Does anyone know what the hipaa implications would be for an individual practice if the AC servers that housed patient info were breached? my understanding is that as long as the information is encrypted, which it would be in the cloud(presumably), then the breach reporting law does not apply.