Subscribe to our YouTube GDPR Playlist. Purchase our accredited GDPR - Certified Data Protection Officer (DPO) training in the Arrakis store.
Healthcare organizations face an increasingly complex cybersecurity landscape where patient data protection isn't just a best practice—it's a legal mandate with severe financial and reputational consequences. The Health Insurance Portability and Accountability Act (HIPAA) serves as the cornerstone of healthcare privacy protection in the United States, establishing rigorous standards that closely align with international frameworks such as ISO 27001:2022 and NIST 800-53.
Understanding HIPAA's Cybersecurity Foundation
HIPAA's Security Rule, enacted in 2003 and updated regularly, requires covered entities to implement administrative, physical, and technical safeguards to protect electronic protected health information (ePHI). These requirements create a comprehensive security framework that aligns with many principles of modern cybersecurity standards.
Administrative Safeguards: The Human Element
Administrative safeguards form the backbone of HIPAA compliance, focusing on policies, procedures, and workforce training. These requirements align closely with ISO 27001:2022's emphasis on information security management systems and human resource security.
Key administrative safeguards include:
- Security Officer designation (similar to ISO 27001's requirement for information security roles)
- Workforce training and access management (paralleling NIST 800-53's AC (Access Control) family)
- Information access management procedures (corresponding to ISO 27001's A.9 Access Control)
- Security awareness and training programs (matching NIST 800-53's AT (Awareness and Training) controls). Read our one-pager on Awareness Training here.
Physical Safeguards: Protecting the Infrastructure
Physical safeguards protect computer systems, equipment, and facilities housing ePHI. These requirements align with ISO 27001:2022's A.11 Physical and Environmental Security controls and NIST 800-53's PE (Physical and Environmental Protection) family.
Critical physical safeguards encompass:
- Facility access controls with unique user identification and emergency access procedures
- Workstation use restrictions limiting access to authorized personnel. See our one-pager on Privileged Access Management here.
- Device and media controls governing the receipt, removal, and disposal of hardware and electronic media
Technical Safeguards: The Digital Defense
Technical safeguards are the technological controls that protect ePHI during transmission and storage. These align extensively with ISO 27001:2022's technical controls and NIST 800-53's technical control families.
Essential technical safeguards include:
- Access control with unique user identification, emergency access, and automatic logoff (corresponding to NIST 800-53's AC family and ISO 27001's A.9)
- Audit controls for recording and examining ePHI access (aligning with NIST 800-53's AU (Audit and Accountability) and ISO 27001's A.12.4)
- Integrity controls ensuring ePHI isn't improperly altered or destroyed (matching NIST 800-53's SI (System and Information Integrity))
- Person or entity authentication verifying user identity (corresponding to NIST 800-53's IA (Identification and Authentication))
- Transmission security protecting ePHI during electronic transmission (aligning with NIST 800-53's SC (System and Communications Protection))
The Privacy Rule: Beyond Technical Controls
While the Security Rule focuses on protecting ePHI, the Privacy Rule governs the use and disclosure of protected health information (PHI). This creates a comprehensive framework that extends beyond technical controls to encompass data governance—a concept central to ISO 27001:2022's risk management approach.
The Privacy Rule establishes:
- Minimum necessary standards for PHI use and disclosure
- Patient rights, including access to their own health information
- Business associate agreements extending HIPAA obligations to third-party vendors
- Breach notification requirements mandating the timely disclosure of security incidents
Financial Consequences: The Cost of Non-Compliance
No Knowledge ($137-$68,928 per violation)
The organization didn't know and reasonably wouldn't have known about the violation
- Annual maximum: $2,067,813
Reasonable Cause ($1,379-$68,928 per violation)
Violation due to reasonable cause, not willful neglect
- Annual maximum: $2,067,813
Willful Neglect (Corrected) ($13,785-$68,928 per violation)
Violation due to willful neglect, but corrected within 30 days
- Annual maximum: $2,067,813
Willful Neglect (Uncorrected) ($68,928-$2,067,813 per violation)
Violation due to willful neglect, not corrected within 30 days
- Annual maximum: $2,067,813
Real-World HIPAA Violations: Learning from Costly Mistakes
$1.6 Million Settlement (2020)
The Texas HHS Commission paid $1.6 million after an unencrypted laptop containing PHI of over 6,600 individuals was stolen from an employee's vehicle.
Key Failures:
- Failure to encrypt devices containing ePHI
- Inadequate device and media controls
- Insufficient workforce training on data protection
- Aligning HIPAA with Modern Security Frameworks
$5.5 Million Settlement (2017)
Memorial Healthcare System in Florida settled for $5.5 million after reporting multiple breaches affecting over 115,000 patients. The violations included the theft of unencrypted laptops and impermissible disclosures of PHI.
Key Failures:
- Failure to encrypt portable devices containing ePHI
- Inadequate physical safeguards for mobile devices
- Insufficient workforce training on HIPAA requirements
- Lack of comprehensive risk assessment
$6.85 Million Settlement (2019)
Premera Blue Cross paid $6.85 million following a 2014 cyberattack that exposed PHI of over 10.4 million individuals. The attack went undetected for nearly eight months, highlighting critical gaps in monitoring and incident detection.
Key Failures:
- Inadequate network segmentation and monitoring
- Insufficient logging and audit controls (violating NIST 800-53 AU controls)
- Lack of timely breach detection and response
- Inadequate risk assessment processes
$16 Million Settlement (2018)
Anthem, one of the largest health insurers in the United States, agreed to pay $16 million to settle potential HIPAA violations stemming from a 2015 cyberattack that compromised the PHI of nearly 79 million individuals. The breach occurred when hackers gained unauthorized access to Anthem's IT system through spear-phishing emails.
Key Failures:
- Inadequate risk analysis and management (violating ISO 27001's risk management principles)
- Insufficient access controls and monitoring (failing NIST 800-53 AC and AU controls)
- Lack of encryption for sensitive data at rest
- Inadequate incident response procedures
This case demonstrates how failures in fundamental cybersecurity controls (encryption, access management, and risk assessment) can result in massive financial penalties and reputational damage.
ISO 27001's risk assessment methodology directly supports HIPAA's required risk analysis. Continuous monitoring and improvement processes enhance ongoing compliance, and management commitment requirements ensure organizational accountability.
Arrakis can help with Enterprise Risk Management (ERM) and integrate risk management frameworks such as ISO 27005, ISO 31000, and the NIST RMF. See our one-pager on ERM here.
ISO 27001's A.9 (Access Control) directly supports HIPAA's access control requirements
- A.12.6 (Management of Technical Vulnerabilities) enhances HIPAA's integrity controls
- A.13.2 (Information Transfer) strengthens HIPAA's transmission security requirements
- AC-2 (Account Management) supports HIPAA's unique user identification requirements
- AC-3 (Access Enforcement) ensures minimum necessary access principles. See our one-pager on Privileged Access Management (PAM) here.
- AC-11 (Session Lock) implements HIPAA's automatic logoff requirements
- AU-2 (Event Logging) and AU-3 (Content of Audit Records) support HIPAA's audit control requirements
- AU-6 (Audit Review, Analysis, and Reporting) enhances breach detection capabilities
- SC-8 (Transmission Confidentiality and Integrity) directly addresses HIPAA's transmission security
- SC-13 (Cryptographic Protection) supports encryption requirements for data at rest and in transit
Building a Comprehensive Compliance Strategy
Successful HIPAA compliance begins with a comprehensive risk assessment—a principle shared with both ISO 27001:2022 and NIST 800-53.
Organizations must:
- Conduct regular risk assessments identifying vulnerabilities in systems containing ePHI. Arrakis can help with our Enterprise Risk Management program. Read our one-pager on Enterprise Risk here.
- Implement appropriate safeguards based on risk assessment findings
- Document security measures and their effectiveness
- Regularly review and update security measures as technology and threats evolve
Effective incident response capabilities are crucial for minimizing the impact of security breaches and ensuring compliance with HIPAA's breach notification requirements:
Immediate Response (0-24 hours):
- Activate the incident response team
- Contain the breach and assess scope
- Preserve evidence for investigation
Short-term Response (1-30 days):
- Conduct a thorough investigation
- Implement corrective measures
- Prepare breach notifications if required
Long-term Response (30+ days):
- Complete breach risk assessment
- Submit required notifications to OCR
- Implement preventive measures to avoid recurrence
Human error remains a leading cause of HIPAA violations. Comprehensive training programs should address:
- HIPAA fundamentals, including Privacy and Security Rule requirements
- Phishing and social engineering awareness to prevent credential theft
- Proper handling of mobile devices and remote access procedures
- Incident reporting procedures to ensure timely breach notification
Emerging Challenges and Future Considerations
Healthcare organizations increasingly rely on cloud services and third-party vendors, creating new compliance challenges:
- Business Associate Agreements (BAAs) must clearly define security responsibilities
- Data residency and sovereignty concerns require careful vendor evaluation
- Shared responsibility models demand a clear understanding of security control allocation
AI and ML technologies present both opportunities and risks for healthcare data protection:
- Data minimization principles must guide AI training data selection
- Algorithmic transparency requirements may conflict with proprietary AI models
- Bias detection and mitigation become crucial for equitable healthcare delivery
Connected medical devices expand the attack surface for healthcare organizations:
- Device inventory and management become critical for security oversight
- Patch management for medical devices requires careful coordination with clinical operations
- Network segmentation helps isolate medical devices from other systems
Becoming Compliant
A DPO should be assigned if processing large sums of ePHI data. This person must be available and involved in any situation where there is a possibility of data loss. The DPO will be the point person for any issues with the affected persons and the Regulatory Authorities. Do you need DPO training? Arrakis can help with our accredited Data Protection Officer Training.
Does your company have a lawful right to receive the data, store the data, or process the data? If you are unsure, you are advised to resolve this immediately, as unlawful possession of ePHI data would constitute a serious violation.
You can no longer buy or build software and then run security assessments or vulnerability analysis after that software tool is in production. Now, you must assess data protection in DevOps and ensure data protection for 3rd-party software before deploying to production.
You can't keep your legacy Windows boxes around anymore because you didn't plan to upgrade, or don't have the budget to do so, and the same applies to software you simply didn't want to go through the hassle of upgrading. Amazingly, even Fortune 100 companies still have Windows 95 computers performing functions on the network. With HIPAA, you must "implement appropriate technical and organizational measures". This means that old equipment or software isn't appropriate and will come to bite you in the end.
To put it simply, if your HIPAA data (or any sensitive data) isn't encrypted, you are in serious trouble. This means it is completely encrypted at rest and in transit. One question is about a site-to-site VPN tunnel. In this particular case, there is not enough encryption because the tunnel is encrypted, but the traffic is not computer-to-computer. Other areas of appropriate security are recommended besides just encryption, but failing to encrypt will be a huge red flag for an investigator if it comes up.
As a part of doing business you will now be expected to assess your levels of data protection and acknowledge or remediate what is needed in order to become HIPAA compliant.
Similar to a data protection assessment, you are now expected to conduct a privacy impact assessment to increase visibility into the level of impact on data subjects and your company in the event of a privacy issue.
As part of transparent communication, data subjects (the person to whom the data actually refers) have the right to request a clear understanding of how their data was used. This means that you will have to be able to effectively report on who accessed or opened data, what they did with the data, who they sent the data to, how the data was destroyed, etc Essentially, complete awareness as it relates to all aspects of how the data was used...this means intense logging.
Data subjects must have a clear and concise method for consenting to the collection of their data, as well as a complete understanding of how their data will be used and stored. So, remember all those websites that indicate they use cookies? You will see a lot more of that! There can be no confusion on the consent message at all. The data subject must also be able to revoke consent as easily as invoking it.
You must be able to demonstrate how HIPAA data flows accurately through your network, is processed, and is stored.
Now, you must have the appropriate administrative controls in place to protect HIPAA data. This means you can no longer run a business without solid policies that meet ISO, NIST, GDPR, and other standards. Your policies would need to cover data classification, data retention, data destruction, encryption, and related topics. Do you need auditable policies? Read our one-pager on Policies here.
Data Subject Rights
Similar to the logging concept, the data subject has the right to complete and transparent communication about how their data is stored or used. This communication must be conducted in a secure manner that doesn't put the data subject at risk. Additionally, the first request from a data subject is free; any follow-up request may be charged.
Again, as mentioned in the logging bullet point, the data subject has a right to see their own information. There can be no restrictions on access, or intentional deletion or denial of data.
The data subject has the right to correct or change their information if they feel it is incorrect. There are caveats to this, though. For example, a person who was diagnosed with HIV can't demand that the official record reflect something different.
The data subject has the right to insist on the total and complete erasure of their data. There are exceptions to this, but they mostly concern the health industry and the criminal justice system.
The data subject has the right to restrict processing or prevent specific entities from accessing HIPAA data.
The data subject has every right to be notified as soon as possible of any issues or loss of their data, and the company has a limited amount of time to ensure this happens.
You may only keep HIPAA data for as long as you legitimately need it. Retaining longer puts your company at risk and violates HIPAA.
The data subject has the right to object to the reason for processing or storage.
Conclusion: Building Resilient Healthcare Security
HIPAA compliance goes far beyond a regulatory checkbox—it's a comprehensive approach to protecting patient privacy and maintaining trust in healthcare systems. By aligning HIPAA requirements with proven frameworks like ISO 27001:2022 and NIST 800-53, healthcare organizations can build robust security programs that not only meet regulatory requirements but also defend against evolving cyber threats.
The financial and reputational consequences of HIPAA violations continue to escalate, making proactive compliance investment a business imperative. Organizations that view HIPAA as an opportunity to strengthen their overall security posture (rather than merely a compliance burden) will be better positioned to protect patient data, maintain operational continuity, and build lasting trust with the communities they serve.
Success in healthcare cybersecurity requires a holistic approach combining technical controls, administrative procedures, physical safeguards, and ongoing risk management. By learning from others' costly mistakes and implementing comprehensive security frameworks, healthcare organizations can transform HIPAA compliance from a challenge into a competitive advantage in an increasingly digital healthcare landscape.
The path forward demands continuous vigilance, regular assessment, and adaptive security measures that evolve with emerging threats and technologies. Healthcare organizations that embrace this challenge will not only protect their patients' most sensitive information but also contribute to a more secure and trustworthy healthcare ecosystem for all.
You should also understand that HIPAA is an overlay regulation. This means you could be fined under HIPAA and then face more stringent penalties under other laws or regulations.
What happens if you get caught? Naturally, you should immediately show an "attitude of compliance" and offer your complete support in their investigation. Even if this results in temporary downtime or a loss of productivity, you should show that you are "very concerned" and are willing to offer any support needed to expedite the closure of the investigation. The short story provides the absolute best example of compliance and cooperation possible. Hold nothing back and keep no secrets from the investigators. Let's not forget that you should also immediately alert your legal team.
However, you should also honestly ask yourself if you deserved to get caught. Did you prepare for HIPAA? Did you even attempt to conform with HIPAA promptly, or did you start to care after you had already received HIPAA data? Do you honestly know you have areas that need improvement, but you just "haven't gotten around to it"? Can you effectively demonstrate that you truly care about protecting data and the lawful processing of that data? If you didn't make any attempts and simply hoped that the regulators would never find you, then you truly deserved to get caught. The protection of data should never be taken lightly; it should be treated with the utmost seriousness. The cost of compliance will always be less than the cost of sanctions. Think of it this way: if you leave your house unlocked and get robbed, the police or your insurance company will probably not look favorably on your lack of concern for protecting your valuables.
What happens if you receive sanctions? Well, first, the sanctions can be extensive. For smaller companies, this can be devastating, simply not possible, and put the company out of business. This means jobs will be lost, and families may be at risk. This doesn't mean sanctions won't occur, just that the sanctions may be of a nature that effectively delivers the message of why they occurred without destroying the entire company. Your company should also consider negotiations and the use of any appeal process that may be available to help reduce the sanctions, or propose the possibility of paying any fines or penalties over time rather than all at once. Assuming none of that works, then you should figure out how you are going to pay those fines. Additionally, you will have to deal with reputational and political risks related to customer trust. You will likely want to connect with a professional PR firm that specializes in mitigating potential damage. What you absolutely should not do is portray anything less than the truth to your customers. If this paragraph reads as new material for you, then you might want to consider an Enterprise Risk Management (ERM) program. Arrakis can help you build out a program to reduce risk to your company. Read our one-pager on ERM here.
This article doesn't cover all aspects of HIPAA; it covers only the highlights. If you even suspect that you may have HIPAA data, then you are encouraged to contact us. Arrakis has experience helping companies move closer to HIPAA compliance and can help you resolve your HIPAA issues before they become serious. Arrakis has provided HIPAA consultation to numerous companies to help achieve this goal. Contact us today so we can help you help yourself!
A rapid assessment that gives you high visibility of your environment to give you a rough understanding of your posture and potential risk. Generally lasts 3-5 weeks. The activities would involve 5-10 hour-long interviews and a review of current policies/standards/procedures, with everything wrapped up in an informative report.
A detailed assessment of your posture and potential risk. Deliverables will include a detailed report and an SOW for Arrakis support in remediation. The activities would involve 10-20 hour-long, detailed interviews; a review of current policies/standards/procedures; and a review of network topology maps, data flow diagrams, etc. Generally lasts 7-9 weeks.
Arrakis will provide detailed, informative support in remediation. Arrakis personnel will be high-quality, with numerous years of experience and remediation projects under their belts, and generally of the "C" suite type.