Category: HIPAA Security Rule

  • 5 HIPAA Compliance Gaps That Put Healthcare Organizations at Risk

    Why Small Gaps Create Big Exposure

    HIPAA compliance failures rarely begin with a single dramatic mistake. More often, they stem from overlooked documentation, inconsistent staff practices, incomplete risk reviews, or security controls that have not kept pace with operational change. For healthcare providers and business associates, these gaps can increase exposure during audits, investigations, and breach response.

    Colington Consulting helps organizations build defensible HIPAA compliance programs that are practical, documented, and aligned with real-world regulatory expectations. Below are five common compliance gaps that deserve immediate attention.

    1. Incomplete Risk Assessments

    A HIPAA risk assessment should do more than satisfy a checkbox. It should identify where protected health information is created, stored, transmitted, and exposed across systems, vendors, workflows, and physical environments. When assessments are outdated, too narrow, or unsupported by evidence, organizations may struggle to demonstrate a reasonable compliance posture.

    A defensible risk assessment creates the foundation for stronger decisions, better documentation, and more credible compliance efforts.

    2. Weak Risk Management Follow-Through

    Finding risks is only the beginning. A common problem is the absence of a documented risk management plan that prioritizes issues, assigns responsibility, and tracks remediation over time. Without follow-through, known weaknesses remain unresolved and can become harder to explain after an incident.

    3. Staff Training That Lacks Depth

    HIPAA training should reflect actual job responsibilities and current threats, not just generic annual reminders. Workforce members need clear guidance on privacy expectations, security practices, phishing awareness, device use, reporting procedures, and how to handle protected health information in day-to-day operations.

    • Role-based training improves relevance
    • Recurring refreshers reinforce accountability
    • Documented completion records support compliance readiness

    4. Outdated Policies and Documentation

    Policies that do not match current systems, vendors, or workflows can create significant compliance risk. Organizations should regularly review privacy and security documentation, business associate oversight practices, facility safeguards, and incident response procedures to ensure written materials reflect operational reality.

    5. Limited Access to Expert Guidance

    Many organizations do not need a large internal compliance department, but they do need reliable expertise when important decisions arise. Virtual HIPAA compliance officer support and hourly consulting can help leadership evaluate risks, respond to questions, and strengthen documentation before issues escalate.

    What a Stronger Program Looks Like

    A stronger HIPAA compliance program is not built on assumptions. It is built on documented assessments, practical risk management, informed staff, current policies, and access to experienced consulting support. When these elements work together, organizations are better positioned to reduce risk exposure and respond confidently to regulatory scrutiny.

    How Colington Consulting Helps

    Colington Consulting supports healthcare providers and business associates with HIPAA risk assessments, risk management plans, staff training, policy reviews, privacy and security rule documentation, facility security planning, and ongoing consulting guidance. The goal is to help organizations create compliance programs that are practical, defensible, and ready for real-world challenges.

    If your organization is unsure whether its current HIPAA program would hold up under an audit, investigation, or breach review, now is the right time to evaluate the gaps and strengthen the foundation.

    Schedule a Free HIPAA Risk Review

    No Obligation. No Committment

  • Is the New HIPAA Security Rule Final Yet?

    Is the New HIPAA Security Rule Final Yet? What Covered Entities Need to Know Right Now

    Quick answer: No. As of mid-2026, the proposed HIPAA Security Rule overhaul is still just that โ€” proposed. OCR has not issued a final rule, its informal May 2026 target came and went with nothing published, and a coalition of more than 100 hospital and provider groups has formally asked HHS to withdraw the rule altogether. That said, organizations shouldn’t treat “not final” as “not urgentโ€ as HIPAA’s civil penalty tiers already increased this year under current law, and history shows compliance windows shrink fast once a final rule does land.

    What the Proposed Rule Would Actually Change

    The HIPAA Security Rule hasn’t seen a substantive update since 2013. The Notice of Proposed Rulemaking published in January 2025 would be the most significant rewrite in the rule’s history, and the headline change is structural: it eliminates the long-standing distinction between “addressable” and “required” safeguards. Today, organizations can implement reasonable alternatives to certain controls and document why. Under the proposal, that flexibility disappears โ€” nearly every safeguard becomes mandatory.

    In practice, that means encryption of electronic PHI at rest and in transit with no documented-alternative exception, multi-factor authentication required for any system that touches ePHI, network segmentation written explicitly into the technical safeguards, and a shift from occasional testing to recurring, scheduled technical assessments such as penetration testing. Business associates would also face tighter, faster incident-reporting obligations to the covered entities they serve.

    Where Things Actually Stand

    OCR’s own regulatory agenda pointed to a May 2026 finalization, but that window has passed without action. Pushback has been significant: HHS’s own regulatory impact analysis estimated roughly $9 billion in first-year industry compliance costs, climbing toward $34 billion over five years, and that price tag is a big part of why provider groups are lobbying for withdrawal rather than finalization. There’s no confirmed new timeline. If and when a final rule does publish, the expected compliance runway is short โ€” roughly 60 days until the rule takes effect, then another 180 days to come into full compliance.

    The Part That’s Already Real: Penalties Went Up

    Separately from the Security Rule fight, OCR’s civil monetary penalty tiers received their routine annual inflation adjustment effective January 28, 2026. The top tier โ€” willful neglect that goes uncorrected โ€” now caps at $2,190,294 per calendar-year violation category, with the other tiers adjusted upward as well. This is current law today, independent of whatever happens with the proposed overhaul.

    What to Do Now, Regardless of the Final Rule’s Fate

    The organizations best positioned aren’t waiting for a final rule to start the clock. Encrypting ePHI everywhere, rolling out MFA, segmenting networks, and testing on a schedule are good security practice today and lower your real exposure under the penalty structure that already exists. A practical starting point: refresh your documented risk analysis, confirm your business associate agreements already require prompt breach notification language, and budget for these controls now rather than scrambling on a 240-day deadline later.

    Frequently Asked Questions

    Has the HIPAA Security Rule update been finalized? No. As of mid-2026 it remains a proposed rule with no confirmed finalization date.

    Will MFA become mandatory under HIPAA? Under the proposed rule, yes โ€” for any system accessing ePHI. It isn’t legally required yet, though many auditors already treat it as a baseline expectation.

    How long would organizations get to comply once it’s final? Industry estimates point to about 240 days total: roughly 60 days until the rule takes effect, then 180 more days to reach full compliance.

    Did HIPAA penalties increase in 2026? Yes. The annual inflation adjustment took effect January 28, 2026, raising the maximum penalty tier.

    At Colington Consulting, we specialize in helping healthcare organizations and business associates build proactive compliance programs. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review to evaluate your current policies and protect your organization.

    Reviewed on June 18, 2026, By: Jay Hodes, President – Colington Consulting, HIPAA Compliance Expert

    Sources:

    • U.S. Department of Health and Human Services, Office for Civil Rights. “HIPAA Security Rule To Strengthen the Cybersecurity of Electronic Protected Health Information,” Notice of Proposed Rulemaking, 90 Fed. Reg. 898 (Jan. 6, 2025). federalregister.gov
    • HHS.gov, “HIPAA Security Rule NPRM” overview page. hhs.gov
    • HHS.gov, Fact Sheet on the HIPAA Security Rule NPRM. hhs.gov
    • U.S Department of Health and Human Services, “Annual Civil Monetary Penalties Inflation Adjustment,” Fed. Reg. (Jan. 28, 2026). federalregister.gov
    • HHS.gov, “Summary of the HIPAA Security Rule” (current rule in effect). hhs.gov

    Disclaimer: The information provided in this article is for educational and informational purposes only and does not constitute formal legal advice or an official regulatory determination. For specific guidance regarding your organization’s unique operational workflows, consult directly with a HIPAA compliance specialist or legal counsel.

  • HIPAA Security Rule Policies And Procedures: Complete Guide

    Most organizations know they need HIPAA Security Rule policies and procedures. Fewer know what that actually means in practice. The Security Rule requires covered entities and business associates to document how they protect electronic protected health information (ePHI), not in vague terms, but through specific, implementable policies that address administrative, physical, and technical safeguards. Getting this wrong isn’t a minor oversight. It’s the single most common finding in OCR enforcement actions.

    The challenge is that the Security Rule is deliberately flexible. It tells you what to address but leaves how largely up to you. That flexibility is a feature for organizations that understand their risk environment, and a trap for those that don’t. Without clear guidance, many healthcare organizations either over-engineer policies they can’t maintain or adopt generic templates that fall apart under scrutiny. Neither approach produces a defensible compliance program.

    At Colington Consulting, we’ve helped hundreds of organizations build HIPAA compliance programs that hold up when it matters, during audits, breach investigations, and enforcement actions. This guide breaks down what the Security Rule actually requires for your policies and procedures, how to structure them, and what separates documentation that checks a box from documentation that protects your organization. Whether you’re building from scratch or overhauling an outdated program, you’ll walk away with a clear framework for implementation.

    Why HIPAA security rule policies and procedures matter

    When the Office for Civil Rights (OCR) investigates a breach or complaint, documented policies and procedures are among the first things auditors request. Your organization needs to show not just that a policy existed, but that it was in place before the incident, that workforce members received training on it, and that your team actually followed it. Without that paper trail, organizations with otherwise solid security controls still face significant penalties. The Security Rule exists to make ePHI protection systematic and verifiable, and your policies are the mechanism that proves you’ve done the work.

    Documentation is what OCR actually audits

    OCR’s enforcement investigations rely heavily on written documentation review. When auditors arrive, they request your policies, your risk analysis, your training records, and your sanction logs. If those documents don’t exist, or if they don’t reflect what your staff actually does day-to-day, that gap becomes a formal finding. Organizations frequently lose enforcement cases not because their security controls were technically inadequate, but because they couldn’t demonstrate those controls existed in writing. Your policies aren’t just internal guidance; they function as legal evidence of your compliance posture at any given point in time.

    OCR has cited missing or inadequate security policies as a contributing factor in enforcement actions even in cases where no breach actually exposed patient data.

    The financial stakes are concrete and growing

    OCR has collected over $150 million in HIPAA settlements and civil monetary penalties since enforcement began. Fines vary by violation tier, reaching up to $73,111(inflation adjusted) per violation for willful neglect that goes uncorrected. But your financial exposure doesn’t stop with OCR. Cyber insurers now routinely require documented HIPAA security policies as a condition of coverage, and many carriers deny claims when your documentation fails to demonstrate that reasonable safeguards were in place before a breach. A missing or outdated policy can cost your organization both the regulatory penalty and the insurance payout simultaneously.

    Beyond insurance, business associate agreements and contract requirements from health systems and payers increasingly include HIPAA compliance documentation as a contractual obligation. If you can’t produce current policies during a vendor audit, you risk losing those contracts entirely.

    Policies create a clear, consistent standard for your workforce

    Your staff cannot follow rules they don’t know exist. HIPAA security rule policies and procedures translate abstract regulatory language into specific, actionable instructions for the people who handle ePHI every day. A workstation use policy tells employees exactly what they can and cannot do on devices that access patient records. An access management policy tells your IT team precisely how to provision and revoke user credentials when roles change or employees leave. Without written standards, every person makes independent judgment calls, and your security posture depends entirely on individual behavior rather than organizational control.

    Written policies also reduce liability for your leadership team. When a workforce member follows a documented procedure and an incident still occurs, your organization can demonstrate reasonable diligence to regulators and insurers. When no procedure exists, both the organization and individual executives face significantly greater personal exposure. Sound documentation protects your staff and your leadership, not just your patients.

    Who must follow the HIPAA Security Rule

    The Security Rule applies to two broad categories of organizations under HIPAA: covered entities and business associates or referred to as regulated entities. If your organization falls into either group and handles electronic protected health information in any form, you are legally required to have HIPAA Security Rule policies and procedures in place. There is no minimum size threshold. A solo medical practice carries the same core compliance obligations as a large hospital system.

    Covered entities

    Covered entities are healthcare providers, health plans, and healthcare clearinghouses that transmit health information electronically in connection with standard transactions. This includes physicians, dentists, hospitals, outpatient clinics, health insurers, and Medicare/Medicaid programs. If your organization sends electronic claims, checks eligibility, or transmits any other standard healthcare transaction, you qualify as a covered entity regardless of how small your practice is.

    Many small practices mistakenly assume they fall below the regulatory threshold. OCR has enforced HIPAA against solo practitioners and small group practices in numerous documented cases.

    Size and patient volume do not affect your status as a covered entity. A two-physician practice that submits electronic claims to a single insurer has the same obligation to maintain written security policies as a 500-bed hospital. The Security Rule does allow smaller organizations to scale the complexity of their policies to match their risk environment, but it does not exempt them from having those policies at all.

    Business associates

    Business associates are vendors, contractors, and service providers that create, receive, maintain, or transmit ePHI on behalf of a covered entity. This category is broad and includes medical billing companies, IT managed service providers, cloud storage vendors, EHR software companies, and third-party transcription services. If your company touches patient data while performing a service for a healthcare organization, you are a business associate under HIPAA.

    Your business associate agreement (BAA) with a covered entity does not substitute for your own internal compliance program. You still need written security policies that meet the Security Rule’s requirements. If OCR investigates a breach that originates from your systems, your policies, not your BAA, will determine your exposure.

    What HIPAA requires for security policies and procedures

    The Security Rule organizes its requirements around three safeguard categories: administrative, physical, and technical. Within each category, individual standards contain specific implementation specifications. Your HIPAA Security Rule policies and procedures must address every applicable standard, but the rule gives you two types of specifications to work with, and understanding the difference directly affects how you write and structure your documentation.

    Required vs. addressable specifications

    Required specifications are non-negotiable. You must implement them as written, and your policies must reflect that you’ve done so. Addressable specifications carry more flexibility, but they are not optional. For each addressable specification, you must either implement it as described, implement an equivalent alternative, or document why it does not apply to your organization based on your risk analysis.

    Many organizations treat “addressable” as a synonym for “optional.” It is not. Failing to document your decision on an addressable specification is itself a compliance gap.

    Your policies need to capture the outcome of each of these decisions in writing. If you implemented multi-factor authentication as an alternative to a specification’s default control, your policy should state what you implemented and why that choice is appropriate for your risk environment.

    Documentation requirements

    Beyond the content of your policies, the Security Rule specifies how long you must retain your documentation. You are required to keep written policies, procedures, and related records for six years from the date of creation or the date they were last in effect, whichever is later. This means you cannot simply replace an outdated policy without retaining the prior version.

    Your documentation also needs to reflect changes in your organization over time. When you update a workflow, adopt a new system, or change workforce roles that affect ePHI access, your policies must be reviewed and revised accordingly. Static documentation that no longer matches how your organization actually operates creates significant risk during an OCR audit, because auditors compare your written procedures against your actual operational practices, and gaps between the two become formal findings.

    Administrative safeguard policies and procedures

    Administrative safeguards represent the largest and most foundational category of the HIPAA Security Rule. These are the management-level controls that govern how your organization identifies risk, trains staff, manages access, and responds when things go wrong. Your HIPAA Security Rule policies and procedures for administrative safeguards set the foundation that every other safeguard category builds on. Without them, your physical and technical controls have no governance structure supporting them.

    Security Management Process

    Your security management process policies need to document how your organization identifies, analyzes, and responds to risks to ePHI. This standard includes four required implementation specifications: risk analysis, risk management, sanction policy, and information system activity review. Each one requires a written policy explaining what your organization does, how often it does it, and who is responsible.

    Your risk analysis is not a one-time event. OCR expects documented evidence that you repeat this process when your environment changes, such as when you adopt new technology or experience a workforce restructuring.

    Your sanction policy is one of the most frequently overlooked elements in this category. It must specify the consequences your organization applies when workforce members violate your security policies. Without a written sanction policy, you cannot demonstrate to OCR that you hold your staff accountable, which becomes a significant problem during breach investigations.

    Workforce and Access Management

    Access management policies cover who gets access to ePHI, under what conditions, and how that access gets removed. Your authorization and supervision policies should define the process your organization uses to grant access based on job function, not individual preference. When employees change roles or leave the organization, your policies need to specify the exact steps for modifying or terminating their access and the timeframe in which those steps must be completed.

    Your workforce training policies fall under this category as well. These policies must describe how you deliver security awareness training, how you track completion, and how often you refresh that training. Training records tied directly to your written policies give you the documentation trail that OCR auditors look for when evaluating whether your administrative safeguards function as a real program rather than a set of documents stored in a drawer.

    Physical safeguard policies and procedures

    Physical safeguards govern how your organization controls access to the physical spaces and devices that store or process ePHI. Most organizations underestimate this category because it feels less technical than firewalls or encryption, but OCR takes physical access controls seriously. Your HIPAA Security Rule policies and procedures for this category need to address your facilities, your workstations, and every device that touches patient data, including laptops, mobile devices, and workstations in shared clinical areas.

    Facility Access and Control

    Your facility access policies must define who can enter areas where ePHI systems are housed and how your organization documents, monitors, and restricts that access. This includes server rooms, records storage areas, and any space where unattended workstations could give an unauthorized person access to patient data. Your policies should specify the physical controls you use, such as key cards, locks, or visitor logs, and assign clear accountability for maintaining and reviewing those controls.

    Physical access events that go undocumented create a compliance gap that OCR investigators can use to establish a pattern of insufficient safeguards, even when no breach occurred.

    Your contingency access procedures also belong in this category. When your normal access controls fail during an emergency, your staff needs a written protocol for maintaining facility security while still allowing appropriate personnel to reach critical systems. Document that protocol explicitly so it is available and tested before an incident requires it.

    Workstation and Device Controls

    Workstation use policies must define what employees are permitted to do on devices that access ePHI and what physical environment those workstations should be in. Screens that face public waiting areas, unlocked devices left unattended, and shared login credentials are all physical security failures that belong in your policy documentation. Your workstation security policy should describe the physical positioning, screen lock requirements, and access restrictions that apply to every ePHI-capable device in your environment.

    Device and media controls extend this to hardware that moves in and out of your organization. Your policies need to address how you track, transfer, and dispose of devices that store ePHI, including the steps required before any hardware leaves your control through reassignment, repair, or destruction.

    Technical safeguard policies and procedures

    Technical safeguards define the technology-based controls your organization uses to protect ePHI at rest and in transit. Your HIPAA Security Rule policies and procedures for this category need to cover how your systems restrict access, generate audit logs, protect data integrity, and secure transmissions. These policies must reflect the actual technology your organization uses, not generic descriptions of controls that don’t match your environment.

    Access Controls and Audit Controls

    Your access control policies must specify how your systems limit ePHI access to authorized users only and what technical mechanisms enforce those limits. This includes unique user identification requirements, emergency access procedures, automatic logoff settings, and encryption or decryption protocols. Each of these elements needs its own policy language that assigns responsibility and defines the technical standard your organization meets.

    A policy that simply states “we control access to ePHI” gives OCR auditors nothing to work with. Your documentation needs to name the specific controls in place and explain how they function within your environment.

    Your audit control policies address how your organization captures and reviews activity logs across systems that contain ePHI. You need written procedures that describe which systems generate logs, what those logs capture, how long you retain them, and who reviews them and at what frequency. Without a documented review process, your logs become a liability rather than an asset because you collect evidence of potential violations without any mechanism to detect or respond to them.

    Transmission Security and Integrity Controls

    Transmission security policies must define how your organization protects ePHI when it moves across networks, including email, patient portals, file transfers, and API connections. Your policies should identify the encryption standards your organization applies and specify which transmission types require those controls. Staff need clear written guidance on which channels are approved for sending ePHI and which are prohibited.

    Integrity controls belong alongside your transmission policies. These procedures describe how your organization detects whether ePHI has been altered or destroyed without authorization, both in storage and during transmission. Document the specific mechanisms your systems use and assign a responsible party for monitoring and responding to integrity alerts.

    Final takeaways

    HIPAA Security Rule policies and procedures are not a compliance checkbox. They are the documented foundation that determines whether your organization can defend itself when OCR comes knocking, when a breach triggers an investigation, or when a cyber insurer reviews your claim. Every administrative, physical, and technical safeguard your organization implements needs written policies that reflect how your systems actually operate, who owns each control, and what happens when something goes wrong.

    Generic templates and one-time documentation projects leave you exposed. Your policies need to evolve as your organization changes, and they need to be enforced through training, sanction procedures, and regular review. The gap between having a policy and having a defensible compliance program is exactly where most organizations fail.

    If you want to build a compliance program that holds up under scrutiny, work with a HIPAA compliance consulting firm that takes ownership of the process alongside you.

    Schedule a 30 minute HIPAA Risk Review

  • OCR Releases Guidance for Implementing the HIPAA Security Rule

    On February 16, the U.S. Department of Health and Human Services (HHS) released of the final version of Special Publication 800-66 Rev. 2, titled โ€œImplementing the Health Insurance Portability and Accountability Act (HIPAA) Security Rule: A Cybersecurity Resource Guideโ€.

    Overview

    The HIPAA Security Rule is a critical framework for safeguarding electronic protected health information (ePHI) held or maintained by regulated entities. To address the evolving cybersecurity landscape, the National Institute of Standards and Technology (NIST) has revised and updated Special Publication 800-66 to provide practical guidance and resources for regulated entities.

    Key Details

    • Publication Title: Special Publication (SP) 800-66 Rev. 2
    • Date Published: February 2024
    • Supersedes: SP 800-66 Rev. 1 (10/23/2008)

    Purpose and Scope

    The revised publication, developed in collaboration with the HHS Office for Civil Rights, serves several purposes:

    1. Risk Assessment and Management: It assists regulated entities (including HIPAA-covered entities and business associates) in assessing and managing risks related to ePHI.
    2. Information Security Program: It identifies typical activities that regulated entities should consider implementing as part of their information security program.
    3. Cybersecurity Guidance: It offers practical guidance to improve cybersecurity posture and achieve compliance with the HIPAA Security Rule.

    Key Content Areas

    The resource guide covers the following topics:

    1. Administrative Safeguards: Strategies for managing ePHI security at the organizational level.
    2. Physical Safeguards: Measures to protect physical access to ePHI.
    3. Technical Safeguards: Recommendations for securing ePHI through technology controls.
    4. Risk Assessment and Risk Management: Practical approaches to identifying and mitigating risks.
    5. Mappings to NIST Cybersecurity Framework: Aligning HIPAA Security Rule standards with NIST Cybersecurity Framework subcategories.
    6. Relevant NIST Publications: Listings of NIST publications relevant to each HIPAA Security Rule standard.

    Conclusion

    For the most part, the totality of the release is a collection of links to access supplemental documentation. Organizations that have never conducted an accurate and thorough Security Risk Assessment will probably find the documentation to be overwhelming. Even for experienced assessors, most of what is provided is not new but more of a one-stop location to find these resources.

    As the healthcare industry continues to rely on electronic health records and digital systems, adherence to the HIPAA Security Rule is paramount. Regulated entities, especially small to mid-size organizations, can use this resource guide to enhance knowledge of cybersecurity practices and how to better protect sensitive health information.

    Remember, safeguarding ePHI is not just a legal requirementโ€”itโ€™s essential for maintaining trust and ensuring patient privacy in this very connected digital world.

    Colington Consulting | HIPAA Compliance, Risk Assessment & Management

    Helping Organizations Achieve HIPAA Complianceโ„ข

    HIPAA compliance is vital to maintain a thriving compliant organization. Colington Consulting offers scalable solutions and compliance consultations to help healthcare practices and vendors meet HIPAA regulatory compliance requirements. Contact us at 844-740-7100 or schedule a free 30-minute HIPAA risk review.

  • Protect Our Health by Protecting our Healthcare

    Our healthcare system, while far from perfect, is an absolute necessity for living. It would make sense then to be sure that it was well-protected.

    Unfortunately, this is often not the case. As we have seen over and over again, database breaches are more common in the healthcare industry than anywhere else. Weโ€™re not just experiencing a loss of data, but a loss of trust as well. How can people live their lives and stay safe from data theft at the same time?

    HIPAA Compliance

    It starts with a set of rules. Such a set has already been put together: The Health Insurance Portability and Accountability Act of 1996 (HIPAA). But rules are meaningless if no one is following them. According to the HIPAA journal, breaches in patient records during 2018 doubled to more than 13 million records. This is unacceptable – both from a patient standpoint and a legal one. And itโ€™s only going to get worse as technology grows.

    Data Breaches and Technology

    Our healthcare technology has improved in leaps and bounds since the 1990โ€™s. This is terrific. The average lifespan of Americans has also increased thanks to amazing breakthroughs and wearable devices like smart inhalers and insulin pens. Patients can have their glucose levels monitored from almost anywhere. We have remote MRI machines and smart beds. These are all helpful things. They greatly improve our quality of life.

    But what happens when all of these terrific inventions are used for ill purpose?

    Each of these devices works because theyโ€™re connected in some way shape or form to a database. Every patient uploads a massive amount of data about themselves whenever theyโ€™re used. Then, attackers breach these databases, access patients records, steal them and sell them on the dark web. In countries like the U.S., attackers from anywhere in the world can access expensive medical services, products, and drugs with the help of stolen medical records. The healthcare sector has proven to be extremely profitable for attackers, with a single record costing an average of $408.

    Data Breaches and Ransomware

    Itโ€™s not always about buying, selling, and manipulating patient data. Disturbingly often, itโ€™s about holding hospitals hostage to fund criminals, political actors abroad and even terrorism. That might sound like an extremely bold declaration, but itโ€™s an unfortunate and well-known truth. Ransomware attacks account for 85% of all the cyber-attacks on the healthcare sector. In one example which we mention in a previous article, Indiana-based healthcare system, Hancock Health, was hit by a ransomware attack that completely locked down all of their computers. In many instances, those computers were depended upon for keeping critical hospital systems running. They felt they had no choice but to pay the ransom in order to keep their patients safe. That attack had cost the company about $55,000 in Bitcoin.

    It was a risky move either way. Historically, only 19% of ransomware victims who pay the ransom actually get their files back. And the worst part is, that money goes to places that are in no way good.

    Our healthcare system is possibly the most important institution in our country. It definitely has its flaws, but itโ€™s literally what keeps us alive. The absolute least we can do is follow the rules that were originally put in place to protect it. Weโ€™re here to help you make sense of those rules.ย  Call us today at 800-733-6379 to schedule a free, initial consultation.