
8 ways to clean up the tech your practice already stopped using
The systems you retired are still on the network, here are eight steps to shut them down before a regulator or an attacker finds them.
The old check scanner in the back office is still plugged in. So is the fax server nobody has logged into since the practice moved to e-fax, the tablet that ran the intake app you dropped last spring and the vendor remote-access account somebody opened during a 2022 go-live.
None of that is harmless. Retired systems keep their data, their credentials and their network connections long after the staff stops thinking about them, and the HIPAA Security Rule does not stop applying to a server because it fell off the org chart. Federal regulators have spent the past two years building enforcement cases around the same root cause, a risk analysis that never accounted for everywhere electronic protected health information actually lived. The proposed Security Rule update would go further, requiring a written technology asset inventory and a network map showing how ePHI moves through every system, reviewed at least once a year,
Decommissioning is nobody's job until it becomes everybody's problem. It has no go-live date, no vendor pushing it forward and no obvious owner, which is why the leftovers pile up quietly for years. Here are eight places to start.





