The first flag is human · Healthcare

HIPAA doesn't stop at the firewall.

Most breach spending goes toward hacking and ransomware — and should. But a steady share of reportable healthcare breaches every year is simpler than that: someone on staff looked at, took, or mishandled records they had no reason to touch. That's not a technical failure. It's a program gap.

The regulatory backdrop

The regulator publishes what goes wrong. Insider misuse is a fixture, not an outlier.

HHS's Office for Civil Rights (OCR) has published every large healthcare breach since 2009. The pattern holds year over year: most incidents are external hacking, but a persistent share is workforce members doing something they shouldn't — and OCR treats that as seriously as an outside attack.

700+

large healthcare data breaches (500+ records) reported to HHS OCR in a typical recent year — each one now part of the public record.

HHS OCR Breach Portal · HIPAA Journal analysis
12–15%

of reported healthcare breaches fall under “Unauthorized Access/Disclosure” — workforce snooping, misuse, and insider misdirection, distinct from outside hacking.

HHS OCR breach data, analyzed by HIPAA Journal
60 days

is the maximum window under the HIPAA Breach Notification Rule to report a breach of unsecured PHI to HHS and affected individuals.

45 CFR §164.400–414
What actually goes wrong

It's rarely a hacker. It's usually someone with a badge.

Across the breaches OCR categorizes as unauthorized access or disclosure, the pattern repeats across practices of every size.

Record snooping

A staff member looks up a coworker, an ex-partner, or a public figure's chart out of curiosity — not treatment. The access is technically valid and the log shows nothing wrong until someone asks why.

Access that outlives the job

A departing employee's EHR credentials stay active past their last day, or they export patient lists on the way out. Small practices are the most exposed here — offboarding is rarely formalized.

Shared logins, broad access

Front-desk and clinical staff share a login “just for today,” or everyone has access to the full record instead of what their role requires. Convenience quietly becomes exposure.

A rushed disclosure under pressure

A stressed or overloaded staffer sends records to the wrong recipient, or skips a verification step to move faster. The behavior precedes the mistake — and it's visible beforehand.

Who this is for

Practices with real risk and no one dedicated to watching it.

Healthcare

Medical, dental, mental health, and addiction treatment practices

Independent and small-group practices handling protected health information every day — without a dedicated compliance or security officer. The practice manager already owns scheduling, billing, and HR. Insider risk becomes the thing nobody owns until OCR asks who was supposed to.

Services

Three ways to work together.

Same arc every time: find the gaps, train the eyes, build the program that holds.

Start here 01 · Workshop

Before the Breach

Train the eyes

A half-day session for your practice manager, front-desk lead, and clinical staff — the precursor framework adapted to EHR access, patient interactions, and HIPAA's workforce security expectations, plus a one-page escalation plan.

From $3,500Founding rate $2,500 for the first cohorts
02 · Assessment

Program Readiness & Gap Assessment

Find the gaps

2–3 weeks: access review, offboarding process, documentation review, and interviews — benchmarked against the HIPAA Security Rule's administrative safeguards, with a prioritized roadmap.

From $5,500Fixed fee · scope set before we start
03 · Retainer

Program Advisory

Build it for real

Ongoing advisory as staff and systems change — access reviews, refresher training, and mock-audit prep before OCR or a payer ever asks.

From $3,000/mo6-month minimum
Let's talk

Curious where your practice actually stands?

A 20-minute call, no pitch. Tell me where you're exposed — I'll tell you honestly whether I can help and where I'd start.

Book a 20-minute call