top of page
Search

What Your IT Provider Can't Show You If They Don't Have a SIEM


If you asked your IT provider right now to show you everything that happened on your network last Tuesday — every login, every file access, every connection attempt, every anomaly — could they do it?


If the honest answer is no, or if you're not sure, that's one of the most important IT conversations your practice needs to have. Because that question isn't hypothetical. It's exactly what a federal investigator asks after a healthcare data breach.


I've been doing healthcare IT for 25 years. The question of what an IT provider can actually show you — and what they can't — has become one of the most consequential differences between providers in this market. Most dental and medical practices don't know to ask it. This article is going to explain why it matters, what a SIEM actually is, and what the absence of one means for your practice.


What is a SIEM?


SIEM stands for Security Information and Event Management. It's a system that continuously collects, correlates, and analyzes security event logs from across your entire technology environment — every device, every server, every network component, every application — and creates a searchable, continuous audit trail of everything that happens.


Think of it as the security camera system for your IT environment. Individual security tools — antivirus, endpoint protection, email filtering — are like locks on individual doors. They prevent certain things from happening. A SIEM is the camera that records everything that does happen, across every door, continuously, so that if something goes wrong you have a complete record of exactly what occurred and when.


The distinction matters because no security tool stops every threat. Attacks get through. Credentials get compromised. Insiders make mistakes. When those things happen — and eventually, for any practice operating long enough, some of them will — what happens next depends entirely on what you can document and how quickly you can find it.


Why HIPAA investigators ask for it first


The HIPAA Security Rule requires covered entities to implement hardware, software, and procedural mechanisms that record and examine activity in information systems that contain or use ePHI. This is the audit control requirement — and it's one of the specific technical safeguards the Security Rule mandates.


When HHS Office for Civil Rights investigates a breach, the audit log question comes early in the process. Investigators want to understand the scope of what was accessed — which records, how many patients, over what time period. They want to understand the attack vector — how did the attacker get in, what credentials did they use, which systems did they touch. They want to understand the timeline — when did the breach begin, when was it detected, what actions were taken and when.


Without a SIEM, none of those questions can be answered precisely. Individual security tools generate their own logs, but those logs exist in isolation — they can't be correlated across your environment, they often have limited retention windows, and they weren't designed to support a forensic investigation. When investigators ask for a complete picture of what happened, a provider without a SIEM produces fragments. Fragments that may be insufficient to demonstrate compliance, insufficient to satisfy a corrective action plan, and potentially insufficient to defend against a determination of willful neglect.


Willful neglect is the HIPAA violation tier that carries the highest penalties — up to $50,000 per violation, with an annual cap of $1.9 million per violation category. The determination of willful neglect often hinges on whether an organization had reasonable security controls in place. A practice that cannot produce audit logs after a breach is in a difficult position to argue that its controls were reasonable.


What a SIEM actually catches that other tools miss


This is where the practical security value — separate from the compliance value — becomes clear.


Individual security tools protect against specific threat categories. Endpoint detection and response catches malware and ransomware executing on devices. Email filtering catches phishing attempts before they reach your staff. Identity threat detection monitors for compromised credentials. Each of these tools generates its own alerts and its own logs.


But sophisticated attacks don't operate within a single category. They use multiple techniques, across multiple systems, over an extended period — specifically because they know individual tools monitor for specific signatures and can be evaded by staying below individual detection thresholds.


A SIEM correlates activity across all of those tools simultaneously. It identifies patterns that no single tool would flag — a login at 2am that's within normal parameters on its own, followed by access to a file share that's individually unremarkable, followed by a small outbound data transfer that no individual tool would catch, but that together constitute a clear pattern of data exfiltration.


This correlation capability is why the average healthcare breach takes 279 days to identify and contain without proper monitoring in place. Attackers who know individual tools are watching them operate between the detection thresholds of each tool individually. A SIEM watching all of them simultaneously closes that gap.


The detection timeline matters enormously for HIPAA. The breach notification rule requires covered entities to notify affected individuals within 60 days of discovering a breach. If your provider doesn't discover the breach for six months — because they had no SIEM providing the correlation visibility that would have surfaced it earlier — your notification timeline starts from that discovery date. But your liability exposure extends back to when the breach actually began. The gap between those two dates is where the most significant damage, and the most significant regulatory risk, accumulates.


What providers without a SIEM are actually offering instead


This is worth being direct about, because the marketing language in the IT industry makes it easy to confuse endpoint monitoring with SIEM capability.


Many IT providers — particularly those operating at lower price points — offer what they describe as 24/7 monitoring or SOC coverage. What they mean, in most cases, is that their endpoint detection and response tool runs continuously and alerts when it detects a known threat signature on a device. That is not a SIEM. It's endpoint monitoring. It's valuable — but it's a single camera watching a single door, not a security system covering your entire environment.


Some providers use SMB-focused security platforms that bundle multiple tools — endpoint protection, email security, phishing simulation, dark web monitoring — into a single dashboard. These platforms have genuine value for small businesses. They are not equivalent to a SIEM. They lack the log collection breadth, the correlation capability, and the forensic depth that a true SIEM provides. When an investigator asks for a complete audit trail of what happened across your environment over the past 90 days, a bundled SMB security platform cannot produce it.


The distinction is not a technicality. It's the difference between being able to answer an investigator's questions and not being able to. Between having a defensible compliance posture and having to explain why your audit controls were insufficient. Between managing an incident cleanly and managing an incident while simultaneously managing a regulatory investigation.


The questions to ask your current IT provider


If you're not sure whether your current IT provider has a SIEM, here are the specific questions to ask.


Do you have a SIEM in our environment? Ask for the name of the platform. Then look it up. If it's primarily marketed as an SMB security tool or a bundled cybersecurity platform, ask specifically how it handles cross-environment log correlation and forensic investigation support.


If we had a breach today, what could you show investigators? Ask for a specific answer — what logs exist, how far back they go, and in what format they could be produced for an OCR investigation. A provider with a real SIEM can answer this specifically. A provider without one will be vague.


What is your log retention period? HIPAA requires that audit logs be retained for a minimum of six years. Ask your provider how long event logs are retained in your environment and where they're stored. If the retention period is measured in weeks or months rather than years, your audit control requirement is not being met.


Have you ever supported a practice through a HIPAA breach investigation? This is less about the SIEM specifically and more about whether your provider has the practical experience to support you through the worst-case scenario. A provider who has navigated an OCR investigation with a client understands what's actually required. One who hasn't may not.


What would a forensic investigation of our environment cost, and who conducts it? When a breach occurs, someone needs to conduct a forensic analysis to determine scope, timeline, and impact. Ask your provider whether that's included in your agreement, whether they conduct it internally or outsource it, and what the process looks like. The answer will tell you a great deal about how prepared they are for a real incident.


Why this matters specifically for dental practices


Dental practices have a compliance exposure that medical practices of comparable size often don't — the combination of a high-value data environment with historically lower security investment.


A 10-operatory dental practice in Palm Beach County may have 15 to 20 workstations, multiple servers, a dozen imaging devices, and data integrations with imaging software vendors, patient communication platforms, insurance portals, and dental lab systems. That is a significant attack surface — comparable to a small hospital in its complexity, with far fewer internal security resources.


When a breach occurs in that environment, the forensic investigation needs to determine which of those systems was compromised, what data was accessed, and which patients are affected. Without a SIEM collecting and correlating logs across that entire environment, answering those questions requires manual forensic analysis of individual system logs — a slow, expensive, and often incomplete process.


The practices that navigate breach investigations with the least damage — financially, operationally, and reputationally — are the ones that can produce clear, complete, correlated evidence of what happened. That evidence comes from a SIEM. There is no substitute.


A note on cost and value


SIEM technology was historically expensive — the domain of enterprise IT departments with dedicated security teams. That's no longer true. Modern managed SIEM solutions have brought the technology within reach of independent healthcare practices without the need for internal security expertise to operate it.


What hasn't changed is the cost of not having it. When you evaluate IT providers on monthly rate, the question worth asking is not "which provider is cheapest?" but "which provider can show me everything that happened in my environment last Tuesday?" The answer to the second question tells you far more about the real value you're buying.


Where to start


If you're not sure whether your current IT environment includes a SIEM — or if you know it doesn't and you're not sure what that means for your practice — the right starting point is an honest assessment of your current security and compliance posture.

Skyline Technology offers a complimentary HIPAA IT Risk Assessment for dental and medical practices in Palm Beach Gardens, Jupiter, Stuart, and Port St. Lucie. It covers your security posture across six categories including audit controls and SIEM capability, and produces a written summary with prioritized recommendations — yours to keep with no obligation.


Anthony Lauria is the founder of Skyline Technology, a Palm Beach Gardens-based managed IT provider serving dental and medical practices exclusively across Palm Beach, Martin, and St. Lucie counties. He has been in IT since 2000 and has lived in Palm Beach Gardens since 2001.


Request a complimentary HIPAA IT Risk Assessment at skyline.technology/hipaa-assessment or call or text (561) 316-8665.

 
 
bottom of page