7 Things Sacramento Medical Practices Get Wrong About Their IT

July 22, 2026  |  Technology

medical care
by:admin July 22, 2026 0 Comments
medical care

The most expensive assumption in healthcare technology isn’t that something will never go wrong. It’s that everything is already handled.

Practice managers tell us regularly that their IT is fine. Backups run. Antivirus is installed. Someone comes out when a workstation dies. On paper, nothing looks broken — and that’s exactly the problem, because the gaps that matter most in a medical practice tend to be invisible right up until the moment they aren’t.

What follows are seven beliefs we encounter repeatedly in Sacramento practices, along with what’s actually true. Some will apply to your clinic. Some won’t. The ones that make you pause are worth ten minutes with whoever manages your systems.

Quick reference

The beliefThe reality
Backups are running, so we’re coveredA completed backup job says nothing about whether data can be restored
Our EHR vendor handles our ITVendors support the application, not the infrastructure it runs on
We’re too small to be a targetMost attacks are automated and indiscriminate by design
Antivirus protects our workstationsSignature-based tools miss behaviour-based threats entirely
HIPAA compliance was completed at setupThe Security Rule describes an ongoing obligation, not a one-time task
Slow systems are just the EHR being slowThe constraint usually sits in storage, network, or workstation age
MFA is inconvenient for clinical staffModern implementations add seconds, and exemptions are what attackers seek

Myth 1: “Our backups run every night, so our data is safe”

What’s actually true: A backup job reporting success confirms one thing only — that the job ran. It says nothing about whether the data inside is usable.

We’ve tested backups at practices where the nightly job had been completing cleanly for four years. The restore failed. Corrupted data backs up perfectly well, and nobody had ever attempted a recovery to find out.

There’s a second issue that catches practices out more often. Ransomware specifically hunts for connected backup storage, because attackers know a clinic that can restore doesn’t pay. If your backup drive sits in the server room and is reachable from any infected workstation, it will be encrypted alongside everything else. You’ll discover this on the morning you need it most.

What to do instead:

  • Ask for the date of the last actual restore test — a restore, not a backup
  • Confirm at least one copy lives off-site, unreachable from your office network
  • Check how many recovery points exist, and how far back you can go
  • Establish, roughly, how many hours a full recovery would take

If nobody can answer these, that’s your finding.

Myth 2: “Our EHR vendor takes care of our technology”

This one causes more confusion than any other, and it’s worth being precise about where the line sits.

Your EHR vendor supports the application. They maintain the software, push updates, and troubleshoot issues within their own product. What they don’t support is the workstation the software runs on, the server underneath it, the network carrying the traffic, the imaging system beside it, or the internet connection everything depends on.

When a practice calls the vendor about slowness, the vendor checks their side, finds it healthy, and reports that the problem is local. That’s usually accurate. It’s rarely helpful.

The gap between “the application is fine” and “the practice is working properly” is where most clinical technology frustration actually lives — and filling it requires someone who can determine whether a delay originates in the software or the infrastructure, and resolve the second without a three-way call the practice has to coordinate.

Myth 3: “A practice our size isn’t worth attacking”

Nobody is going looking for your clinic specifically. That’s precisely why this belief is dangerous.

The overwhelming majority of attacks on practices this size are automated. Systems get scanned in bulk for known vulnerabilities. Phishing goes out in enormous volume. Attention follows wherever something responds. Size doesn’t remove a practice from that process — lighter defenses often make it a more productive result.

There’s also the matter of what you hold. A stolen credit card gets cancelled within hours. A medical record contains a name, date of birth, Social Security number, insurance details, address history, and clinical information — almost none of which can be cancelled, and most of which remains valid for years. That’s why health records consistently command higher prices on criminal markets than financial data does.

Add the operational pressure. A practice with a full waiting room can’t pause the way a manufacturer can pause a production line, and attackers understand exactly what that’s worth.

Myth 4: “We have antivirus, so the workstations are protected”

Antivirus does a real job. It just isn’t the job most people think.

Traditional antivirus works by recognition — it identifies threats that have been catalogued before. That’s genuinely useful against known malware and completely ineffective against anything new, which describes most of what actually reaches a practice today.

Modern ransomware doesn’t announce itself with a recognisable signature. It arrives through legitimate credentials, moves quietly through a network for days or weeks, locates the backup system, and triggers over a weekend. Antivirus watching for known files sees nothing unusual throughout.

Endpoint detection and response takes a different approach, watching for suspicious behaviour — processes doing things they shouldn’t, encryption starting where it shouldn’t, credentials being used from unexpected places. That’s what catches an intrusion during the mapping phase, in the window between an attacker getting in and the damage beginning.

The practical difference: antivirus asks “have I seen this before?” EDR asks “is this normal?” Only the second question catches what’s actually happening in healthcare right now.

Myth 5: “We did our HIPAA compliance when we set up”

HIPAA gets discussed as though it were a certificate hanging in the back office. The Security Rule describes something different: an ongoing process.

The requirement is to conduct a risk analysis, act on the findings, document what was done, and repeat as circumstances change. Not once. Continuously — as staff join and leave, as software is replaced, as the practice grows.

This is why a clinic can have reasonable protections and still be in a difficult position after an incident. The question asked afterward isn’t only whether safeguards existed. It’s whether risks had been identified, addressed, and recorded. A practice that can produce that history sits in a materially different position from one that can only say things had seemed fine.

Cyber insurance has moved in the same direction. Applications now ask directly about MFA, backup testing, monitoring, and endpoint protection — and claims have been reduced where a practice attested to controls it didn’t have. That application is a legal document, signed by someone on behalf of the practice.

Worth knowing: when the underlying work is being done properly, the documentation largely produces itself. Monitoring generates logs. Scheduled testing generates reports. Managed patching generates compliance figures. The paperwork burden people fear is mostly a symptom of the work not happening.

Myth 6: “The EHR is just slow — that’s how it is”

Sometimes accurate. More often, the delay originates somewhere nobody has examined.

When a practice reports a slow EHR, the cause is rarely the application itself. It’s usually one of several things underneath it:

  1. Workstation age. Clinical machines stay in service far longer than office computers because they still technically work. A five-year-old workstation without solid-state storage will feel noticeably slower on identical software.
  2. Storage performance at the server. If the EHR runs locally, storage response time governs almost everything — and it degrades gradually enough that nobody can say when it started.
  3. Network bottlenecks. Older switches or saturated links. Imaging transfers in particular can flood a network and slow everything else while they run.
  4. Internet capacity for cloud systems. Connections adequate three years ago now carry the EHR, the patient portal, VoIP phones, and imaging uploads simultaneously.
  5. Maintenance during clinic hours. Antivirus scans, backup jobs, and updates running mid-morning. Individually reasonable, collectively expensive.

Here’s a test that costs nothing: time how long a chart takes to open at 8am, then time the same operation at 11am. If there’s a meaningful difference, the constraint is shared — storage or network — and replacing individual workstations won’t fix it.

That single comparison has redirected a great many misdirected budgets.

Myth 7: “MFA would slow our clinical staff down”

This objection was reasonable several years ago. It isn’t now.

Modern implementations add a few seconds to a login, and most support approaches that reduce prompts on trusted devices within a clinical environment. Against that, Multi-Factor Authentication stops the substantial majority of account-takeover attempts — and stolen credentials remain the single most common way attackers enter a practice.

The genuine risk isn’t the inconvenience. It’s the exemptions.

Practices commonly exempt physicians and practice managers because MFA felt disruptive during a busy clinic. Those are precisely the accounts with the broadest access to patient data and the most authority attached to their messages. Attackers actively look for the accounts that were left out, and finding one is usually straightforward.

Partial coverage isn’t partial protection. It’s a marked map.

Common questions from practice managers

How long does it take to fix the gaps we find?

Most of them, faster than expected. Enforcing MFA across a practice is typically an afternoon. Getting backups replicated off-site and tested is a short project. Patch management runs automatically once configured. The larger items — replacing aging workstations, addressing storage performance — depend on findings, but they can be prioritised and staged rather than done all at once.

Will any of this disrupt patient care?

It shouldn’t, and it doesn’t need to. Work of this kind gets phased deliberately, with anything potentially disruptive scheduled outside clinic hours. The improvements patients notice are shorter check-in queues and appointments that stay on schedule.

Do you replace our EHR vendor?

No. We work alongside them. They own the application; we handle everything the application depends on, and we deal with the vendor directly when an issue genuinely sits on their side rather than leaving the practice to mediate.

What about our imaging systems and connected devices?

These need particular attention, because they’re often overlooked exactly for being reliable — while running embedded software that stopped receiving updates years ago. Where a device genuinely can’t be patched, the right approach is network isolation rather than leaving it alongside everything else.

We already have someone handling our IT. Is this different?

It depends entirely on whether the arrangement is reactive or proactive. Break-fix support is capable at what it does: something breaks, you call, it gets repaired. What it structurally cannot do is watch a network during the weeks an attacker sits inside one, confirm backups would restore, or notice a control drifting out of effectiveness. Not through anyone’s failing — it was never that arrangement’s job.

Key takeaways

  • A backup that has never been restored is an assumption, not protection
  • Your EHR vendor supports the software; the infrastructure it runs on is someone else’s responsibility
  • Automated attacks don’t check your size before scanning
  • Antivirus recognises known threats; behaviour-based detection catches current ones
  • HIPAA describes continuous effort, and the documentation is what gets examined afterward
  • Slow systems usually have a specific, measurable cause worth identifying before spending
  • MFA exemptions are the accounts attackers hope to find

What a well-run practice actually looks like

Clinics that get this right share a fairly consistent picture. Every workstation, server, imaging system, and network device sits under continuous monitoring, so a failing drive gets replaced on a scheduled Tuesday rather than during a Monday morning emergency. Patching runs automatically, holding compliance high without depending on anyone’s memory.

Multi-Factor Authentication applies to every account without exception. Email threat filtering and DNS security intercept most malicious messages before staff have to make a judgment call about them at four in the afternoon. Backups are verified daily, replicated off-site, and tested quarterly with a written result that can be handed to an insurer.

And when something does need attention, help arrives in minutes rather than tomorrow — which matters disproportionately when a waiting room is full.

Our managed IT services, cybersecurity, and backup and disaster recovery are built specifically around this for medical and dental practices, with HIPAA safeguards treated as a design requirement rather than paperwork completed afterward.

Before you close this page

Pick the myth above that gave you the longest pause. Take that single question to whoever manages your technology this week, and ask for a specific answer rather than a reassurance.

If you get a date, a percentage, or a number — good. If you get “it should be fine,” you’ve learned something useful about where to start.

Call our team on 209-920-4077 to talk through what you find. We’ll tell you plainly which gaps matter for a practice your size and which ones don’t, without a sales conversation attached.

Categories:

Get Access To Your Free White Papers

Enter your details and we’ll take you straight to the download page.