I do tech work for small businesses. Lately I have encountered doctors with small practices that want their technology upgraded. I know HIPAA has lots and lots of regulations, but I'm not really understanding them. Pretty much all the practices that I deal with have 5 workstations at most with data sharing on a central server. I know HIPAA requires a firewall for any medical practice with an Internet connection, but what standards? Does any kind of regulation need to be met on the LANs? Also, most of these practices have billing software that is done over the Internet. I know the vendors are HIPAA compliant, but is there any special regulations that I need to meet for billing? What data needs to be secure and what doesn't? I'm kind of at a loss, so if anyone can provide answers or reading material that isn't so cryptic, that would be much appreciated.