Shadow AI in the browser
Staff paste referral letters, visit summaries, and billing questions into free chatbots because it genuinely saves time. Consumer tools may retain that text, and without written rules, every paste is an unrecorded disclosure decision made under time pressure.
In the sprintAn anonymous-friendly staff tool inventory, a clear allowed / restricted / blocked list, and an attestation staff can actually sign.
Vendor AI feature creep
The phone system adds AI answering. The messaging platform adds drafting. The EHR offers a scribe. Each arrived as a product update, on by default or one click away, and the BAA you signed two years ago says nothing about any of it.
In the sprintEvery AI feature in your stack inventoried, checked against contract and BAA terms, with ready-to-send questions for each vendor that falls short.
Email fraud at the front desk
Credential phishing and "change the bank account" requests remain the most common way in. One trusted click at scheduling can mean an inbox full of patient conversations in the wrong hands, plus a breach-notification project you never budgeted for.
In the sprintA passive check of your email security posture (SPF, DKIM, DMARC), MFA coverage review, and wire-fraud playbooks in the optional training pack.
Access that outlived its purpose
The billing contractor from 2023. The old MSP's admin account. The shared front-desk login everyone knows. Stale access is invisible day to day and decisive the day something goes wrong. It's also the first thing reviewers ask about.
In the sprintAn access and offboarding review across your core systems: who can reach what, which accounts should be gone, and what evidence of review exists.
Backups nobody has restored
"We back up to the cloud" is a sentence, not a recovery plan. Whether the practice survives a ransomware Tuesday depends on immutability, what's actually covered, and whether anyone has ever performed a real restore. Most haven't.
In the sprintA recovery-story review and a one-hour downtime tabletop that answers: who does what in the first hour, and how does care continue?
Patient data outside the EHR
Web forms, billing exports, text reminders, shared drives, fax-to-email, personal phones. Data sprawl makes exposure impossible to describe, which turns a contained incident into an open-ended legal question when someone asks exactly what was exposed.
In the sprintThe patient-data-outside-the-EHR map: where data enters, moves, rests, and leaves, so exposure has an address and an owner.