M&R Systems — IT Solutions & Support

Healthcare

HIPAA Compliance

How M&R Systems supports dental practices, orthodontists, oral surgeons, and other covered entities as a Business Associate under HIPAA.

Last updated February 10, 2026

Our role as a Business Associate

When we manage systems that create, receive, maintain, or transmit electronic protected health information (ePHI) for a covered entity, we act as a Business Associate under HIPAA. Before we access any system containing ePHI, we sign a Business Associate Agreement (BAA) that defines our responsibilities and limits how PHI may be used.

Safeguards we implement

We align our services with the HIPAA Security Rule’s administrative, physical, and technical safeguards:

  • Annual security risk analysis and documented risk management plans.
  • Unique user accounts, multi-factor authentication, and least-privilege access to practice management and imaging systems.
  • Encryption of ePHI at rest on servers, workstations, and laptops, and in transit for email and remote access.
  • Encrypted, tested backups with offsite copies and a written disaster recovery plan.
  • Endpoint protection, patch management, and continuous monitoring with audit logging.
  • Workforce security awareness training and phishing simulations.
  • Vendor review to confirm BAAs are in place with cloud, email, and imaging providers.

Breach response

If we discover a security incident affecting ePHI we manage, we notify the covered entity without unreasonable delay and as required by our BAA, and we help investigate, contain, and document the incident. Covered entities remain responsible for notifying patients and HHS under the Breach Notification Rule; we support that process with technical findings.

California requirements

California adds obligations on top of HIPAA. The Confidentiality of Medical Information Act (CMIA) restricts disclosure of medical information, and California Health & Safety Code § 1280.15 requires certain providers to report unauthorized access within 15 business days. California Civil Code § 1798.82 also sets breach notification requirements. We build our incident response timelines to meet these state deadlines.

Tracking technologies on healthcare websites

HHS guidance warns that analytics and ad pixels on healthcare websites can disclose PHI to third parties without a BAA, for example on appointment request or patient portal pages. We review client websites for tracking technologies and help configure them so health information is never sent to ad platforms. Our free site scan flags common trackers for this reason.

This website

This marketing website is not used to collect PHI. Please do not enter patient information in our forms. Advertising pixels on this site are limited to general business inquiries and are never placed on pages that collect health information.

Questions or requests

To ask a question or exercise any right described here, call us or use the request form on our site. We will verify your identity before acting on a request about personal information.

This page describes M&R Systems's practices and is provided for transparency. It is not legal advice.

Call nowScan my site free