Posted by Shane Morris | Reading time: 8 minutes.
Most HIPAA violations don’t start with a deliberate breach. They start with something far more mundane — a setting left at default, a backup that was never tested, an account that should have been disabled months ago. By the time anyone notices, it’s already a reportable incident.
This isn’t a legal compliance guide — for that, talk to your healthcare attorney. This is a practical look at the technical misconfigurations we see most often, the ones that turn an ordinary IT oversight into a HIPAA Security Rule violation with real financial and reputational consequences.
Why IT Misconfigurations Are a HIPAA Problem
The HIPAA Security Rule requires “reasonable and appropriate” administrative, physical, and technical safeguards to protect electronic Protected Health Information (ePHI). The technical safeguards section is where most violations actually originate — not because practices are careless, but because the technical requirements are specific, ongoing, and easy to drift out of compliance with over time without anyone noticing.
A system that was compliant at setup six months ago can drift out of compliance through nothing more than normal operational changes — a new employee, a software update, a forgotten setting.
The 10 Most Common Violations We See
1. No encryption on devices that access ePHI. Laptops, tablets, and phones used by staff often aren’t encrypted at the device level. If one of those devices is lost or stolen, unencrypted ePHI on it is a reportable breach. Encryption isn’t technically “required” under the letter of the rule, but it’s an “addressable” safeguard that auditors expect to see implemented unless there’s a documented reason it isn’t.
2. Shared login credentials. Multiple staff members logging in under one shared username is one of the most common findings in real audits. HIPAA requires the ability to uniquely identify and track each user’s activity — shared logins make that impossible.
3. No audit logging, or logs nobody reviews. Systems need to log access to ePHI, and someone actually needs to be reviewing those logs periodically. Logging that exists but is never reviewed provides no real protective value and doesn’t satisfy the intent of the rule.
4. Former employees with active access. An employee leaves, and their account access to the EHR, email, or practice management system isn’t revoked promptly. This is one of the single most common findings in actual breach investigations.
5. Unpatched systems and software. Operating systems and applications running outdated, unpatched versions are vulnerable to known exploits — and “known” is the key word. If a vulnerability was publicly disclosed and patched months ago but your systems weren’t updated, that’s a difficult gap to explain after an incident.
6. No formal risk assessment on file. The Security Rule requires a documented risk assessment, and it has to be specific to your organization — not a generic template downloaded online. Practices that have never conducted a real risk assessment, or haven’t updated one in years, are exposed regardless of how secure their actual systems are.
7. Untested or missing backups. A backup that exists on paper but has never been tested for actual restoration is functionally the same as no backup at all, the moment you actually need it.
8. Email used for ePHI without proper safeguards. Standard email is not secure for transmitting ePHI unless specific encryption and safeguards are in place. Staff emailing patient information to specialists, insurance companies, or each other without those safeguards is a common, often unnoticed exposure.
9. No Business Associate Agreements (BAAs) with IT vendors. Any vendor with access to your ePHI — your IT provider, your cloud storage, your backup service — needs a signed BAA in place. Practices sometimes assume their vendor relationship implicitly covers this. It doesn’t, unless it’s documented.
10. Mobile devices with no remote wipe capability. If a phone or tablet with access to ePHI is lost and there’s no way to remotely wipe it, that’s a gap that’s both preventable and commonly overlooked, especially with personal devices used for work (BYOD).
What These Have in Common
Almost every item on this list is a technical safeguard that’s straightforward to implement and maintain — but only if someone is actively managing it on an ongoing basis. None of these require exotic security tools. They require consistent operational discipline: patching on schedule, revoking access promptly, testing backups regularly, reviewing logs, keeping documentation current.
This is exactly the kind of ongoing operational discipline that reactive, break-fix IT support structurally struggles to provide — because nobody’s watching these things between service calls.
What to Do With This List
Go through these 10 items honestly with whoever currently manages your practice’s IT. For each one, you want a confident “yes, here’s how” — not a guess. Anywhere you get a hesitant answer is a real exposure worth addressing before it becomes an incident, not after.
Get a Free HIPAA-Aligned IT Assessment
We’ll evaluate your current environment against these exact safeguards and give you a clear, honest picture of where your practice stands — no obligation, no sales pressure.
[Schedule Your Free IT Assessment →]
No commitment. No sales pressure. Just clarity on where your IT stands.
Silotech Services provides HIPAA-aligned managed IT and compliance support for healthcare practices nationwide.
Sources: HHS Office for Civil Rights 2024 Report to Congress on HIPAA Compliance and Breaches · HHS OCR Enforcement Highlights
ABOUT SILOTECH
National IT. Local Engineers. One Standard.
Silotech provides managed IT, cybersecurity, and compliance services for SMBs and mid-market businesses nationwide — with on-site engineers in 11 markets across Texas, Georgia, and Colorado.
WHAT WE DO
Business Operations
Strategic IT leadership — vCIO roadmaps, budget planning, and technology decisions aligned to your revenue goals. Learn about vCIO services →
IT Infrastructure
Custom infrastructure — no one-size-fits-all approach. Networks, servers, cloud environments, and endpoints built to scale with your growth. See what's included →
Employee Support
Your team built something worth protecting. Sub-15-minute help desk response, 24/7 coverage, and engineers who know your environment. See our SLA →
INDUSTRIES WE SERVE
RECENT POSTS
-
How Much Should Managed IT Services Cost? A 2026 Benchmark by Industry
Posted by Shane Morris | Reading time: 8 minutes. If you’ve ever tried to get a straight answer on what managed IT services should cost, you probably noticed most MSPs don’t tell you. They want…
Posted by Shane Morris | Reading time: 8 minutes.
Most HIPAA violations don’t start with a deliberate breach. They start with something far more mundane — a setting left at default, a backup that was never tested, an account that should have been disabled months ago. By the time anyone notices, it’s already a reportable incident.
This isn’t a legal compliance guide — for that, talk to your healthcare attorney. This is a practical look at the technical misconfigurations we see most often, the ones that turn an ordinary IT oversight into a HIPAA Security Rule violation with real financial and reputational consequences.
Why IT Misconfigurations Are a HIPAA Problem
The HIPAA Security Rule requires “reasonable and appropriate” administrative, physical, and technical safeguards to protect electronic Protected Health Information (ePHI). The technical safeguards section is where most violations actually originate — not because practices are careless, but because the technical requirements are specific, ongoing, and easy to drift out of compliance with over time without anyone noticing.
A system that was compliant at setup six months ago can drift out of compliance through nothing more than normal operational changes — a new employee, a software update, a forgotten setting.
The 10 Most Common Violations We See
1. No encryption on devices that access ePHI. Laptops, tablets, and phones used by staff often aren’t encrypted at the device level. If one of those devices is lost or stolen, unencrypted ePHI on it is a reportable breach. Encryption isn’t technically “required” under the letter of the rule, but it’s an “addressable” safeguard that auditors expect to see implemented unless there’s a documented reason it isn’t.
2. Shared login credentials. Multiple staff members logging in under one shared username is one of the most common findings in real audits. HIPAA requires the ability to uniquely identify and track each user’s activity — shared logins make that impossible.
3. No audit logging, or logs nobody reviews. Systems need to log access to ePHI, and someone actually needs to be reviewing those logs periodically. Logging that exists but is never reviewed provides no real protective value and doesn’t satisfy the intent of the rule.
4. Former employees with active access. An employee leaves, and their account access to the EHR, email, or practice management system isn’t revoked promptly. This is one of the single most common findings in actual breach investigations.
5. Unpatched systems and software. Operating systems and applications running outdated, unpatched versions are vulnerable to known exploits — and “known” is the key word. If a vulnerability was publicly disclosed and patched months ago but your systems weren’t updated, that’s a difficult gap to explain after an incident.
6. No formal risk assessment on file. The Security Rule requires a documented risk assessment, and it has to be specific to your organization — not a generic template downloaded online. Practices that have never conducted a real risk assessment, or haven’t updated one in years, are exposed regardless of how secure their actual systems are.
7. Untested or missing backups. A backup that exists on paper but has never been tested for actual restoration is functionally the same as no backup at all, the moment you actually need it.
8. Email used for ePHI without proper safeguards. Standard email is not secure for transmitting ePHI unless specific encryption and safeguards are in place. Staff emailing patient information to specialists, insurance companies, or each other without those safeguards is a common, often unnoticed exposure.
9. No Business Associate Agreements (BAAs) with IT vendors. Any vendor with access to your ePHI — your IT provider, your cloud storage, your backup service — needs a signed BAA in place. Practices sometimes assume their vendor relationship implicitly covers this. It doesn’t, unless it’s documented.
10. Mobile devices with no remote wipe capability. If a phone or tablet with access to ePHI is lost and there’s no way to remotely wipe it, that’s a gap that’s both preventable and commonly overlooked, especially with personal devices used for work (BYOD).
What These Have in Common
Almost every item on this list is a technical safeguard that’s straightforward to implement and maintain — but only if someone is actively managing it on an ongoing basis. None of these require exotic security tools. They require consistent operational discipline: patching on schedule, revoking access promptly, testing backups regularly, reviewing logs, keeping documentation current.
This is exactly the kind of ongoing operational discipline that reactive, break-fix IT support structurally struggles to provide — because nobody’s watching these things between service calls.
What to Do With This List
Go through these 10 items honestly with whoever currently manages your practice’s IT. For each one, you want a confident “yes, here’s how” — not a guess. Anywhere you get a hesitant answer is a real exposure worth addressing before it becomes an incident, not after.
Get a Free HIPAA-Aligned IT Assessment
We’ll evaluate your current environment against these exact safeguards and give you a clear, honest picture of where your practice stands — no obligation, no sales pressure.
[Schedule Your Free IT Assessment →]
No commitment. No sales pressure. Just clarity on where your IT stands.
Silotech Services provides HIPAA-aligned managed IT and compliance support for healthcare practices nationwide.
Sources: HHS Office for Civil Rights 2024 Report to Congress on HIPAA Compliance and Breaches · HHS OCR Enforcement Highlights
ABOUT SILOTECH
National IT. Local Engineers. One Standard.
Silotech provides managed IT, cybersecurity, and compliance services for SMBs and mid-market businesses nationwide — with on-site engineers in 11 markets across Texas, Georgia, and Colorado.
WHAT WE DO
Business Operations
Strategic IT leadership — vCIO roadmaps, budget planning, and technology decisions aligned to your revenue goals. Learn about vCIO services →
IT Infrastructure
Custom infrastructure — no one-size-fits-all approach. Networks, servers, cloud environments, and endpoints built to scale with your growth. See what's included →
Employee Support
Your team built something worth protecting. Sub-15-minute help desk response, 24/7 coverage, and engineers who know your environment. See our SLA →
INDUSTRIES WE SERVE
RECENT POSTS
-
The Difference Between Co-Managed and Fully Managed IT: How to Know Which One Your Business Needs
Posted by Shane Morris | Reading time: 6 minutes. Once a business decides outside IT support makes sense, the next question is rarely asked clearly enough: fully managed, or co-managed? The two models solve different…
-
What Is a vCIO — and Why Growing SMBs Can’t Afford to Not Have One
Posted by Shane Morris | Reading time: 6 minutes. Most growing businesses eventually hit a point where their technology decisions stop being simple. What started as “buy a few laptops and a server” becomes a…
-
Is Your IT Provider Actually Securing Your Business — or Just Managing It?
Posted by Shane Morris | Reading time: 7 minutes. If you already have an IT provider, this post isn’t trying to convince you that you need one — you’ve already made that decision. The real…
-
Cloud Migration Gone Wrong: 7 Mistakes SMBs Make and How to Avoid Them
Posted by Shane Morris | Reading time: 7 minutes. Cloud migration sounds simple in a sales pitch: move your systems to the cloud, cut your hardware costs, gain flexibility. In practice, it’s one of the…


