What Healthcare Organizations Get Wrong About HIPAA and IT Security

A single stolen laptop. An unencrypted email. A former employee whose system access was never revoked. These are the kinds of everyday oversights that lead to HIPAA violations, and they happen far more often than most healthcare organizations want to admit. The U.S. Department of Health and Human Services logged over 700 major healthcare data breaches in 2024 alone, affecting tens of millions of patient records. The scary part? Many of those incidents were entirely preventable with the right IT security measures in place.

For healthcare providers, insurers, and their business associates across the Long Island, NYC, Connecticut, and New Jersey region, HIPAA compliance isn’t just a regulatory checkbox. It’s an ongoing operational responsibility that touches every corner of an organization’s technology infrastructure. And getting it wrong carries real consequences, from six-figure fines to reputational damage that can take years to recover from.

HIPAA’s Security Rule Is More Technical Than Most People Think

Many healthcare professionals have a solid grasp of HIPAA’s Privacy Rule, which governs how protected health information (PHI) can be used and shared. But the Security Rule is where IT teams earn their keep. It specifically addresses electronic PHI (ePHI) and requires administrative, physical, and technical safeguards to protect it.

The technical safeguards alone include requirements for access controls, audit controls, integrity controls, and transmission security. That means healthcare organizations need to think carefully about who can access what data, how that access is logged, how data integrity is verified, and how information is protected when it moves across networks. Most small and mid-sized practices don’t have the in-house expertise to properly implement all of these controls, which is why so many turn to managed IT providers with specific HIPAA experience.

Risk Assessments Aren’t Optional

One of the most commonly overlooked HIPAA requirements is the security risk assessment. The Office for Civil Rights (OCR) has been clear about this: every covered entity and business associate must conduct a thorough risk assessment. Not once, but regularly. Yet studies consistently show that a significant percentage of healthcare organizations either skip this step entirely or treat it as a one-time exercise.

A proper risk assessment identifies where ePHI lives within an organization’s systems, evaluates potential threats and vulnerabilities, and determines the likelihood and impact of various breach scenarios. It’s the foundation that every other security decision should be built on. Without it, organizations are essentially guessing about where their biggest exposures are.

Security professionals in the healthcare space recommend conducting these assessments at least annually, and also whenever there’s a significant change to systems or infrastructure. Moving to a new electronic health records platform? That triggers a new assessment. Migrating servers to the cloud? Same thing. Adding a new telehealth application? You get the idea.

The Business Associate Problem

Here’s something that catches a lot of healthcare organizations off guard: HIPAA liability doesn’t stop at the front door. Any vendor, contractor, or service provider that handles ePHI on behalf of a covered entity is considered a business associate, and they’re subject to the same security requirements.

That cloud hosting provider storing patient records? Business associate. The IT support company managing the network? Business associate. The billing service processing insurance claims? Also a business associate. Each of these relationships requires a formal Business Associate Agreement (BAA) that spells out each party’s responsibilities for protecting patient data.

Too many organizations treat BAAs as boilerplate paperwork. They shouldn’t. A well-crafted BAA clearly defines how ePHI will be safeguarded, what happens in the event of a breach, and how data will be handled when the relationship ends. Organizations that fail to properly vet their business associates or maintain current agreements are leaving themselves exposed to compliance gaps they may not even know about.

What to Look for in a Technology Partner

Healthcare organizations evaluating IT service providers should ask pointed questions. Does the provider have documented experience with HIPAA-regulated environments? Can they provide evidence of their own security controls? Do they offer encrypted communication channels, compliant cloud hosting, and detailed audit logging? Will they sign a comprehensive BAA without hesitation? Any reluctance to answer these questions is a red flag.

Encryption Still Isn’t Universal, and That’s a Problem

HIPAA classifies encryption as an “addressable” safeguard rather than a “required” one, and this distinction has caused a tremendous amount of confusion. Some organizations interpret “addressable” as “optional.” It’s not. If an organization decides not to encrypt ePHI, it must document why an equivalent alternative measure is in place. In practice, there are very few scenarios where encryption isn’t the most practical solution.

Data should be encrypted both at rest and in transit. That means patient records stored on servers, workstations, and portable devices all need encryption. Emails containing PHI need to be encrypted. Data moving between locations over a network needs to be encrypted. The technology to do all of this is mature and widely available, so there’s really no excuse for leaving patient data exposed in plain text on any device or communication channel.

Lost or stolen devices remain one of the top causes of healthcare data breaches. But if a laptop or USB drive is properly encrypted and that encryption meets recognized standards, it typically doesn’t qualify as a reportable breach under HIPAA. That single layer of protection can be the difference between a minor inconvenience and a front-page incident.

Employee Training Is the Weakest Link

All the technical safeguards in the world won’t help if staff members are clicking phishing links, sharing passwords, or sending PHI through unsecured channels. Human error is a factor in a staggering number of healthcare breaches, and phishing attacks targeting healthcare workers have grown more sophisticated every year.

HIPAA requires workforce training on security policies and procedures, but it doesn’t prescribe exactly what that training should look like. The best programs go well beyond an annual slide deck. They include simulated phishing exercises, role-specific training for clinical vs. administrative staff, and regular refreshers that keep security awareness top of mind. Organizations that invest in continuous security education see measurably fewer incidents than those that treat training as a once-a-year formality.

Creating a Culture of Compliance

Effective HIPAA compliance isn’t just about technology or policies on paper. It requires a cultural shift where every employee, from front-desk staff to C-suite executives, understands their role in protecting patient information. That means clear reporting procedures for suspicious activity, no-blame policies that encourage people to speak up when something goes wrong, and visible leadership commitment to data security.

Incident Response Planning Deserves More Attention

HIPAA’s Breach Notification Rule gives organizations specific timelines for reporting breaches. Affected individuals must be notified within 60 days. Breaches affecting 500 or more people require notification to the media and HHS. Smaller breaches must still be logged and reported annually. These timelines are strict, and organizations that don’t have an incident response plan ready to go will struggle to meet them.

A solid incident response plan defines roles and responsibilities, outlines containment and investigation procedures, addresses communication protocols for patients and regulators, and includes steps for post-incident review and remediation. Testing the plan through tabletop exercises at least once a year helps identify gaps before a real incident exposes them.

Healthcare organizations that take a proactive, layered approach to HIPAA compliance tend to fare much better than those scrambling to respond after a breach. The regulations can feel overwhelming, especially for smaller practices without dedicated IT departments. But the cost of noncompliance, both financial and reputational, almost always exceeds the investment required to get it right. Building strong IT security foundations, partnering with knowledgeable technology providers, and fostering a workforce that takes data protection seriously are the most reliable paths to staying on the right side of HIPAA.