Cybersecurity

Cybersecurity Compliance Requirements for Oklahoma Healthcare Practices: HIPAA & Beyond

Run a healthcare practice in the Tulsa metro and the compliance questions come from every direction at once. The EHR vendor sends a Business Associate Agreement. The cyber-insurance renewal asks about multi-factor authentication and backups. The card processor wants its questionnaire back. And behind all of it sits HIPAA, with a risk analysis you are fairly sure should be written down somewhere. This guide sorts out what actually applies to an Oklahoma practice — medical, dental, or behavioral health — and the order in which to work through it.

Who this guide is for

Owners, practice administrators, and office managers who are responsible for compliance on top of scheduling, payroll, and keeping the schedule full — typically practices with a handful to a few dozen people and no compliance department. One boundary up front: nothing here is legal advice. Where a rule needs interpreting for your specific situation, your privacy officer or healthcare counsel is the right stop. What follows is the technology side of compliance, in plain language.

What HIPAA actually requires day to day

HIPAA splits into three rules. The Privacy Rule governs how protected health information (PHI) is used and disclosed — consents, minimum necessary, patient rights. The Security Rule governs how electronic PHI is protected, and it is where IT does its work. The Breach Notification Rule governs what happens when protection fails. For most practices, the day-to-day gap is the Security Rule.

The risk analysis comes first

The Security Rule’s foundation is a risk analysis: a written assessment of where electronic PHI lives — EHR, practice-management system, imaging, email, file shares, laptops, phones, cloud services, vendors — what threatens it, and how likely and severe each risk is, followed by a risk-management plan that addresses what you found. OCR’s enforcement history shows the risk analysis is the most-cited gap: when the Office for Civil Rights investigates a complaint or a breach, “show us your risk analysis” is an early request, and a practice that cannot produce one starts the conversation in the worst possible position. It is not a one-time document, either — it has to be revisited when your systems, vendors, or locations change.

Three families of safeguards

The rest of the Security Rule is organized into three groups of safeguards, and the names map cleanly onto practical work:

  • Administrative safeguards — a named security official, workforce training, access management, security incident procedures, a contingency plan for outages and disasters, periodic evaluation, and Business Associate Agreements with every vendor that touches PHI.
  • Physical safeguards — who can reach the server closet and the workstations, how screens are positioned in patient areas, and how devices and drives that held PHI are reused or destroyed.
  • Technical safeguards — unique accounts for every person, automatic log-off, encryption, audit logging, integrity controls, authentication, and secure transmission.

None of this is exotic. It is the same disciplined IT a well-run business should have anyway — done deliberately, and written down so you can produce it when someone asks.

Breach notification runs on a clock

When unsecured PHI is compromised, the Breach Notification Rule sets deadlines:

SituationWho is notifiedDeadline
Any breach of unsecured PHIAffected individualsWithout unreasonable delay, and no later than 60 days after discovery.
500 or more people affectedHHS, plus prominent media in the affected stateHHS at the same time as the individual notices; media within the same 60-day window.
Fewer than 500 people affectedHHS, through an annual breach logWithin 60 days after the end of the calendar year.

Note the word “unsecured.” PHI that is encrypted in line with HHS guidance generally is not “unsecured,” which is why a lost laptop with full-disk encryption is usually a bad afternoon rather than a reportable breach. Encryption is the single cheapest way to shrink this entire section.

The 2025 proposed Security Rule update

In early 2025, HHS proposed the most substantial update to the Security Rule since it took effect — making controls such as multi-factor authentication, encryption, asset inventories, network segmentation, and tested restores explicit requirements rather than “addressable” ones. The status matters: proposed, comment period closed, not finalized as of August 2026. Plan for MFA, encryption, and asset inventories regardless, since the proposal points where enforcement is going — and cyber-insurance carriers already treat those controls as given.

Beyond HIPAA: Oklahoma’s breach notification law

HIPAA is federal, but Oklahoma has its own Security Breach Notification Act, and it reaches data HIPAA does not. In general terms, the Act requires notice to Oklahoma residents when unencrypted, unredacted personal information — a name combined with identifiers such as a Social Security number, driver license number, or financial account number — is compromised in a way that creates a real risk of identity theft or fraud. That definition covers more than patient charts: employee records, payroll files, and billing systems hold exactly this kind of data. How the state law interacts with HIPAA’s notification duties in a specific incident is a question for counsel. The practical takeaway for a practice owner is simpler: the same encryption that shrinks a HIPAA breach shrinks a state-law one, and your incident-response plan should assume both laws are in play.

Cyber insurance is the other regulator now

Whatever the regulations require, your cyber-insurance carrier asks sooner and checks harder. Underwriting applications for healthcare practices have converged on the same table stakes: multi-factor authentication on email, remote access, and administrative accounts; endpoint detection and response (EDR) on every computer, not just antivirus; backups with a copy isolated from the network and restore tests to prove they work; and security-awareness training for staff. Practices that cannot check those boxes face higher premiums, narrowed coverage, or declined renewals — and an application answered optimistically rather than truthfully is a claim dispute waiting to happen. Treat the renewal as a free audit: every control it asks about is one the Security Rule expects anyway, and tested backups double as the contingency plan HIPAA requires.

PCI DSS, if the front desk takes cards

If your practice accepts credit or debit cards — and most do — PCI DSS applies through your agreement with your payment processor, entirely separate from HIPAA. For most practices that means an annual Self-Assessment Questionnaire and, depending on how card data flows, quarterly vulnerability scans. The biggest lever is scope: a terminal that encrypts card data at the point of interaction and sends it straight to the processor keeps your network largely out of the picture, while a terminal sharing a flat network with the front-desk PC and the guest Wi-Fi drags the whole office into scope. Segmenting payments onto their own network and never storing card numbers keeps the questionnaire short and honest. Our PCI compliance services page covers the details.

Business associates: agreements in both directions

HIPAA extends past your walls. Every vendor that creates, receives, stores, or transmits PHI on your behalf — the IT provider, the EHR host, the e-fax service, the billing company, the transcription service, the shredding company, the cloud phone system — is a business associate, and HIPAA requires a Business Associate Agreement with each one before PHI flows. The agreements run in both directions: vendors owe them to you — NSN Management signs one with every healthcare client as a matter of course, and a vendor that hesitates is telling you something — and if your practice performs services for another provider, such as billing or reading studies, you may be the business associate in that relationship, owing an agreement the other way. Just as important is the inventory: a current list of which vendors touch PHI and which agreements are on file. A missing BAA is one of the most common findings when OCR reviews a practice.

Where to start: a prioritized list

Trying to do all of this at once fails. Done in order, it compounds:

  1. Get the risk analysis written. It is the foundation of everything else, the document OCR asks for first, and the map that tells you which of the steps below matter most in your practice.
  2. Turn on MFA for email, remote access, and the EHR wherever it supports it.
  3. Encrypt every laptop and mobile device, and confirm servers and backups are encrypted too. Encryption converts most lost-device incidents into non-events under both federal and state law.
  4. Put EDR and patching on every computer, with someone confirming both actually happen.
  5. Test a restore. A backup that has never been restored is a hope, not a contingency plan. Agree on how much downtime and data loss the practice can tolerate, and design to that.
  6. Build the BAA inventory — every vendor that touches PHI, with a signed agreement on file for each.
  7. Train your people and write the incident plan. Short, regular awareness training with completion records, and a one-page incident-response procedure that maps to the notification deadlines above.

What an IT partner can and cannot do

An honest boundary, because this field attracts overpromising: NSN Management is a managed IT provider and a HIPAA business associate, not a law firm or a compliance auditor. We implement and document the technical and administrative safeguards — the risk analysis, MFA, encryption, EDR, logging, tested backups, policies, and training records — and help you produce them when someone asks. Your privacy officer or counsel remains responsible for the Privacy Rule, patient notices, and legal interpretation. And no vendor can “certify” HIPAA compliance, because no such certification exists — anyone selling one is selling something else.

NSN Management has provided HIPAA compliance services and IT support for healthcare practices across the Tulsa metro since 2012 — Tulsa-owned from the start. If you want to know where your practice actually stands — what is in place, what is written down, and what an investigator or underwriter would see — book a Discovery Call. We will walk through it plainly, without scare tactics.

Questions Tulsa businesses ask about this

Does a small practice really need a HIPAA risk analysis?

Yes. The Security Rule scales its expectations to a practice’s size and resources, but it does not exempt small practices, and OCR settlements regularly involve solo and small-group providers. It is the most-cited gap in OCR’s enforcement history. A small practice’s risk analysis can be proportionately small — it just has to exist, be accurate, and be written down.

What is the penalty for a HIPAA violation?

HHS sets civil money penalties in four tiers based on culpability — from violations the practice could not reasonably have known about, through reasonable cause, up to willful neglect left uncorrected — with per-violation amounts and annual caps that HHS publishes and adjusts for inflation. Many cases resolve as settlements with corrective action plans, and state attorneys general can also bring HIPAA actions. Willful neglect draws the highest penalties — one more reason the written risk analysis matters.

Do we need a BAA with our IT company?

Yes. An IT provider with access to systems that hold PHI is a business associate under HIPAA, and a Business Associate Agreement is required before that access exists. NSN Management signs a BAA with every healthcare client as standard practice. If your current provider has not offered one, that is a finding in itself.

Does HIPAA require MFA?

Not by name — today. The current Security Rule requires person-or-entity authentication and leaves the method to your risk analysis. The 2025 proposed Security Rule update would make multi-factor authentication an explicit requirement, and while that proposal had not been finalized as of August 2026, cyber-insurance carriers already require MFA and OCR expects to see it. Turn it on regardless of where the rulemaking lands.

Is Oklahoma’s breach notification law the same as HIPAA’s?

No. Oklahoma’s Security Breach Notification Act is a separate state law covering unencrypted, unredacted personal information of Oklahoma residents — data such as Social Security and financial account numbers, which practices hold on employees as well as patients. Its triggers and duties differ from HIPAA’s, and how the two interact in an incident is a question for your counsel. Encrypting data at rest is the practical defense under both.

Written and reviewed by the NSN Management engineering team in Tulsa.

Published · Updated

Cybersecurity