Practice Academy: Practice Management Track - Register Now
Blog|Articles|October 8, 2026

11 ways to prove your practice's security and AI controls actually work

Fact checked by: Chris Mazzolini

Most practices have a cyber plan and an AI policy. Far fewer can show either one works. Here's how to turn paperwork into proof.

Ask a practice administrator whether the office could bounce back from a ransomware attack, and the honest answer is usually some version of "probably." In an MGMA Stat poll published Oct. 7, only 19 percent of 238 medical group leaders said they were very confident their organization could recover from a cyberattack. Sixty-one percent were somewhat confident, and 21 percent were not confident.

The same gap is opening on artificial intelligence. A 2026 AI security and governance benchmark released Oct. 8 by Clearwater Security & Compliance, which surveyed 105 organizations including physician and dental groups, found 91 percent could not verify what AI is running in their environments. Nearly half had AI policies with no technical enforcement behind them. The committees have met and the policies are written. What's missing is evidence.

That distinction matters more every quarter. Cyber insurers, auditors and regulators increasingly want practices to show their work, and a proposed overhaul of the HIPAA Security Rule would require written plans to restore critical systems within 72 hours and yearly verification of business associates' safeguards. None of the fixes below require a big budget. Most require staff time and a willingness to find out what doesn't work. Here are 11 places to start.


Related to this article