Healthcare cyber attacks - HIPAA security and data protection

HIPAA Tip: HIPAA Responses

We all know how much our coworkers love HIPAA requirements, annual training(s) and constant (I hope!) reminders from management and the compliance team. We are also well aware of the push-back and comments when it comes to communicating and executing HIPAA requirements to staff, physicians and owners.

Here are some TIPS on how to respond to less than positive feedback:

  • “We are far too busy to sign into our computers and our systems with individual IDs and passwords!” HIPAA requires unique IDs and passwords for ALL users logging into systems and applications containing ePHI, including Windows logins to the computers. There is no audit trail with shared user accounts. A HIPAA audit trail is an essential security measure that tracks and records all activities related to ePHI.
  • “It’s ridiculous that I have to create such a long password, and on top of that, I have to authenticate with a code from my phone!” A 7- or 8-character password can potentially be cracked within minutes or a few hours. Using 2-factor or multi-factor authentication for an individual’s device adds another layer of protection and security for the system or application containing ePHI.

And end with this: we are all patients somewhere and expect our medical information to be kept as secure and confidential as possible. Lets treat our patients’ data with same respect.

Compliance Is Ongoing

HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.


About the Author: Dawn Meglino
HIPAA Compliance Specialist, CHPSE, CCSA, CCAP

Dawn Meglino is a certified HIPAA Compliance Specialist at Anatomy IT helping healthcare organizations navigate complex security and compliance requirements. She holds multiple cybersecurity and compliance certifications and regularly advises medical practices on breach prevention and HIPAA best practices.

123 healthcare cybersecurity companies to know | 2026