A medical or dental office needs a connection that keeps the practice management system, imaging, phones and card payments running, a network inside the office that keeps patient systems apart from guest Wi-Fi and gadgets, and vendors that will sign a business associate agreement where HIPAA calls for one. The circuit itself is rarely the compliance problem; the choices around it are.
This article describes common network practice for healthcare offices. It is not legal or compliance advice. Your practice's HIPAA risk analysis, and the advisor who helps you with it, decide what you must do.
What runs on a practice's connection
Ten years ago a practice could lose the internet and keep seeing patients, because the schedule and charts lived on a server in the back room. Today much of that has moved to the cloud, and the connection carries far more:
- Practice management and electronic health records, often cloud-hosted.
- Insurance eligibility checks and claims through a clearinghouse.
- E-prescribing and lab orders.
- Imaging: digital X-rays and intraoral scans in dental offices, and larger files such as CBCT scans or studies sent to a radiologist or specialist.
- Telehealth video visits.
- The phones, which are now usually VoIP, and in many practices, fax.
- Card terminals and patient payment portals.
- Check-in tablets, guest Wi-Fi for the waiting room, cameras and door access.
When the connection drops in a cloud-based practice, the front desk cannot see the schedule, verify insurance or take a card. That is the reason uptime planning comes first.
HIPAA and the network, in plain terms
The HIPAA Security Rule requires covered entities and their business associates to protect electronic protected health information (ePHI) with administrative, physical and technical safeguards, based on a risk analysis of their own environment. It does not name products or brands. The technical safeguards include access controls, audit controls, integrity protections, authentication and transmission security.
Some safeguards in the current rule are "addressable" rather than "required," which is widely misread. Addressable does not mean optional. It means you implement the safeguard if it is reasonable and appropriate for your practice, or document why not and what you do instead. Encryption of data in transit is the common example, and in practice most offices encrypt. HHS proposed changes to the Security Rule in 2025 that would make several safeguards stricter; ask your compliance advisor what is final and what applies to you.
Business associates and the conduit exception
A business associate is a vendor that creates, receives, maintains or transmits ePHI on your behalf. HIPAA requires a business associate agreement (BAA) with them. HHS treats pure transmission services, such as an internet provider that carries data without storing it beyond what transmission needs, as conduits that generally do not need one. The exception is narrow, and many "telecom" vendors store data.
| Vendor type | Stores or accesses patient data? | BAA usually expected? |
|---|---|---|
| Internet circuit only | Transmits, does not store | Generally no (conduit) |
| Hosted phones or UCaaS with voicemail, recording or fax | Often yes: voicemails, recordings, faxes | Usually yes |
| Answering service or AI receptionist taking patient messages | Yes: caller details and reasons for calling | Usually yes |
| Managed IT or managed firewall provider | Often has access to systems holding ePHI | Usually yes |
| Cloud EHR, imaging or backup service | Yes | Yes |
Treat the table as a starting point for questions, not a ruling. If a vendor that will touch patient data declines to sign a BAA, that is usually the end of the conversation.
A network checklist for a practice
- Segmentation. Separate networks (VLANs) for clinical workstations, business systems, card terminals, imaging devices, guest Wi-Fi and internet-of-things devices such as cameras and TVs. Guest Wi-Fi should never be able to reach a workstation.
- A business-grade firewall with logging kept long enough to be useful in an investigation, and updates applied on a schedule.
- Secure remote access. Multi-factor authentication and an encrypted VPN or equivalent for anyone reading charts or images from home.
- Wi-Fi security. WPA2-Enterprise or WPA3 for staff, with individual logins rather than one shared password that former employees still know.
- Backups that are encrypted, kept off site and tested by actually restoring something.
- Power. A UPS on the firewall, switches and phone system so a brief power blip does not reboot the office.
- Documentation. A simple diagram and inventory, so your risk analysis describes the network you actually have.
Our managed network and Wi-Fi service designs segmentation from the start, and cybersecurity and DDoS protection covers managed firewalls and monitoring.
Choosing the circuit
A single-provider office with a modest schedule is often well served by good shared fiber with a backup underneath. A multi-provider or multi-specialty practice that lives in cloud systems all day usually belongs on dedicated internet access, with a written SLA, symmetrical upload and a static IP block for remote access and imaging links. In both cases, the backup matters more than the headline speed: a second connection on a different path, with failover that switches automatically. Coax or a cellular link under a fiber primary is a common pairing. We cover the design in does your business need backup internet.
A worked example
A hypothetical dental practice, invented to show the arithmetic. Your numbers will differ.
A four-operatory practice has three providers and ten staff. On a busy morning, eight workstations use the cloud practice management system, two telehealth consults run at once, six phone calls are active and the waiting room has a dozen phones on guest Wi-Fi. The steady traffic is modest: six calls at roughly 100 kbps each is well under 1 Mbps, and two video consults at a few megabits each add little more.
The spike is imaging. Suppose the practice sends a 500 MB CBCT scan to an oral surgeon. That is about 4,000 megabits. On a connection with 20 Mbps of upload, it takes over three minutes at full speed while competing with everything else. On a 500 Mbps symmetrical circuit, it takes around eight seconds in theory. Neither figure is a crisis on its own, but a thin upload means every large send slows the phones and the front desk for the duration. The same method works for your own office: add up what runs at the same time, then look hard at the largest single upload.
Now the downtime side. If the practice sees a hypothetical 30 patients a day and a two-hour outage stops check-in, eligibility checks and payments, the cost is not just the lost appointments. It is the rescheduling calls, the claims that go out late and the patients kept waiting. That is the case for the backup circuit, more than for a bigger primary.
The systems people forget
When we map a practice's network, a few items almost always turn up late:
- Fax. Healthcare still runs on it for referrals, records requests and pharmacy traffic. Fax over VoIP can be unreliable on a poorly tuned network, and cloud fax services store documents, which brings the BAA question back.
- Imaging and lab devices that phone home to their manufacturer for updates or remote support. Put them on their own segment and know who can reach them.
- Old workstations kept alive to run one piece of legacy software. They are often the weakest machine on the network and should be isolated.
- The waiting-room TV and music, which belong on the guest or device network, never the clinical one.
- Remote vendors with standing access for support. Keep a list, and remove access that is no longer needed.
Write a downtime plan before you need it
Even with a backup circuit, plan for the day both fail or the cloud system itself is down. A one-page plan covers most of it: how the front desk sees the day's schedule (a printed or exported copy each morning), how to record visits and payments on paper and enter them later, who calls patients if appointments must move, and which number to call for support. Test the failover every few months by unplugging the primary during a quiet hour. A backup that has never been tested is a hope, not a plan.
The phones deserve their own plan
Front desks in healthcare handle a heavy mix of scheduling, refills, billing questions and urgent calls. Good call flows route each type sensibly, send after-hours urgent calls to whoever is on call, and keep lunch-hour callers from hitting voicemail. Hosted phones make those rules easy to change. If you record calls, remember that several states require every party's consent, and that recordings and voicemails containing patient information are ePHI. An AI receptionist can take overflow and after-hours calls, but because it will collect patient details, ask the BAA question before it goes live.
Questions to ask your carrier and vendors
- Is this circuit dedicated or shared, and what is the upload speed on its own?
- Is there a written SLA with a repair window, and does it cover nights and weekends?
- Can the backup enter the building on a different path from the primary?
- For phone, fax, answering and IT vendors: will you sign a business associate agreement?
- Where are voicemails, recordings and faxes stored, for how long, and who can access them?
- Is data encrypted in transit and at rest, and can you document it for our risk analysis?
- How are firewall and Wi-Fi updates applied, and who is notified when something fails?
Getting the practice connected
We price circuits, backups, phones and network services for your exact address across several carriers, and we are straightforward when a smaller product is the right fit. The carrier pays FiberX, so the invoice is not marked up, and the quote is free with no obligation. See how we design for healthcare on the industries page, send us your address, call 478-758-8091 or text (347) 870-0965. You will usually hear back the same day.