Small and mid-size care providers often assume that serious cyberattacks are aimed at large hospital systems. In practice, attackers use automated tools that probe any organization with weak defenses, and smaller operators often have fewer people watching. The good news is that most successful attacks exploit a short list of ordinary mistakes, and those are fixable.
Here are seven we see repeatedly, and what to do instead.
When security is delegated entirely to a single IT person or a vendor, leadership may not know the risks being carried. Decisions such as budget, staffing and acceptable downtime are business decisions.
Fix: Assign a named security officer, as HIPAA requires, and review risks with the administrator at least quarterly. Ask your IT provider for reporting in plain language.
Many providers have policies but no current security risk analysis. This is one of the most frequently cited problems in federal enforcement.
Fix: Complete an enterprise-wide analysis, document it, and build a remediation plan with owners and deadlines. Review it each year and after major changes.
A single password protects email, remote access and sometimes the health record. Stolen credentials are one of the most common ways attackers get in.
Fix: Turn on multi-factor authentication for email, remote access, administrator accounts and clinical systems. Begin with the most privileged accounts and work outward.
A backup that has not been restored is only a theory. Many organizations discover failed backups during an emergency.
Fix: Follow a layered approach with an offline or immutable copy, review backup reports weekly and test restores on a schedule.
Old operating systems, unpatched firewalls and forgotten servers are open invitations. Equipment that works fine often gets ignored because nothing seems broken.
Fix: Keep a current inventory, patch on a schedule, track end-of-support dates and budget to replace what vendors no longer update.
In a busy building, it is easier to give a new hire the same permissions as a coworker than to define exactly what they need. Over time, many users hold access they do not use. If their accounts are compromised, the attacker inherits it all.
Fix: Use role-based access, review accounts quarterly, remove former employees the same day and limit administrator rights to the few who need them.
When an incident hits at night or on a holiday, confusion costs hours. Staff may not know who to call, whether to power off computers or how to run the building without the EHR.
Fix: Write a short incident response plan with a call list, decision authority and downtime procedures. Run a tabletop exercise once a year, including night shift.
None of these requires advanced technology. They require attention, ownership and regular follow-up. The organizations that fare best are not necessarily those with the largest budgets, but those that treat security as an ongoing operating practice.
If you cannot fix everything at once, use this order:
Enable multi-factor authentication on email and remote access
Verify and test your backups
Patch exposed systems, especially firewalls and remote access tools
Train staff and make reporting easy
Complete or update your risk analysis
Write and rehearse your incident response plan
The HHS 405(d) program publishes Health Industry Cybersecurity Practices written for organizations of different sizes, including small ones. The NIST Cybersecurity Framework 2.0, released in February 2024, offers a structure for organizing your efforts. Neither is a substitute for a tailored assessment, but both give you a vocabulary and a checklist.
UnityCare IT works with care providers across Oklahoma, Texas and Arkansas, and we can perform a quick baseline review of these seven areas, show you where you stand and suggest the highest-value fixes first.
Call or text: 405-285-3845
New customers: start@unitycareit.com
Existing customers: support@unitycareit.com
Address: UnityCare Technologies, 2524 N Broadway Ste 554, PMB 947974, Edmond, Oklahoma 73034-4172