Healthcare cyber attacks - HIPAA security and data protection

HIPAA Tip: Why Should I Care?

Essential Security Awareness for Every Healthcare Team Member

Welcome to this week’s HIPAA Tip Tuesday! This article is designed to be shared with your entire staff—from front desk to clinical teams. Dawn Meglino explains why HIPAA compliance matters on a personal level and provides five critical security practices every healthcare worker should follow.

TL;DR – Why Staff Should Care About HIPAA:

  • We are all patients—your data could be breached too
  • Treat patient PHI the way you’d want yours treated
  • Secure computers when not in use (Windows key + L)
  • Lock up papers containing PHI at end of day
  • Never share login credentials to systems with ePHI

(Please Share With Your Staff)

Put Yourself in the Patient’s Position

How did you feel the first time you received a letter in the mail informing you that your personal identifiable information (PII) including your medical data was accessed due to a security breach or ransomware attack on an organization that deals with you and your family’s PHI? Frustration? Anger? What is wrong with this company and how did they let this happen?

Working in an internet-connected healthcare environment is very tricky business these days, given the value of medical information on the black market, and that unfortunately, healthcare organizations continue to be lax in securing their data.

So Why Care?

Because we are all patients, including our family members; and we do NOT want our identities or our medical information accessed by strangers. Treat each patient’s medical data or PHI exactly the same way you would want your PHI to be handled – with privacy and security.

Five Critical Security Practices for All Staff

Secure Computers When Not in Use

Secure computers when not in use (auto-lock: Windows key + L key, or ctrl + alt + delete).

Secure Papers Containing PHI

Secure papers containing PHI at the end of the business day (medical records rooms, locked cabinets) and never leave exposed on a desk in a public area during the business day.

Never Share Login Credentials

Never share user logins or passwords to systems and applications containing ePHI.

Educate All Staff on Security Best Practices

Educate all staff on best practices for securing PHI/ePHI, email security and what to look for in email phishing attacks.

Implement Role-Based Access

Always implement role-based access to PHI/ePHI – minimum necessary rule.

HIPAA compliance isn’t a one-time checklist. It’s ongoing, programmatic in nature, and requires demonstrated reasonable diligence to stay in good standing with the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR). Anatomy IT can provide you peace of mind with our expert HIPAA compliance services. To learn more, contact us here.


About the Author: Dawn Meglino
HIPAA Compliance Specialist, CHPSE, CCSA, CCAP

Dawn Meglino is a certified HIPAA Compliance Specialist at Anatomy IT helping healthcare organizations navigate complex security and compliance requirements. She holds multiple cybersecurity and compliance certifications and regularly advises medical practices on breach prevention and HIPAA best practices.