A 90-Day Plan to Reduce Your Clinic’s Risk
You don’t need a security department. You need 90 days and a prioritized list. Here’s the exact roadmap we’d walk a busy Coastal Bend practice through, in order.

Weeks 1-2: stop the bleeding
The first two weeks are about closing the doors that are standing open right now. Don’t buy anything yet. Don’t redesign anything. Just do the free, fast things:
- Multi-factor authentication on everything — email first, then remote access, then every cloud app the practice uses. This is the highest-value hour you’ll spend all quarter.
- Verify backups exist and are isolated. Confirm there’s a copy ransomware can’t reach from your network, and find out when a restore was last actually tested. Schedule the next test now.
- Update everything. Computers, server, firewall, the EHR workstation nobody touches. Unpatched systems are how attackers walk in without phishing anyone.
- Change shared passwords. If the front desk, the Wi-Fi, or any system uses a password everyone knows — including people who no longer work there — change them this week.
Month 1: build the foundation
With the bleeding stopped, build the things every later step depends on:
- Inventory. List every computer, tablet, phone, printer, and medical device on the network, plus every cloud service holding patient data. You can’t protect what you haven’t counted.
- Staff training kickoff. One short session, real phishing examples, and a dead-simple reporting rule: forward anything suspicious, no blame.
- Email filtering. Most attacks arrive as email. Good filtering quietly discards the obvious ones before your staff ever sees them.
- Unique logins for everyone. No more shared usernames. When everyone has their own login, you can see who did what — and revoke one person’s access without disrupting the practice.
Months 2-3: harden and document
Now the structural work:
- Review who can see what. Walk through every system and confirm each person’s access matches their actual job — the minimum necessary, nothing more. Remove ex-employees everywhere, not just the front door.
- Separate the network. Patient Wi-Fi, staff devices, and medical equipment should not all share one flat network. Segmentation limits how far one compromised device can reach.
- Write the incident plan. One page: who gets called, in what order, when something goes wrong at 6 a.m. Include your IT provider, your EHR vendor’s support line, and your cyber insurance carrier.
- Document for HIPAA. Write down what you’ve done — the risk analysis, the training dates, the backup tests. HIPAA’s Security Rule expects documentation, and your future self will thank you.
Who owns each piece
A plan without an owner is a wish. For each phase, name one person in the practice who owns it — not “the office,” one human being with a name.
Weeks 1-2 belong to whoever can touch the systems: your IT provider plus one staff member who can sit with them and make decisions. Month 1’s inventory and training need the office manager, who knows where every device actually lives (as opposed to where the last inventory said it lives). Months 2-3 need the practice owner in the room for the access review, because only you can say who should see what.
Write the names next to the tasks. When something slips — and something always slips — you know exactly who to ask, and they know it was theirs. Accountability is the cheapest security tool there is.
How to keep it going after day 90
Security isn’t a project with an end date; it’s a rhythm. After the 90 days, keep four habits on a schedule: test a backup restore quarterly, run a short training refresh monthly, review user access when anyone joins or leaves, and revisit the whole plan once a year — or whenever something significant changes, like a new EHR or a new location. Put all four on the calendar now, while the momentum is here. The practices that stay safe aren’t the ones with the biggest budgets. They’re the ones that kept the rhythm.
One more thing: budget for it. Security spending feels optional until the week it wasn’t. After the 90 days, you’ll know what the practice actually needs — maybe it’s better email filtering, maybe it’s replacing the firewall from 2019, maybe it’s nothing at all for a while. Put a real line item in next year’s budget based on what you learned, even a small one. “We’ll deal with it when we have to” is how practices end up dealing with it at the worst possible time.
Not sure where your practice stands?
Our free network assessment reviews your computers, backups, and security — and gives you a plain-English read on what's solid and what isn't. No scare tactics.
Call (361) 704-1373 or request yours online.
Request your assessment →Not ready to book? Start with the checklist.
Our 10-Point Small Business IT Security Checklist walks you through the ten things that matter most — in plain English, no jargon. Work through it at your own pace. No sales call, no pitch — just the checklist.
Frequently asked questions
Can a small practice really do this in 90 days?
Yes — because the plan is sequenced, not simultaneous. Weeks 1-2 are a handful of high-impact fixes. The rest spreads across three months. Nobody’s asking the office manager to become a security engineer.
What does this cost?
Weeks 1-2 are mostly free: MFA, updates, password changes. Month 1 onward may involve email filtering or backup improvements, but the plan is designed so the expensive items come after the free wins — and every step is cheaper than a week of downtime.
Do we need to hire IT staff for this?
Not necessarily. Most small practices do this with a managed IT provider handling the technical pieces and one person in the office owning the schedule. The plan tells you what to do; you decide who does each piece.
What if we find problems during the 90 days?
You will — that’s the point. Finding a gap during a planned review is a win. Finding it during a ransomware incident is a disaster. Fix what you find, write it down, keep moving.
How does this relate to HIPAA compliance?
It maps directly: risk analysis, safeguards, training documentation, and backup plans are all things HIPAA’s Security Rule expects. Do the 90-day plan honestly and you’re most of the way to a defensible compliance posture.