Healthcare cyber attacks - HIPAA security and data protection

HIPAA Tip: The Cybersecurity Game

Stop Being Scared. Start Being Strategic

Here’s an idea: what if we stopped getting scared and freaked out by Cybersecurity threats and attacks? Remember when you were young, playing a game with your family or friends, and realizing how to be more clever in order to win? Maybe those strategies can now pay off for your organization.

TL;DR – The Cybersecurity Game:

  • Classic games teach valuable cybersecurity lessons: Jenga shows single points of failure, Chess demonstrates layered defense, and Simon Says highlights verification over blind trust
  • Apply game strategies to your security program: risk analysis, protecting critical assets, addressing vulnerabilities, and security awareness training
  • HIPAA compliance is ongoing and programmatic, not a one-time checklist—it requires continuous diligence to maintain good standing with HHS OCR
  • Strategic thinking from games translates directly to defending against cyber threats and protecting patient data

Jenga: Understanding Single Points of Failure

Lets take the game Jenga that involves strategic removal of blocks from the lower and middle sections of the tower ensuring the structure remains stable. This game illustrates how even a seemingly small single point of failure can lead to a catastrophic collapse, enforcing the need for risk assessment and thoughtful decision-making.

Chess: Strategic Defense and Asset Protection

Chess is a game where players move pieces with unique abilities across a checkered board, capturing enemy pieces by landing on their squares. Playing the game provides a powerful framework for understanding security by highlighting strategic thinking, the importance of protecting critical assets, the need for layered defense and the necessity of anticipating adversary moves.

Simon Says: Verification Over Blind Trust

In the classic children’s game of Simon Says, players are eliminated for not acting on commands that were instructed by the designated leader; lack of listening skills. This illustrates how a reliance on authority rather than verification can create significant vulnerabilities. A “security breach” can occur when players fail to distinguish between legitimate and malicious instructions and act without thinking.

Where Am I Going With This?

  • Risk Analysis / Risk Management
  • Securing Critical Assets
  • Addressing Vulnerabilities
  • Cybersecurity and Security Awareness Training

HIPAA Compliance Is an Ongoing Journey

HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.


About the Author: Dawn Meglino
HIPAA Compliance Specialist, CHPSE, CCSA, CCAP

Dawn Meglino is a certified HIPAA Compliance Specialist at Anatomy IT helping healthcare organizations navigate complex security and compliance requirements. She holds multiple cybersecurity and compliance certifications and regularly advises medical practices on breach prevention and HIPAA best practices.