One phishing message, sent to five organizations of different sizes, produces five different outcomes. Although the attack may not change, different companies have different levels of security and response protocols, ultimately impacting patient safety.
Paubox surveyed 150 US healthcare IT leaders with independent research firm TrendCandy in early 2025, and the resulting research on rural providers found 60% reporting at least one email-related security incident in the previous twelve months.
Read more: What is a phishing attack? | Understanding HIPAA violations and breaches
The solo practitioner
A solo practice has no IT department, no security team, and nobody to escalate a suspicious message to. The clinician is the entire security function alongside being the entire clinical function. Gretchen Murchison, a licensed clinical social worker running Sunrise LCSW, set her practice up on Google Workspace and later discovered that "the BAA did not cover outside communication." A gap like this is easy to miss because a business associate agreement with a platform provider genuinely covers how that provider handles data inside its own systems, but it stops there. A compromised account at this scale exposes a comparatively small patient panel, but the practitioner carries the full weight of the breach analysis, the notification obligation, and any OCR investigation personally, with no compliance officer to hand it to.
The small practice
More than 80% of small practices surveyed by Paubox expressed confidence in their compliance posture, and 98% said their platform encrypts email by default. The same research found 83% of them believed patient consent removes the need for encryption, and 64% believed portals are required under HIPAA, and neither belief is correct.
The gaps underneath that confidence are specific. Half have no phishing or spoofing protection beyond default spam filters, and 20% keep no email archiving or audit trail at all, leaving one in five unable to investigate an incident after it happens. Asked why small practices fail HIPAA email compliance audits, respondents named reliance on default email provider settings and the absence of an incident response plan at 47% each, missing business associate agreements at 44%, and no documented risk assessment at 39%.
Detection times compound it. Healthcare breaches in 2025 took an average of 224 days to detect and another 84 to contain, so a small practice without audit trails is unlikely to know anything happened for the better part of a year.
OCR settled with a small New York neurology practice as the twelfth action in its ransomware series and the eighth under its Risk Analysis Initiative. Melanie Fontes Rainer, then Director of the HHS Office for Civil Rights, addressed the assumption behind that gap directly, stating that "risk assessments are not optional, they're foundational."
The rural hospital
Paubox found 73% of rural leaders struggling to maintain HIPAA compliance through a lack of staff and funding, with 50% citing budget limitations as a top barrier, nearly double the rate among urban peers. Adoption of AI-based threat detection sat at 38% for rural organizations against 60% for urban ones, and rural teams cited staffing as a barrier at close to three times the urban rate.
Kate Pierce, CIO and CISO at North Country Hospital in Vermont, described the underlying difficulty in the report, noting that "cyber defense is a moving target" requiring time, energy, and resources that rural facilities frequently do not have. Jenny Niblock, Chief Clinical Officer at Citizens Health, put the consequence more directly, observing that as larger hospitals harden their defenses, "the cyberattackers are targeting the more vulnerable rural hospitals."
The same research found 81% of rural organizations running cybersecurity training twice a year, while a third of staff consistently fail to identify phishing in practice. Eight in ten rural IT leaders said infrastructure itself holds them back, and 69% named implementation difficulty as a top barrier to adopting compliant email.
The large health system
Paubox's mid-year breach analysis describes the enterprise problem as fragmentation rather than weakness. Departments, locations, and acquired organizations frequently run separate systems with different email protections and varied security policies, which raises the odds of misconfiguration and incomplete risk analysis. OCR enforcement data cited in that research found failure to conduct an adequate enterprise-wide risk analysis in more than 75% of HIPAA resolution agreements involving security incidents between 2020 and 2024.
Attackers reached Covenant Health's systems on May 18, 2025, and were detected eight days later. The Record reported Qilin claiming 852 gigabytes across roughly 1.35 million files, and the final count came to 478,188 individuals across a network operating in several states.
Acquisitions compound the exposure. Episource reported a 2025 breach affecting 5.4 million individuals after being acquired by Optum, and lawmakers questioned whether UnitedHealth Group had upgraded the legacy systems or implemented multi-factor authentication following the purchase.
Robin McKinney, Digital Marketing Strategist at North Mississippi Health Services, works at the other end of that scale problem across more than 90 clinics. She ruled out mainstream email platforms early, knowing "a Constant Contact or MailChimp was not going to be the solution" for sends reaching roughly 86,700 individuals.
The business associate
MMG Fusion, a software company acting as a business associate, resolved an OCR investigation into a breach affecting roughly 15 million individuals for $10,000. A billing company, coding service, or software provider holds data from many covered entities at once, so one compromised mailbox exposes patients who have never heard of the company.
Ryan Winchester, Director of IT at CareM, coordinates communication with hundreds of practices, which made executive impersonation a persistent problem. CareM uses ExecProtect, which compiles verified lists of employee names and addresses and quarantines messages impersonating them, and Winchester's assessment of it was that "it catches a lot of stuff. It really does."
What does not change with size
Every organization above receives roughly the same phishing message. Paubox's 2025 Healthcare Email Security Report found employees reporting 5% of known phishing attempts to their security teams, a figure that does not improve with headcount, and the 2026 report recorded a 47% increase in attacks getting past the defenses built into Microsoft 365 and Google Workspace.
Controls that depend on someone noticing scale badly in both directions. A solo practitioner has nobody to notice, and a health system has thousands of people whose attention is spread across a shift. Paubox Inbound Email Security reads sender behavior, message intent, and contextual signals before delivery, which removes the dependency on either.
Learn more: Paubox Inbound Email Security
FAQs
Does a small practice face the same regulatory exposure as a hospital?
The obligations are identical. Breach notification, risk analysis, and OCR investigation apply regardless of size, and OCR's Risk Analysis Initiative has settled with practices employing a handful of clinicians.
Why are rural hospitals targeted more than they used to be?
As large systems hardened their defenses, attackers moved toward organizations with fewer fail-safes and less recovery capacity. Rural providers adopt AI-based threat detection at 38% against 60% for urban peers, and cite staffing as a barrier at nearly three times the rate.
If we run phishing training twice a year, is that enough?
The Paubox rural research found 81% of organizations train twice yearly, while a third of staff still consistently fail to identify phishing. Training raises awareness without reliably changing behavior under time pressure.
Why did a breach affecting 15 million people settle for $10,000?
OCR weighs culpability, cooperation, prior compliance history, and remediation alongside the number affected. A cooperative organization that corrects its failures can settle far below one that ignored known problems.
What should an organization with no IT staff prioritize?
Controls that work without configuration or ongoing management. Automatic outbound encryption and pre-delivery inbound filtering both operate without requiring someone to make a decision or maintain a rule set.
