REPORT

What small healthcare practices get wrong about HIPAA and email security

HIPAA failure is skyrocketing in small healthcare practices.

REPORT

2025 healthcare email security report

Key insights from 180 email-related healthcare breaches and actionable steps to protect your organization.

 

Download the report

Cybersecurity graphic
REPORT

2025 healthcare email security report

Key insights from 180 email-related healthcare breaches and actionable steps to protect your organization.


Download the report

2025-03-07_REPORT_StateofSecurity-1

Top takeaways

What the data reveals about where small healthcare practices are getting HIPAA wrong, and what it means for patient trust, compliance, and security.
RPT.202508.SMB Stats-3

83% of small practice IT managers believe that patient consent removes the need for encryption

RPT.202508.SMB Stats-2

64% believe portals are required for HIPAA

RPT.202508.SMB Stats

20% of SMBs don't utilize any form of email archiving or audit trail

RPT.202508.SMB Stats-4

The average amount of time to detect and contain healthcare breaches is 10 months

Email vs patient portals-1
Email vs patient portals (2)
Low risk email security infographic
HIPAA fines infographic

Key resources

1

2025 Report: What small healthcare practices get wrong about HIPAA and email security

Many small practices rely on false assumptions about HIPAA compliance, leaving patient data exposed.

2
Executive summary: What small healthcare practices get wrong about HIPAA and email security

Survey data reveals small healthcare organizations are overconfident yet dangerously unprepared for HIPAA risks.

3
Infographic; What small healthcare practices get wrong about HIPAA and email security

Visual insights show how common misconceptions about encryption and portals create compliance blind spots.

4
Report excerpt: Small practices think they're compliant. The data says otherwise
Despite strong confidence in compliance, most small practices misunderstand HIPAA’s encryption and logging requirements.

5
Report excerpt: Audit trails, encryption, logging–most SMBs skip the basics

Without audit trails or enforced encryption, small practices cannot prove HIPAA compliance or prevent breaches.

6
Report excerpt: Small means safe? Not anymore

Phishing now targets small practices directly, exploiting weak defenses and overwhelming clinical staff workloads.