LOGIN

IMPORTANT: You can find our statement regarding the COVID-19 outbreak here.

Increased HIPAA Audits in 2025: Is Your Print and Cybersecurity Up to Date?

Healthcare organizations currently face increased Health Insurance Portability and Accountability Act (HIPAA) audits, specifically focused on cybersecurity. Although these changes bring a positive shift in keeping patient data secure, implementing the proper protections can present challenges.  

What are the most effective ways to keep your organization’s print infrastructure and cybersecurity measures up to date? Learn about the best approaches to meet HIPAA compliance needs and confidently tackle audits with this guide. 

Why are HIPAA Audits Increasing in 2025? 

In the simplest terms, HIPAA audits continue to rise due to various governmental and technological changes. This chain reaction begins with enhanced cyberattacks, which have now resulted in regulatory shifts.  

As cyberattacks become more sophisticated and difficult for organizations to defend against, the healthcare industry has seen an increase in successful ransomware attacks and data breaches, which creates major privacy issues with electronic protected health information (ePHI). 

Findings from the Office of Inspector General’s Report 

In November 2024, the Office of Inspector General (OIG) published a report covering the findings of an audit spurred by increased cyberattacks in the healthcare space. OIG found that the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR)’s audit implementation did not adequately assess ePHI protections, resulting in an ineffective reduction of cyber risks.  

OIG’s report made recommendations for OCR to enhance its HIPAA audit program to achieve the following goals: 

Expand the scope of its HIPAA audits to assess compliance with physical and technical safeguards from the HIPAA Security Rule, document and implement standards and guidance for ensuring that deficiencies identified during the HIPAA audits are corrected in a timely manner, and define metrics for monitoring the effectiveness of OCR’s HIPAA audits at improving audited covered entities and business associates’ protections over ePHI and periodically review whether these metrics should be refined. 

Updates to HIPAA in 2025 

As a result, the HHS issued a Notice of Proposed Rulemaking to improve the protection of ePHI. Changes will be made in 2025 to remediate these issues. Previously, healthcare organizations and companies only needed to claim HIPAA compliance without proof, and audits generally only occurred in the event of a breach affecting 500+ patients. However, the HIPAA 2025 proposal suggests various robust enhancements. These proposed requirements include: 

  • Annual compliance audits of administrative, technical, and physical safeguards  
  • Mandatory implementation of Multi-Factor Authentication (MFA) on all ePHI access points 
  • Encryption of ePHI in transit and at rest 
  • Biannual vulnerability scans and annual penetration tests 
  • Required notification within 24 hours when ePHI access is revoked 

How to Meet HIPAA Requirements in Print and Cybersecurity 

Now that HIPAA requirement changes are on the horizon and OCR audits are underway, your healthcare organization must enhance operations to ensure compliance. How can healthcare organizations meet HIPAA requirements in print and cybersecurity? The following strategies can help you protect your sensitive patient data more effectively: 

1. Develop Robust Organizational Policies 

Healthcare facilities deal with highly valuable protected health information daily. To keep cybercriminals at bay, organizations of all sizes need to implement robust policies. Developing organization-wide policies that carefully outline rules and guidelines for handling data empowers your entire workforce to use technology responsibly. Your IT department or a third-party cybersecurity provider should create detailed guidelines according to industry best practices, and this information should be easily accessible for all employees. 

2. Conduct Risk Assessments 

Preparing your organization for HIPAA audits means conducting in-house audits. Healthcare organizations should regularly conduct risk assessments to search for vulnerabilities and assess the current strength of cybersecurity measures. Analyzing the current cybersecurity infrastructure allows organizations to proactively address weaknesses and implement changes to maintain the utmost security. 

3. Keep Your Print Infrastructure Up to Date 

As simple as this step may sound, keeping your systems up to date is a crucial part of maintaining security. Many organizations overlook the importance of updating printer firmware, but keeping these devices updated ensures any vulnerabilities are patched promptly. In the same vein, outdated print devices should be phased out and replaced with modern models that can implement the necessary security measures. Vulnerable print devices can serve as easy entry points for hackers, so consider the security of all devices within your facility’s network. 

4. Implement Secure Print Release 

Ensuring the right users access printed documents is a critical aspect of printer security. All print devices within your organization should have secure print release features, as this step can prevent information from getting into the wrong hands. Secure print release halts immediate printing and instead requires the user to verify their identity on the device before the print job is completed. In the healthcare setting, this is necessary to keep PHI safe. 

5. Physically Secure Your Print Fleet 

Although implementing digital security measures is incredibly valuable, physically protecting your print fleet is another important part of cybersecurity. Your printers should be placed strategically where only authorized users can access them. Additionally, all employees should be instructed not to leave unsecured documents sitting on the printer. These measures, along with encrypted data and regular data wiping on your printers, ensure your devices are secure from physical threats. 

6. Enhance Employee Security Awareness 

Last but not least, your employees need comprehensive, regular security awareness training to keep your organization safe. The human risk is a major threat to cybersecurity at organizations across all industries, and the only way to combat this risk is to keep your employees educated and informed. Regularly train your employees on cybersecurity best practices to avoid common attacks like phishing and rising threats such as deepfake scams. 

Prepare Your Healthcare Facility for HIPAA Auditing 

The rise of audits and proposed changes to regulations present new hurdles for healthcare organizations to overcome, but understanding the changes and implementing security features accordingly will minimize risks at your organization. With the help of a trusted cybersecurity provider, you can stay secure in the healthcare space. 

GoodSuite offers comprehensive technology solutions, including cyber risk assessments, managed IT services, and managed print services in Woodland Hills and throughout Southern California, all designed to keep your company’s infrastructure secure. We have delivered top-rated solutions for over 25 years, and with our help, you can effectively prepare for HIPAA audits.  

Request an assessment of your business online or call us today to learn more about our services. 

This website is using cookies.

We use cookies to enhance your browsing experience, personalize content, and analyze our traffic. By continuing to use our site, you agree to our use of cookies as outlined in our Privacy Policy.

Request A Quote

[ninja_form id=17]

Get Your Free Cyber Threat Assessment

Gary Dergazarian

Vice President

Gary brings 15 years of experience in the technology, office software, and equipment world. He is a business development professional and a workflow solution solver with proven success as a sales leader in services and technology organizations. Gary has been one of our Top selling producers and strategists year after year. He possesses major strengths such as excellent communication skills and business acumen. Gary is passionate, dedicated, and creative. He thrives when working with other business leaders to find innovative ways to create better efficiency and productivity in their offices, and he is comfortable providing solutions for many different types of industries. He is an avid fisherman and outdoors man. When he is not problem solving, Gary loves to hike, golf, and enjoys cycling.

Michael Shoop

Field Service Supervisor

Field Service Supervisor Michael is a Sharp Master Technician. If you aren’t familiar with that term, it’s a bit like winning Iron Chef – the best of the best. There aren’t a lot of them around. He is a veteran and was with AOA for 30 years. His main service area will be Ventura County. He is also very committed to his customers, and always seeks to provide world class service.

Nasim Attaripour

Marketing Coordinator

Nasim brings 5 years of Graphic Design experience to GoodSuite and has been with the company for a year now. She minored in Psychology and received her Bachelor of Fine Arts with a concentration in Graphic Design from California State University, Fullerton. Nasim is extremely detail oriented, creative, and loves building relationships. Nasim is a big asset to company and her strive to constantly learn more has allowed her to grow from her original position as an Administrative Assistant to her new position as Marketing Coordinator. Nasim is a big Foodie and is constantly searching for new places to dine and has a passion for traveling to new places and learning about new cultures when given the chance.

Saleh Shirafkan

Technician

Saleh brings 16 years of industry knowledge to the team and is copier certified on Sharp, Xerox, HP, Samsung, Brother, and Oki. His attention to detail, need for efficiency, and superior customer service skills earns him constant praise from customers and colleagues alike. As a great leader and a fast learner, Saleh is always eager to learn more. When he’s not troubleshooting, Saleh enjoys playing soccer, poker, or solving jigsaw puzzles in his spare time.

Garry Dominiak

Technician

Garry has a 30 year history in the industry and carries a degree in electronics technology. He has completed courses with network administration and is also certified for Xerox, HP, Sharp, Samsung, Oki, and Brother copiers. Garry is a demonstrated hard worker who is willing to go above and beyond to complete job tasks. Garry’s interests include education, street bikes, recreational activities, camping, travel, and family time.

Brent Portera

Director of Managed Services

Brent has been in the Managed Services field for 12+ years focusing on strategic client alignment. He began his career in the document imaging space as an Account Executive and consistently overachieved expectations with a primary focus on Managed Print Services. He has served at numerous roles in the past ranging from MPS Specialist to Vice President of Sales & MPS. Brent has a degree in Computer Science which has continually aided in his ability to deliver custom tailored solutions for his clients. Brent is currently leading the charge for GoodSuite as the Director of Managed Services focusing on Managed IT, Managed Print, and Managed Phone systems for our clients enabling each customer to leverage technology to reach their organizational goals. Brent also focuses on devoting time to coaching his children in numerous sports and loves to unwind at Dodger Stadium with his family.

Colby Noji

Vice President of Service

Colby has been in the copier industry for 27 years. With a degree in electronics and various network certifications, he brings a lot of industry knowledge to GoodSuite. Colby is certified on the following brands: Sharp, Xerox, HP, Samsung, Brother, Oki, Kyocera, Konica Minolta, Canon, and Risograph. He has great customer communications skills and is a strong leader, team player, and self-starter. Outside of the office, Colby likes to bowl, exercise, watch sports, and make trips to Vegas when he gets the chance.

Thomas Chacko

Controller

Thomas Chacko holds a master’s degree in Accounting and brings more than 15 years of industry experience to GoodSuite. He has held a variety of roles, which enable him to identify areas of opportunity and solutions quickly. His honest, humble yet determined personality makes him an invaluable resource. Thomas has always enjoyed sports. Highlights of his high school baseball career include pitching two no-hitters. In his free time, he plays both basketball and softball in recreational leagues. He also loves cooking, experimenting with new recipes all the time. If he is not playing sports or cooking, you can find him exploring nature with his family.

Stuart Fratkin

Executive Vice President

You may recognize Stuart from his previous career as a professional actor in which he amassed over 20 years’ experience in entertainment. Most notably, guest starring on Friends, N.Y.P.D and Judging Amy several times. He co-starred in the films Teen Wolf Too as “Stiles” and the cult classic Ski School as “Fitz”. He starred in his own TV series in 1989-1990 called They Came From Outer Space.

In 2002, wanting to transition to a career that could provide steadier income for his family, he started as a Xerox Account Manager. He worked his way up to Training Manager and began his role as Sales Operation Manager with Copier Headquarters in 2006. He was promoted to Vice President of Agency Operations in 2010 and to his current position as Executive Vice President in 2015. Stuart’s main focus is training his sales staff to bring levity to every situation you are in, people always remember who made them laugh. He is focused on being the anti-salesman; creating relationships and reasons to make the office easier to work in, which are always more beneficial than a quick sale.

Dan Strull

Founder / CEO

After graduating from the Marshall School of Business from USC, Dan worked in various roles at Xerox Corporation for 11 years learning the industry before starting Copier Headquarters, now GoodSuite in 1998.

Dan’s focus from day 1 has been to provide the best level of customer service at the speed of business. Dan’s ambition to be the number one vendor in the area is by trying to find a way to improve the level of service by thinking of creative ways and using dynamic consumer tools to stay ahead of the market.

Dan is proud of what he has built and has used the company success to be a beacon in the community and give back. The company feels that giving time and effort is more important and the company provides two days a year for Volunteer Time Off to serve the community. After all, if you are not giving, you are not living.

Christianne Strull

CFO

Christianne Strull graduated from the Marshall School of Business at the University of Southern California. She has been GoodSuite since its infancy, and her role has expanded along with the company. She is excited to see the growth and transformation of GoodSuite has managed over the years. Christianne enjoys spending time with her family, their dogs and attending USC football games, among other pursuits.