Guide

Office networks: guest wifi, the router password, and the audit

Summary

Yes. If patient information travels over your office Wi-Fi, that network is part of your ePHI environment, and the HIPAA Security Rule requires safeguards scaled to your practice — even a practice of one. The controls are ordinary: a separate guest network, WPA2 or WPA3 encryption, a changed router password, current firmware, and a written record that your risk analysis looked at the network. None of it is expensive; skipping it is what draws penalties.

By Gale Editorial · Updated 2026-07-26. Every figure cited to a dated source. How we write.

Does office Wi-Fi matter for HIPAA?

Yes — the moment electronic patient information moves across it. The Security Rule does not name Wi-Fi by word, but it requires administrative, physical, and technical safeguards for electronic protected health information, scaled to the size and resources of the practice, and anchored in a risk analysis 1. Your network is part of that environment whether you have one exam room or ten, so it belongs in the analysis.

ePHI is any protected health information your systems create, store, or transmit — the scheduling app, the EHR sync, the email that quotes a chart note. Wi-Fi is the road all of it travels, which is why the setup is not a purely technical afterthought. Whether you sublease a room or run a home office, the office options for a solo determine how much of the network you actually control, but the duty to secure the part you use does not change.

Start with the risk analysis, not the router

Before buying anything, run the risk analysis the Security Rule requires — it is the step that decides which network controls you actually need 2. A solo practice does not need a consultant for this. The free Security Risk Assessment Tool from ONC and OCR is sized for small offices and walks you through the network questions in plain language 3. The document it produces is also the record an investigator asks for first.

The analysis is where you inventory what is actually on the network. Networked devices count too: a smart speaker, a printer with onboard storage, or cameras on the practice Wi-Fi are all endpoints the analysis should list and rate.

Split the network: a guest SSID and a clinical one

Run two separate networks from the same router: a clinical network for your EHR, printer, and work devices, and a guest network for patients and visitors. Almost every business-grade router offers this in a few taps. Segmentation means a visitor's compromised phone never shares a subnet with the machine holding your charts — a reasonable, low-cost safeguard, exactly the kind the Security Rule expects a small practice to adopt 1.

  • Name the guest network so it is obviously the visitor one, and rename or hide the clinical SSID.
  • Turn on client isolation on the guest side so guest devices cannot see each other.
  • Never print, scan, or sync ePHI over the guest network.

The wireless split is the network half of a larger habit: a screen angled toward the waiting room or a shared printer tray creates incidental disclosures that no amount of encryption fixes.

The router itself: five controls

The router is where most small-practice network exposure actually lives, and five controls close most of it: the admin password, the encryption standard, the Wi-Fi passphrase, the firmware, and remote management. None requires a vendor. Work down this list the day you set the network up, then re-check it whenever you replace hardware or once a year, whichever comes first.

ControlWhat to doWhy it matters
Admin passwordChange the router's default login immediatelyDefault credentials are published and scanned for
EncryptionWPA3, or WPA2 at minimum — never WEP or openWeak encryption exposes ePHI in transit
PassphraseLong and unique, not the practice nameA guessable key defeats the encryption
FirmwareEnable auto-update or patch on a set scheduleUnpatched firmware is a known ransomware entry point
Remote managementDisable unless you actively use itCloses an internet-facing attack surface

When the network is the breach: ransomware

If ransomware encrypts ePHI reachable from your Wi-Fi, OCR treats that as a presumed reportable breach unless a documented risk assessment shows a low probability that the data was compromised 4. That single rule is why the unglamorous controls matter: the risk assessment you can point to afterward, and the backups that let you refuse a ransom, both begin with a secured, segmented network and a current firmware baseline.

This is where the contingency plan earns its place — the Security Rule's required backup and disaster-recovery piece is what turns a network compromise into a bad week instead of a practice-ending event. Keep offline or immutable backups, and keep the audit logs that show what an intruder could and could not reach.

Telehealth and your office Wi-Fi

If you see patients over video, the network carrying that session is in scope too. Since the pandemic enforcement discretion ended, telehealth must run on HIPAA-compliant arrangements, which OCR spells out for both video and audio-only visits 5. On your side that means the same secured, encrypted network — not a coffee-shop hotspot — plus a business associate agreement with the platform.

Configure the telehealth platforms deliberately rather than trusting their defaults: waiting rooms on, session encryption on, recording off unless you have a reason and a consent. The vendor secures its servers; the last mile — your Wi-Fi and your settings — is yours.

What an investigator actually asks for

OCR does not inspect your router; it asks for documents. When a complaint or a breach brings an investigation, the office wants your risk analysis, your policies, and evidence that you acted on what the analysis found 6. Small practices are not exempt — OCR has resolved cases against solo and very small offices 6. Keep the Security Rule documentation for the required six years, and store it where you can produce it within a day 2.

The practical takeaway: the Wi-Fi controls are cheap and the documentation is free, but an investigator measures both by what you can show, not by what you did. Write down the analysis, write down the decisions, and date them. Then revisit the whole setup on a schedule — a new device, a new app, or a moved office each changes the picture, and the analysis is only as trustworthy as its last date.

Common questions

It is not named in the rule, but it is one of the clearest low-cost safeguards for a small practice. A separate guest network keeps visitors' devices off the same subnet as your EHR machine, shrinking what a compromised phone can reach. Most business routers offer it in a few taps, and documenting the choice in your risk analysis is easy.

WPA3 is preferred because it is stronger, but WPA2 with a long, unique passphrase is widely accepted where your hardware does not support WPA3. What matters is that you are not running open or WEP encryption, both of which expose data in transit. Upgrade to WPA3 when you next replace the router.

Yes, when that network carries electronic patient information. The Security Rule follows the ePHI, not the address, so a home office network used for telehealth or EHR access is in scope and belongs in your risk analysis. Apply the same controls you would in a clinical suite: encryption, a strong password, current firmware, and separation from household devices.

The missing risk analysis is one of the most common findings in OCR enforcement, because it is the foundation the rest of the Security Rule builds on. Without it you cannot show your network decisions were reasoned. The fix is free: run the ONC/OCR Security Risk Assessment Tool, document the results, and act on the gaps it surfaces.

It can be, if you configure it: change the default admin password, enable WPA2 or WPA3, set a strong passphrase, keep firmware current, and turn off remote management. A business-grade router adds easier network segmentation and longer firmware support, which is why many practices upgrade, but the controls matter more than the price tag.

Run your practice on Gale

The software is free. Gale earns one flat 3.5% all-in per paid transaction — only on transactions that actually pay. No subscription, no setup fee, no network cut.

Start or manage a practice →

References

  1. 1.HHS Office for Civil Rights (2026). Summary of the HIPAA Security Rule. U.S. Department of Health and Human Services. linkThat the Security Rule requires administrative, physical, and technical safeguards for ePHI, scaled to the practice and anchored in a risk analysis.
  2. 2.Office of the Federal Register (2026). 45 CFR Part 164 — Security and Privacy. eCFR. linkThe operative rule text for the risk-analysis obligation and the six-year documentation-retention requirement.
  3. 3.Office of the National Coordinator / ASTP (2026). Security Risk Assessment Tool. HealthIT.gov. linkThe free ONC/OCR Security Risk Assessment Tool a small practice can use to conduct the required risk analysis.
  4. 4.HHS Office for Civil Rights (2016). FACT SHEET: Ransomware and HIPAA. U.S. Department of Health and Human Services. linkThat a ransomware encryption of ePHI is a presumed reportable breach absent a documented low-probability risk assessment.
  5. 5.HHS Office for Civil Rights (2026). HIPAA and Telehealth. U.S. Department of Health and Human Services. linkThat telehealth must run on HIPAA-compliant arrangements after the end of the enforcement discretion, including audio-only guidance.
  6. 6.HHS Office for Civil Rights (2026). HIPAA Compliance and Enforcement. U.S. Department of Health and Human Services. linkThat OCR enforces the rules through investigations, resolution agreements, and civil money penalties, including against very small practices.

https://www.gale.care/for-providers/hip-office-wifi-security · 6 sources. Competitor details are cited to dated public sources and maintained as they change; figures are estimates, not commitments. Synthetic demonstration.

Findability, by specialty

How practices like yours get found in local search and AI answers — the honest playbook, per specialty.

SEO for private practices · SEO for AI search / answer engines (all verticals)