Substantial HIPAA Data Breaches: Only a Matter of Time

by Jay Hodes, President – Colington Consulting

With all the news about data breaches and the potential for personally identifiable information (PII) to make its way into the wrong hands of criminals or hackers, is it only a matter of time before there is a substantial breach of patient records? When checking the U.S. Department of Health and Human Services (HHS) Breach List, you will find these occurrences already happening on a regular basis. In June, the state of Montana announced 1.3 million people were affected by a recent health records data breach.

Between March 1 and May 30, 2014, there were eight separate breach notifications made to HHS, each affecting 500 or more individuals, totaling almost 35,000 compromised patient records. The largest breach affected more than 8,800 individuals from an HMO and related insurance provider. But these breaches affect small healthcare providers, also. One of the reported breaches affecting 1,000 individuals was at a podiatry office and another at a dental practice that involved 6,900 individuals. There is no percipience with the size and type of healthcare practice, and most breaches appear to be theft related.

There is usually limited press coverage of these breaches, except by those who track these industry occurrences. But when a newsworthy and extensive breach of millions of records does happen, it will be front page news. When will the tsunami of a health record breach occur? Regrettably, it may be sooner than later. When the FBI recently warned healthcare providers that their cybersecurity networks are more susceptible than retail and financial sectors, hopefully the alarm bells went off and proper information technology countermeasures are now being implemented.

According to Chris Albright, network security expert and owner of CMIT Solutions of Centreville (VA), โ€œHackers, just like other predators, always go after the most vulnerable or โ€˜softโ€™ targets first. This approach guarantees the hacker greater success with the least amount of effort. More often than not, data breaches are not professional hackers in the traditional sense. Rather, it is members of the medical staff who know there are no policies or effective security measures in place, and they know the violation will go unnoticed. Healthcare offices that fail to address HIPAA head on are essentially sitting on a time bomb.โ€

Conducting a HIPAA Risk Assessment is an excellent way to identify vulnerabilities and threats to patient electronic health records. Besides being a fundamental requirement of HIPAA compliance, the assessment helps professionals to recognize problem areas where the potential for unauthorized access, lack of proper internal protocols for tampering and outright theft of protected health information may occur.

Need Help with Your HIPAA Compliance Program?

At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

Updated on June 21, 2025 and Reviewed By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert

Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.