IT for Healthcare
IT that keeps patients seen and PHI protected.
Managed IT for Texas healthcare organizations — HIPAA and HB300 compliance built into daily operations, EHR-aware support, and 24/7 monitoring.
- The EHR slows down mid-morning and nobody can tell you why
- You're one staff departure away from not knowing who has access to what
- A hospital system sent a vendor security questionnaire you can't answer
- Your last HIPAA risk assessment is old enough to be a liability itself
The compliance picture
Texas healthcare providers answer to both HIPAA and Texas HB300 — and HB300 goes further, covering more organizations, requiring faster employee training, and adding state penalties on top of federal ones. We build both into how your IT runs, not as an annual scramble.
We come from this world: Black Lab began as the internal IT operation behind three Texas care companies — Disability Services of the Southwest (DSSW), Lifespan Home Care, and CDS in Texas — and our leadership presents on IT and security to the Texas healthcare community — including as speakers at the TAHC&H (Texas Association for Home Care & Hospice) Annual Meeting. Those three are named with their written permission; we do not identify clients otherwise.
We know the rhythm of a clinic
Healthcare IT problems aren’t like office IT problems. A down workstation is a provider not seeing patients. A slow EHR ripples through the whole schedule and every exam room feels it by noon. After-hours “maintenance windows” are the only windows, because the schedule is the business. We plan around your patient day: changes happen when the calendar is clear, support reaches a human fast, and the front desk is treated as the critical infrastructure it is.
That rhythm extends to people. The riskiest moments in healthcare IT are staffing moments — a new hire who needs EHR access, e-prescribe credentials, and building access on day one, and a departure whose access needs to end the same hour it should. We run both as same-day checklists, logged and confirmed, because “we’ll get to the account cleanup next week” is how audit findings and breaches start.
Compliance that runs itself
Encryption at rest and in transit, quarterly access reviews, audit logging, automatic account disabling on departure, documented annual risk assessments — these are daily operations at Black Lab, not an annual project that everyone dreads. The practical difference shows up in three moments:
- The vendor security questionnaire. Hospital systems and payors increasingly demand security attestations before sending referrals or renewing contracts. When one lands, the answers already exist as documents, not homework.
- The insurance renewal. Cyber liability carriers now ask the same questions auditors do — MFA coverage, backup testing, training completion. Complete answers keep coverage available and premiums sane.
- The audit or investigation. The first request is always the risk assessment and the training records. Ours are dated, current, and organized to hand over.
What 24/7 actually means for a care organization
Care doesn’t keep business hours, and neither do the systems behind it. Our monitoring watches your servers and critical services around the clock; alerts page an on-call engineer with automated response beginning immediately and a human typically engaged within five minutes. For a healthcare organization, that’s the difference between “the nurse supervisor discovered the system was down at 6 a.m.” and “it was fixed before the first shift arrived.”
Where to start
Most healthcare engagements begin with the assessment run through a compliance lens: where PHI lives, who can reach it, whether backups would actually restore, and how far your current documentation would get you in an audit. You keep the findings either way — including the honest version of how your current arrangement is performing.
Healthcare questions we hear
Do you sign business associate agreements?
Yes, without hesitation — we're a business associate under HIPAA and we act like one, maintaining our own safeguards and helping you track the BAAs your other vendors owe you. An IT provider that hesitates to sign a BAA is telling you something.
What's the difference between HIPAA and Texas HB300 for my practice?
HB300 is Texas's stricter overlay: it defines covered entities more broadly (many businesses that merely handle health information are covered, not just providers), requires privacy training within 90 days of hire and every two years after, and adds state civil penalties on top of federal ones. If you're HIPAA-covered in Texas, you're almost certainly HB300-covered too.
Can you work with our EHR vendor?
That's the normal arrangement. Your EHR vendor supports their application; we manage everything it depends on — servers or hosted connectivity, workstations, network, backups, and access control — and we get on the phone with the vendor directly instead of leaving your office manager to translate.
What happens if we have a breach?
Every covered client has a written incident response plan that includes HIPAA's breach notification requirements and HB300's state obligations — who we isolate, what we preserve for investigation, who gets notified and by when. The hours after an incident are the wrong time to learn those rules.
Get an IT assessment built for healthcare.
A local engineer reviews your environment against the stakes of your industry — compliance, uptime, and the systems your revenue runs through. Confidential, and yours to keep.