A recent analysis on Healthcare Security Breaches in the United States: Insights and their Socio-Technical Implications found thata significant proportion of breaches are precipitated by human errors and practices.

The authors describe healthcare data management as existing at the intersection of technology and human conduct, finding that many security incidents involve human errors, practices, organizational weaknesses, and technological vulnerabilities.

As a result, HIPAA-covered entities, like healthcare organizations, must consider how employees use technology, whether security policies support workflows, how vendors handle PHI, and whether the organization's culture encourages secure behavior.

 

Socio-technical systems in healthcare security

A socio-technical system is one in which people and technology interact to achieve a particular outcome. In healthcare, this includes electronic health record systems (EHRs), email platforms, networks and servers, cloud applications, and mobile devices.

The social side includes organizational staff, like healthcare workers, administrative staff, IT and security teams, management practices, and relationships with vendors and business associates. The authors explain that socio-technical systems incorporatethe technical aspects (software, hardware, network configurations)andthe social aspects (work routines, organizational structures, user behaviors)of a system. HIPAA security should therefore be viewed as the result of an entire system working together.

 

Digitization and new security challenges

The abovementioned analysis says that while EHR adoption has increased in the United States, human systems and organizational practices often change much more slowly. They identify this mismatch as a source of socio-technical challenges, including challenges related to information security.

Moreover, employees may develop informal workarounds when approved technology is inconvenient. For example, an employee may know that protected health information (PHI) should be safeguarded but still use an unapproved application because it is faster than the organization's designated system.

A socio-technical approach encourages healthcare organizations to ask whether their technology supports secure workflows and if employees are given practical guidance for using it.

 

Why human behavior is a security concern

The research paper found that phishing, unauthorized access, and hacking incidents were prominent among healthcare breaches. It explains that the prominence of phishing and unauthorized accessunderscores the human component as a significant vulnerability in the healthcare data ecosystem.

Cybercriminals create phishing messages and social engineering attacks that exploit ordinary human behavior. An employee may be busy, distracted, tired, or working with a patient. Attackers understand these conditions and use urgency to make malicious communications appear legitimate.

To combat these risks, healthcare organizations must implement technical safeguards that can help identify suspicious activity and limit unauthorized access. Administrative safeguards can also help organizations implement their policies and responsibilities.

Regular cybersecurity training can help employees recognize potential threats. The research article notes that mandatory HIPAA security training can be viewed as achoreand that healthcare workers may not always pay practical attention to it. The researchers also identify staff retraining, particularly in email security, as a common response to security incidents.

This suggests that security awareness should be ongoing, especially as attackers use new social engineering techniques. Employees encounter new applications and communication methods. Effective training should therefore be ongoing and connected to employees' actual responsibilities.

For example, staff members who regularly handle email should understand how phishing messages can appear in healthcare communications. Employees who manage patient records should understand appropriate access controls. Managers should understand their responsibilities for enforcing security policies. IT teams should understand how technical decisions affect clinical workflows.

Training can also be more effective when employees understand the consequences of a security incident, like how a data breach can affect an organization's operations and reputation.

Learn more: The human impact of cyberattacks

 

Technology vs weak organizational practices

The paper identifies inadequate security management processes as another socio-technical problem. According to the article on healthcare security breaches in the US, insufficient procedures can leave healthcare organizations vulnerable to breaches of individuals’ PHI.

The study suggests that organizational policies confirm who can access PHI, how it can be shared, how risks are identified and addressed, and how security incidents are reported and investigated. Moreover, these policies should also be maintained and updated as technology and organizational practices change. A good organizational policy must reflect clinical and administrative workflows, so employees aren’t burdened with unnecessary or inconvenient security steps.

In addition, healthcare organizations that rely on business associates, like cloud providers, billing companies, communication vendors, transcription services, and consultants, must verify that these third parties also adhere to the same PHI security policies. This includes conducting regular audits and assessments to confirm compliance and address any potential vulnerabilities in the handling of sensitive information.

As the study states, prioritizing data securitynot just within a single entity but across all partners and stakeholders is crucial.Healthcare organizations must understand what PHI the vendor receives, who can access it, and whether the vendor can support HIPAA obligations by signing a business associate agreement (BAA).

Vendor management is therefore a socio-technical issue as it involves legal agreements and technical safeguards, as well as communication, accountability, governance, and organizational relationships.

 

Why holistic HIPAA security matters

According to the research article,addressing isolated vulnerabilities might offer temporary respite,but a strategy that considers both technological and socio-technical factors can create a better system.

When implementing another security tool, the organization should also address other contributing factors, like whether the organization's email environment provides appropriate safeguards for sensitive information. The paper specifically discusses the risks associated with outdated systems and why vendor support and encryption mechanisms are necessary.

It also suggestsCollaborating with tech vendors who specialize in healthcare IT ensures access to cutting-edge protective measures, regular software refreshes, and state-of-the-art encryption mechanisms.

 

How HIPAA compliant email can help

The researchers specifically identifyemail phishing attacksamong the recurring themes in healthcare breach descriptions. They also identify retraining staff and disabling email accounts as examples of organizational responses to security incidents.

This is evidenced further by the Paubox report, What small healthcare practices get wrong about HIPAA and email security stating,As of 2024, over 70% of healthcare data breaches originated from phishing attacks.Implementing HIPAA compliant email systems can help healthcare organizations mitigate the risk of email phishing attacks, as well as improve staff training and response protocols to security incidents. It helps organizations address their vulnerabilities to better protect patient data and reduce the likelihood of breaches originating from phishing attacks in the future.

Healthcare organizations must use a HIPAA compliant email solution, like Paubox, which offers advanced security measures to address the technical side of this challenge. Additionally, Paubox automatically encrypts outgoing emails, making it easier for employees to handle sensitive communications appropriately. It also reduces friction in healthcare organizations, allowing staff to incorporate security into normal communication workflows.

For example, a nurse can securely send patient information directly to the attending physician, giving them immediate access to a patient's PHI. It also streamlines sharing medical information between different departments within a healthcare organization, ultimately incorporating security protections that operate as part of the workflow.

When secure email requires additional steps, like manually encrypting messages or navigating inconvenient patient portals, employees may be more likely to make mistakes or use less secure alternatives. Paubox reduces these barriers, so providers can securely exchange PHI with colleagues, specialists, laboratories, patients, and other authorized recipients.

A secure email platform can help organizations establish consistent processes for sending sensitive information and support organizational security practices. Organizations must combine these platforms with regular phishing awareness training and incident response procedures to better protect patient information.

Go deeper: Training staff on recognizing and preventing data breaches

 

FAQs

Why has the healthcare sector become more vulnerable to cyberattacks?

The sector heavily relies on digitization, the use of electronic health records, interconnected systems, and networked medical devices, expanding the number of potential entry points for attackers.

 

What is a HIPAA breach?

A HIPAA breach is an unauthorized use or disclosure of PHI that compromises its privacy or security. This includes situations where PHI is accessed, viewed, or acquired without permission, unless a risk assessment determines there is a low probability that the information has been compromised. Examples can include cyberattacks, unauthorized employee access, or accidental disclosure of patient data.

 

Are healthcare providers required to report cyber breaches?

Yes. Under HIPAA, covered entities must notify affected individuals, the U.S. Department of Health and Human Services, and, in some cases, the media when unsecured protected health information (PHI) is breached.

Notifications must generally be made without unreasonable delay and no later than 60 days after discovery. The notice should describe what happened, the type of information involved, steps individuals should take to protect themselves, what the organization is doing in response, and how to contact the provider for more information.

Read also: Suspect a HIPAA violation? Here's what to do