Skip to main content
Commerce Security logo, "All 12 PCI DSS Requirements in Plain English," "Get it now for free," "Complete Survival Guide" and a button toclick to get it
Three Healthcare Breaches, Three Failures: What Your HIPAA Program Is MissingIncident & Breach Response
5 min readFor IT Security Teams

Three Healthcare Breaches, Three Failures: What Your HIPAA Program Is Missing

Between November 2025 and May 2026, three healthcare organizations reported breaches affecting hundreds of thousands of patients. Boston Healthcare for the Homeless Program, Monongalia County General Hospital Company, and Open Door Health Center of Illinois each failed differently, but the regulatory gaps were identical.

What Happened

Boston Healthcare for the Homeless Program detected a network disruption on November 11, 2025. Third-party forensics confirmed unauthorized access to files containing names, Social Security numbers, payment card data, government IDs, financial account codes, medical records, and health insurance information. The data review wasn't completed until June 8, 2026. At least 184,914 Massachusetts residents were affected.

Monongalia County General Hospital Company identified suspicious email activity on May 6, 2026. Employees had responded to phishing emails, compromising their credentials. The unauthorized party accessed email accounts containing patient names, birth dates, contact information, Social Security numbers, health data, and insurance details.

Open Door Health Center of Illinois was added to the Inc Ransom group's data leak site on May 21, 2026. The ransomware group claims to have exfiltrated sensitive data. Open Door filed a breach report with HHS' Office for Civil Rights but has not yet posted a public substitute notice.

Timeline Breakdown

Organization Detection Investigation Complete Notification Delay
Boston Healthcare Nov 11, 2025 Jun 8, 2026 Aug 2026 7+ months from detection to data review completion
Mon General May 6, 2026 [Not disclosed] [Recent] Investigation timeline unclear
Open Door [Not disclosed] [Not disclosed] Reported to HHS Incident added to leak site May 21, 2026

The Boston Healthcare timeline reveals a critical problem: seven months elapsed between detecting the disruption and completing the data review. That's not incident response. That's incident archaeology.

Which Controls Failed

Boston Healthcare for the Homeless Program:

  • No evidence of network segmentation preventing lateral movement
  • Seven-month gap suggests inadequate forensic readiness and evidence collection procedures
  • Delayed data inventory completion indicates missing data classification or poor asset documentation

Monongalia County General Hospital:

  • Employees successfully responded to phishing emails, indicating ineffective security awareness training
  • Email accounts contained multiple data types (SSNs, health records, insurance data), suggesting violations of the Principle of Least Privilege and need-to-know access
  • No email authentication controls (DMARC, SPF) or anti-phishing technology mentioned

Open Door Health Center:

  • Ransomware deployment and data exfiltration suggests missing endpoint detection and response capabilities
  • No mention of backup integrity or offline backup storage
  • Incident appears on attacker leak site before public disclosure, indicating potential negotiation or delayed response

What HIPAA Actually Requires

The HIPAA Security Rule § 164.308(a)(1)(ii)(B) mandates a risk analysis identifying threats to electronic protected health information. All three organizations had identifiable, addressable risks they didn't remediate:

§ 164.308(a)(5)(ii)(C) - Log-in Monitoring (Addressable): Mon General's phishing incident required monitoring procedures to detect unauthorized access attempts. If you're not alerting on credential use from anomalous locations or impossible travel patterns, you can't meet this standard's intent.

§ 164.308(a)(6)(ii) - Security Incident Procedures (Required): Boston Healthcare's seven-month data review violates the spirit of incident response. The Health Information Technology for Economic and Clinical Health Act requires breach notification "without unreasonable delay and in no case later than 60 calendar days" after discovery. You can't notify if you don't know what was compromised.

§ 164.312(a)(2)(iv) - Encryption (Addressable): While addressable, if you document why encryption isn't reasonable and appropriate, you're accepting the risk that stolen data is immediately readable. Inc Ransom's ability to leak Open Door's data suggests it wasn't encrypted at rest.

§ 164.308(a)(5)(i) - Security Awareness Training (Required): Mon General's phishing success is a direct training failure. HIPAA requires training on malicious software and log-in monitoring. Your annual training video doesn't satisfy this if employees can't identify a credential harvesting attempt.

Lessons and Action Items

1. Build a 72-hour data scoping capability. Boston Healthcare took seven months to complete its data review. Your Computer Security Incident Response Team needs documented procedures to inventory affected systems and data types within 72 hours of containment. Map your data flows now, before the incident. If you can't produce a Statement of Applicability showing where regulated data lives, you can't scope a breach.

2. Test your phishing controls monthly. Mon General's incident proves annual training doesn't work. Implement:

  • Monthly simulated phishing campaigns with immediate remedial training for clickers
  • Email authentication (DMARC at enforcement, not monitoring)
  • Conditional access policies requiring MFA for email access from new locations
  • Privileged Access Management for any account touching patient data

Don't just measure click rates. Measure time-to-report: how quickly do users forward suspicious emails to your security team?

3. Segment email from clinical data. Mon General's email accounts contained SSNs, health records, and insurance data. That's a design failure. Your email system shouldn't be your medical record repository. Implement Role-Based Access Control limiting email access to patient identifiers and reference numbers only. Full records belong in your EHR with audit logging, not in Outlook folders.

4. Assume breach in your backup strategy. Open Door's appearance on a leak site suggests exfiltration before detection. Your backups must be:

  • Offline or immutable (write-once-read-many storage)
  • Tested for restoration monthly
  • Encrypted with keys the backup system can't access

If your backup server is domain-joined and accessible from your production network, ransomware will encrypt it too.

5. Document your "addressable" decisions now. HIPAA's addressable specifications aren't optional. They require documented risk assessment and equivalent alternative controls if you don't implement them. If you're not encrypting email at rest, document why and what compensating controls you've implemented. OCR will ask during the investigation.

6. Establish third-party forensic retainers before the incident. All three organizations engaged external experts after detection. That's too late. Negotiate retainers with digital forensics firms now. Your incident response plan should include contact information, escalation procedures, and pre-authorized spending limits. When you're seven hours into an active breach, you don't have time to compare vendor proposals.

The pattern across these incidents isn't sophisticated attack techniques. It's basic control failures: unmonitored access, untrained users, unencrypted data, and unprepared response teams. Your next audit shouldn't be the first time you test whether you can scope a breach in 72 hours.

Digital advertisement promoting the whitepaper “The State of Application Security in Modern Software,” showing the cover f the whitepaper and text highlighting AppSec risks, AI code threats, API vulnerabilities, and a button to download the whitepaper.

You Might Also Like