Skip to main content
The state of ai impact assessment
Healthcare Data Breach Prevention ChecklistData Privacy
5 min readFor Data Privacy Officers

Healthcare Data Breach Prevention Checklist

Healthcare data breaches pose a dual threat: insiders with access and external attackers seeking it. Recent incidents at women's health centers highlight this divide. On April 28, 2026, Women's Wellness of Southern Delaware found a former provider had unauthorized patient data, while Women's Center for Radiology in Florida detected unauthorized network access.

This checklist targets both threats with specific controls, aligning with Health Insurance Portability and Accountability Act (HIPAA) requirements and referencing ISO/IEC 27001 controls where applicable.

Prerequisites

Before you begin, ensure you have:

  • An up-to-date inventory of systems containing electronic protected health information (ePHI)
  • A list of all workforce members with ePHI access, including contractors and providers
  • Documentation of your organization's designated HIPAA Security Officer
  • Access to your Incident Response Plan and breach notification procedures

Access Control and Insider Threat Prevention

1. Implement automated account deactivation for departing workforce members

Your HR system should automatically suspend accounts on an employee's last day, covering email, EHR systems, VPN access, and physical badges.

Effective practice: Accounts disabled within one hour of HR processing termination paperwork. No manual intervention needed. (HIPAA Security Rule § 164.308(a)(3)(ii)(C); ISO/IEC 27001 Control 5.18)

2. Conduct data access reviews for terminated users within 48 hours

Review audit logs for data accessed by departing users in their final 30 days. Check for bulk downloads or unusual access patterns.

Effective practice: Security team receives an automated report listing all ePHI accessed by the user. Anomalies are flagged for investigation before network access expires. (HIPAA Security Rule § 164.308(a)(1)(ii)(D))

3. Require return of all devices and credentials before final paycheck release

Create a checklist for returning laptops, mobile devices, security tokens, and access cards. HR should not process final payments until IT confirms receipt.

Effective practice: Signed acknowledgment from departing employee listing returned devices. IT verification that devices have been wiped or forensically imaged. (ISO/IEC 27001 Control 5.10)

4. Disable local data storage capabilities on endpoints accessing ePHI

Configure systems to prevent users from saving patient data to local drives, USB devices, or personal cloud storage.

Effective practice: Group Policy or mobile device management rules block local saves. Users work only with data in approved systems. Audit logs confirm no local copies created. (HIPAA Security Rule § 164.310(d)(1))

5. Implement Role-Based Access Control tied to current job functions

Map every role to the minimum ePHI access required. Review quarterly to ensure access matches current responsibilities.

Effective practice: Written access matrix showing role definitions and data access levels. Automated quarterly reports highlight users whose access hasn't been reviewed. Manager sign-off required for access continuation. (HIPAA Security Rule § 164.308(a)(4)(ii)(B); ISO/IEC 27001 Control 5.15)

Network Security and External Threat Prevention

6. Deploy Multi-Factor Authentication on all systems containing ePHI

Require a password plus an authenticator app, hardware token, or biometric. No exceptions for "trusted" networks or senior staff.

Effective practice: MFA enforced at login for EHR, email, VPN, and administrative tools. Authentication logs show 100% MFA adoption. (NIST SP 800-171 Control 3.5.3; ISO/IEC 27001 Control 5.17)

7. Segment your network to isolate ePHI systems

Place systems containing patient data on a separate network segment with firewall rules restricting access from general corporate networks.

Effective practice: Network diagram showing clear segmentation. Firewall rules documented and reviewed quarterly. Only authorized systems can initiate connections to ePHI segment. (HIPAA Security Rule § 164.312(a)(1); ISO/IEC 27001 Control 8.20)

8. Enable comprehensive logging on all systems accessing ePHI

Capture authentication attempts, data access, configuration changes, and administrative actions. Retain logs for at least six years per HIPAA requirements.

Effective practice: Centralized log management system collecting from all ePHI systems. Automated alerts on suspicious patterns. Logs protected from tampering. (HIPAA Security Rule § 164.308(a)(1)(ii)(D); ISO/IEC 27001 Control 8.15)

9. Conduct Vulnerability Scanning and penetration testing quarterly

Scan all internet-facing systems and internal networks for known vulnerabilities. Annual penetration test should simulate real attacker techniques.

Effective practice: Automated scans running weekly. Critical vulnerabilities patched within 15 days, high-risk within 30 days. Annual pentest report with remediation tracking. (HIPAA Security Rule § 164.308(a)(8); ISO/IEC 27001 Control 8.8)

10. Document and test your incident response plan twice annually

Your plan should address both insider threats and external breaches. Include steps for containment, evidence preservation, and breach notification to the Department of Health and Human Services (HHS) Office for Civil Rights.

Effective practice: Tabletop exercise simulating data breach scenario. All Computer Security Incident Response Team members know their roles. Breach notification templates ready. Contact information for forensics firm and legal counsel current. (HIPAA Security Rule § 164.308(a)(6); ISO/IEC 27001 Control 5.24)

Common Mistakes

Assuming former employees can't cause harm after termination. The Delaware incident shows data retention by departed workforce members is a real risk. Don't wait for exit interviews to think about data return.

Treating all access equally. Administrative accounts and provider accounts with broad ePHI access require stronger controls than general staff. Apply Privileged Access Management principles to high-risk accounts.

Ignoring audit logs until after an incident. The Florida center identified unauthorized access on April 28, 2026. How long had the attacker been in their network? Regular log review catches intrusions faster.

Assuming perimeter security is sufficient. Once an attacker bypasses your firewall, can they move laterally to ePHI systems? Network segmentation limits blast radius.

Delaying breach notification planning. You have 60 days from discovery to notify affected individuals under the Health Information Technology for Economic and Clinical Health Act requirements. That timeline starts the day you should have known, not when you finished investigating.

Next Steps

Start with items 1, 6, and 10. Automated account deactivation, multi-factor authentication, and incident response planning address your highest-risk gaps for both threat vectors.

Within 90 days, complete the access control items (2-5). These prevent insider threats from materializing.

Within six months, implement the remaining network security controls (7-9). These reduce your external attack surface.

Document completion of each item with evidence: screenshots, configuration exports, policy acknowledgments, test results. Your next audit or breach investigation will demand proof you took reasonable steps to protect patient data.

a promotional banner asking how ready are you for PCI DSS 4.0? With a call-to-action to get the checklist now.

You Might Also Like