Healthcare information technology security priorities for safer connected care

The security question has shifted from data protection to care continuity
Healthcare information technology security is no longer limited to preventing unauthorized disclosure of electronic protected health information. It also means keeping scheduling, claims, pharmacy, imaging, laboratory, telehealth, remote monitoring and connected medical device workflows available when an attack occurs. Recent U.S. healthcare breach reporting shows how attackers are exploiting networked systems, credentials, business associates and recovery gaps at a scale that can disrupt care. HHS Office for Civil Rights reported 663 breaches affecting 500 or more individuals that occurred in calendar year 2024, affecting about 242.9 million individuals; hacking and IT incidents made up 81% of those large-breach reports and 99% of the affected individuals. (hhs.gov)
For hospitals, clinics, device makers and healthcare technology vendors, the operational conclusion is clear: security programs need to move beyond policy-only compliance into measurable controls. Identity, least privilege, asset inventory, segmentation, logging, tested recovery, vendor oversight and device lifecycle governance should be treated as operating requirements, not optional technical projects.

What recent breach data says about security priorities
The 2024 HHS OCR breach report gives healthcare leaders a useful evidence base for setting priorities when budgets and staff time are limited. Network servers were the largest location category for large breaches, accounting for 63% of reports and 98% of affected individuals. Business associates represented only 16% of large-breach reports but 85% of affected individuals, pointing to concentration risk in clearinghouses, cloud providers, revenue-cycle vendors, managed service providers and other third parties. (hhs.gov)
| Risk signal | Reported evidence | Security implication |
|---|---|---|
| Hacking and IT incidents dominate large breaches | 534 large-breach reports in 2024, affecting about 241.6 million individuals | Prioritize authentication, vulnerability management, endpoint protection, monitoring and incident response |
| Network servers carry the largest exposure | 418 reports involved network servers, affecting about 238.5 million individuals | Segment sensitive systems, harden servers, monitor privileged access and test backup restoration |
| Business associates amplify impact | 106 reports from business associates affected about 206.9 million individuals | Strengthen vendor due diligence, contract security requirements, access reviews and incident-notification procedures |
| Email remains a common breach location | 164 reports involved email, affecting about 4.0 million individuals | Use phishing-resistant MFA where feasible, mailbox logging, secure email gateways and rapid account containment |
These figures do not mean every organization should buy the same tools. A rural clinic, specialty practice, device manufacturer and multi-hospital system all have different architectures and risk profiles. The pattern does mean every healthcare entity should be able to answer the same operational questions: which systems hold ePHI, who can access them, which vendors can reach them, how suspicious activity is detected, and how quickly critical functions can be restored.
HIPAA remains the baseline, but expectations are becoming more specific
As of September 30, 2026, the current HIPAA Security Rule remains in effect. HHS OCR issued a proposed rule on December 27, 2024, to strengthen cybersecurity protections for electronic protected health information, but a proposed rule is not the same as a final rule. The federal regulatory agenda entry for the HIPAA Security Rule to strengthen cybersecurity lists final action for July 2027, so organizations should not present proposed provisions as current legal requirements. Even so, the proposal is a strong signal of where regulators believe healthcare security controls need to mature. (hhs.gov)
The practical baseline remains risk analysis, risk management and implementation of appropriate administrative, physical and technical safeguards. NIST Special Publication 800-66 Revision 2, published in February 2024, provides a healthcare-specific resource for understanding the HIPAA Security Rule and safeguarding ePHI across organizations of different sizes. NIST Cybersecurity Framework 2.0, also released in February 2024, places stronger emphasis on governance and supply-chain risk, which fits a healthcare environment built around vendors, cloud platforms and device ecosystems. (nist.gov)
OCR’s 2024 enforcement discussion also highlights recurring weak points: incomplete risk analysis, weak risk management, insufficient information system activity review, missing or ineffective audit controls, weak authentication and access-control failures. In practice, the most important healthcare information technology security work is often not exotic. It is disciplined execution of basic controls in complex clinical environments.
The control priorities that matter most in clinical environments
Identity and access management
Compromised credentials remain a common pathway into healthcare systems. OCR’s 2024 report described weak passwords, default passwords, single-factor remote access and excessive privileges as problems observed in investigations. Healthcare organizations should start with multi-factor authentication for remote access and privileged accounts, unique user accounts, role-based access, periodic access reviews and rapid removal of access when workers or vendors change roles. Shared administrator accounts should be eliminated or tightly controlled because they make accountability and containment harder.
Asset inventory and segmentation
Security teams cannot protect what they cannot see. A useful inventory should include EHR systems, imaging archives, laboratory systems, pharmacy systems, billing platforms, identity systems, backup repositories, network appliances, cloud services, laptops, mobile devices, connected medical devices and vendor-managed systems. Segmentation should then separate high-risk or high-value systems so that a compromised workstation or vendor account cannot easily reach every clinical and administrative platform.
Monitoring and audit review
Logging is valuable only when it is reviewed, tuned and tied to response procedures. OCR has identified ad hoc or breach-only review of system activity as a weakness. At a minimum, healthcare IT teams should monitor privileged login activity, remote access, unusual data export, suspicious mailbox rules, disabled security tools, failed login spikes, new administrator accounts and unexpected communication between clinical networks and external destinations.
Resilience and downtime readiness
Backups are not enough if they are reachable by attackers, untested or too slow to restore. Healthcare organizations should define recovery priorities by clinical impact, not just by application owner. Emergency department registration, medication administration, imaging access, lab results, call-center functions and claims submission may each have different recovery-time needs. Downtime procedures should be tested with clinical, IT, compliance, legal, finance, communications and vendor teams involved together.
Medical devices make security a patient safety issue
Connected medical devices expand the definition of healthcare IT. FDA notes that medical devices are increasingly connected to the internet, hospital networks and other devices, which can improve care but also increase cybersecurity risk. FDA also states that threats and vulnerabilities cannot be eliminated and that manufacturers, hospitals and facilities must work together to manage risk. Section 524B of the Federal Food, Drug, and Cosmetic Act took effect on March 29, 2023, and FDA issued updated final guidance on June 27, 2025, addressing cybersecurity design, labeling and premarket submission documentation for cyber devices. (fda.gov)
For healthcare delivery organizations, device cybersecurity cannot sit outside the main security program. Procurement teams should request security documentation, software component information where available, patch and support commitments, coordinated vulnerability disclosure processes, remote-access details and network requirements before purchase. Clinical engineering and IT should maintain a shared inventory, agree on patch-testing procedures, segment device networks and document compensating controls for devices that cannot be patched quickly. See also: clinical equipment.
Third-party concentration is now a board-level risk
The Change Healthcare ransomware attack in February 2024 showed how a single technology dependency can affect claims processing, provider cash flow and patient care across the sector. GAO reported that the incident involved theft of data, estimated losses of $874 million and widespread impacts on healthcare providers and patient care. GAO also noted that HHS had not yet implemented all prior recommendations for strengthening sector cybersecurity coordination and risk management, including work related to IoT and operational technology risk. (gao.gov)
The board-level lesson is that vendor security cannot be reduced to a questionnaire filed during procurement. Healthcare organizations should maintain a current list of critical third parties, identify which vendors can access ePHI or core systems, classify vendors by operational dependency, require incident-notification obligations, review business continuity plans and test how the organization would operate if a major vendor were unavailable for days or weeks.
A practical roadmap for healthcare information technology security
A mature program does not need to start with dozens of disconnected initiatives. It should begin with a focused roadmap that connects security work to patient care, compliance and operational resilience. For more healthcare technology coverage, visit the healthcare technology section.
| Timeframe | Priority actions | Expected value |
|---|---|---|
| First 30 days | Confirm ePHI system inventory, remote-access paths, critical vendors, backup locations and privileged accounts | Creates visibility into the most likely breach and outage paths |
| 30 to 90 days | Expand MFA, remove shared admin accounts, segment critical systems, validate backup restoration and formalize incident roles | Reduces credential abuse, lateral movement and recovery uncertainty |
| 90 to 180 days | Improve logging use cases, conduct tabletop exercises, review business associate controls and align risk analysis with NIST guidance | Turns compliance artifacts into operational response capability |
| Ongoing | Review access, patch exposure, device support status, vendor risk, downtime procedures and lessons from incidents | Maintains security as clinical systems, threats and regulations change |
This roadmap is not a substitute for legal advice or a full security assessment. It is a practical way to translate HIPAA, NIST, FDA and OCR signals into actions that can be assigned, tested and improved.
Frequently asked questions
Is healthcare IT security the same as HIPAA compliance?
No. HIPAA compliance is a legal and regulatory foundation for protecting ePHI, but healthcare IT security also includes operational resilience, medical device risk, vendor dependency, network security, identity governance, monitoring and recovery planning. A compliant policy that is not implemented or tested may still leave patients and operations exposed.
What should a small clinic prioritize first?
A small clinic should start with an accurate risk analysis, MFA for remote access and email, unique accounts, secure backups, endpoint protection, patching, phishing awareness, vendor access review and a simple downtime plan. These controls address common attack paths without requiring a large security department.
How should healthcare organizations handle medical device cybersecurity?
They should treat devices as part of the enterprise technology environment. That means maintaining an inventory, segmenting device networks, tracking patch status, reviewing manufacturer security information, controlling remote access and coordinating decisions among clinical engineering, IT, security, procurement and patient-safety leaders.
Should organizations wait for a final HIPAA Security Rule update before making changes?
No. The current Security Rule remains in effect, and the main improvement areas identified by OCR and NIST already point to practical actions: risk analysis, access control, authentication, audit activity review, vendor oversight and recovery readiness. Waiting for a final rule can leave known risks unaddressed.
Bottom line
Healthcare information technology security is becoming more specific, measurable and operational. The organizations that are better prepared will not be the ones with the longest policy binders. They will be the ones that know their assets, control identities, limit lateral movement, monitor meaningful events, govern vendors and devices, and practice recovery before an outage threatens care delivery.


