Loading…

IT Support Services

Articles About Information Technology Support Services and Topics

Why Healthcare Organizations on Long Island Still Struggle with HIPAA Technical Safeguards

A surprising number of healthcare organizations believe they’re HIPAA compliant simply because they’ve trained their staff on privacy policies and locked their filing cabinets. But the technical side of HIPAA compliance is where most violations actually occur, and it’s where the financial penalties hit hardest. The Department of Health and Human Services settled or imposed penalties exceeding $130 million between 2003 and 2024, and a significant chunk of those cases involved failures in IT security rather than someone accidentally faxing records to the wrong number.

For healthcare practices, clinics, and organizations across the Long Island, New York City, Connecticut, and New Jersey region, the stakes keep climbing. Patient data is worth more on the black market than credit card numbers, and threat actors know that smaller healthcare organizations often lack the IT infrastructure to stop them.

The Technical Safeguards Most Organizations Get Wrong

HIPAA’s Security Rule breaks down into three categories of safeguards: administrative, physical, and technical. Most healthcare organizations put their energy into administrative safeguards because those feel manageable. Policies get written. Training sessions get scheduled. Compliance officers get appointed. That’s all necessary, but it doesn’t address how electronic protected health information (ePHI) actually moves through an organization’s network.

Technical safeguards cover access controls, audit controls, integrity controls, and transmission security. These aren’t optional recommendations. They’re requirements, and each one has specific implementation specifications that healthcare IT environments need to meet.

Access controls are a common weak spot. The rule requires unique user identification, emergency access procedures, automatic logoff, and encryption. Yet many small practices still share login credentials among staff or use systems that don’t lock after periods of inactivity. One receptionist’s compromised password can expose an entire patient database when everyone uses the same credentials.

Encryption: The Baseline That’s Still Missing

It’s genuinely alarming how many healthcare organizations in the tri-state area still transmit ePHI without proper encryption. HIPAA requires that organizations implement a mechanism to encrypt electronic protected health information whenever it’s deemed appropriate. In practice, security professionals almost universally agree that encryption should be applied both at rest and in transit.

Data at rest means the information sitting on servers, workstations, laptops, and backup drives. Data in transit means emails, file transfers, and any communication between systems. A stolen laptop without full-disk encryption is one of the most common HIPAA breach scenarios reported to HHS. It’s also one of the most preventable.

Healthcare organizations that rely on standard email to communicate patient information with specialists, labs, or insurance providers are taking a significant risk. Encrypted email solutions and secure messaging platforms designed for healthcare exist specifically to close this gap, and they’ve become much more practical to deploy in recent years.

Audit Logs and Why Nobody Checks Them

HIPAA requires healthcare organizations to implement hardware, software, and procedural mechanisms that record and examine activity in information systems containing ePHI. That means audit logs. Every access to patient records should be logged, and those logs should be reviewed regularly.

The problem isn’t usually generating the logs. Most modern EHR systems and network infrastructure produce plenty of log data. The problem is that nobody looks at them. Small and mid-sized healthcare organizations rarely have dedicated IT security staff sifting through access logs to spot anomalies. An employee accessing records they have no clinical reason to view might go unnoticed for months or even years.

Security information and event management (SIEM) tools can automate much of this monitoring. These platforms aggregate logs from multiple sources and flag unusual patterns, like a user accessing an abnormal volume of records or logging in from an unfamiliar location at 2 a.m. Managed IT providers that specialize in healthcare often deploy these tools as part of their compliance service packages, giving smaller organizations access to the kind of monitoring that would otherwise require a full-time security analyst.

The Risk Assessment Gap

Every covered entity under HIPAA is required to conduct a thorough risk assessment. This isn’t a one-time checkbox. It’s supposed to be an ongoing process that evaluates threats to ePHI, identifies vulnerabilities in current systems, and determines the likelihood and impact of potential breaches. HHS has been clear that failure to conduct an adequate risk assessment is one of the most common findings in breach investigations.

Many organizations treat this as a paperwork exercise. They fill out a template once, file it away, and revisit it when an auditor asks. But a meaningful risk assessment requires actually testing network defenses, reviewing access permissions, evaluating vendor security practices, and mapping how patient data flows through every system it touches. The IT environment changes constantly as new devices connect, software updates roll out, and staff turnover shifts access needs. A risk assessment from eighteen months ago doesn’t reflect today’s threat landscape.

Business Associates and the Extended Attack Surface

Healthcare organizations don’t operate in isolation. They share data with billing companies, cloud service providers, IT support firms, transcription services, and dozens of other vendors. Under HIPAA, any entity that handles ePHI on behalf of a covered entity is considered a business associate and must comply with the same security requirements.

Business associate agreements (BAAs) are legally required before sharing ePHI with any vendor. But having a signed BAA doesn’t mean the vendor is actually secure. Several major healthcare data breaches in recent years originated not with the healthcare organization itself but with a third-party vendor whose security practices didn’t hold up.

Healthcare organizations should be vetting their business associates’ security controls, asking for evidence of their own compliance efforts, and ensuring that the BAA includes specific provisions about breach notification timelines and liability. The organization that collected the patient data bears significant responsibility even when a vendor is the one that drops the ball.

Incident Response: Planning Before the Breach

HIPAA’s breach notification rule requires covered entities to notify affected individuals, HHS, and in some cases the media within 60 days of discovering a breach. That timeline moves fast, especially for organizations that don’t have an incident response plan ready to execute.

An effective incident response plan covers how to detect a breach, contain it, assess its scope, notify the right parties, and document everything along the way. It assigns roles so that people know their responsibilities before panic sets in. And it gets tested through tabletop exercises where staff walk through simulated scenarios.

Healthcare organizations that wait until a breach occurs to figure out their response process end up making costly mistakes. They miss notification deadlines, fail to preserve forensic evidence, or communicate inconsistently with affected patients. All of these missteps can compound the regulatory penalties and reputational damage that follow a breach.

The Human Element Still Matters

Even the best technical safeguards can be undermined by a single employee clicking a phishing link. Healthcare remains one of the most targeted industries for phishing attacks because the data is valuable and the workforce is busy, stressed, and often not deeply technical. Regular security awareness training that goes beyond an annual slide deck makes a real difference. Short, frequent training sessions with simulated phishing tests have been shown to reduce click rates significantly over time.

Multi-factor authentication (MFA) adds another layer of protection that’s particularly effective against credential-based attacks. If a staff member’s password gets compromised through phishing, MFA can still prevent unauthorized access. It’s one of the highest-impact, lowest-cost security measures available, and HHS has increasingly pointed to it as an expected safeguard.

Getting Ahead of Enforcement

HHS has signaled repeatedly that HIPAA enforcement is intensifying, not relaxing. The agency has expanded its audit program and shown willingness to impose penalties on smaller organizations, not just large hospital systems. State attorneys general in New York, New Jersey, and Connecticut have also pursued HIPAA-related actions independently, adding another layer of regulatory exposure for organizations in the region.

Healthcare organizations that treat HIPAA compliance as a living, ongoing program rather than a static set of documents put themselves in a much stronger position. That means regular risk assessments, continuous monitoring, updated policies that reflect actual IT practices, and a relationship with IT security professionals who understand the specific requirements of healthcare data protection. The cost of proactive compliance is almost always less than the cost of responding to a breach after the fact.