Skip to main content
Promotional banner for the pentest readiness checklist
Build a Breach-Proof PHI Environment: 90-Day Technical Hardening PlanIncident & Breach Response
6 min readFor Risk Managers

Build a Breach-Proof PHI Environment: 90-Day Technical Hardening Plan

When OnePoint Patient Care settled for $2,115,000 after hackers accessed files belonging to 1,741,152 individuals, the forensics showed a three-day window between initial access and detection. Clay-Platte Family Medicine's $1,000,000 settlement revealed unencrypted data on network systems. Both lawsuits cited negligence in maintaining cybersecurity safeguards.

You're reading this because your organization can't afford to be next. This playbook guides you through implementing the technical controls that could've prevented both breaches. You'll build layered defenses that detect intrusions within hours, not days, and ensure encryption protects data even when perimeter controls fail.

Why This Matters

Healthcare organizations face specific legal exposure: negligence claims succeed when plaintiffs demonstrate you failed to implement "reasonable and appropriate safeguards." The Health Insurance Portability and Accountability Act (HIPAA) Security Rule requires covered entities to encrypt electronic protected health information (PHI) at rest and in transit. The Clay-Platte lawsuit specifically called out the absence of network encryption.

Your vulnerability window matters. OnePoint's breach ran from August 6 to August 8, 2024, before detection on August 8. Modern attackers move laterally through networks in under 48 hours. If your detection capabilities can't identify unauthorized file access within a single shift, you're operating with the same blind spots that led to these settlements.

The financial math is straightforward: OnePoint paid roughly $1.21 per affected individual. Clay-Platte paid $18.55 per individual. Smaller breaches cost more per record because settlement funds must cover credit monitoring, legal fees, and administrative costs regardless of scale. Your 10,000-patient practice faces the same baseline costs as a 100,000-patient system.

What You Need Before Starting

Before you configure anything, inventory what you have:

Network visibility: Can you list every system that stores or processes PHI? You need a complete asset inventory with data classification tags. If you're running electronic health record systems, practice management software, billing platforms, or patient portals, each one goes on the list.

Administrative access: You'll need domain admin rights, EHR system admin credentials, and access to your firewall management console. If you're using a managed service provider, confirm they can implement configuration changes within your 90-day window.

Budget allocation: Expect $15,000-$50,000 for a mid-sized practice, depending on your current security posture. This covers endpoint detection and response tooling, SIEM licensing, encryption certificates, and security awareness training platforms.

Stakeholder buy-in: Your physicians will complain about multi-factor authentication. Your front desk staff will resist password changes. Get your practice administrator or chief medical officer to sponsor the project before you start.

Step-by-Step Implementation

Days 1-14: Establish Detection Capabilities

Deploy a Security Information and Event Management (SIEM) system that aggregates logs from your EHR, firewall, and authentication systems. You're looking for failed login attempts, file access patterns, and lateral movement indicators.

Configure alerting rules for:

  • More than five failed login attempts from a single account within 15 minutes
  • File access outside normal business hours
  • Bulk file downloads exceeding 100 records
  • New admin account creation
  • Authentication from geographic locations outside your service area

Connect your SIEM to your email and SMS systems so alerts reach your security contact immediately. The OnePoint breach might've been contained in hours if automated alerts had triggered when bulk file copying began.

Days 15-30: Implement Encryption Everywhere

Start with data at rest. If you're running Windows Server environments, enable BitLocker on all drives containing PHI. For Linux systems, use LUKS encryption. Your EHR vendor should support transparent data encryption at the database layer; enable it and verify with a test restore.

For data in transit, audit every application that transmits PHI. Patient portal logins must use TLS 1.3. Email containing PHI requires encrypted transport through an email gateway that supports S/MIME or PGP. If you're still using unencrypted SMTP for patient communications, you're replicating the Clay-Platte vulnerability.

Configure your firewall to block outbound connections on port 25 (unencrypted email) and log any application that attempts to send data without encryption.

Days 31-45: Harden Authentication

Enable multi-factor authentication on every system that touches PHI. Use authenticator apps, not SMS codes, which can be intercepted. Configure your EHR to require MFA for remote access and after 15 minutes of inactivity.

Implement Role-Based Access Control so front desk staff can't access billing records and billing staff can't open clinical notes. Your EHR should have granular permission settings; use them. The Principle of Least Privilege means a scheduler doesn't need access to lab results.

Deploy privileged access management for your IT staff. Admin credentials should require approval workflows and time-limited sessions. If a contractor needs domain admin access, they get it for two hours with full session recording.

Days 46-60: Build Network Segmentation

Create VLANs that isolate PHI systems from general office networks. Your EHR servers should sit behind a firewall that only allows traffic from authenticated workstations. Patient kiosks in the waiting room shouldn't have network paths to your billing database.

Configure your firewall to log and alert on any attempt to access PHI systems from non-authorized network segments. If someone plugs a laptop into an exam room network jack, you should know within minutes.

Days 61-75: Deploy Endpoint Protection

Install endpoint detection and response agents on every workstation and server. Configure them to block known ransomware behaviors: rapid file encryption, shadow copy deletion, and lateral movement tools.

Enable application allowlisting on EHR servers. Only approved executables should run. If an attacker drops malware, it dies before execution.

Days 76-90: Train and Test

Run tabletop exercises with your staff. Walk through scenarios: "A user receives an email claiming to be from your EHR vendor asking them to reset their password. What do they do?" Your front desk should know to forward suspicious emails to IT, not click links.

Conduct a simulated phishing campaign. Send test emails and track who clicks. Anyone who fails gets remedial training before you go live.

Schedule a penetration test with an external firm. They'll attempt to breach your network using the same techniques that compromised OnePoint and Clay-Platte. Fix what they find.

Validation - How to Verify It Works

Your encryption works when you can't read database files directly from the disk. Copy a database file to a USB drive and try to open it outside your network. You should see encrypted gibberish.

Your detection works when you can simulate an attack. Have a colleague attempt to log in with incorrect passwords ten times. Your SIEM should alert within two minutes.

Your access controls work when you audit user permissions quarterly. Run a report showing which accounts accessed PHI in the last 90 days. Terminated employees shouldn't appear. Contractors should only have access during their engagement period.

Maintenance and Ongoing Tasks

Weekly: Review SIEM alerts and investigate any anomalies. Even false positives teach you about normal behavior patterns.

Monthly: Patch all systems. The OnePoint breach occurred in August 2024; if they were running unpatched systems with known vulnerabilities, the negligence argument becomes easier to prove.

Quarterly: Audit user access. People change roles, leave the organization, or move to part-time status. Your access controls should reflect current responsibilities.

Annually: Conduct a risk assessment under the HIPAA Security Rule. Document what you've implemented and what residual risks remain. If you choose not to encrypt certain data elements, document why the risk is acceptable. That documentation becomes your defense if you're sued.

The settlements against OnePoint and Clay-Platte demonstrate that "we didn't think it would happen to us" isn't a defense. Negligence claims succeed when organizations fail to implement controls that are technically feasible and economically reasonable. Everything in this playbook meets that standard. Now you implement it before you're writing a settlement check.

Application Security Isn’t Optional Anymore.

You Might Also Like