Why HIPAA Compliance Still Trips Up So Many Healthcare Organizations

Every year, the Department of Health and Human Services publishes a list of healthcare data breaches affecting 500 or more individuals. It’s sometimes called the “Wall of Shame,” and it keeps getting longer. In 2025 alone, hundreds of organizations appeared on that list, many of them mid-sized practices and clinics that assumed their IT setup was good enough. It wasn’t.

HIPAA compliance isn’t just a checkbox exercise. It’s a living, breathing set of requirements that touches every piece of technology a healthcare organization uses, from the EHR system to the Wi-Fi network in the waiting room. And for organizations in the Long Island, New York City, Connecticut, and New Jersey corridor, where healthcare is a major employer, getting this right has real consequences for patient trust, financial stability, and long-term survival.

What HIPAA Actually Requires on the IT Side

Most people in healthcare have a general sense that HIPAA protects patient information. But the technical requirements are more specific than many realize. The HIPAA Security Rule breaks down into three categories of safeguards: administrative, physical, and technical. IT teams tend to focus on the technical safeguards, but all three overlap in practice.

Technical safeguards include things like access controls, audit logs, integrity controls, and transmission security. That means every system that stores or transmits electronic protected health information (ePHI) needs to have mechanisms in place to restrict who can see the data, track who actually accessed it, verify it hasn’t been tampered with, and encrypt it when it moves across a network.

Administrative safeguards cover policies and procedures. Who is the designated security officer? Has a risk analysis been completed? Are workforce members trained on security awareness? These aren’t just HR formalities. The Office for Civil Rights (OCR) looks at documentation closely during audits and investigations.

Physical safeguards are sometimes overlooked in IT planning. They include facility access controls and workstation security. A server room that anyone can walk into or a laptop left unlocked at a nurse’s station can lead to a reportable breach just as easily as a sophisticated phishing attack.

Where Organizations Keep Getting It Wrong

The most common HIPAA violation cited by OCR isn’t some exotic cyberattack. It’s the failure to conduct a thorough risk analysis. Year after year, this shows up in settlement agreements and corrective action plans. Organizations either skip the risk analysis entirely, do it once and never update it, or treat it as a paper exercise that doesn’t actually inform their security decisions.

A proper risk analysis identifies where ePHI lives, how it moves, what threats exist, and what vulnerabilities could be exploited. It then assigns risk levels and guides the organization toward reasonable and appropriate safeguards. The key phrase there is “reasonable and appropriate,” which means HIPAA doesn’t demand perfection, but it does demand thoughtfulness.

Encryption Gaps

Another persistent problem is inconsistent encryption. HIPAA doesn’t technically mandate encryption in all cases, but it’s considered an “addressable” specification. That means an organization needs to either implement it or document why an equivalent alternative is in place. In practice, not encrypting data at rest and in transit is extremely hard to justify. Encrypted emails, encrypted drives, encrypted backups. These should be standard across any healthcare IT environment by now, and yet breach reports regularly cite unencrypted devices as the root cause.

Access Control Failures

Too many organizations still operate with overly broad access permissions. Front desk staff shouldn’t have the same level of access as a physician. Billing departments don’t need to see clinical notes. Role-based access control (RBAC) is a well-established approach that assigns permissions based on job function, and it should be reviewed regularly. Staff turnover, role changes, and system updates can all create access creep if nobody is paying attention.

The Ransomware Problem Isn’t Going Away

Healthcare has become one of the most targeted sectors for ransomware. The reason is straightforward: healthcare organizations hold sensitive data, often run on legacy systems, and face enormous pressure to restore operations quickly. Attackers know that a hospital or clinic is more likely to pay a ransom than a company that can afford a week of downtime.

Ransomware attacks on healthcare entities can constitute HIPAA breaches if ePHI is accessed or exfiltrated during the attack. OCR has issued guidance specifically on this point. Even if an organization pays the ransom and recovers its data, it may still face an investigation and potential penalties if the incident wasn’t handled according to HIPAA’s breach notification requirements.

Preventing ransomware comes down to layered security. Email filtering catches many phishing attempts before they reach inboxes. Endpoint detection and response (EDR) tools monitor for suspicious behavior on workstations and servers. Network segmentation limits how far an attacker can move laterally once inside. And reliable, tested backups stored offline or in immutable cloud storage provide a recovery path that doesn’t involve paying criminals.

Business Associates and Third-Party Risk

HIPAA compliance doesn’t stop at an organization’s own walls. Any vendor or partner that handles ePHI on behalf of a covered entity is considered a business associate, and they’re subject to the same security requirements. This includes IT service providers, cloud hosting companies, billing services, shredding companies, and even some software vendors.

A signed Business Associate Agreement (BAA) is legally required before sharing ePHI with any third party. But a signed contract alone doesn’t reduce risk. Smart organizations also evaluate their business associates’ security posture, ask for evidence of compliance, and monitor the relationship over time. Some of the largest healthcare breaches in recent years originated not with the healthcare organization itself but with a business associate that had weaker security controls.

How Managed IT Services Fit Into the Picture

For small and mid-sized healthcare organizations, building an in-house IT security team with deep HIPAA expertise can be prohibitively expensive. That’s one reason many turn to managed IT service providers that specialize in healthcare and regulatory compliance. These providers can handle everything from day-to-day help desk support to security monitoring, risk assessments, and incident response planning.

The right managed services partner will understand not just the technology but the regulatory landscape. They’ll know how HIPAA intersects with state-level privacy laws, which vary across New York, Connecticut, and New Jersey. They’ll also be familiar with related frameworks like the NIST Cybersecurity Framework, which OCR has pointed to as a useful structure for building a HIPAA-compliant security program.

Outsourcing IT doesn’t relieve a healthcare organization of its compliance obligations, though. The covered entity remains responsible for ensuring that its business associates, including IT providers, meet HIPAA requirements. Due diligence in selecting and overseeing these relationships is part of the compliance equation.

Building a Culture of Compliance

Technology alone won’t solve HIPAA compliance. The human element matters just as much, if not more. Security awareness training should happen regularly, not just during onboarding. Staff need to recognize phishing emails, understand why they shouldn’t share passwords, and know how to report a suspected incident without fear of punishment.

Organizations that treat compliance as a one-time project tend to fall behind quickly. Threats evolve. Systems change. Staff turn over. A compliance program needs ongoing attention, regular risk assessments, updated policies, periodic audits, and leadership that takes it seriously from the top down.

The financial stakes are significant. HIPAA penalties can range from $100 to $50,000 per violation, with annual maximums reaching into the millions depending on the level of negligence. Beyond fines, breaches damage reputation, erode patient trust, and can trigger class-action lawsuits. For smaller practices operating on thin margins, a major breach can be an existential event.

Healthcare organizations that invest in solid IT security infrastructure, partner with knowledgeable service providers, and commit to ongoing compliance aren’t just avoiding penalties. They’re protecting the patients who trust them with some of the most sensitive information that exists. That’s a responsibility worth taking seriously.