My aunt is looking to open her own practice and is wanting me to set up IT things for her. We both stumbled upon Open EMR and really like the demos… but we are wondering if Open EMR can be HIPPA-compliant without the added subscriptions listed on this page. She would really like to use the patient portal for its scheduling features, and I am thinking that SSL and HTTPS would be sufficient if the server (on-site) has a firewall (USG ?) in front of it and is locked down as listed in this article.
The second question is will HIPPA compliance be achieved if onsite computers are connected with ethernet, Bitlocker enabled, 30second lock time, and use MFA on Open EMR.
Please feel free to poke any holes in my ideas and thanks for the feedback/response,