What Healthcare Organizations Get Wrong About HIPAA Security (And How to Fix It)

Every year, the U.S. Department of Health and Human Services publishes a “wall of shame” listing healthcare data breaches affecting 500 or more individuals. In 2025 alone, hundreds of organizations appeared on that list, exposing tens of millions of patient records. The frustrating part? Many of those breaches were entirely preventable. They didn’t result from sophisticated nation-state attacks or zero-day exploits. They happened because of misconfigured servers, unpatched software, lost laptops, and employees clicking on phishing emails.

For healthcare organizations across the Long Island, New York City, Connecticut, and New Jersey region, HIPAA compliance isn’t just a regulatory checkbox. It’s a living, breathing security program that requires constant attention. And too many organizations treat it like a one-time project instead of an ongoing commitment.

The Compliance vs. Security Trap

Here’s where a lot of healthcare providers stumble right out of the gate: they confuse compliance with security. These two concepts overlap, but they aren’t the same thing. An organization can check every box on a HIPAA audit checklist and still be vulnerable to a breach. Compliance represents a minimum standard. Security is the broader goal.

HIPAA’s Security Rule requires administrative, physical, and technical safeguards to protect electronic protected health information (ePHI). That covers everything from access controls and audit logs to workstation security and transmission encryption. But the rule was written to be flexible, which means organizations have to make judgment calls about what’s “reasonable and appropriate” for their size and complexity. Many smaller practices interpret that flexibility as permission to do the bare minimum.

That’s a mistake. Threat actors don’t care whether an organization has 10 employees or 10,000. Healthcare data is worth more on the black market than credit card numbers because it contains everything needed for identity theft, insurance fraud, and more. A small medical practice in Nassau County faces many of the same threats as a major hospital system in Manhattan.

Risk Assessments That Actually Mean Something

The HIPAA Security Rule explicitly requires organizations to conduct a thorough risk assessment. This is arguably the single most important compliance activity, and it’s the one that gets shortchanged most often. Too many organizations treat it as a paperwork exercise, filling out a template once and filing it away.

A meaningful risk assessment identifies where ePHI lives, how it moves through the organization, who has access to it, and what could go wrong at every step. It should examine the technical infrastructure, yes, but also the human element. Are employees trained to recognize phishing attempts? Do contractors and vendors have appropriate access limitations? What happens when a staff member leaves the organization?

Security professionals recommend conducting risk assessments at least annually, and also whenever there’s a significant change to the IT environment. Moving to a new cloud platform, onboarding a new electronic health records system, or opening a satellite office all warrant a fresh look at the risk landscape.

Common Gaps That Assessments Reveal

Organizations that take risk assessments seriously tend to uncover the same issues over and over. Encryption gaps are near the top of the list. HIPAA doesn’t technically mandate encryption in every scenario, but the regulation requires organizations to document why they chose not to encrypt if they skip it. Given that encryption is widely available and affordable today, regulators have little patience for organizations that leave ePHI unencrypted on laptops, portable drives, or email systems.

Access control problems are another frequent finding. The principle of least privilege says that employees should only have access to the data they need for their specific job functions. In practice, many organizations grant broad access by default because it’s easier to manage. A billing clerk doesn’t need access to clinical notes, and a nurse doesn’t need access to financial records. Tightening these controls reduces both the risk of insider threats and the blast radius if an account gets compromised.

The Vendor Problem Nobody Wants to Talk About

Third-party vendors represent one of the biggest and most underappreciated risks in healthcare IT. Under HIPAA, any business associate that handles ePHI on behalf of a covered entity must sign a Business Associate Agreement and maintain their own compliance. But signing a BAA doesn’t magically make a vendor secure.

Healthcare organizations need to vet their vendors carefully and revisit those assessments periodically. That cloud storage provider, that IT support company, that billing service, that appointment scheduling platform? Each one is a potential entry point for attackers. Some of the largest healthcare breaches in recent years originated not with the healthcare organization itself but with a third-party vendor.

Many IT security consultants now recommend maintaining a formal vendor risk management program. This means cataloging every vendor that touches ePHI, evaluating their security posture, and monitoring for changes. It’s not a small undertaking, but the alternative is trusting that every link in the chain is doing the right thing without verification.

Training Is Not a One-and-Done Activity

HIPAA requires workforce training on security policies and procedures. Most organizations check this box with an annual training session, often a dry slide deck that employees click through as fast as possible. That approach doesn’t work. Research consistently shows that people forget the majority of training content within weeks if it isn’t reinforced.

Effective security awareness programs use a mix of approaches. Short, frequent reminders work better than long annual sessions. Simulated phishing campaigns help employees practice identifying threats in a safe environment. Quick huddle topics during staff meetings keep security top of mind without eating up hours of productivity.

The human element is involved in the vast majority of data breaches. An employee who can spot a phishing email is worth more than a million dollars of security software. Organizations that invest in genuine, ongoing security culture see measurably better outcomes than those that treat training as a compliance formality.

Incident Response: Planning for the Inevitable

No security program is perfect. Breaches happen even to well-prepared organizations. What separates the organizations that recover quickly from those that face catastrophic consequences is whether they had an incident response plan in place before something went wrong.

HIPAA requires organizations to have policies for responding to security incidents. A solid incident response plan spells out exactly who does what when a potential breach is detected. It identifies the response team, establishes communication protocols, defines escalation procedures, and outlines the steps for containment, investigation, and recovery. It also addresses HIPAA’s breach notification requirements, which mandate notifying affected individuals within 60 days and reporting to HHS.

The plan needs to be tested, too. Tabletop exercises, where the response team walks through a hypothetical scenario, reveal gaps and confusion before a real incident puts the organization under pressure. Many healthcare organizations in the tri-state area have started conducting these exercises quarterly, recognizing that an untested plan is barely better than no plan at all.

Documentation Is Your Best Defense

If there’s one piece of advice that security and compliance professionals repeat more than any other, it’s this: document everything. HIPAA regulators want to see evidence that an organization is taking reasonable steps to protect patient data. That evidence comes in the form of written policies, training records, risk assessment reports, audit logs, and incident response documentation.

When OCR (the Office for Civil Rights, which enforces HIPAA) investigates a breach, the first thing they ask for is documentation. Organizations that can demonstrate a good-faith effort to comply, even if the breach still occurred, face significantly lower penalties than those that can’t produce any evidence of a security program.

Getting It Right Takes Commitment

HIPAA compliance and healthcare IT security aren’t problems that can be solved once and forgotten. The threat landscape shifts constantly. New vulnerabilities emerge. Staff turn over. Technology changes. Regulations get updated. An organization that was fully compliant two years ago may have significant gaps today if it hasn’t been actively maintaining its program.

For healthcare providers, particularly small and mid-sized practices that don’t have dedicated security teams, the challenge is real. But the resources available have never been better. From NIST’s cybersecurity framework to HHS’s own guidance documents for small healthcare organizations, there’s no shortage of practical, accessible information on building a strong security program. The key is treating HIPAA not as a burden to endure but as a framework for genuinely protecting the patients who trust these organizations with their most sensitive information.