A new medical office brings together construction, carriers, EHR and clinical vendors, phones, security, furniture, workstations, cloud services, and staff training. Every dependency has a lead time, an owner, and a test that should occur before the first patient arrives.
The Office of the National Coordinator's SAFER System Management Guide recommends multidisciplinary participation in EHR system management and attention to hardware, software, interfaces, physical environments, configuration, validation, and maintenance. That same operating principle applies to the full office build: clinical, operational, vendor, facilities, and IT decisions must be coordinated.
1. Establish one plan and one owner
Create a shared project plan with dates, dependencies, decision owners, vendor contacts, approvals, and evidence. Include the landlord or general contractor, architect, low-voltage contractor, internet carrier, phone provider, EHR vendor, clinical equipment vendors, security or access-control vendors, furniture team, IT provider, and practice leadership.
Define who can approve changes that affect opening day. A missed carrier order or unsupported EHR workstation should not remain hidden in separate vendor email threads.
2. Map rooms and workflows before cabling
Use the floor plan to identify front-desk stations, clinical rooms, provider offices, nursing areas, labs, imaging, check-in devices, printers, scanners, phones, access points, cameras, building controls, network closets, and spare capacity. Record which workflows require wired connectivity, mobility, printing, scanning, voice, video, or vendor-managed devices.
Plan cable pathways, labeling, patch panels, rack space, cooling, electrical power, surge protection, and uninterruptible power before walls close. Wireless coverage does not eliminate the need for well-planned wired infrastructure.
3. Order internet early and define resilience
Carrier construction, permitting, and building access can outlast ordinary equipment lead times. Confirm the service address, demarcation point, handoff, static IP requirements, installation path, equipment responsibility, target delivery, and escalation contacts.
Decide what the practice will do if the primary circuit fails. A secondary connection may reduce disruption, but only if firewall failover, bandwidth, critical applications, voice, remote access, and operational procedures are tested.
4. Design the network around trust boundaries
Document firewall ownership, secure wireless, guest access, clinical or business devices, vendor-connected equipment, remote access, monitoring, configuration backup, and administrative control. Segment traffic when reasonable and appropriate to reduce unnecessary exposure between different device and user groups.
HHS Health Industry Cybersecurity Practices identifies network management, asset management, access management, endpoint protection, and connected medical-device security as related parts of healthcare cybersecurity. The office design should make those responsibilities maintainable after opening.
5. Obtain written EHR and application requirements
Ask each vendor for supported operating systems, browsers, memory, storage, display, scanners, printers, peripherals, network ports, bandwidth, remote-support methods, identity requirements, interface specifications, backup responsibility, and testing procedures. Confirm who owns data migration, templates, interfaces, reports, and post-go-live support.
A cloud EHR still depends on local identity, internet, workstations, browsers, printing, scanning, network performance, and vendor availability. Document the complete service chain.
6. Build identity before deploying devices
Establish organization-controlled domains and cloud tenants, administrative ownership, licensing, unique user accounts, MFA, role-based access, shared-account exceptions, service accounts, and onboarding approval. Separate daily-use accounts from privileged administration where appropriate.
Prepare staff start dates, roles, locations, devices, application access, phone assignments, training, and verification so opening morning is not the first login test.
7. Standardize supported devices
Select supported workstations, laptops, displays, docks, scanners, printers, label devices, phones, and accessories based on workflow and vendor requirements. Record ownership, location, warranty, configuration, encryption, patching, endpoint protection, local-data restrictions, and replacement strategy.
Where equipment vendors supply connected systems, document who owns the operating system, updates, security agents, remote access, network connection, data, and replacement decisions. Never assume the medical-equipment vendor manages the complete cybersecurity lifecycle.
8. Review cloud services and business associate relationships
Inventory services that create, receive, maintain, or transmit ePHI. HHS explains that a cloud provider maintaining ePHI on behalf of a regulated entity is generally a business associate even when the data is encrypted and the provider lacks the key. Review BAAs, configuration, access, availability, recovery, termination, and data-return terms with qualified advisers.
Do not treat a signed BAA as a configuration review. The practice still needs risk analysis, access decisions, monitoring, appropriate safeguards, and a clear understanding of shared responsibilities.
9. Prepare backup and downtime operations
Document what the EHR vendor backs up, what the practice must back up separately, how Microsoft 365 and local data are protected, how failures are monitored, and how representative restores are tested. Include network configurations, critical contacts, recovery credentials, and other information needed to rebuild services.
Create downtime procedures for patient identification, documentation, scheduling, prescriptions, orders, results, referrals, communication, and later reconciliation. Keep controlled copies accessible when normal systems are unavailable.
10. Validate complete workflows
Test from the user's perspective, not only from a technical dashboard. Validate logins, MFA, EHR access, printing, scanning, phones, fax workflows where still required, laboratory or imaging interfaces, patient communications, payment devices, internet failover, guest Wi-Fi separation, remote support, alerts, and backups.
Record defects with an owner, due date, retest, and evidence. Keep construction dust, unfinished power, missing furniture, and changing room assignments from invalidating the final technology test.
11. Staff opening day and stabilize
Schedule vendor and IT coverage for go-live, define a single issue channel, triage by patient-care and operational impact, and document workarounds. Avoid uncontrolled configuration changes under pressure. After opening, reconcile assets, remove temporary access, close project accounts, update diagrams, review incidents, and assign remaining improvements.
Medical office opening checklist
- One integrated project plan covers facilities, carriers, vendors, applications, and IT.
- Floor plans include cabling, wireless, power, closets, devices, and future capacity.
- Primary and backup connectivity are installed and tested.
- EHR, interface, device, and application requirements are confirmed in writing.
- Domains, cloud tenants, accounts, MFA, roles, and administrative ownership are ready.
- Workstations and connected devices are inventoried, protected, and supported.
- Cloud services, BAAs, backup responsibilities, and data-return terms are reviewed.
- Downtime, recovery, vendor escalation, and opening-day procedures are available.
- Complete clinical and business workflows pass documented tests.
Authoritative resources
- ONC: 2025 SAFER Guides
- ONC: SAFER System Management Guide
- HHS: Health Industry Cybersecurity Practices
- HHS: HIPAA and Cloud Computing
- HHS: Guidance on Risk Analysis
This guide is educational and does not provide legal, construction, clinical, or compliance advice. Requirements and responsibilities must be confirmed with qualified professionals and each vendor.