Blog|Articles|September 17, 2026

The old HIPAA breach is dying out. A sneakier one is taking over

Author(s)Dave Bailey
Fact checked by: Todd Shryock

Lost and stolen devices used to cause half of all major health care breaches. Now the real exposure is hiding in staff phones, outdated medical equipment and unmanaged passwords.

For a decade, the biggest story in health care endpoint security was the laptop left in a car. A stolen device, unencrypted, holding thousands of patient records, followed by a public breach notice and, often, a six or seven figure settlement with the federal Office for Civil Rights (OCR). That story is largely over, and it is worth pausing on why, because the reason explains where the risk actually went.

Before 2015, roughly half of all large breaches reported to OCR under the Health Insurance Portability and Accountability Act involved a lost or stolen device that was not encrypted. By 2024, that share had fallen under 10%. In 2025, only about six such breaches were reported nationwide, affecting roughly 24,500 people combined, a fraction of what a single lost laptop used to cost a health system. Two things changed. Full disk encryption became the default setting on nearly every laptop, phone and tablet sold, rather than an optional feature someone in information technology had to remember to turn on. And unified endpoint management, the software that lets an organization see, patch and remotely wipe every device it issues, became standard practice instead of a luxury reserved for large hospital systems.

That is a genuine security win, and physician practices deserve credit for it. A decade of OCR enforcement and settlements built something close to institutional muscle memory around encrypting what a practice issues.

But "what a practice issues" is doing a lot of work in that sentence. Endpoint risk did not disappear. It moved to the devices and systems that default encryption and centralized management never touched in the first place.

The device you didn't buy

Start with the phone in your medical assistant's pocket, or the laptop your billing coordinator uses at home after hours. Bring your own device, or BYOD, has been standard practice in outpatient medicine for years, largely because it is cheaper than issuing hardware to every staff member. A 2025 peer-reviewed study in JMIR Human Factors, examining BYOD security maturity across hospital settings, found that most personal devices used for clinical work are inconsistently enrolled in any device management system, if they are enrolled anywhere at all. They rely instead on app level containers, which separate a work app's data from the rest of the phone but confirm nothing about whether the device itself is encrypted, patched or free of malware.

Every personal phone and laptop that touches scheduling, billing, patient messaging or a portal login is, in practical terms, part of your practice's network. Most were never inventoried as such. That is the least governed corner of the modern health care attack surface, not because anyone was careless, but because no one owns it on paper.

The equipment nobody replaces

The second blind spot sits in the exam room and the imaging suite. The Department of Health and Human Services' Health Sector Cybersecurity Coordination Center (HC3) has reported that 28% of health care organizations operate devices past the manufacturer's end of support date, and 44% knowingly run end of support devices with unpatched, publicly known vulnerabilities. That covers infusion pumps, imaging workstations and diagnostic equipment built on operating systems that were current a decade ago and cannot be patched without the manufacturer's involvement, assuming the manufacturer still exists to provide it.

A connected device does not need to hold patient records to be dangerous. It needs only to sit on the same network as the systems that do. An imaging workstation running an unsupported operating system is a doorway to a billing server if nothing separates the two.

The key you forgot you had

The third blind spot is a direct byproduct of the first success story. Full disk encryption is only as strong as the recovery key that unlocks a device when a password is forgotten or a drive has to be reset. Those recovery keys have to live somewhere, and in too many small practices, they live on a shared office drive, in a spreadsheet or on a printed sheet in a desk drawer. Storing a BitLocker or FileVault recovery key in an accessible shared location defeats the purpose of the encryption it protects, since anyone who reaches that file can unlock the device it was meant to secure. Both Microsoft and Apple publish guidance recommending centralized, access-controlled storage for these keys, tied to a directory service that logs who retrieved a key and when. Few small and mid-size practices have that in place, because recovery key management was never something anyone taught them to think about.

What to do this quarter

None of this requires a large budget or a large IT department, both in short supply at most independently owned practices. It requires an accurate inventory, because a practice cannot govern what it has not counted.

Start by listing every personal device, not just practice-issued ones, that can reach the electronic health record, patient portal or billing system, and confirm whether each one is enrolled in a device management or app protection tool. Ask medical device vendors directly, in writing, what operating system each connected device runs and when the manufacturer's support ends, then use that answer to decide what belongs on a separate, isolated network segment rather than sharing one with billing and scheduling systems. Find out where the practice's encryption recovery keys are actually stored today, and if the answer is a shared drive or a desk drawer, move them to a managed, access-logged location before the end of the quarter.

Finally, treat all three of these as part of the risk analysis HIPAA already requires a practice to perform and keep current, not as a separate project. OCR's enforcement pattern has been consistent for years: organizations rarely get penalized for lacking a security program entirely. They get penalized because their risk analysis had a gap that nobody closed. The device that was never issued, the equipment nobody replaced and the key nobody moved are exactly the kind of gap that regulators, and the people trying to break into health care networks, have learned to look for first.

Dave Bailey is Vice President of Consulting Solutions and Strategy at Clearwater, where he advises healthcare organizations on cybersecurity risk management and regulatory compliance and leads the firm's monthly Healthcare Cyber Briefing series. Connect with him on LinkedIn or learn more at clearwatersecurity.com.


Related to this article