Skip to content
All resources
CybersecurityAugust 24, 2026·6 min read

The Real Cybersecurity Risks Facing Small Medical Practices

Patient records are among the most attacked data in the country. Here are the risks that actually hit small practices, and the fixes regulators expect to see.

By Cohesive Security

Most practice owners assume the danger sits somewhere else: with the hospital systems, the big insurers, the breaches that make the news. Attackers go after two-provider practices, dental offices, imaging centers, and specialty clinics precisely because they expect the defenses to be thinner than a health system’s, and the disruption to be painful enough that someone pays quickly.

The good news is that the risks aren’t exotic. They’re documented in federal enforcement records, and nearly all of them come down to controls a small office can genuinely put in place. Here’s what actually goes wrong, in the order we tend to find it.

Key takeaways:

  • Almost no attack starts by breaking your EHR. It starts with a stolen password, a clicked link, or a device nobody could patch. The chart system is just what the attacker reaches next.
  • The compliance failure federal regulators cite most often isn’t a missing firewall. It’s the absence of a current, written risk analysis.
  • Downtime is the underestimated risk. When scheduling and charting go dark, the cost shows up in canceled appointments, not IT hours.
  • Your cloud EHR vendor secures their platform, not your workstations, email, or sign-ins. That gap is yours, and it’s where incidents begin.

Why practices your size are worth an attacker’s time

A patient record is worth more, for longer, than a stolen credit card. It bundles identity, insurance, and payment details in one place, and a patient can’t cancel their medical history the way they cancel a card. HHS publishes every breach affecting 500 or more people on its public breach portal, and the list is dominated by hacking and IT incidents, not lost laptops. The pattern repeats: someone got in through a password or an unpatched system, then moved.

Risk one: a stolen password, not a hacked EHR

The most common way into a practice is the most boring one. A staff member reuses a password that leaked in an unrelated breach, or types their credentials into a convincing fake login page, and the attacker signs in as them. Nothing gets “hacked” in the movie sense. Someone logs in.

Two fixes carry most of the weight. Multi-factor authentication on every account that touches patient information means a stolen password alone isn’t enough. A password manager, with a unique password per account, ends the reuse that turns someone else’s breach into yours. Our breached password checker tells you in seconds whether a password you rely on has already leaked, without sending the password itself.

Risk two: ransomware that stops the schedule

For most businesses, ransomware means lost files. For a practice, it means a full waiting room. Scheduling, charting, imaging, and billing go down together, staff fall back to paper, and the appointments you cancel today can’t be re-run tomorrow.

Federal enforcement has followed. In April 2026, HHS settled four ransomware investigations totaling $1,165,000, covering more than 427,000 affected individuals. The ransom is rarely the whole bill: there’s the downtime, the notification, the investigation, and the penalty after.

What blunts this is layered: protection on every computer that can isolate an infected machine automatically, including at 2 a.m., offsite backups ransomware can’t quietly delete, and test restores so you know they work before you need them. We cover the layers in how small businesses get hit by ransomware.

Risk three: the equipment nobody can patch

Every practice has some. An imaging workstation running an operating system the manufacturer stopped supporting, a check-in tablet, a vendor-locked monitor, all on the same flat network as the front desk computers and the server.

You often can’t update these. What you can do is fence them off: put that equipment in its own lane so it only reaches what it needs, and so a compromised front desk PC doesn’t hand someone your imaging system. It’s an afternoon of network work that removes a whole class of risk.

Risk four: the risk analysis nobody has done

This is the one that turns a bad week into a fine. In the settlements above, and across the enforcement actions HHS has announced under its risk analysis initiative, the failure regulators cite over and over isn’t a missing product. It’s that nobody ever completed an accurate, thorough, organization-wide analysis of where electronic patient information lives and what threatens it.

HIPAA’s Security Rule requires that analysis, in writing, kept current. Most small practices either never did one or did one years ago, for an office that has since changed its software, its vendors, and half its equipment. As OCR’s director put it when announcing those settlements, implementing the Security Rule before a breach “is a regulated entity’s best opportunity to prevent or mitigate the harmful effects of a successful cyberattack.”

If nobody owns this, it doesn’t happen. Carrying that ownership is what our compliance and vCISO service is for.

Risk five: the vendors you assumed were covered

Your EHR, clearinghouse, billing service, transcription tool, IT provider, and cloud backup all touch patient information, and HIPAA requires a signed business associate agreement with each. We routinely find gaps: an agreement nobody countersigned, a newer tool the office adopted without asking, a vendor that changed hands.

A cloud EHR vendor secures their platform, and that protection is real, but it stops at their front door. Your workstations, network, mailboxes, and sign-in accounts are still yours, and that’s where incidents start. Email especially, because impersonation is how much healthcare fraud begins: a fake records request, a payment redirection, a “new banking details” message to billing. Check whether someone can send email as your exact domain with our email security checker, then see how your team handles the bait with the Spot the Phish quiz.

The rules are tightening, not loosening

In January 2025, HHS proposed a rewrite of the HIPAA Security Rule. The headline change: safeguards that are currently “addressable,” meaning you can document a reason not to implement them, would become required. That list includes encryption of patient data and multi-factor authentication, plus an asset inventory and a network map kept current at least yearly.

The proposal isn’t final and its timing could shift, but every item on it is something a well-run practice should be doing anyway. Treat it as advance notice, not a deadline to wait for.

Where to start this week

You don’t need a formal project to make real progress. In roughly this order:

  1. Turn on multi-factor authentication for email and your practice management system, for everyone.
  2. Confirm your backups run offsite and have been restored in a test within the last year.
  3. Find your last written risk analysis. If you can’t find it, or it predates your current systems, that’s your next task.
  4. List every vendor that can see patient information and check you have a signed agreement with each.
  5. Give your front desk fifteen minutes on the scams aimed at medical offices. They’re the ones being targeted.

The harder part is what keeps running afterward: the monitoring, the patching, the training, the documentation staying current. That’s the work our healthcare clients hand to us, along with dealing directly with the EHR and imaging vendors so your office manager isn’t relaying messages between two companies pointing at each other.

If you’d like an honest read on where your practice stands, we offer a free assessment: what’s exposed, what’s missing from your HIPAA documentation, and what we’d fix first. Or email hello@cohesivesecurity.com with a question. We work on-site with practices across Rock Hill, SC and the Charlotte metro, and support clients remotely well beyond it.

#healthcare#HIPAA#ransomware#compliance#phishing

Enjoyed this article?

Get more like it by email. Short, practical security tips for business owners. No jargon, no spam, unsubscribe anytime.

We only use your email to send the tips. Nothing else, and never shared.

Want help putting this into practice?

Our team can assess your environment and handle the heavy lifting. Start with a free, no-pressure conversation.