows which are reporting, and shows which have stopped.
What we provide
We license business endpoint protection products to the practice, sized to the actual device count, and deliver keys and console access by email. The licence is registered to the practice, not to us, so whoever carries your security responsibilities can sign in and see the estate without going through a reseller.
Before quoting we ask what machines exist, what they run and what they are used for, specifically including treatment-room workstations, servers and any machine attached to equipment. Older operating systems are worth raising early: some publishers’ current products no longer support them, and it is better to find that out during a quote than after a purchase.
We align renewal dates where they are scattered, so that coverage does not lapse on the one machine nobody logs into.
What we do not do
We do not perform risk analyses, write policies, or represent that any product delivers compliance. We do not administer your console, connect to your machines, or handle patient information in any form. We are not your business associate and we do not act as your IT department.
How pricing works
Business endpoint products are licensed per device, per year. Per-device cost falls as device count and term length rise. Quotes are itemised by product, seat count, term, unit price and total, and there is no charge for a quote. We publish no prices on this site, because distributor pricing and publisher promotions both move and a stale figure is worse than none.
Common questions
Does the HIPAA Security Rule require antivirus software?
The Security Rule does not name products or brands. It requires covered entities to conduct a risk analysis and to implement reasonable and appropriate safeguards, and protection against malicious software appears among its implementation specifications. In practice most practices conclude that endpoint protection is part of a reasonable response, but the requirement is to make and document that judgement, not to buy a particular product. Confirm your obligations with your own counsel or compliance advisor.
Are you a business associate?
No. We sell and renew software licences. We do not create, receive, maintain or transmit protected health information on your behalf, we do not administer your console, and we do not connect to your machines. A licence reseller in that position is ordinarily not a business associate, but if your compliance advisor takes a different view of your specific arrangement, tell us and we will discuss it rather than argue about it.
Does buying this make our practice HIPAA compliant?
No. Compliance is a programme covering administrative, physical and technical safeguards, workforce training, policies, and documented risk analysis. Endpoint protection supports part of one of those categories. Any supplier that offers HIPAA compliance as a product feature is overstating what software can do.
What about machines in treatment rooms and at reception?
They are ordinarily licensed the same way as any other computer, per installed device. These are also the machines most often missed in a device count, because nobody thinks of them as computers. We ask about them specifically before quoting.
Can you help us produce evidence for an audit or a questionnaire?
We can supply your licence documentation, showing what is licensed, for how many devices and until when, and the publisher's console will show deployment status. We cannot attest to your compliance and will not write your documentation for you.
Request a quote for your practice
Tell us how many computers you have and what you run today. We reply with options and pricing during business hours — there is no automated checkout and no obligation.