HIPAA and IT: The 10 Most Common Violations That Start With a Misconfigured System

Posted by Shane Morris | Reading time: 8 minutes.

Most HIPAA violations don’t start with a deliberate breach. They start with something far more mundane — a setting left at default, a backup that was never tested, an account that should have been disabled months ago. By the time anyone notices, it’s already a reportable incident.

This isn’t a legal compliance guide — for that, talk to your healthcare attorney. This is a practical look at the technical misconfigurations we see most often, the ones that turn an ordinary IT oversight into a HIPAA Security Rule violation with real financial and reputational consequences.

Why IT Misconfigurations Are a HIPAA Problem

The HIPAA Security Rule requires “reasonable and appropriate” administrative, physical, and technical safeguards to protect electronic Protected Health Information (ePHI). The technical safeguards section is where most violations actually originate — not because practices are careless, but because the technical requirements are specific, ongoing, and easy to drift out of compliance with over time without anyone noticing.

A system that was compliant at setup six months ago can drift out of compliance through nothing more than normal operational changes — a new employee, a software update, a forgotten setting.

The 10 Most Common Violations We See

1. No encryption on devices that access ePHI. Laptops, tablets, and phones used by staff often aren’t encrypted at the device level. If one of those devices is lost or stolen, unencrypted ePHI on it is a reportable breach. Encryption isn’t technically “required” under the letter of the rule, but it’s an “addressable” safeguard that auditors expect to see implemented unless there’s a documented reason it isn’t.

2. Shared login credentials. Multiple staff members logging in under one shared username is one of the most common findings in real audits. HIPAA requires the ability to uniquely identify and track each user’s activity — shared logins make that impossible.

3. No audit logging, or logs nobody reviews. Systems need to log access to ePHI, and someone actually needs to be reviewing those logs periodically. Logging that exists but is never reviewed provides no real protective value and doesn’t satisfy the intent of the rule.

4. Former employees with active access. An employee leaves, and their account access to the EHR, email, or practice management system isn’t revoked promptly. This is one of the single most common findings in actual breach investigations.

5. Unpatched systems and software. Operating systems and applications running outdated, unpatched versions are vulnerable to known exploits — and “known” is the key word. If a vulnerability was publicly disclosed and patched months ago but your systems weren’t updated, that’s a difficult gap to explain after an incident.

6. No formal risk assessment on file. The Security Rule requires a documented risk assessment, and it has to be specific to your organization — not a generic template downloaded online. Practices that have never conducted a real risk assessment, or haven’t updated one in years, are exposed regardless of how secure their actual systems are.

7. Untested or missing backups. A backup that exists on paper but has never been tested for actual restoration is functionally the same as no backup at all, the moment you actually need it.

8. Email used for ePHI without proper safeguards. Standard email is not secure for transmitting ePHI unless specific encryption and safeguards are in place. Staff emailing patient information to specialists, insurance companies, or each other without those safeguards is a common, often unnoticed exposure.

9. No Business Associate Agreements (BAAs) with IT vendors. Any vendor with access to your ePHI — your IT provider, your cloud storage, your backup service — needs a signed BAA in place. Practices sometimes assume their vendor relationship implicitly covers this. It doesn’t, unless it’s documented.

10. Mobile devices with no remote wipe capability. If a phone or tablet with access to ePHI is lost and there’s no way to remotely wipe it, that’s a gap that’s both preventable and commonly overlooked, especially with personal devices used for work (BYOD).

What These Have in Common

Almost every item on this list is a technical safeguard that’s straightforward to implement and maintain — but only if someone is actively managing it on an ongoing basis. None of these require exotic security tools. They require consistent operational discipline: patching on schedule, revoking access promptly, testing backups regularly, reviewing logs, keeping documentation current.

This is exactly the kind of ongoing operational discipline that reactive, break-fix IT support structurally struggles to provide — because nobody’s watching these things between service calls.

What to Do With This List

Go through these 10 items honestly with whoever currently manages your practice’s IT. For each one, you want a confident “yes, here’s how” — not a guess. Anywhere you get a hesitant answer is a real exposure worth addressing before it becomes an incident, not after.

Get a Free HIPAA-Aligned IT Assessment

We’ll evaluate your current environment against these exact safeguards and give you a clear, honest picture of where your practice stands — no obligation, no sales pressure.

[Schedule Your Free IT Assessment →]

No commitment. No sales pressure. Just clarity on where your IT stands.


Silotech Services provides HIPAA-aligned managed IT and compliance support for healthcare practices nationwide.

Sources: HHS Office for Civil Rights 2024 Report to Congress on HIPAA Compliance and Breaches · HHS OCR Enforcement Highlights

ABOUT SILOTECH

National IT. Local Engineers. One Standard.

Silotech provides managed IT, cybersecurity, and compliance services for SMBs and mid-market businesses nationwide — with on-site engineers in 11 markets across Texas, Georgia, and Colorado.

200+ businesses supported nationally
<15 min avg. response time — guaranteed
99.9% uptime commitment
B2G security heritage — STG origin

Have a question? We pick up.

Mon–Fri 8AM–6PM CT · Emergency support 24/7

WHAT WE DO

Business Operations

Strategic IT leadership — vCIO roadmaps, budget planning, and technology decisions aligned to your revenue goals. Learn about vCIO services →

IT Infrastructure

Custom infrastructure — no one-size-fits-all approach. Networks, servers, cloud environments, and endpoints built to scale with your growth. See what's included →

Employee Support

Your team built something worth protecting. Sub-15-minute help desk response, 24/7 coverage, and engineers who know your environment. See our SLA →

INDUSTRIES WE SERVE

HEALTHCARE

GOVERNMENT

ENGINEERING

INDUSTRIAL

NON-PROFIT

EDUCATION

PRIVATE-EQUITY

FINANCIAL SERVICES

RECENT POSTS

Posted by Shane Morris | Reading time: 8 minutes.

Most HIPAA violations don’t start with a deliberate breach. They start with something far more mundane — a setting left at default, a backup that was never tested, an account that should have been disabled months ago. By the time anyone notices, it’s already a reportable incident.

This isn’t a legal compliance guide — for that, talk to your healthcare attorney. This is a practical look at the technical misconfigurations we see most often, the ones that turn an ordinary IT oversight into a HIPAA Security Rule violation with real financial and reputational consequences.

Why IT Misconfigurations Are a HIPAA Problem

The HIPAA Security Rule requires “reasonable and appropriate” administrative, physical, and technical safeguards to protect electronic Protected Health Information (ePHI). The technical safeguards section is where most violations actually originate — not because practices are careless, but because the technical requirements are specific, ongoing, and easy to drift out of compliance with over time without anyone noticing.

A system that was compliant at setup six months ago can drift out of compliance through nothing more than normal operational changes — a new employee, a software update, a forgotten setting.

The 10 Most Common Violations We See

1. No encryption on devices that access ePHI. Laptops, tablets, and phones used by staff often aren’t encrypted at the device level. If one of those devices is lost or stolen, unencrypted ePHI on it is a reportable breach. Encryption isn’t technically “required” under the letter of the rule, but it’s an “addressable” safeguard that auditors expect to see implemented unless there’s a documented reason it isn’t.

2. Shared login credentials. Multiple staff members logging in under one shared username is one of the most common findings in real audits. HIPAA requires the ability to uniquely identify and track each user’s activity — shared logins make that impossible.

3. No audit logging, or logs nobody reviews. Systems need to log access to ePHI, and someone actually needs to be reviewing those logs periodically. Logging that exists but is never reviewed provides no real protective value and doesn’t satisfy the intent of the rule.

4. Former employees with active access. An employee leaves, and their account access to the EHR, email, or practice management system isn’t revoked promptly. This is one of the single most common findings in actual breach investigations.

5. Unpatched systems and software. Operating systems and applications running outdated, unpatched versions are vulnerable to known exploits — and “known” is the key word. If a vulnerability was publicly disclosed and patched months ago but your systems weren’t updated, that’s a difficult gap to explain after an incident.

6. No formal risk assessment on file. The Security Rule requires a documented risk assessment, and it has to be specific to your organization — not a generic template downloaded online. Practices that have never conducted a real risk assessment, or haven’t updated one in years, are exposed regardless of how secure their actual systems are.

7. Untested or missing backups. A backup that exists on paper but has never been tested for actual restoration is functionally the same as no backup at all, the moment you actually need it.

8. Email used for ePHI without proper safeguards. Standard email is not secure for transmitting ePHI unless specific encryption and safeguards are in place. Staff emailing patient information to specialists, insurance companies, or each other without those safeguards is a common, often unnoticed exposure.

9. No Business Associate Agreements (BAAs) with IT vendors. Any vendor with access to your ePHI — your IT provider, your cloud storage, your backup service — needs a signed BAA in place. Practices sometimes assume their vendor relationship implicitly covers this. It doesn’t, unless it’s documented.

10. Mobile devices with no remote wipe capability. If a phone or tablet with access to ePHI is lost and there’s no way to remotely wipe it, that’s a gap that’s both preventable and commonly overlooked, especially with personal devices used for work (BYOD).

What These Have in Common

Almost every item on this list is a technical safeguard that’s straightforward to implement and maintain — but only if someone is actively managing it on an ongoing basis. None of these require exotic security tools. They require consistent operational discipline: patching on schedule, revoking access promptly, testing backups regularly, reviewing logs, keeping documentation current.

This is exactly the kind of ongoing operational discipline that reactive, break-fix IT support structurally struggles to provide — because nobody’s watching these things between service calls.

What to Do With This List

Go through these 10 items honestly with whoever currently manages your practice’s IT. For each one, you want a confident “yes, here’s how” — not a guess. Anywhere you get a hesitant answer is a real exposure worth addressing before it becomes an incident, not after.

Get a Free HIPAA-Aligned IT Assessment

We’ll evaluate your current environment against these exact safeguards and give you a clear, honest picture of where your practice stands — no obligation, no sales pressure.

[Schedule Your Free IT Assessment →]

No commitment. No sales pressure. Just clarity on where your IT stands.


Silotech Services provides HIPAA-aligned managed IT and compliance support for healthcare practices nationwide.

Sources: HHS Office for Civil Rights 2024 Report to Congress on HIPAA Compliance and Breaches · HHS OCR Enforcement Highlights

ABOUT SILOTECH

National IT. Local Engineers. One Standard.

Silotech provides managed IT, cybersecurity, and compliance services for SMBs and mid-market businesses nationwide — with on-site engineers in 11 markets across Texas, Georgia, and Colorado.

200+ businesses supported nationally
<15 min avg. response time — guaranteed
99.9% uptime commitment
B2G security heritage — STG origin

Have a question? We pick up.

Mon–Fri 8AM–6PM CT · Emergency support 24/7

WHAT WE DO

Business Operations

Strategic IT leadership — vCIO roadmaps, budget planning, and technology decisions aligned to your revenue goals. Learn about vCIO services →

IT Infrastructure

Custom infrastructure — no one-size-fits-all approach. Networks, servers, cloud environments, and endpoints built to scale with your growth. See what's included →

Employee Support

Your team built something worth protecting. Sub-15-minute help desk response, 24/7 coverage, and engineers who know your environment. See our SLA →

INDUSTRIES WE SERVE

HEALTHCARE

GOVERNMENT

ENGINEERING

INDUSTRIAL

NON-PROFIT

EDUCATION

PRIVATE-EQUITY

FINANCIAL SERVICES

RECENT POSTS

Posted in

Shane Morris

Shane is an EVP of Silotech Group, a managed IT service provider. He's passionate about consulting with business leaders over how to align their business processes with the best technological solutions available. He's helped many scale their growth by increasing efficiency and reducing costs. He loves hunting, extreme physical activity, and most of all, his wife and children.

Leave a Comment





GET STARTED

Wherever your business operates, we're already there.

Schedule your free Nationwide IT Assessment. We'll evaluate your current multi-location IT environment, identify standardization opportunities, and show you what true nationwide managed IT looks like — with on-site presence in the markets that matter to your business.

Or call us directly — we pick up.