Healthcare cyber attacks - HIPAA security and data protection

HIPAA Tip: Stop HIPAA Violations From Happening

Practical Steps to Prevent Common Healthcare Compliance Issues

Welcome to this week’s HIPAA Tip Tuesday! HIPAA violations continue to happen daily in healthcare organizations—often for the same preventable reasons. In this guide, Dawn Meglino shares the most common violations she encounters and practical steps to stop them before they occur.

TL;DR – Stop These Common HIPAA Violations:

  • Eliminate shared login credentials—every user needs unique access
  • Configure auto-lock on all computers (5-15 minute timeout)
  • Implement email encryption for all ePHI communications
  • Conduct security training regularly, not just annually
  • Apply HIPAA rules to everyone—owners and physicians included

No one working in the healthcare industry is above HIPAA rules and regulations – no one! And yet every day compliance officers hear: “I can’t do that – we don’t have time to log out and log back in!” “Have someone else log me in; I can’t be bothered to remember a password.” “Those rules don’t apply to me – I’m the owner.” “IT has security on our systems, we don’t have to worry about hackers – that’s not going to happen to us.”

Common Themes (Violations) Continuing to Happen That Must Be Broken:

Shared User Login Credentials

Shared user logins to any systems and applications containing electronic Protected Health Information (ePHI), including Windows Operating Systems (logging into the computers), diagnostic devices, Xray machines. There is no audit trail with shared user accounts and zero accountability of access to ePHI. No minimum necessary rule followed.

Unlocked Computers and Workstations

Computers with no auto-lock or time out after 5-10-15 minutes of inactivity. Staff not adhering to locking computers every time they walk away (ctrl+alt+del / windows key + L key) and leaving a computer screen open with the last patient’s chart open or the EMR or Practice Management schedule available for anyone (including patients and other staff members) to see.

Unencrypted Emails Containing ePHI

Emails sent that include ePHI with no encryption. Why take this chance when encryption is inexpensive and the only secure way to email sensitive data and ePHI?

Inadequate Staff Education and Training

Staff education must be conducted for HIPAA, Cybersecurity and Security Awareness training – regularly, not annually. This includes all management, physicians, owners and staff. To not train or educate is to not know – so whose fault is it then?

HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.


About the Author: Dawn Meglino
HIPAA Compliance Specialist, CHPSE, CCSA, CCAP

Dawn Meglino is a certified HIPAA Compliance Specialist at Anatomy IT helping healthcare organizations navigate complex security and compliance requirements. She holds multiple cybersecurity and compliance certifications and regularly advises medical practices on breach prevention and HIPAA best practices.

116 healthcare cybersecurity companies to know | 2025