Call or Text
HIPAA Compliance

HIPAA-Compliant Security Camera and Access Control Installation for Oklahoma Medical and Dental Practices

Lawton, Wichita Falls, and across Southwest Oklahoma. Engineered to support your practice's obligations under 45 CFR Part 164 and Texas HB 300, on hardware your practice owns.

Call or text (580) 289-8181

Every independent medical, dental, optometry, and veterinary practice operates under the HIPAA Security Rule, which carries explicit technical safeguards under 45 CFR §164.312 covering access control, audit controls, integrity, transmission security, and authentication. Practices handling controlled substances additionally operate under DEA recordkeeping requirements in 21 CFR §1304. Practices accepting card payments, which is nearly all of them, also fall under PCI DSS v4.0.1. Texas practices carry an additional layer. The Texas Medical Records Privacy Act, codified in Chapter 181 of the Texas Health and Safety Code and amended by HB 300, imposes privacy requirements that are stricter than HIPAA in several respects: a broader definition of covered entity, faster patient access timelines, and separate state-level penalties up to $1.5 million annually that stack on top of any federal HHS Office for Civil Rights enforcement. A Texas practice that experiences a breach can be liable for two penalties for one event. The penalties are not abstract. HIPAA Tier 4 violations now reach over $2 million per violation under HHS adjusted maximums. An OCR investigation triggered by a single complaint or breach report is months of legal exposure, mandatory patient notifications, and reputation damage that closes practices. The problem isn’t that practices don’t take compliance seriously. The problem is that most practices are sold “HIPAA-compliant” cameras, networking equipment, and access control systems by vendors who have never read 45 CFR §164.312, much less Chapter 181 of the Texas Health and Safety Code, and cannot tell you which technical safeguards their product actually satisfies. Red River Integration deploys the Ubiquiti UniFi ecosystem (enterprise infrastructure used in hospitals, universities, and critical-care facilities worldwide) engineered specifically for the practice it’s installed in. The exam rooms. The corridors where charts are visible. The medication storage. The front desk. Every system we deliver is designed around HIPAA’s technical safeguards and the additional state-level requirements that apply to Texas practices, documented for audit, and built to hold up the day OCR, the Texas Attorney General’s office, or a state board inspector walks through the door.

The Requirement

What HIPAA and Texas HB 300 Actually Require. What We Build.

45 CFR §164.310(a) and §164.312(a)

Physical and Technical Access Control (Two Different Sections, and Vendors Mix Them Up)

Worth getting straight, because most vendors do not. §164.312 covers technical safeguards for electronic information systems: unique user identification and emergency access procedures are required, while automatic logoff and encryption are addressable. Physical doors are not in §164.312 at all. They live in §164.310(a) (Facility Access Controls), where all four specifications are addressable.

“Addressable” does not mean optional, and it does not mean mandatory. Per §164.306(d)(3) it means you assess whether the safeguard is reasonable and appropriate for your practice, implement it if so, or document why not and implement an equivalent alternative where reasonable. It is a documented-decision obligation, and the documentation is the part OCR asks for.

UniFi Access is how we help you land that decision on the record. Every door to a records area, medication storage room, server closet, or restricted clinical zone is logged with timestamp, credential, and a camera-linked video record. Time-based permissions restrict after-hours access.

Credentials are revoked the moment an employee separation is recorded: no key rotation, no lock changes, no gap between termination and access removal. When OCR or the Texas Attorney General asks who entered your records storage room on a specific date, you produce the answer in seconds (with timestamps, credentials, and camera-verified video) from the same platform managing your network and surveillance.

45 CFR §164.312(b)

Audit Controls

The Security Rule requires hardware, software, and procedural mechanisms that record and examine activity in systems containing electronic protected health information. UniFi’s centralized management console produces a complete, exportable audit trail of every access event, every administrator action, every configuration change, and every camera event across the entire infrastructure. When an audit demands evidence of who did what, when, and on which system, you produce it from a single console rather than reconciling logs across four separate vendors.

The Cloud Camera Problem Most Practices Don’t Know They Have

Most cloud-based camera and access control vendors do not sign a Business Associate Agreement. A camera in an exam room corridor that captures a patient’s face, a chart visible at a workstation, a prescription label, or a patient name on a sign-in sheet is capturing PHI-adjacent imagery. If that footage is stored on a third-party cloud server without a BAA, which is the default for nearly every consumer-grade and prosumer-grade surveillance product on the market, the practice is, technically, transmitting PHI to a third party with no compliant agreement in place.

For Texas practices, the exposure is amplified. Chapter 181 defines “covered entity” more broadly than HIPAA: extending to virtually any organization that assembles, collects, analyzes, uses, evaluates, stores, or transmits PHI of a Texas resident. Your cloud camera vendor is almost certainly a covered entity under Texas law whether they know it or not, and your practice is responsible for the relationship.

No practice has ever audited themselves on this. OCR has. The Texas Attorney General has. Every system Red River Integration deploys records and stores locally.

Footage lives on Network Video Recorder hardware you own, inside your practice, on a network segment isolated from your EHR and your business network. No third-party cloud. No vendor servers. No BAA gap because there is no third party in the loop.

45 CFR §164.312(e)(1)

Transmission Security

The Security Rule requires technical security measures to guard against unauthorized access to electronic protected health information transmitted over electronic networks. UniFi enterprise networking provides the foundation (managed switches, enterprise-grade routers, professionally configured wireless coverage) with proper VLAN segmentation that isolates clinical workstations, EHR traffic, surveillance, access control, guest Wi-Fi, and back-office systems from each other. Network segmentation is the single most overlooked technical safeguard in independent practice IT.

A flat network, where every device sees every other device, means a compromised guest device, a compromised IoT thermostat, or a compromised front desk PC can reach your EHR. Proper segmentation eliminates that path entirely.

DEA Recordkeeping for Controlled Substance Handling

Being precise here, because the citations get abused. 21 CFR §1304 is records and inventories, not surveillance: complete, accurate, readily retrievable records. Physical security for practitioners is §1301.75, which requires controlled substances be stored in a “securely locked, substantially constructed cabinet.” Neither section requires a camera. Any vendor telling you DEA mandates video for your med room has not read either one.

What cameras and credentialed access do is document the access those records already assume. UniFi Access logs every entry to medication storage with credential and camera-linked timestamp, so when a count comes up short you can answer the question rather than open an investigation into your own staff with nothing to go on. UniFi Protect records to local NVR hardware regardless of internet status. That is a risk decision, and a good one for most practices handling Schedule II substances. It is not a mandate, and we will not sell it as one.

PCI DSS v4.0.1

For Practices Accepting Card Payments

Every practice running card payments at the front desk falls under PCI DSS v4.0.1. (Note the version: v4.0 was retired at the end of 2024, so anyone still quoting “PCI DSS 4.0” at you is a revision behind.)

To be accurate about it: PCI does not require network segmentation. What segmentation does is reduce your scope. Without it, your entire flat network is the cardholder data environment and every device on it is in scope, including the cameras and door controllers we install, which PCI explicitly counts as in-scope security systems. With it, the assessment stops at an isolated VLAN. Card terminals on one. Clinical systems on another. Guest Wi-Fi on a third.

The one place PCI does reach into physical security is Requirement 9.2.1.1: entry and exit points to sensitive areas (your server closet or back office, not the front counter, which PCI expressly excludes where only POS terminals sit) must be monitored by either cameras or physical access control, with the data retained at least three months. Either satisfies it. This is, as far as we can find, the only three-month retention rule that touches a medical practice, and it comes from the card brands rather than from HIPAA.

Cellular Failover for Uninterrupted Access and Alerts

UniFi Protect records continuously to local NVR hardware on your network regardless of internet status: that footage is captured and retained on infrastructure inside your practice, not dependent on a cloud connection. What an internet outage does compromise is everything that depends on a working connection: cloud-hosted EHR access, e-prescribing and PMP submission, point-of-sale and insurance claim adjudication, real-time alert delivery to the practice administrator, and the management plane for surveillance and access control. UniFi 5G Max provides automatic dual-SIM cellular failover: the moment your primary connection drops, the system fails over without manual intervention and your EHR access, e-prescribing, claim submission, and management capabilities stay online without interruption. For practices in rural service areas across Southwest Oklahoma and North Texas where wired internet reliability is inconsistent, 5G Max can also serve as the primary connection, the difference between treating today’s patients and rescheduling them.

Why It Matters

Why Local Infrastructure Matters for Practices Specifically

Cloud-based surveillance and access control systems present a uniquely poor fit for healthcare. Your operational data (who entered your medication room, what your cameras recorded in your treatment areas, who accessed your records storage) is stored on servers owned and operated by a third party, in jurisdictions you don’t control, accessible to parties beyond your practice under terms of service you accepted without legal review. For a practice operating under HIPAA (and, in Texas, under Chapter 181) where the privacy of every patient interaction is both a regulatory and ethical obligation, that architecture is exactly the wrong choice.

Every system Red River Integration deploys records and stores locally. Your footage stays on hardware you own, in your practice, accessible only by personnel you authorize. Your access logs stay on systems you control. No third party holds your operational records. When OCR, the Texas Attorney General, or a state board investigator requests footage, you produce it from your own storage on your own timeline.

Why This Is Different

What You Are Actually Choosing Between

Consumer / prosumer gear Cloud-subscription vendor Red River on UniFi
Where the footage lives A card in the camera The vendor's cloud Local NVR hardware you own, on site
If the internet drops Recording stops Recording stops Keeps recording; cellular failover keeps alerts flowing
Retention Whatever fits the card Whatever the plan tier allows Sized to your rule, documented for the inspector
Access audit trail None Partial, and theirs Every door, every credential, every timestamp, exportable
Who owns the equipment You They do, or you lease it You. Outright. No lock-in.
Ongoing cost None, until it fails A subscription that renews forever A support plan you can cancel; the system still works
When the inspector asks "Let me check the card" "I have to call the vendor" You produce it from your own storage, in minutes
Who We Build For

Built for Your Practice Type

  • Independent Primary Care, Specialty, and Dental Practices Practices with one to ten providers are too small for hospital IT and too large for consumer-grade equipment. We design infrastructure that fits the floor plan, segments the network properly, secures every restricted area, and produces the audit trail HIPAA and Texas Chapter 181 actually require, without the overhead of an enterprise IT department.
  • Veterinary Practices Schedule II–V handling under DEA recordkeeping, surgical suites, controlled medication storage, and high-volume client traffic create a unique infrastructure profile. We design surveillance and access control systems that satisfy DEA inspection expectations alongside Oklahoma and Texas state veterinary board standards.
  • Medspa, Dermatology, and Aesthetics Clinics Practices with on-site controlled substance handling, high-value inventory, and patient privacy expectations that exceed standard medical practice need infrastructure designed for the operation. We deliver it.
  • Outpatient Surgery Centers Higher stakes, smaller IT teams than hospitals, and a compliance burden that combines HIPAA, Texas HB 300, DEA, state surgical center licensing, and accrediting body requirements. We build systems engineered for the specific operating environment.

Every Installation Is Engineered for That Practice. Not Adapted From a Template.

We don’t offer a standard healthcare package. We assess your practice type, your facility layout, the state you operate in, your specific compliance obligations, and the technical safeguards your current infrastructure is or isn’t satisfying, and we engineer a system that meets every requirement, documents every event, and holds up under inspection. Built on the Ubiquiti UniFi ecosystem (enterprise infrastructure with a 20+ year track record, deployed in hospitals, universities, and critical care facilities worldwide) installed and configured by a team that understands why the phrase “HIPAA-compliant equipment” is meaningless. No product is HIPAA compliant. You are, or you are not. The Security Rule’’s duties run to your practice, and §164.306(b) explicitly leaves you flexibility in how you meet them. What infrastructure can do is make the decisions you made under 45 CFR Part 164 documented, enforceable, and evidenced, alongside the additional protections in Chapter 181 of the Texas Health and Safety Code. Anyone selling you a compliant camera is selling you a category error.

Built on Ubiquiti UniFi

The Same Platform Running Hospitals, Campuses, and Fortune 500 Sites

Not a consumer brand with a professional badge. Enterprise hardware with a two-decade track record, a single management console, and no mandatory cloud between you and your own footage.

Dream Machine

Dream Machine

Gateway, firewall, VLAN segmentation

UniFi Access Points

UniFi Access Points

Wi-Fi 7 coverage, no dead zones

UniFi Protect

UniFi Protect

AI detection, local recording

UniFi Access

UniFi Access

Doors, credentials, audit trail

UniFi Talk

UniFi Talk

One phone system, every site

Enterprise Switching

Enterprise Switching

PoE, managed, documented

One console. One vendor. You own all of it.

What You Get

Every Installation Ships With This

A labelled, documented rack

Not a hand-tied tangle in a closet. Organised, cooled, and built so the next person can work on it.

As-built network diagram

Yours to keep. VLANs, IPs, port assignments, and what is plugged into what.

A written retention configuration

What the rule requires, what we set, and how to prove it. The page you hand an inspector.

Credentials handed to you

Admin access to your own system, in writing. No vendor holding the keys.

Managed from day one

Monitoring, firmware, and health checks, so it still works in year three.

A named person who answers

You call the person who built it, not a ticket queue.

Service Area

Serving Southwest Oklahoma and North Texas

Red River Integration serves independent medical, dental, veterinary, and specialty practices across Southwest Oklahoma (including Lawton, Duncan, Altus, Chickasha, and the surrounding communities) and across North Texas, including Wichita Falls and the surrounding communities.

Common Questions

Questions We Get Asked

Do security cameras in a medical office fall under HIPAA?

If a camera can see protected health information, a chart at a workstation, a patient name on a sign-in sheet, a face in an exam room, then that footage is subject to the Security Rule's technical safeguards under 45 CFR §164.312. Most practices never consider this until an audit does.

Does a cloud camera vendor need to sign a Business Associate Agreement?

If their system stores footage that contains PHI, yes. Most consumer and prosumer cloud camera vendors will not sign one. Recording locally to hardware you own removes the question entirely, which is why we build it that way.

What does 45 CFR §164.312 actually require?

Five standards: access control, audit controls, integrity, transmission security, and authentication. The detail that matters, and that most vendors get wrong: only some specifications are required (unique user identification, emergency access procedures, audit controls). others are addressable, including automatic logoff and encryption. Addressable is not optional. You must assess it, implement it if reasonable and appropriate, or document why not and put an equivalent measure in place. So no, HIPAA does not flatly require encryption. It requires you to decide about encryption and be able to show your work. Also note §164.312 is technical safeguards only. Physical door access is §164.310(a).

Do you serve dental and veterinary practices too?

Yes. Dental, optometry, veterinary, and surgical practices across Lawton, Wichita Falls, Duncan, Altus, and the surrounding region.

Free Scoping Session

Ready to Talk About Your Practice?

Your patients trust you with their most sensitive information. Your infrastructure should be built to deserve that trust. Call us at (580) 289-8181 or fill out the form on our contact page. Consultations are confidential and there’s no obligation.

Pick a time below, or call or text (580) 289-8181. Consultations are confidential and there is no obligation.

Pick a time

Real openings from our calendar. 30 minutes, free, no obligation.

Prefer to write it out? Send us the details instead.