Skip to main content
Dark green background, "Weak Application Security Can Cost You Millions," 3 slanted images of fingers pointing to digital locks, and a "Learn the Basics" button
Build a Defensible PHI Security Program Before the Lawsuit ArrivesIncident & Breach Response
5 min readFor CISOs

Build a Defensible PHI Security Program Before the Lawsuit Arrives

Highland Health Systems will pay $650,000 to settle negligence claims from an 83,543-patient data breach. Albany Gastroenterology Consultants is settling for $200,000 after compromising 57,751 patient records. Both organizations denied wrongdoing but settled anyway. The settlements aren't just about the dollar figures, they're about what the plaintiffs successfully argued: these breaches resulted from failures to implement appropriate cybersecurity measures that should have been in place.

If you're running security for a healthcare organization, you need a defensible program before an incident occurs. Here's how to build one that can withstand both technical scrutiny and legal examination.

Essential Preparations

Documented scope definition. Create an inventory of every system that stores, processes, or transmits electronic protected health information (PHI). Include workstations, servers, network devices, cloud services, and third-party applications. Your inventory needs system names, data classifications, and responsible owners.

Executive commitment in writing. Secure board or C-suite approval for a cybersecurity program budget and a documented risk acceptance process. When plaintiffs argue negligence, they'll look for evidence that leadership was informed of risks and chose not to act. Document what you asked for, what you received, and what risks remain.

Baseline compliance documentation. Pull your most recent HIPAA Security Rule gap analysis. If you don't have one, that's your first deliverable. Map your current controls to the 45 CFR §164.308 (Administrative), §164.310 (Physical), and §164.312 (Technical) safeguards. Document which are implemented, which are planned, and which are not applicable with justification.

Incident response fundamentals. You need a Computer Security Incident Response Team with defined roles, contact information, and authority to act. If you're waiting to build this until after you detect an intrusion, you've already failed the negligence test.

Step-by-Step Implementation

Month 1: Access control remediation. Start with HIPAA Security Rule §164.312(a)(1), access controls for electronic PHI. Implement Role-Based Access Control across your electronic health record system and supporting applications. Every user account needs a documented business justification. Remove shared credentials entirely. Configure session timeouts at 15 minutes of inactivity for workstations accessing PHI.

Deploy Privileged Access Management for administrative accounts. Your EHR administrators, database admins, and network engineers need separate privileged accounts that require approval workflows for elevation. Log every privileged session and retain those logs for seven years to match your HIPAA retention requirements under §164.316(b)(2)(i).

Month 2: Encryption and transmission security. Address §164.312(a)(2)(iv) and §164.312(e)(1). Encrypt all PHI at rest using AES-256. This includes database encryption, full-disk encryption on workstations and laptops, and encrypted backups. For data in transit, enforce TLS 1.2 or higher for all web applications and disable legacy protocols.

Configure your firewall to block outbound connections on ports commonly used for data exfiltration (FTP, Telnet, unencrypted database protocols). Create network segmentation that isolates PHI systems from general corporate networks. Your billing system shouldn't share a VLAN with your guest Wi-Fi.

Month 3: Audit controls and monitoring. Implement §164.312(b) by deploying centralized logging for all systems handling PHI. At minimum, log authentication events, authorization failures, data access, configuration changes, and privileged operations. Forward logs to a security information and event management system that you monitor daily.

Create detection rules for:

  • Multiple failed authentication attempts (5+ in 15 minutes)
  • After-hours access to patient records by non-clinical staff
  • Bulk data exports exceeding normal baselines
  • Privileged account usage outside maintenance windows
  • New user account creation
  • Changes to security group memberships

Assign a security analyst to review alerts within four hours during business hours. For after-hours alerts, establish an on-call rotation with escalation procedures.

Month 4: Vendor risk management. Document your business associate agreements and verify they meet §164.314(a) requirements. For each vendor with PHI access, obtain current SOC 2 Type II reports or HITRUST CSF certifications. If they can't provide third-party attestation, conduct your own security assessment using a standardized questionnaire.

Require vendors to notify you within 24 hours of any security incident affecting your data. This is tighter than the HITECH Act's business associate notification requirement but gives you time to investigate before the 60-day patient notification clock starts.

Month 5: Workforce training and sanctions. Satisfy §164.308(a)(5) with role-specific training. Clinical staff need training on workstation security and minimum necessary access. IT staff need technical security training on secure configuration and incident response. Leadership needs training on breach notification obligations and regulatory penalties.

Document training completion and create a sanctions policy for security violations. Your policy needs to specify consequences for sharing passwords, accessing records without authorization, and failing to report suspected incidents. Apply sanctions consistently, selective enforcement undermines your entire program during litigation.

Month 6: Risk analysis and documentation. Conduct your annual risk analysis per §164.308(a)(1)(ii)(A). Use NIST SP 800-30 as your methodology. Document identified threats, vulnerabilities, likelihood ratings, impact assessments, and existing controls. For each risk, document whether you're mitigating, accepting, transferring, or avoiding it.

This documentation is your legal defense. When plaintiffs claim you failed to implement appropriate safeguards, you need evidence that you identified the risk, evaluated controls, and made a documented decision.

Validation: How to Verify It Works

Run quarterly tabletop exercises with your Computer Security Incident Response Team. Use the scenario: "A user reports they can't access the EHR. Your monitoring shows 500 patient records were accessed by an unknown account in the last hour." Walk through detection, containment, investigation, and notification steps. Document gaps.

Conduct annual penetration testing focused on PHI access paths. Your tester should attempt to access patient records from both external and internal positions. Test multi-factor authentication bypass, privilege escalation, and data exfiltration controls.

Audit a random sample of user accounts quarterly. Verify that access matches documented job functions and that terminated employees are disabled within 24 hours. Check that privileged accounts require approval and that sessions are logged.

Review your audit logs monthly. Verify you're capturing the events you configured and that your detection rules are firing. Test your alert escalation by triggering a known detection rule and confirming the on-call analyst responds.

Maintenance and Ongoing Tasks

Weekly: Review security alerts and investigate anomalies. Update threat intelligence feeds. Check backup completion and test one restore.

Monthly: Review access control lists for new systems. Audit user account changes. Update risk register with new threats or vulnerabilities. Review vendor security questionnaires for renewals.

Quarterly: Test incident response procedures. Review and update security policies. Conduct access recertification for privileged accounts. Analyze security metrics and report to leadership.

Annually: Complete full risk analysis. Conduct penetration testing. Renew business associate agreements. Update disaster recovery and business continuity plans. Train workforce on security requirements.

The settlements against Highland Health Systems and Albany Gastroenterology Consultants turned on one question: did they implement appropriate safeguards? Your program needs to answer "yes" with documentation, not assertions. Build controls, document decisions, test effectiveness, and maintain evidence. When the lawsuit arrives, you'll defend with evidence, not excuses.

Digital advertisement promoting the whitepaper “The State of Application Security in Modern Software,” showing the cover f the whitepaper and text highlighting AppSec risks, AI code threats, API vulnerabilities, and a button to download the whitepaper.

You Might Also Like