What Healthcare Organizations Get Wrong About HIPAA Compliance (And How to Fix It)

A single data breach in healthcare costs an average of $10.93 million, according to IBM’s 2023 Cost of a Data Breach Report. That figure has climbed year after year, and it’s not slowing down. Yet many healthcare organizations across the tri-state area and beyond still treat HIPAA compliance as a checkbox exercise rather than an ongoing security commitment. The result? Gaps that regulators notice and attackers exploit.

HIPAA Isn’t Just About Paperwork

There’s a common misconception that HIPAA compliance starts and ends with policies binders and signed employee acknowledgment forms. Those documents matter, sure. But the Department of Health and Human Services (HHS) Office for Civil Rights has made it clear through enforcement actions that they expect organizations to actually implement the safeguards they claim to have in place.

The HIPAA Security Rule requires administrative, physical, and technical safeguards to protect electronic protected health information (ePHI). That means encryption, access controls, audit logs, and contingency planning aren’t optional. They’re the law. And small to mid-sized practices are held to the same standards as large hospital systems, even if their budgets look very different.

The Risk Assessment Problem

If there’s one area where healthcare organizations consistently fall short, it’s the risk assessment. HHS has cited inadequate or missing risk assessments in the majority of its enforcement actions and settlements. It’s the foundation of a HIPAA compliance program, and skipping it is like building a house without checking the soil underneath.

A proper risk assessment identifies where ePHI lives, how it moves through an organization, and what threats could compromise it. This isn’t a one-time project. The Security Rule expects organizations to review and update their risk assessments regularly, especially after significant changes like adopting a new EHR system, moving to cloud-based infrastructure, or opening a new location.

Many IT professionals recommend conducting a formal risk assessment at least annually. Organizations operating in the Long Island, New York City, Connecticut, and New Jersey corridor face additional considerations given the density of healthcare providers and the volume of interconnected systems sharing patient data across facilities.

Access Controls That Actually Work

Role-based access control sounds straightforward. Give people access to the information they need to do their jobs, nothing more. In practice, though, healthcare environments are messy. Staff rotate between departments. Temporary workers come and go. Physicians may work across multiple facilities.

Without disciplined access management, organizations end up with former employees who still have active credentials and clinical staff with access to records they have no reason to view. Both scenarios create compliance violations and real security risks.

What Good Access Management Looks Like

Strong programs tie access provisioning directly to HR processes. When someone joins, their role determines their access. When they leave or change positions, access gets updated the same day. Automated tools can help with this, but even organizations without sophisticated identity management platforms can implement manual checklists that catch the most common oversights.

Multi-factor authentication has also become a baseline expectation. While HIPAA doesn’t explicitly mandate MFA, enforcement trends and guidance from the National Institute of Standards and Technology (NIST) make it clear that relying on passwords alone is no longer defensible. A compromised credential is the starting point for most healthcare data breaches, and MFA is one of the most effective ways to stop that chain of events.

Encryption: The Safeguard Too Many Organizations Skip

HIPAA calls encryption an “addressable” safeguard, which some organizations have misinterpreted as “optional.” That’s not what addressable means. It means an organization must implement it or document why an equivalent alternative is in place. In most cases, there’s no reasonable justification for leaving ePHI unencrypted, whether it’s sitting on a server or traveling across a network.

Full-disk encryption on workstations and laptops is table stakes. Email encryption matters too, particularly for organizations that communicate with patients or send referral information electronically. Encrypted messaging platforms designed for healthcare have become more accessible and affordable, making it harder to argue that encryption is impractical.

Stolen or lost laptops account for a surprising number of reported breaches. If the device was encrypted, the organization can demonstrate that the data was protected and may avoid the breach notification process entirely. That single technical control can save millions in regulatory penalties and reputational damage.

Employee Training Isn’t a Once-a-Year Slide Deck

Phishing remains the top attack vector in healthcare. Staff members with access to sensitive systems receive convincing emails every day designed to trick them into handing over credentials or clicking malicious links. Annual compliance training alone doesn’t prepare people for the sophistication of modern social engineering attacks.

Effective security awareness programs include simulated phishing campaigns, short and frequent training modules, and clear reporting procedures that make employees feel safe flagging suspicious activity. Organizations that foster a culture of security awareness see dramatically lower click rates on phishing attempts compared to those that treat training as a compliance formality.

New hires should receive security training during onboarding, not three months later when the next scheduled session rolls around. And training content should reflect actual threats the organization faces, not generic scenarios pulled from a template.

Business Continuity and Disaster Recovery

The HIPAA Security Rule requires contingency planning, including data backup, disaster recovery, and emergency operations plans. Healthcare doesn’t stop during a ransomware attack, a hurricane, or a power outage. Patients still need care, and the systems supporting that care need to come back online fast.

Organizations in the northeastern United States know this firsthand. Superstorm Sandy exposed how many healthcare facilities lacked adequate disaster recovery capabilities. Years later, some organizations still haven’t tested their backup and recovery procedures in a meaningful way.

Testing Recovery Plans

Having a disaster recovery plan on paper isn’t enough. Regular testing reveals gaps that assumptions miss. Can the organization actually restore from backups within an acceptable timeframe? Do staff members know their roles during an incident? Are backup systems stored in a geographically separate location that wouldn’t be affected by the same regional event?

Tabletop exercises, where key stakeholders walk through a hypothetical incident scenario, are a low-cost way to identify weaknesses. Full recovery drills that simulate an actual system failure provide even more valuable insight. Many managed IT service providers recommend quarterly reviews of backup integrity combined with at least one full recovery test per year.

Business Associate Agreements Aren’t Just Legal Formalities

Every vendor that handles ePHI on behalf of a healthcare organization needs a Business Associate Agreement (BAA) in place. Cloud providers, IT support companies, billing services, shredding companies, even the answering service that takes after-hours calls. If they touch patient data, they need a BAA.

But signing the agreement is just the beginning. Healthcare organizations should be evaluating their business associates’ security posture before entering into contracts and periodically throughout the relationship. A vendor’s breach becomes the covered entity’s problem, both from a regulatory and a reputational standpoint.

Where Things Are Heading

HHS proposed significant updates to the HIPAA Security Rule in late 2024, aiming to strengthen requirements around encryption, multi-factor authentication, and network segmentation. While the final rule is still taking shape, the direction is clear: regulators expect healthcare organizations to keep pace with evolving threats, not rely on practices that were considered adequate a decade ago.

Organizations that view compliance as a living program, one that adapts and improves continuously, will find themselves in a much stronger position than those scrambling to catch up after an audit or breach. The cost of proactive compliance is a fraction of what a breach costs in fines, legal fees, and lost patient trust. That math hasn’t changed, and it probably never will.