Healthcare Breach Types: Hacking, Unauthorized Access and Loss

When people hear "data breach," they picture hackers in hoodies. In healthcare, the reality is broader. The HHS Office for Civil Rights categorizes reported breaches by type, and each type suggests a different weakness in an organization's defenses. Understanding the categories helps you decide where to spend limited time and money.

This post explains the main breach types and what each suggests for controls, in plain terms for administrators and operators.

Hacking and IT Incidents

What it is

This category covers attacks on networks, servers, email accounts and applications, including ransomware, phishing that leads to account takeover, and exploitation of unpatched software. It is a commonly reported category among larger breaches.

What it suggests

Look at your technical defenses:

Multi-factor authentication on email, remote access and administrator accounts.

Prompt patching of servers, firewalls and workstations.

Endpoint protection and monitoring on every device.

Backups that are tested and kept separate from your main network.

Phishing training and a simple way for staff to report suspicious messages.

Network segmentation, so one compromised device cannot reach everything.

Unauthorized Access or Disclosure

What it is

This category includes people viewing records they have no job need to see, emails or faxes sent to the wrong recipient, and PHI shared with someone not entitled to it. The person involved is often an employee or someone with legitimate system access.

What it suggests

This is mostly a controls and culture issue:

Role-based access that matches job duties.

Audit logs that are reviewed, with alerts for unusual activity such as records opened for residents not on a user's assignment.

A clear sanctions policy, applied consistently.

Training on appropriate access and on checking recipients before sending.

Fax and email safeguards, such as confirmed numbers, address verification and encryption for external messages.

Prompt removal of access when roles change or employees leave.

Theft

What it is

Theft covers stolen laptops, phones, tablets, drives, paper records and equipment, from offices, vehicles or homes.

What it suggests

Full-disk encryption on all portable devices. Encryption can reduce the likelihood that a lost device becomes a reportable breach.

Remote lock and wipe capabilities for mobile devices.

Physical security, including locked doors, cabinets and server rooms, and visitor controls.

Clear rules against leaving devices or paper charts in vehicles.

Loss

What it is

Loss means devices, media or records are missing and cannot be accounted for: a misplaced drive, a lost chart, a phone left behind.

What it suggests

The controls resemble those for theft, with extra emphasis on inventory and tracking. Keep a current list of devices and removable media, limit what PHI is stored locally, and prefer secure cloud or server storage over copies on portable media.

Improper Disposal

What it is

Improper disposal includes throwing away paper records without shredding, or retiring computers, copiers and drives without wiping them.

What it suggests

Locked shred bins and a reliable shredding service with documented handling.

A written device retirement procedure, including secure data wiping or physical destruction, with certificates.

Remembering copiers and printers, which often store images on internal drives.

Other Categories

Reports may also list other or unknown causes, and a single event can involve several categories. For example, a phishing email (hacking) might lead to a mailbox containing years of PHI (location of data), with no one reviewing access (unauthorized access).

Using This in Your Planning

Rank the categories by likelihood and impact for your facility.

Check your controls against each list above and note gaps.

Assign owners and dates for fixes.

Document the work in your HIPAA risk analysis.

Revisit annually, or after major changes.

Do not focus on hacking alone. Smaller providers often face more everyday problems such as misdirected faxes, lost devices and curious employees, which are cheaper to prevent.

How UnityCare IT Helps

UnityCare IT works with long-term care and senior-living operators to map controls against these breach types, close the gaps that matter most and document the results. If you are unsure where to begin, we can help you prioritize.

Related service

Security monitoring, HIPAA safeguards, backups and staff training for healthcare and small businesses.

Related articles

Keep reading

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172