Hey John, I have previously worked in a medical research facility and Hospitals.
HIPAA also includes physical access. Who has access to the data, to the server itself and where is it stored. Records need to be behind 2 separately locked doors with, limited access of only who needs access to it. And, really, a log of who accesses it and when. Is your server a virtual machine or physical machine ? where are they and who all can access them ?
Oh, and it is HIPAA, not HIPPA
"Secure Email" Is a thing where the email never actually leaves their / your servers. Instead, the parties involved (maybe have a gmail or yahooot account) get a generic email and in the body it says something like : "click here to read your email from John Marx" - Then when they click on it they are taken to the clients (or your) email server where they have to : create an account (on that server) to actually read the email if it is the first time getting one from them, or log into their account they created before. But the body of the email itself , nor the subject line, is ever sent out. this helps to avoid accidental client data exposure.
I proposed this in this thread :
www.HawaiianHope.org - Providing technology services to non profit organizations, low income families, homeless shelters, clean and sober houses and prisoner reentry programs. Since 2015, We have refurbished over 11,000 Computers !