Seven Security Mistakes Small Care Providers Keep Making

Small and mid-size care providers often assume that serious cyberattacks are aimed at large hospital systems. In practice, attackers use automated tools that probe any organization with weak defenses, and smaller operators often have fewer people watching. The good news is that most successful attacks exploit a short list of ordinary mistakes, and those are fixable.

Here are seven we see repeatedly, and what to do instead.

1. Treating IT as Someone Else's Job

When security is delegated entirely to a single IT person or a vendor, leadership may not know the risks being carried. Decisions such as budget, staffing and acceptable downtime are business decisions.

Fix: Assign a named security officer, as HIPAA requires, and review risks with the administrator at least quarterly. Ask your IT provider for reporting in plain language.

2. Skipping the Risk Analysis

Many providers have policies but no current security risk analysis. This is one of the most frequently cited problems in federal enforcement.

Fix: Complete an enterprise-wide analysis, document it, and build a remediation plan with owners and deadlines. Review it each year and after major changes.

3. Relying on Passwords Alone

A single password protects email, remote access and sometimes the health record. Stolen credentials are one of the most common ways attackers get in.

Fix: Turn on multi-factor authentication for email, remote access, administrator accounts and clinical systems. Begin with the most privileged accounts and work outward.

4. Having Backups That Have Never Been Tested

A backup that has not been restored is only a theory. Many organizations discover failed backups during an emergency.

Fix: Follow a layered approach with an offline or immutable copy, review backup reports weekly and test restores on a schedule.

5. Letting Software Age

Old operating systems, unpatched firewalls and forgotten servers are open invitations. Equipment that works fine often gets ignored because nothing seems broken.

Fix: Keep a current inventory, patch on a schedule, track end-of-support dates and budget to replace what vendors no longer update.

6. Giving Everyone Too Much Access

In a busy building, it is easier to give a new hire the same permissions as a coworker than to define exactly what they need. Over time, many users hold access they do not use. If their accounts are compromised, the attacker inherits it all.

Fix: Use role-based access, review accounts quarterly, remove former employees the same day and limit administrator rights to the few who need them.

7. Having No Incident Plan

When an incident hits at night or on a holiday, confusion costs hours. Staff may not know who to call, whether to power off computers or how to run the building without the EHR.

Fix: Write a short incident response plan with a call list, decision authority and downtime procedures. Run a tabletop exercise once a year, including night shift.

A Pattern Behind the Mistakes

None of these requires advanced technology. They require attention, ownership and regular follow-up. The organizations that fare best are not necessarily those with the largest budgets, but those that treat security as an ongoing operating practice.

How to Prioritize

If you cannot fix everything at once, use this order:

Enable multi-factor authentication on email and remote access

Verify and test your backups

Patch exposed systems, especially firewalls and remote access tools

Train staff and make reporting easy

Complete or update your risk analysis

Write and rehearse your incident response plan

Use Existing Guidance

The HHS 405(d) program publishes Health Industry Cybersecurity Practices written for organizations of different sizes, including small ones. The NIST Cybersecurity Framework 2.0, released in February 2024, offers a structure for organizing your efforts. Neither is a substitute for a tailored assessment, but both give you a vocabulary and a checklist.

Where We Fit

UnityCare IT works with care providers across Oklahoma, Texas and Arkansas, and we can perform a quick baseline review of these seven areas, show you where you stand and suggest the highest-value fixes first.

More Articles

Contact UnityCare Technologies

Call or text: 405-285-3845

New customers: start@unitycareit.com

Existing customers: support@unitycareit.com

Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172