Many healthcare organizations assume they are HIPAA compliant because they have an EHR system, antivirus software, or an IT provider. Unfortunately, HIPAA violations often occur because critical compliance requirements are overlooked. In our experience working with healthcare organizations, most compliance gaps fall into a handful of predictable categories.
Below are the six most common HIPAA violations medical practices unknowingly commit and what to do about them.
The 6 Most Common HIPAA Violations
- Not Performing a HIPAA Security Risk Assessment
A HIPAA Security Risk Assessment (SRA) is one of the most important compliance requirements, yet many practices either never complete one or fail to update it regularly.
Warning signs include:
- No documented assessment in the past 12 months
- No list of identified security or compliance risks
- No documented remediation plan for addressing vulnerabilities
Without an SRA, it’s difficult to prove compliance or identify vulnerabilities before they become serious problems.
- Inadequate Employee Security Training
Human error remains one of the leading causes of healthcare data breaches.
Common issues include:
- Clicking phishing emails
- Sharing passwords
- Improper handling of patient information
- Using unauthorized applications
HIPAA training should be ongoing, not limited to employee onboarding.
- Weak Passwords and Access Controls
Many healthcare practices still struggle with access management.
Common examples include:
- Shared user accounts
- Former employees with active access
- Lack of Multi-Factor Authentication (MFA)
- Excessive administrative privileges
Every user should have access only to the information necessary to perform their job.
- Unsecured Email and Communication Systems
Email remains one of the most common sources of HIPAA violations.
Examples include:
- Sending PHI without encryption
- Using personal email accounts for work
- Sharing sensitive information through unsecured platforms
Healthcare organizations should implement secure communication tools and establish clear usage policies.
- No Incident Response Plan
When a ransomware attack or security incident occurs, every minute matters.
Many organizations have:
- No documented response procedures
- No breach notification process
- No designated response team
A well-defined incident response plan can significantly reduce downtime and compliance risks.
- Failure to Test Backups and Disaster Recovery
Backups are essential, but many organizations never test them.
Common issues include:
- Failed backup jobs
- Corrupted backup data
- Recovery procedures that don’t work during an emergency
Healthcare organizations should regularly test backup restoration and disaster recovery processes to ensure business continuity.
How to Reduce Your HIPAA Risk
Healthcare organizations should focus on six core areas:
- Conduct annual Security Risk Assessments
- Train employees regularly
- Enforce MFA and access controls
- Secure email and communications
- Maintain an incident response plan
- Test backups and disaster recovery procedures
Organizations that consistently follow this framework are far better positioned to protect patient information and demonstrate HIPAA compliance.
Why Healthcare Organizations Partner with ACT
ACT specializes in helping New York healthcare organizations align technology, cybersecurity, and compliance requirements.
Our healthcare-focused services include:
- HIPAA Security Risk Assessments
- Managed IT Services
- Cybersecurity protection
- Employee security awareness training
- Business continuity and disaster recovery planning
HIPAA compliance is not a one-time project. It requires ongoing attention, documentation, and security improvements. Understanding the most common violations is the first step toward protecting your patients, your organization, and your reputation.


