Cybersecurity

How We Became HIPAA Experts

Post by
Net Friends Icon
John Snyder

I’ll never forget the sinking feeling I had in late 2001. Kevin, one of the Directors of IT in the School of Medicine, leaned over to tell me “John, I really like you guys at Net Friends… which is why I’m giving you a heads-up that you will be out of Duke in about 12 months, 18 tops.” He went on to explain that there was a new Chief Information Officer (CIO) who had recently arrived who wasn’t fond of outsourced IT contractors.  He was going to use the new HIPAA law as the primary reason to bring all IT support in-house.

I had worked with Kevin for a couple of years, as Net Friends rapidly took on more and more departments at Duke.  At the time, Net Friends was a scrappy group of six technicians. We were working 100% at Duke, with no other real prospects to keep us all engaged. The new CIO worked hard over the next few years to get contractors out of Duke. A few years later there were only two contractors left, and by 2006, Net Friends was the only option for outsourced support.

The reason we survived and thrived well beyond Kevin's dire warning is that we launched into a radical period of innovation. We knew that losing Duke’s business would be the end of Net Friends. We innovated in response to the existential crisis before us by adapting our business model in a variety of ways.As we adapted and developed new service offerings, our original and core business at Duke was both protected and continued to grow.

We've found that in moments of crisis, or when real pressures seem to threaten our business, our instinct is always the same. We treat the threat as an opportunity. When we learned the CIO planned to use the HIPAA law as a reason to cut contractors, we made a bet. We would stay essential to Duke by becoming true experts on everything HIPAA related to IT.

It turned out to be a winning bet. Our business grew threefold over the next four years as we repositioned ourselves as HIPAA experts, offering recurring service packages like our 'HIPAA Compliance Reports' to meet the new requirements of the mandate. We noticed a collective anxiety across Duke, with many people unsure whether they could comply with all the new rules. We doubled down on becoming true HIPAA experts, using our unique position to translate the security and privacy rules into real daily, weekly, monthly, and periodic tasks.

Word traveled quickly within Duke. Net Friends was the “easy button” when it came to implementing security design plans. The Information Security Office (ISO) even positioned us as the subject matter experts on HIPAA.This opened up dozens of opportunities to help different departments meet the minimum requirements for HIPAA compliance at first. But over time, we became the go-to group for a whole range of projects that helped Duke build a more cohesive enterprise IT environment. That reputation held strong even a decade later, when Duke began consolidating all their electronic medical records onto EPIC. We had to ramp up significantly in 2011, growing into more of an IT staffing agency to meet the moment. But that's a story for another day...‍

WHAT TO READ NEXT:
Our 6-Month Head Start on the Pandemic
Leakware: The New Ransomware Targeting Hospitals, Law Firms, and... You?
My First Cybersecurity Incident

Take IT Off Your To-Do List.

Tech holding you back? Losing productivity to downtime?
Discover how we can simplify your tech and free up your time, contact us today.

Start a Conversation

At Net Friends, we believe in the power of human expertise. While we leverage AI to enhance our content and processes, all blog posts are written and edited by our knowledgeable staff. You can trust you are getting insights directly from our team.