A cyber incident can affect patient information and the systems clinicians need to deliver care. Healthcare teams need to connect their compliance work with the practical task of keeping those systems available and appropriately protected.
The HHS summary of the HIPAA Security Rule explains the administrative, physical, and technical safeguards required of covered entities and business associates for electronic protected health information. Keep the applicable rule and your organization's risk analysis at the center of the work.
Start with the environment you actually run
HHS risk-analysis guidance calls for evaluating risks and vulnerabilities to the confidentiality, integrity, and availability of ePHI throughout the organization. That means identifying where information lives, who can access it, and which dependencies can interrupt its use.
An assessment should lead to assigned actions and follow-up. Review it as systems, services, and risks change rather than treating its completion date as evidence that the environment remains secure.
Priorities to review
Email and workforce reporting. Review filtering, account protection, and the route for reporting suspicious messages. Use examples relevant to clinical and administrative work, including requests for patient information and payment changes.
Connected devices. Inventory medical devices and the clinical systems they communicate with. Plan patches and access restrictions with biomedical engineering, clinical owners, and equipment vendors. Validate that changes preserve required clinical functions.
Business associates and other service providers. Determine which relationships meet the HIPAA business-associate definition and require the relevant agreements. Alongside contract review, understand data access, security responsibilities, incident contacts, and the evidence you need from providers.
Identity and access. Review shared access, privileged accounts, and the lifecycle of staff and contractor permissions. Select authentication methods that protect access while supporting safe clinical workflows.
The HHS healthcare cybersecurity performance goals offer voluntary priorities, including email security, MFA, vulnerability mitigation, and training. These goals are useful planning guidance; they do not replace HIPAA requirements.
Practice for disrupted care
Run a tabletop exercise using an EHR or other critical system outage. Identify who decides when to activate downtime procedures, how clinicians access essential information, and how the organization communicates with patients and partners.
Test backup restoration and confirm that responders can access the recovery tools during a disruption. Include clinical operations, leadership, legal or compliance staff, and relevant technical specialists.
Make the investment concrete
Avoid using a single industry breach-cost average as your budget model. Estimate the consequences for your own services: disrupted care, recovery work, information exposure, and contractual or reporting obligations.
Use that analysis to sequence the work and identify the specialist support needed. The goal is a maintained security program with clear owners and usable recovery procedures.
Get the next issue in your inbox
Harborcoat Threat Watch sends concise cybersecurity analysis for business and IT leaders when there is something worth your time.