Your Managers Are the First Line of Defense. Most Aren’t Ready.
Ethics and Compliance
Safeguarding protected health information (PHI) requires privacy, security, and workforce preparedness to work together.
From 2018 to 2023, large healthcare breaches increased 102%, while the number of people affected soared 1,002%, according to the U.S. Department of Health and Human Services (HHS). Hacking and ransomware were major drivers of that increase.
For HR, Legal and Compliance leaders, the challenge goes beyond stopping cyberattacks. Safeguarding protected health information (PHI) requires privacy, security, and workforce preparedness to work together. And with HHS considering significant changes to the HIPAA Security Rule, organizations have good reason to assess whether their safeguards and employees are prepared for today’s risks.
The rule change strengthens protections for electronic protected health information (ePHI) by requiring additional administrative and technological safeguards. The proposal would make many safeguards more explicit and prescriptive, including requirements involving risk analysis, incident response, encryption, multi-factor authentication, and identifying technical vulnerabilities.
The proposal isn’t final, and regulated entities must continue to comply with the current Security Rule. But organizations don’t need to wait for a final rule to strengthen safeguards.
Many of the threats and vulnerabilities the proposal addresses, including ransomware and compromised credentials, already exist. The major difference with the rule update would be to prescribe more training elements for subject entities that already implement security safeguards.
Consider a phishing email. One employee clicks a malicious link and exposes login credentials, potentially giving an attacker access to ePHI. This example of a single cybersecurity incident triggers potential privacy rule violations, several breach notification clocks running, and the threat that your organization’s entire system may be compromised.
The employee doesn’t need to categorize those risks. They need to recognize something is wrong and who to report it to.
Technical safeguards are essential, but they can’t eliminate the human decisions behind these risks.
That’s why workforce readiness should connect HIPAA and privacy expectations with cybersecurity awareness, secure data handling, phishing and social engineering, credential protection, and knowing when and how to report a concern.
While the rule change is currently set for July 2027, cybercriminals are actively putting your systems at risk now.
Organizations can prepare now by assessing how well employees recognize and respond to risk. Consider:
The goal isn’t more compliance training. It’s making sure safeguards, policies and workforce practices keep pace with the risks organizations face.
A HIPAA incident can start with a single click, request, or decision. How well employees recognize and respond to that moment can determine what happens next.
Traliant’s Data Privacy, Cyber and AI Learning Track brings related Learning Topics together to help employees recognize and respond to privacy, cybersecurity, and emerging technology risks.
Attorney-developed training builds foundational knowledge, while refreshers, phishing simulations and short Micro Reel videos reinforce key behaviors throughout the year, helping employees retain and apply what they’ve learned when real-world situations arise.