Cybersecurity for Healthcare and Dental Practices: What HIPAA Actually Requires
Healthcare and dental practices are high-value targets for ransomware and data theft. HIPAA has teeth — and so do the attackers. Here is what small to mid-size practices need to do to protect patient data and stay compliant.
By Tom Brennan
Healthcare and dental practices handle some of the most sensitive personal data that exists — protected health information (PHI) — and they are among the most frequently targeted organizations by ransomware operators. HIPAA's Security Rule creates specific technical, physical, and administrative safeguard requirements that apply to every covered entity and business associate.
What Does HIPAA Actually Require — And What Do Most Practices Miss?
HIPAA compliance is frequently misunderstood as a one-time checklist. It is not. The Security Rule requires an ongoing risk management program — a documented, repeatable process for identifying, assessing, and remediating risks to PHI on a continuous basis. Most enforcement actions and breach settlements cite failures in the risk analysis and risk management standards, not failures to deploy a specific technology.
What Are the HIPAA Security Rule's Core Requirements?
Administrative Safeguards
- Security Management Process — documented risk assessment and risk management program conducted regularly, not just at implementation
- Designated Security Responsibility — a named security officer; for small practices, this is typically the office manager or a CyberAdvisor™ serving in a fractional capacity
- Workforce Training — documented, role-appropriate security awareness training with records of completion
- Contingency Planning — a tested business continuity and disaster recovery plan specifically covering PHI systems
- Access Management — formal processes for granting, modifying, and terminating workforce access to PHI
Technical Safeguards
- Access control — unique user IDs, automatic logoff, encryption for remote access to PHI systems
- Audit controls — activity logs for all systems containing PHI, retained and regularly reviewed
- Transmission security — encryption for PHI transmitted over any network, including email and patient portals
- Authentication — verified user identity before PHI access is granted
Physical Safeguards
- Workstation use controls — screens not visible to patients or visitors
- Device and media controls — documented procedures for hardware disposal that prevent PHI recovery
- Facility access controls — documented procedures governing physical access to systems containing PHI
What Do Ransomware Operators Actually Target in Healthcare?
Ransomware operators targeting healthcare specifically look for: unpatched systems running legacy software, unencrypted or network-accessible backup systems, weak or absent MFA on remote access and VPN connections, and practice management software accessible via exposed RDP ports. The pattern is consistent across hundreds of healthcare breaches — the technical entry points are predictable and largely preventable.
A healthcare-specific ransomware attack creates a compounding crisis: clinical operations halt, breach notification obligations trigger under both HIPAA and state law, HHS Office for Civil Rights may initiate an investigation, and the reputational damage to a practice that patients trust with their most personal information can be severe.
What Should Small and Mid-Size Practices Prioritize?
- Complete a formal risk analysis — document every system that touches PHI and assess the risks to each
- Enforce MFA on all remote access — VPN, remote desktop, and practice management software portals
- Encrypt PHI at rest and in transit — including email; standard email is not HIPAA-compliant for PHI
- Test your backup recovery — not just the backup, but the actual restoration process under realistic conditions
- Document your contingency plan — clinical staff need to know exactly what to do when systems go down
Proactive Risk's MEASURERISK practice includes HIPAA-aligned security assessments for healthcare and dental practices of all sizes. Contact us to schedule yours.
Free HIPAA Compliance Resources
Put these HIPAA requirements into practice with Proactive Risk's free resources, available in the Downloads library:
- Department Alignment Interview & Role Mapping Checklist — a structured intake tool for mapping security control ownership across all 18 CIS v8.1 controls to the staff who own them, surfacing the accountability gaps HIPAA's administrative safeguards require you to close
- Security Incident Response Plan (SIRP) Template — a ready-to-customize SIRP aligned to NIST SP 800-61, covering the contingency planning requirements HIPAA mandates for PHI systems — including breach notification timelines