🔧 Demo — built with Ebook Engine · Buy \$29

IT Guide

Practical IT guidance for apprentices and small teams

Chapter 3: Computer Equipment — Choosing, Buying, and Selling the Right Gear


Introduction

One of the most fundamental skills you'll develop as an IT apprentice is learning how to evaluate computer equipment — not just whether a machine works, but whether it's the right tool for the job at the right price. Whether you're setting up a workstation for a client on a tight budget, recommending an upgrade path for an aging office fleet, or helping someone get the most value out of their old Apple gear, your ability to make smart equipment decisions will set you apart.

This chapter covers two of the most common equipment ecosystems you'll encounter in the field: Apple Mac hardware and budget PC desktops. We'll walk through what makes each unique, how to stretch a dollar without sacrificing performance, and how to navigate the secondhand market like a pro. By the end of this chapter, you'll have a practical framework for making confident equipment recommendations — even when the budget is tight.


Section 1: Understanding Mac Equipment

What Makes Macs Different?

Apple's Mac lineup is a staple in creative industries, education, and increasingly in enterprise environments. As an IT professional, you will encounter Macs — so understanding their quirks before you're standing in front of one is essential.

The most important thing to understand about modern Macs is that Apple has moved away from user-upgradeable hardware. Unlike traditional PCs, where you can open the case and swap out components, most Mac models produced in recent years have their storage and memory soldered directly onto the motherboard. This means:

This is a critical point to communicate to clients and end users. If someone is buying a new Mac, they need to think carefully about their needs upfront, because upgrading later simply isn't an option.

RAM Configurations to Know

Most consumer Mac models come in two standard RAM configurations:

Pro Tip for Apprentices: When a client asks "which one should I get?", a good rule of thumb is: if they have to ask, they probably want the 16GB. It's always better to have headroom you don't use than to hit a wall you can't break through.


Section 2: Budget Mac Options — Getting More for Less

The Mac Mini: A Budget-Friendly Workhorse

When budget is a concern but a client is committed to the Mac ecosystem, the Mac Mini is almost always your first recommendation. Here's why it's such a reliable choice:

The key takeaway here is that shopping around pays off. A Mac Mini from 2014 might be more than sufficient for a client who just needs to browse the web, manage spreadsheets, and send emails — and it might cost less than $150 on the secondhand market.


Section 3: Budget PC Desktops — The Underdog Champion

Why Desktops Deserve More Respect

In a world obsessed with sleek laptops and tablets, the humble desktop PC is often overlooked — but in IT, we know better. Budget desktops are one of the most cost-effective and flexible tools in your arsenal, and here's why:

Breathing New Life Into Old Machines

One of the most satisfying skills in IT is taking an aging machine and transforming it into something genuinely powerful. This is where understanding component upgrades becomes incredibly valuable.

Consider this real-world scenario: You find an old desktop on clearance for $60. It runs slowly, the storage is nearly full, and it struggles with modern software. On the surface, it looks like junk. But with a few targeted upgrades, that same machine could become a powerhouse:

The Big Picture: This is the kind of creative problem-solving that makes a great IT professional. You're not just fixing computers — you're maximizing value and finding solutions that fit the client's actual needs and budget.

Where to Find Budget Desktops


Section 4: Buying and Selling Apple Gear

Knowing What Apple Equipment Is Worth

Whether you're helping a client sell their old MacBook before upgrading, or you're sourcing used equipment for a deployment, knowing the market value of Apple gear is an essential skill. Apple products hold their value better than almost any other consumer electronics brand, which cuts both ways — they're more expensive to buy used, but also more rewarding to sell.

Your go-to tool for estimating the value of used Apple equipment is:

🔗 mac2sell.net — Enter the model and specs of any Apple device and get an instant market value estimate. Use this before buying or selling to make sure you're getting a fair deal.

Where to Buy Used Apple Equipment

Platform
Notes
Specializes exclusively in used and refurbished Apple products. Reliable and well-regarded in the Apple community.
BackMarket
Broad refurbished electronics marketplace with quality tiers and buyer protections.
eBay
Wide selection and competitive pricing, but requires more due diligence. Check seller ratings and return policies carefully.
Discount Electronics
Texas-based independent shop with a solid reputation for honest pricing on refurbished gear.

Where to Sell Used Apple Equipment

When it's time to move old Apple gear, you have several options depending on how quickly you need the money:

Selling Strategy Tip: If a client has time and wants maximum value, listing on eBay or BackMarket as a seller will typically yield more money than an instant buyback service. If they need cash quickly or don't want the hassle of managing a listing, BuyBackWorld or Gazelle are the right call. Matching the solution to the client's actual situation — not just the "best" option in theory — is a hallmark of great IT support.


Section 5: Terminology & Jargon Glossary

As you work through this chapter, you'll encounter several technical terms that are important to understand. Here's a clear breakdown of each:


RAM (Random Access Memory)

The short-term memory of a computer. RAM temporarily holds the data that the processor is actively using. More RAM means the computer can handle more tasks at once without slowing down. Unlike storage, RAM is volatile — its contents are erased when the computer is turned off.


SSD (Solid State Drive)

A type of storage device that uses flash memory chips instead of spinning magnetic disks. SSDs are significantly faster, quieter, more durable, and more energy-efficient than traditional HDDs (Hard Disk Drives). Upgrading from an HDD to an SSD is one of the most impactful performance improvements you can make to an older machine.


HDD (Hard Disk Drive)

The traditional form of computer storage, which uses spinning magnetic platters to read and write data. HDDs are slower than SSDs but are often cheaper per gigabyte, making them useful for bulk storage.


GPU (Graphics Processing Unit)

A specialized processor originally designed to handle the complex calculations required for rendering images and video. Modern GPUs are also used for AI and machine learning workloads, scientific computing, and cryptocurrency mining, because they can perform many calculations simultaneously.


Motherboard

The main circuit board inside a computer. It connects and allows communication between all other components — the CPU, RAM, storage, GPU, and more. When components are described as "soldered to the motherboard," it means they are permanently attached and cannot be removed or replaced.


Soldered

In the context of computer hardware, soldering refers to permanently attaching a component (like RAM or storage) directly to the motherboard using molten metal. Soldered components cannot be upgraded or replaced without specialized equipment, which is why this is a significant limitation in modern Macs.


Refurbished

A device that has been previously used, returned, or repaired, and then inspected, cleaned, and restored to working condition before being resold. Reputable refurbishers test components and often provide warranties. Refurbished equipment is a cornerstone of budget IT procurement.


RTX 3060

A mid-range consumer graphics card manufactured by NVIDIA. It represents a strong balance of performance and price, and is capable of handling demanding tasks including gaming, video editing, and running local AI models.


AI Server (Local)

A computer configured to run artificial intelligence models and processes locally — meaning on the machine itself — rather than sending data to a cloud service. Running a local AI server gives users privacy, eliminates subscription costs, and allows for customization. A capable GPU is typically required.


Buyback Service

A company or platform that purchases used electronics directly from consumers at a set price. The process is fast and simple, but typically yields less money than selling directly to another buyer. Examples include BuyBackWorld and Gazelle.


Mac Mini

A compact, affordable desktop computer made by Apple. It does not include a monitor, keyboard, or mouse (it is "headless"), which keeps the price lower. It has been in production since 2006, making it one of the most accessible entry points into the Mac ecosystem.


Key Takeaways


Next Chapter: Peripherals and Accessories — Building a Complete Workstation on Any Budget

Content: Fighting the Android Lockdown

In August 2025, Google announced↗ that as of September 2026, it will no longer be possible to develop apps for the Android platform without first registering centrally with Google. This registration will involve:

The promise of Android - and a marketing advantage it has used to distinguish itself against the iPhone - has always been that it is “open”. But Google clearly feels that they have enough of a lock on the Android ecosystem, along with sufficient regulatory capture, that they can now jettison this principle with prejudice and impunity.

How you can help

Developers: Resist and refuse

If you are an app developer, do not sign up for the early access program, perform identity verification, or accept an invitation to the Android Developer Console. Respond (politely) to any invitation with a list of your concerns and objections.

Discourage fellow app developers and organizations from signing up to the program. Use community forums, social media, and blog posts to spread the message. Include the FreeDroidWarn library↗in your code to inform your app users. If you manage a website, consider adding the countdown banner to the top of your page.

Everyone: Make your voice heard

Web Site Owners: Show your support

Add the countdown banner to your sitewith a single<script>tag — no dependencies, 20 built-in localizations, fully customizable.

Consumers: Contact national regulators

Regulators worldwide are genuinely concerned about monopolies and the centralization of power in the tech sector, and want to hear directly from individuals who are affected and concerned. When contacting regulators directly, you should bepoliteandspecificabout the harm you believe these policies will cause, both to consumers and to competition.

Complaints are especially impactful when they are authored by a citizen of that country or region, and when the language of the email is written in one of the official languages of the region's governing body. Request awritten acknowledgementof the complaint, and consider forwarding any responses you receive tovictory@keepandroidopen.orgso that we might highlight and reference them.

Main References

Other References

Editorials and Blogs

Press Reactions

Video Responses

Discussions

Chapter 4: Introduction to Linux — The Operating System Powering the Modern World


Introduction

When most people think of computers, they think of Windows or maybe macOS. But there is a third operating system quietly running beneath the surface of much of the modern world — and as an IT professional, you need to know it exists. That operating system is Linux.

From the servers that host your favorite websites, to the phone in your pocket, to the tools used by cybersecurity professionals to test and defend networks — Linux is everywhere. You may never see its desktop wallpaper, but you will absolutely encounter it in your IT career. This chapter is not going to make you a Linux expert overnight. That is not the goal. The goal is simple: by the end of this chapter, you should know what Linux is, where it came from, why businesses and tech professionals rely on it, and where you are likely to run into it in the real world. Think of this as your first introduction to a very important colleague you will be working alongside for the rest of your career.


Section 1: What Is Linux and Where Did It Come From?

A Brief History

To understand Linux, we need to take a quick trip back to the 1970s. At that time, computers were enormous, expensive machines called mainframes — room-sized systems that universities, governments, and large corporations used for serious computing work. These machines ran an operating system called Unix, which was powerful, stable, and designed to handle multiple users and tasks at the same time.

Unix was groundbreaking, but it was expensive and tightly controlled by the companies that owned it. Fast forward to 1991, when a Finnish computer science student named Linus Torvalds decided to build his own Unix-inspired operating system from scratch — and then, crucially, give it away for free. He called it Linux.

What made Linux revolutionary was not just that it was free. It was open-source, meaning the underlying code — the actual instructions that make the operating system work — was made publicly available for anyone to read, modify, and improve. Developers all over the world began contributing to it, and over the decades, Linux grew from a hobbyist project into one of the most powerful and widely used operating systems on the planet.

Think of it this way: If Windows is a finished product sold in a box, Linux is more like a recipe that anyone can read, cook from, and improve upon. The result is an operating system that is constantly being refined by thousands of experts worldwide.


Section 2: Why Do Businesses and Tech Professionals Use Linux?

You might be wondering — if Windows works fine, why bother with Linux at all? It is a fair question, and the answer comes down to a few key advantages that make Linux the preferred choice in professional and high-tech environments.

In short, Linux is the backbone of the internet and modern enterprise computing. Knowing it exists — and having a basic familiarity with it — immediately sets you apart as a more well-rounded IT professional.


Section 3: Where You Will Encounter Linux in the Real World

Linux does not always announce itself. It often runs quietly in the background, doing its job without a flashy interface. Here are some of the most common places you will encounter it, both in everyday life and in professional IT settings.

Everyday Encounters with Linux

Linux in Business and Enterprise


Section 4: Advanced Linux Concepts — A Brief Look Ahead

You do not need to master these topics right now, but as an IT apprentice, you should be aware that they exist. These are areas where Linux knowledge becomes especially powerful, and they represent natural next steps as your skills grow.

Virtual Machines (VMs)

A Virtual Machine is essentially a computer running inside another computer. Using software, you can create a simulated environment that behaves exactly like a separate physical machine — complete with its own operating system, files, and settings. Linux is very commonly used as the operating system inside these virtual machines, especially in enterprise and development environments. VMs are great for testing software, learning new systems, or running multiple operating systems on one piece of hardware without conflict.

Docker and Containerization

Docker is a technology that takes the concept of virtual machines a step further by creating lightweight, portable packages called containers. Each container holds an application and everything it needs to run, isolated from the rest of the system. Docker runs on Linux and is one of the most important technologies in modern software development and IT operations. If you find yourself moving into more advanced IT roles — particularly in DevOps, cloud engineering, or systems administration — Docker will be one of the first major tools you encounter. For now, just know it exists and that it is built on Linux principles.

Kali Linux — Linux for Cybersecurity

Kali Linux is a specialized version, or distribution, of Linux that is purpose-built for cybersecurity professionals. It comes pre-loaded with hundreds of tools used for penetration testing — the practice of legally and ethically attempting to hack into systems in order to find and fix vulnerabilities before real attackers can exploit them. When you see cybersecurity professionals in documentaries, news segments, or training videos sitting in front of a dark terminal screen running complex commands, there is a very good chance they are using Kali Linux. It is the industry-standard operating system for ethical hacking and security research.

Important Note: Kali Linux is a professional tool designed for authorized security testing. It is not something to experiment with carelessly. As you grow in your IT career and potentially move toward cybersecurity, Kali Linux will become a topic worth studying in depth.


Terminology & Jargon Glossary

The following terms were introduced in this chapter. Make sure you are comfortable explaining each one in your own words.

Term
Definition
Linux
A free, open-source operating system originally created by Linus Torvalds in 1991, inspired by the older Unix system. It is widely used in servers, mobile devices, and professional IT environments.
Open-Source
Software whose underlying source code is made freely available to the public. Anyone can read it, modify it, and distribute their own version.
Unix
A powerful operating system developed in the 1970s that served as the inspiration for Linux. It was designed for multi-user, multi-tasking environments on mainframe computers.
Mainframe
A large, powerful computer used primarily in the 1960s–1980s by governments, universities, and corporations for heavy-duty computing tasks.
Kernel
The core component of an operating system. It manages communication between software and hardware. When we say Android is "built on Linux," we mean it uses the Linux kernel as its foundation.
Distribution (Distro)
A version of Linux packaged with specific tools, interfaces, and software for a particular purpose or audience. Examples include Ubuntu, Kali Linux, and ChromeOS.
Android
Google's mobile operating system, used on the majority of smartphones worldwide. It is built on top of the Linux kernel.
ChromeOS
Google's operating system for Chromebook laptops, which is based on Linux.
Bootable USB Drive
A USB flash drive configured to run an operating system directly, without installing anything on the host computer. Commonly used by IT technicians for troubleshooting and system recovery.
Virtual Machine (VM)
A software-based simulation of a physical computer. It runs its own operating system and applications inside a host machine, completely isolated from the host environment.
Docker
A platform that uses Linux-based technology to create and run containers — lightweight, portable packages that include an application and all of its dependencies. Widely used in modern software development and IT operations.
Container
A lightweight, self-contained package that holds an application and everything it needs to run, isolated from the rest of the system. Think of it as a very efficient, stripped-down virtual machine.
Kali Linux
A specialized Linux distribution designed for cybersecurity professionals. It comes pre-installed with tools used for penetration testing and ethical hacking.
Penetration Testing (Pen Testing)
The authorized, ethical practice of attempting to hack into a system or network in order to identify security vulnerabilities before malicious attackers can find them.
DevOps
A professional discipline that combines software development and IT operations, focused on automating and streamlining the process of building, testing, and deploying software. Linux and Docker are core tools in DevOps work.
Server
A computer or system that provides resources, data, or services to other computers over a network. Most servers in business environments run Linux.

Key Takeaways


End of Chapter 4 — Up Next: Navigating the Linux Command Line

Chapter 5: Intro to Security - Thinking Like a Protector


Introduction

When most people hear the word "security" in an IT context, their minds immediately jump to images of hooded hackers furiously typing code in a dark room. Hollywood has done a fantastic job of making cybersecurity look like a niche, almost mystical skill reserved for a select few geniuses. The reality, however, is far more grounded — and far more interesting.

Security, at its core, is not just about computers. It is about protecting everything — people, information, systems, and processes — from threats that come in all shapes and sizes. The "cyber" part is simply the modern battlefield where many of those threats now live. As an IT apprentice, understanding security from this broader perspective will set you apart from the very beginning of your career. You will not just be someone who knows how to run a scan or patch a vulnerability. You will be someone who thinks like a protector.

This chapter will introduce you to the foundational mindset, concepts, and vocabulary you need to begin your journey into IT security. We will explore where security thinking comes from, how computers communicate with each other, and why the skills you are building now are the same ones used by professionals guarding some of the most critical systems in the world.


Section 1: Why Security Is More Than "Hacking"

The Misconception

One of the biggest reasons newcomers feel intimidated by cybersecurity is the assumption that you need to be an expert hacker before you can even get started. This misconception is also one of the biggest reasons many talented people never enter the field at all. Let's clear this up right now.

Cybersecurity is a discipline that evolved from two very traditional, very human industries: the military and the physical security industry. Long before computers existed, people were developing strategies to protect valuable assets, guard sensitive information, and anticipate the moves of adversaries. The digital world simply gave those same professionals a new environment to work in.

Think about it this way: if your company needed to transport one million dollars in cash from one bank to another, what would that operation look like?

Now replace "cash" with "sensitive customer data" or "a company's financial records," and you have described a cybersecurity operation. The tools are different, but the thinking is identical. Security professionals ask the same questions their predecessors in the physical security world always have: What are we protecting? Who might want it? How could they get to it? How do we stop them?

The Red Team and the Blue Team

In professional security environments, teams are often divided into two roles that mirror the classic dynamic of attacker and defender:

Here is the critical thing to understand about this dynamic: the villain, or attacker, will stop at nothing. A real-world threat actor is not playing by rules. They are motivated — whether by money, ideology, or mischief — and they are persistent. This is why the Blue Team must always be vigilant, always learning, and always improving. You cannot defend what you do not understand, and you cannot understand a threat you have never studied.

This is also why many security professionals spend time learning both sides. Understanding how an attacker thinks makes you a dramatically better defender.

The Influence of Gaming and CTF Culture

Interestingly, the security field has also been heavily shaped by gaming culture. Many of the brightest minds in cybersecurity got their start not in a classroom, but in competitive security challenges called Capture the Flag (CTF) competitions.

In a CTF, participants are given a series of technical challenges — puzzles, vulnerabilities to exploit, codes to crack — and the goal is to find hidden "flags" (usually a specific string of text) that prove you have successfully completed the challenge. The name is borrowed directly from the classic playground game: there are real flags to find and protect, and if the wrong person captures yours, it is game over.

CTF competitions are a fantastic way to build real skills in a safe, legal environment, and many employers in the security field actively look for CTF experience on a résumé. If you enjoy problem-solving and have a competitive streak, this is a world worth exploring.


Section 2: The Security Mindset

How Military Thinking Shaped IT Security

The military has always operated on a principle that translates perfectly into IT security: be ready for any threat, and always be watching. Military planners do not wait for an enemy to attack before they start thinking about defense. They conduct threat assessments, monitor their perimeter constantly, and run drills to ensure their team is prepared for scenarios they hope will never happen.

IT security professionals operate the same way. A strong security posture is not reactive — it is proactive. This means:

Physical Security: The Foundation You Cannot Ignore

Here is something that surprises many new IT apprentices: a significant portion of real-world security work has nothing to do with software or code. Physical security is the foundation upon which all digital security is built, and it is often the most overlooked layer.

Consider this scenario, famously illustrated by the webcomic xkcd: you could build the most sophisticated, unbreakable encryption system in the world to protect a database of passwords. But if an attacker can simply walk into your server room, unplug the hard drive, and walk out — your encryption means nothing.

Physical security in IT includes:

The lesson here is powerful and worth repeating: security is not a single tool or a single layer. It is a complete system, and every layer matters.


Section 3: How Computers Communicate — Servers and Clients

The Restaurant Analogy

Before you can protect a system, you need to understand how that system works. One of the most fundamental concepts in networking and IT security is the server/client relationship. Let's break it down using an analogy that everyone can relate to: a restaurant.

Imagine you walk into a restaurant and sit down at a table. You are the customer — you have a need (you are hungry), and you are going to make a request. A waiter comes to your table, takes your order, goes back to the kitchen, and returns with exactly what you asked for. The kitchen prepares the food; the waiter delivers it.

In this analogy:

This is exactly how computers communicate across a network.

Servers and Clients in the Real World

Here is something important to understand: any computer can be a server, a client, or both at the same time. The terms describe roles, not specific types of hardware. Your personal laptop is acting as a client right now if you are browsing the internet. But if you installed server software on that same laptop and started hosting a website from it, it would also be acting as a server.

Let's look at some real-world examples:

Why This Matters for Security

Understanding the server/client model is essential for security because it defines the attack surface. Every point of communication between a client and a server is a potential vulnerability. Security professionals need to ask:

When you understand how systems communicate, you begin to see where they can be exploited — and more importantly, how to protect them.


Section 4: A Note on Memory — RAM and VRAM

While this chapter focuses primarily on security concepts, it is worth briefly touching on two hardware terms that come up frequently in IT environments, particularly when discussing the kinds of powerful systems that security professionals often work with or protect.

Understanding the hardware that underlies the systems you are securing is part of being a well-rounded IT professional. Security is not just about software — it is about understanding the complete picture.


Terminology & Jargon Glossary

Here are the key terms introduced in this chapter, defined clearly for your reference:

Term
Definition
Cybersecurity
The practice of protecting computers, networks, programs, and data from digital attacks, damage, or unauthorized access.
Red Team
A group of security professionals who simulate real-world attacks on an organization's systems to identify vulnerabilities. Also known as ethical hackers or penetration testers.
Blue Team
A group of security professionals responsible for defending an organization's systems, monitoring for threats, and responding to incidents.
CTF (Capture the Flag)
A competitive cybersecurity challenge where participants solve security puzzles to find hidden "flags," building real-world skills in a safe, legal environment.
Server
A computer or program that provides resources, data, or services to other computers (clients) upon request.
Client
A computer or program that requests resources or services from a server.
Physical Security
The protection of hardware, personnel, and physical spaces from unauthorized access, theft, or damage.
Social Engineering
A manipulation technique used by attackers to trick people into revealing confidential information or granting unauthorized access, rather than exploiting technical vulnerabilities.
Least Privilege
A security principle stating that every user and system should have access to only the minimum resources necessary to perform their function.
Attack Surface
The total number of points in a system where an unauthorized user could attempt to enter or extract data.
Denial of Service (DoS)
An attack that attempts to overwhelm a server with requests, making it unavailable to legitimate users.
RAM (Random Access Memory)
A computer's short-term, active working memory that holds data currently being used by the processor.
VRAM (Virtual Memory)
An extension of RAM that uses hard drive space as overflow memory, used in high-demand computing environments.
Penetration Testing
An authorized, simulated cyberattack on a system performed to evaluate its security and identify weaknesses before real attackers can exploit them.
Threat Actor
Any individual or group that poses a threat to the security of a system or organization.

Key Takeaways


In the next chapter, we will begin exploring the specific tools and techniques used to monitor, test, and defend IT systems — building directly on the foundational mindset you have developed here.

Intro to Healthcare

Healthcare is a regulated industry with strict guidelines and procedures. This document explains the basics of the healthcare industry, the mindset of healthcare professionals, and

What makes healthcare unique?

Data security in healthcare is essential for protecting patients' sensitive information and avoiding costly penalties due to data breaches.

A Business Associate (BA) is a business that works with a healthcare provider and their protected health information (PHI). The BA is equally liable for the security of the PHI as the healthcare provider.

Protected Health Information (PHI)

Business Associate Agreement (BAA)

A Business Associate (BA) is a business that works with a healthcare provider and their protected health information (PHI). The BA is equally liable for the security of the PHI as the healthcare provider.

A Business Associate Agreement (BAA) is a contract between a healthcare provider and any business that handles their PHI.

Matomo Analytics & HIPAA

The Health Insurance Portability and Accountability Act (HIPAA) is a US regulation developed to protect the privacy and security of certain health information. Matomo Analytics is used by many companies in the healthcare industry, building medical and health-related applications. Matomo can be configured in a way that it is compliant with HIPAA.

When should I care about HIPAA?

When you are a Covered Entity or a Business Associate as defined in HIPAA, and you handle any Protected Health Information (PHI) using Matomo, you must comply with HIPAA rules that govern privacy, security, breach notification, and enforcement, unless that particular processing is exempt.

What is Protected Health Information (PHI)

Not all personal information or data is PHI, which is defined as any health-related data that can be linked to the individual via identifiers such as name, geolocation data, elements of birth date, contact details, device ID, account number, IP address, medical record number, or web URL.

In the context of Matomo, PHI may be, for example, User ID, custom dimensions possibly storing health data, or URLs, page titles, or session recordings that may record personal data.

What is Not Considered PHI?

Steps For HIPAA Compliance

To comply with HIPAA, you must complete at least the following steps:

  1. Develop and maintain a HIPAA-compliant Privacy Rule and Breach Notification Policies and Procedures.
  2. Appoint a Privacy Officer and a Security Officer.
  3. Document how you will comply with patient rights
  4. Conduct risk analysis and establish a risk management plan.
  5. Train your personnel.
  6. Self-Hosting on HIPAA-Compliant Infrastructure
    • Download and install Matomo On-Premise on infrastructure and servers you own or lease from a HIPAA-compliant webhosting company. (The official Matomo Cloud service is not HIPAA compliant.)
    • Partner with web hosting companies that are HIPAA compliant and have processes for protecting PHI and your Matomo.
  7. Business Associate Agreement
    • Sign a business associate contract (BAA) with any third-parties that have access to the PHI.
    • You won’t need to sign the BAA document with us at Matomo since we don’t host your data and we cannot access it.
  8. Security
    • Ensure that you implement safeguards required by HIPAA Security Rule: develop, document and implement security policies and procedures covering administrative safeguards (policies and procedures, risk analysis and management), physical safeguards and technical safeguards.
    • Encrypt your Matomo database with data encryption at rest in MySQL/MariaDB.
    • Establish processes to delete, backup and restore encrypted PHI and Matomo database as needed.
    • Setup SSL certificate for all your websites and apps.
    • Setup SSL certificate for your Matomo server
    • Ideally, implement a secure SSL Database connection between Matomo web server and your MySQL/MariaDB database server.
    • Use Activity Log to keep track of changes done to Matomo entities.
    • Send Matomo emails (some which may contain PHI) through encrypted email servers.
    • Ensure that PHI and Matomo interface and API is only accessible to authorised individuals.

If you have any question or if you need help with your Matomo On-Premise setup contact us, we’re always happy to help.

Office Automations

These are the workflows we use for our business processes.

RSS Feed News Processing

SOP - Removing Customers from Public Spam Lists

Purpose:

Enable the IT team to help customers remove their email addresses from public spam lists.

For a full tutorial on using the OffList tool, go to: .


1. Payment Options


2. Process Overview

  1. No signup is required to start the removal process.
  2. Enter the customer’s email on the Offlist.me page.
  3. You will get an email to copy.

3. Important Guidelines


4. Tracking


5. Notes for IT Apprentices


Securing Your Workstation

Steps

  1. Choose a secure internet browser
    1. Brave (like Chrome but private - follow this guide for adding security measures)
    2. Librewolf (Firefox with extra privacy)
    3. Mullvad Browser (more suited for technical team members - it comes with "extreme privacy" measures out of the box) We highly reccommend you start Brave, then try Librewolf if you dislike it. Mullvad is more suited for high-stakes technical work (and if you don't what we're getting at here, it isn't for you). We discourage using DuckDuckGo. They are a good company, but for our security needs, we can get stronger protection using one of the browsers specified above.
  2. Install internet security plugins and extensions (recommended)
    1. Ghostery to block ads & trackers (or alternatively, PrivacyBadger)
  3. Install antivirus software
    1. We use BitDefender
  4. Join our VPN
    1. Coming soon - ProtonVPn
  5. Set up your Bitwarden account (for password management)

Checklist

AI

Big Tech companies are spying on every conversation you have with your AI. ChatGPT, Claude, Gemini, all of these companies have the ability to see your entire chat history. They can use that information not only to "train" their models, but to take competitive actions against your business, from stealing your business idea to even reporting you to the police if they think you've said something they don't like.

That's why we have our own private AI chat servers. Instead of going through ChatGPT, we prefer you to use our AI models. That way all company information stays private and doesn't get exposed to Big Tech companies.

@todo - add AI info here.

Our AI servers (WIP)

We recommend downloading model files from Hugging Face since it provides several features to verify that the download is genuine and safe.

Also see:

For IT Team Members

Go to https://privacytests.org/ to see where different browsers rank for privacy. These rankings change over time, so browse through this page and notifying team members if any info in this document seems out of date.

Tip: use AI to review the rankings and break down what info you should be paying attention to. Ask it to teach you how to review for yourself in the future.

Verifying AI Models

Before downloading a new AI model, always make sure it is authentic and free from viruses.

To check the authenticity and safety of the model, look for:

A downloaded model is generally safe if it satisfies all the above checks.