Healthcare Cybersecurity Risks: What HIPAA Requires | GoCo

Healthcare Cybersecurity Risks: What HIPAA Requires | GoCo

GoCo Team
September 28, 2026
6 min read

Healthcare cybersecurity risks go beyond your BAA - see what HIPAA already requires and where clinics get caught out. 🔒 Learn more.


Healthcare cybersecurity risks rarely start with an exotic exploit. They start with a login that had no second factor, a laptop that kept access after someone left, or a vendor contract nobody re-read in three years. A signed Business Associate Agreement (BAA) and a HIPAA training sign-in sheet feel like proof of readiness, but neither one tells you whether a real incident would find those gaps. Below are the practices that most directly change what a breach costs a healthcare business, and the HIPAA obligations most clinics assume are already handled.

What Healthcare Cybersecurity Risks Actually Cost

Healthcare has the highest average breach cost of any industry IBM tracks: $6.64 million per incident, per the IBM Cost of a Data Breach Report 2026. IBM's methodology prices a breach primarily by records compromised, at roughly $192 per record - which is why a small practice's real exposure looks nothing like a hospital system's, even in the same industry. Six factors move that number up or down more than any others: security AI and automation (-$1.93M), a written AI usage policy with access controls (-$670K when present), detecting and containing an incident inside 200 days (-$1.33M), encryption at rest and in transit (-$213K), a recent review of vendor security practices (-$227K), and staying current on the compliance requirements that apply to you (-$201K). Each section below is one of those levers, or a HIPAA-specific obligation that compounds them.

Multi-Factor Authentication and Same-Day Access Removal

Stolen or reused credentials remain one of the most common ways attackers get into a network in the first place - a single password is rarely enough friction to stop someone determined to get in. MFA on every account that can reach patient data closes that gap directly. The second, quieter version of the same risk is offboarding: an employee, contractor or intern who changes roles or leaves but keeps access for days or weeks. Every login a former staff member could still use is a login your practice isn't watching. Pair MFA with a same-day access-removal checklist owned jointly by HR and IT, not left to whoever remembers.

Encrypting Patient Data at Rest and in Transit

Encryption doesn't stop every attack, but it changes what an attacker gets when one succeeds - the difference between a breach of exposed records and a breach of unreadable ones. HIPAA's current Security Rule already treats encryption as an addressable specification for ePHI, and the proposed update to the rule would make it a near-universal requirement with only narrow exceptions. A practice that encrypts patient data at rest (on servers, laptops, backups) and in transit (email, file transfers, patient portals) today isn't just lowering its breach cost - it's already ahead of where the rule is heading.

Incident Response and How Fast You Detect a Breach

The gap between when a breach happens and when it's caught and contained is one of the largest cost drivers IBM measures. A written incident response plan matters less for the document itself than for what it forces you to know in advance: who gets called first, which systems get isolated, and how you'd restore the EHR and scheduling system if you had to. If you've never actually timed a restore from backup, you don't know your real recovery time - you know your assumption about it.

Vendor and Third-Party Risk Review

Every clinic accumulates vendors: the EHR platform, the billing service, the practice-management tool, the cloud backup provider. Each one that can reach patient data is a door into your systems that isn't yours to lock. Reviewing vendor security practices - not just collecting a signed contract, but confirming what they actually do - is worth up to $227K in avoided breach cost according to IBM's 2026 data, and it's the kind of review that's easy to defer indefinitely because no single vendor ever forces the question.

Staying Current on Regulatory Compliance

Compliance requirements don't hold still: HIPAA's Security Rule is under active proposed revision, state breach-notification laws vary, and payer and accreditation requirements shift on their own schedule. "Current" doesn't mean a binder from two years ago - it means someone owns the question of what changed and when your policies were last checked against it.

Your Business Associate Agreements

A BAA with every vendor that touches ePHI isn't optional - it's a specific, named requirement, and it's also one of the most commonly incomplete pieces of a practice's HIPAA posture. Practices accumulate IT vendors over years, and rarely does one person hold a current list of who has access, which agreement covers them, and when it was last reviewed. If your MSP or IT vendor can reach patient data and there's no signed BAA on file, that's not a paperwork gap - it's an open compliance finding waiting for an audit or a breach to surface it.

Your HIPAA Security Risk Analysis

HHS's Office for Civil Rights has been direct about this: in ransomware settlements announced in 2026 covering more than 427,000 affected people, the common finding across every case wasn't the ransomware itself - it was the absence of an accurate, thorough, and current risk analysis under 45 CFR 164.308(a)(1)(ii)(A). A risk analysis that hasn't been updated since your last EHR migration, office move, or new vendor doesn't reflect your actual exposure anymore. It has to name where ePHI lives, rate the real risks, and assign an owner and a date to each one - not sit as a one-time compliance exercise from years ago.

Shadow AI, Patient Data, and What to Do Next

healthcare cybersecurity risks: Shadow AI, Patient Data, and What to Do Next

A newer version of the same risk: staff using AI tools with patient information that were never reviewed for HIPAA compliance - pasting notes into a chatbot, summarizing charts with an unapproved tool. Without a written policy governing AI use and the access controls behind it, there's no way to know where that data went or whether the tool itself is a business associate that needed a BAA in the first place. IBM's 2026 data prices a written AI governance policy at roughly $670K in avoided breach cost - one of the more overlooked levers on this list, because it's a risk few practices have thought to ask about yet.

None of these healthcare cybersecurity risks require an exotic defense - MFA, encryption, a tested incident response plan, reviewed vendors, current compliance, real BAAs, a fresh risk analysis, and a policy for how staff use AI. Most of them are things a practice already believes it has handled. The businesses that hold up under a real incident are the ones that checked.

Do you know which of these gaps your practice has?

Most practices believe MFA, BAAs, and the HIPAA risk analysis are handled, and learn otherwise from an OCR finding or a breach - the most expensive moment to find out. The good news: every item on this list is fixable once someone names it.

In a short meeting, our team will walk through where you stand today, which gaps carry the most risk, and what to fix first. Pick a time that works for you.

Book your meeting with our team

Because better decisions start with better understanding.

Good Company IT

GoCo

You are in Good Company