From 2018 to 2023, large healthcare breaches increased 102%, while the number of people affected soared 1,002%, according to the U.S. Department of Health and Human Services (HHS). Hacking and ransomware were major drivers of that increase.
For HR, Legal and Compliance leaders, the challenge goes beyond stopping cyberattacks. Safeguarding protected health information (PHI) requires privacy, security, and workforce preparedness to work together. And with HHS considering significant changes to the HIPAA Security Rule, organizations have good reason to assess whether their safeguards and employees are prepared for today’s risks.
HHS Proposed a Major Update to HIPAA’s Security Rule
The rule change strengthens protections for electronic protected health information (ePHI) by requiring additional administrative and technological safeguards. The proposal would make many safeguards more explicit and prescriptive, including requirements involving risk analysis, incident response, encryption, multi-factor authentication, and identifying technical vulnerabilities.
The proposal isn’t final, and regulated entities must continue to comply with the current Security Rule. But organizations don’t need to wait for a final rule to strengthen safeguards.
Many of the threats and vulnerabilities the proposal addresses, including ransomware and compromised credentials, already exist. The major difference with the rule update would be to prescribe more training elements for subject entities that already implement security safeguards.
Employees Need to Be Ready to Implement Security Safeguards, Not Recite Them
Consider a phishing email. One employee clicks a malicious link and exposes login credentials, potentially giving an attacker access to ePHI. This example of a single cybersecurity incident triggers potential privacy rule violations, several breach notification clocks running, and the threat that your organization’s entire system may be compromised.
The employee doesn’t need to categorize those risks. They need to recognize something is wrong and who to report it to.
Technical safeguards are essential, but they can’t eliminate the human decisions behind these risks.
That’s why workforce readiness should connect HIPAA and privacy expectations with cybersecurity awareness, secure data handling, phishing and social engineering, credential protection, and knowing when and how to report a concern.
Don’t Wait for the July 2027 Rule Change
While the rule change is currently set for July 2027, cybercriminals are actively putting your systems at risk now.
Organizations can prepare now by assessing how well employees recognize and respond to risk. Consider:
- Do employees understand how HIPAA’s Security, Privacy, and Breach Notification rules intersect and have complementary obligations?
- Does learning reflect situations employees actually encounter?
- Can employees recognize threats to sensitive information?
- Are critical behaviors reinforced beyond onboarding or annual training?
- Do employees know what to do when something doesn’t look right?
The goal isn’t more compliance training. It’s making sure safeguards, policies and workforce practices keep pace with the risks organizations face.
A HIPAA incident can start with a single click, request, or decision. How well employees recognize and respond to that moment can determine what happens next.
From 2018 to 2023, large healthcare breaches increased 102%, while the number of people affected soared 1,002%, according to the U.S. Department of Health and Human Services (HHS). Hacking and ransomware were major drivers of that increase.
For HR, Legal and Compliance leaders, the challenge goes beyond stopping cyberattacks. Safeguarding protected health information (PHI) requires privacy, security, and workforce preparedness to work together. And with HHS considering significant changes to the HIPAA Security Rule, organizations have good reason to assess whether their safeguards and employees are prepared for today’s risks.
HHS Proposed a Major Update to HIPAA’s Security Rule
The rule change strengthens protections for electronic protected health information (ePHI) by requiring additional administrative and technological safeguards. The proposal would make many safeguards more explicit and prescriptive, including requirements involving risk analysis, incident response, encryption, multi-factor authentication, and identifying technical vulnerabilities.
The proposal isn’t final, and regulated entities must continue to comply with the current Security Rule. But organizations don’t need to wait for a final rule to strengthen safeguards.
Many of the threats and vulnerabilities the proposal addresses, including ransomware and compromised credentials, already exist. The major difference with the rule update would be to prescribe more training elements for subject entities that already implement security safeguards.
Employees Need to Be Ready to Implement Security Safeguards, Not Recite Them
Consider a phishing email. One employee clicks a malicious link and exposes login credentials, potentially giving an attacker access to ePHI. This example of a single cybersecurity incident triggers potential privacy rule violations, several breach notification clocks running, and the threat that your organization’s entire system may be compromised.
The employee doesn’t need to categorize those risks. They need to recognize something is wrong and who to report it to.
Technical safeguards are essential, but they can’t eliminate the human decisions behind these risks.
That’s why workforce readiness should connect HIPAA and privacy expectations with cybersecurity awareness, secure data handling, phishing and social engineering, credential protection, and knowing when and how to report a concern.
Don’t Wait for the July 2027 Rule Change
While the rule change is currently set for July 2027, cybercriminals are actively putting your systems at risk now.
Organizations can prepare now by assessing how well employees recognize and respond to risk. Consider:
- Do employees understand how HIPAA’s Security, Privacy, and Breach Notification rules intersect and have complementary obligations?
- Does learning reflect situations employees actually encounter?
- Can employees recognize threats to sensitive information?
- Are critical behaviors reinforced beyond onboarding or annual training?
- Do employees know what to do when something doesn’t look right?
The goal isn’t more compliance training. It’s making sure safeguards, policies and workforce practices keep pace with the risks organizations face.
A HIPAA incident can start with a single click, request, or decision. How well employees recognize and respond to that moment can determine what happens next.







