- Explain major health privacy regulations globally
- Identify common cybersecurity threats in healthcare
- Implement security controls for health data
- Describe de-identification standards and organisational privacy safeguards

Introduction
Health information privacy and security are core requirements for digital health, maintaining patient trust and enabling the beneficial use of health data. As healthcare becomes increasingly digital and data-driven, protecting sensitive health information from unauthorised access, misuse, and breach becomes both more challenging and more important. Healthcare organisations face sophisticated cyber threats while managing complex regulatory requirements and rapidly evolving technology. The stakes are high: compromised health data can lead to identity theft, insurance fraud, discrimination, and serious personal embarrassment for patients whose most intimate medical details become exposed.
This chapter explores the regulatory frameworks governing health information privacy, cybersecurity threats facing healthcare, and the security controls and organisational approaches needed to protect health data. These are not abstract IT concerns: clinicians who understand how data is protected - and how that protection fails - are better placed to safeguard their patients and their organisations.
This chapter extends concepts from Chapter 2: Electronic Health Records (EHRs), Chapter 4: Mobile Health and Connected Devices, and Chapter 5: Health Data and Analytics. The data stored in EHRs, collected by connected medical devices, and analysed through health analytics platforms all require robust privacy protections and security controls discussed in this chapter.
Privacy Regulations
In 1994, after Philadelphia Inquirer reporting and a settlement brokered by the AIDS Law Project of Pennsylvania, Rite Aid agreed to stop divulging AIDS-related prescription information to Pennsylvania employers, a case that exposed how routine pharmacy billing practices could leak the most sensitive diagnoses to people the patient never intended to share them with (Goldfein and Schalman-Bergen, 2010). Cases like this demonstrated that the healthcare industry's patchwork of state laws and professional ethics codes was inadequate for the information age. Congress responded with the Health Insurance Portability and Accountability Act (HIPAA) in 1996, creating the first comprehensive federal framework for protecting health information privacy and security in the United States (HHS Office for Civil Rights, 2024).
HIPAA's foundational insight was that health information flows in predictable patterns that regulations could address systematically. When you visit a doctor, your information naturally travels to the pharmacy filling your prescription, the laboratory processing your tests, the insurance company paying your claims, and the billing company collecting your copay. HIPAA calls the first three groups "covered entities" and holds them directly accountable for protecting your information. But recognising that modern healthcare depends on countless third-party services (from cloud computing providers to analytics vendors), the law extends these obligations to "business associates" who handle protected health information on behalf of covered entities.
What exactly counts as protected health information? The definition is deliberately expansive, encompassing any individually identifiable health information: your diagnoses and treatments, but also your demographics, insurance details, and even your appointment history. The breadth reflects a sobering reality about modern data: seemingly innocuous details become identifying when combined. Your date of birth, postcode, and hospital visit date might uniquely identify you even without your name attached. For researchers and public health officials who need health data without individual identities, HIPAA provides de-identification standards: either expert statistical determination that re-identification is very unlikely, or removal of eighteen specified identifier types under the safe harbour method.
The Privacy Rule balances protection with the practical demands of healthcare delivery. Treatment, payment, and routine healthcare operations can proceed without patients signing authorisation forms for each information exchange. This recognises that requiring explicit consent for every prescription transmission or insurance claim would grind healthcare to a halt. Beyond these routine uses, however, patient authorisation becomes necessary unless specific exceptions apply for public health reporting, approved research, or law enforcement. Patients retain rights to access their own records, request corrections, and receive an accounting of who has received their information and why.
If the Privacy Rule establishes what protections apply, the Security Rule specifies how to achieve them. Rather than mandating specific technologies that would quickly become outdated, HIPAA requires organisations to conduct risk analyses and implement safeguards appropriate to their circumstances. A rural solo practice and a major academic medical centre face different threats and have different resources; the Security Rule accommodates this reality while requiring both to maintain adequate protection. The safeguards span three domains: administrative (security policies, training, incident response), physical (facility access, workstation security), and technical (access controls, encryption, audit trails) (NIST, 2024).
HIPAA's enforcement strengthened in 2009 when the HITECH Act responded to the growth of electronic health records. The new law established breach notification requirements that improved transparency: organisations must now notify affected patients, the federal government, and sometimes the media when unsecured protected health information is compromised. This public accountability created strong incentives. Organisations facing the prospect of explaining a breach to thousands of patients and seeing their name on the federal "wall of shame" invest more seriously in prevention (HHS Office for Civil Rights, 2025). As of the August 2024 inflation adjustment, penalties can reach approximately $2.13 million per violation category per year (up from the original statutory cap of $1.5 million), and state attorneys general gained authority to pursue HIPAA violations on behalf of their residents.
The 21st Century Cures Act, enacted in 2016, addressed "information blocking": practices that interfere with patients' or clinicians' access to electronic health information without reasonable justification. However, the information blocking provisions were not finalised until the ONC Information Blocking Final Rule in 2020, and enforcement did not begin until April 2021. This provision recognises that privacy protections, while necessary, can be misused as excuses to prevent beneficial information sharing. The tension between protecting privacy and enabling interoperability remains one of digital health's central challenges.
Across the Atlantic, the European Union took a different philosophical approach. While HIPAA applies specifically to healthcare entities, the General Data Protection Regulation (GDPR), which took effect in 2018, protects all personal data regardless of industry (European Data Protection Board, 2023). Its premise is that individuals have rights over their personal information: not just healthcare information, but all data that identifies them. These rights include data portability (receiving your data in a format you can take elsewhere), the right to erasure (the "right to be forgotten"), and rights to explanation when automated systems make decisions about you.
Health data receives enhanced protection under GDPR as a "special category" that generally cannot be processed without explicit consent or other specific legal justifications. The regulation's extraterritorial reach means that any organisation processing EU residents' data must comply, regardless of where that organisation is located. An American hospital treating European tourists, or a health app downloaded by EU citizens, falls within GDPR's scope. Non-compliance carries penalties that dwarf HIPAA's: up to 4% of global annual revenue or €20 million, whichever is greater. Enforcement in healthcare has been concrete: in 2019, the Dutch Data Protection Authority fined Haga Hospital €460,000 for inadequate access controls after dozens of staff inappropriately accessed a celebrity patient's medical records (Autoriteit Persoonsgegevens, 2019); in 2023, the Italian Data Protection Authority fined ASL Napoli 3 Sud €30,000 for inadequate security measures following a ransomware attack affecting over 840,000 patients and employees (Garante per la Protezione dei Dati Personali, 2023).
Table 9.1: HIPAA vs GDPR Comparison
| Aspect | HIPAA (US) | GDPR (EU) |
|---|---|---|
| Scope | Covered entities and business associates | All organisations processing EU resident data |
| Consent | Not always required; permits many uses | Generally required for health data processing |
| Individual Rights | Access, amendment, accounting of disclosures | Access, rectification, erasure, portability, objection |
| Breach Notification | Individuals within 60 days; HHS within 60 days (500+ individuals) or annually; media for breaches affecting more than 500 residents of a state | 72 hours to supervisory authority; individuals without undue delay if high risk |
| Penalties | Up to ~$2.13M per violation category/year (inflation-adjusted) | Up to 4% global revenue or €20M |
| Enforcement | HHS Office for Civil Rights | National Data Protection Authorities |
The United Kingdom retained GDPR's requirements through the UK GDPR following Brexit, but NHS organisations face additional layers of obligation that reflect the long history of medical confidentiality in British law. The Caldicott Principles, first articulated in 1997, provide ethical guidance on using patient-identifiable information. They emphasise that such information should only be used when necessary and access should be on a strict need-to-know basis. The Common Law Duty of Confidentiality creates legal obligations that predate and supplement statutory requirements. NHS organisations must complete the Data Security and Protection Toolkit annually, demonstrating compliance with national data security standards, while the Information Commissioner's Office oversees enforcement as the independent data protection authority.
In the United States, HIPAA represents a floor rather than a ceiling. States have enacted their own privacy laws that may exceed federal requirements, creating a complex patchwork that multi-state healthcare organisations must manage carefully. California's Consumer Privacy Act and Privacy Rights Act provide broad consumer data rights affecting healthcare, while Virginia, Colorado, Connecticut, and other states have followed with comprehensive privacy legislation. For healthcare organisations operating nationally, compliance requires understanding not just HIPAA but the most stringent applicable state requirements.
A healthcare organisation discovers that an employee has been accessing patient records without a legitimate clinical reason, viewing the records of a neighbour involved in a high-profile local news story. What factors should guide the organisation's response? How do you balance workforce discipline, regulatory obligations, patient notification, and organisational learning from this incident?
Cybersecurity Threats
In September 2020, a ransomware attack struck University Hospital Dusseldorf in Germany. With critical systems encrypted and inaccessible, the emergency department could not accept patients. An ambulance carrying a woman with a life-threatening condition was diverted to a hospital 30 kilometres away. She later died, and German prosecutors investigated whether the attack constituted negligent homicide (Ralston, 2020). The investigation was discontinued in November 2020 after prosecutors concluded that the patient's underlying medical condition was the sole cause of death and the diversion delay had no bearing on the outcome (O'Neill, 2020). The case remains the first widely-cited instance in which a patient death was initially linked to a hospital ransomware attack, and it became a turning point in how healthcare cybersecurity is treated as a patient-safety issue.
This tragedy illustrates why healthcare has become the preferred target of sophisticated cybercriminal organisations. The sector presents a combination of vulnerabilities: health records command premium prices on dark web markets (far more valuable than stolen credit cards, which can be quickly cancelled), complex technology environments offer numerous entry points, and the life-safety stakes mean hospitals face strong pressure to restore operations immediately. This makes them more likely to pay ransoms quickly and in full.
Ransomware has evolved from a nuisance into a serious threat for healthcare organisations (Sophos, 2024). Modern attacks do not simply encrypt data and demand payment; criminal groups now exfiltrate sensitive patient records first, then threaten public release even if organisations recover from backups without paying. This "double extortion" model means that organisations face both operational paralysis and data breach consequences simultaneously. When clinical systems go dark, the consequences cascade: clinicians cannot access medication lists to avoid dangerous interactions, radiologists cannot view imaging studies, laboratory results become invisible, and care teams lose the shared situational awareness that modern medicine depends upon. Hospitals have diverted ambulances for weeks, postponed surgeries, and reverted to paper processes that multiply error rates and exhaust staff.
The attack vectors that enable such devastation often begin with something deceptively simple: a convincing email. Phishing remains the most common initial compromise technique because it exploits human psychology rather than technical vulnerabilities. Healthcare workers operate under time pressure in hierarchical environments where questioning instructions from apparent superiors feels uncomfortable. These are precisely the conditions that make phishing effective. A message appearing to come from the chief medical officer, flagged urgent, requesting immediate action to review an attached policy document, can bypass the scepticism that might catch cruder attempts. Once an employee clicks a malicious link or opens a weaponised attachment, attackers gain their initial foothold. From there, they move laterally through networks, escalating privileges, mapping valuable targets, and positioning for maximum impact before launching their visible attack.
Business email compromise takes social engineering further by impersonating executives, vendors, or other trusted parties to redirect financial transactions. An accounts payable clerk receives an email that appears to come from a long-standing medical supply vendor, explaining that the company has changed banks and providing new wire transfer instructions. The email address is subtly misspelled (perhaps "vend0r" instead of "vendor"), but under time pressure, the difference goes unnoticed. Healthcare's complex vendor relationships and substantial financial flows create abundant opportunities for such frauds.
Not all threats come from outside. Insider threats (employees, contractors, or others with legitimate access who misuse it) account for a significant proportion of healthcare breaches. The motivations vary widely. Simple curiosity drives healthcare workers to look up neighbours, coworkers, or local celebrities in the medical record. Financial desperation leads some to sell patient data. Personal vendettas prompt others to access ex-partners' records inappropriately. In rare cases, stalkers use clinical system access to track victims. Unlike external attackers who must find vulnerabilities and breach defences, insiders already possess authorised access. Their abuse is limited primarily by logging and monitoring controls that organisations may implement inconsistently.
The proliferation of connected medical devices has opened another front in healthcare cybersecurity. An infusion pump running outdated software might be vulnerable to attacks that alter medication delivery. An imaging system on an old operating system provides attackers with a foothold from which to reach other network resources. Security researchers have demonstrated vulnerabilities in pacemakers and insulin pumps that could theoretically enable targeted attacks on individual patients. As of 2026, no confirmed patient harm from medical device hacking had been reported, but the expanding attack surface means this risk grows each year as more devices connect to networks for clinical integration and remote monitoring. Manufacturers, regulators, and healthcare organisations continue to grapple with securing devices that were often designed before cybersecurity became a serious concern.
Finally, supply chain attacks represent a concerning threat vector. Rather than attacking healthcare organisations directly, criminals compromise the software, services, or hardware those organisations rely upon. A single compromised software update can provide access to thousands of downstream customers simultaneously. The 2020 SolarWinds attack demonstrated this approach at scale, affecting government agencies and major corporations alike (US Government Accountability Office, 2022). Healthcare organisations depend on countless third-party services, including electronic health record vendors, cloud providers, medical device manufacturers, and billing systems. Each represents a potential pathway for supply chain compromise.
The February 2024 ransomware attack on Change Healthcare demonstrated the catastrophic potential of supply chain compromise in healthcare. Change Healthcare processes approximately 15 billion healthcare transactions annually, serving as critical payment and claims infrastructure for pharmacies, hospitals, and insurers across the United States (American Hospital Association, 2024). When the ALPHV/BlackCat ransomware group breached the system, the cascading effects were immediate and far-reaching: pharmacies could not process prescriptions, hospitals could not submit insurance claims, and providers faced severe cash-flow disruptions. The breach ultimately affected approximately 193 million individuals (HHS Office for Civil Rights, 2025), making it the largest healthcare data breach in US history.
Table 9.2: Healthcare Cybersecurity Threats
| Threat Type | Description | Impact | Prevention Strategies |
|---|---|---|---|
| Ransomware | Encrypts data, demands payment | System downtime, data loss, patient safety risk | Backups, segmentation, endpoint protection |
| Phishing | Deceptive emails to steal credentials | Account compromise, initial access for attacks | Training, email filtering, MFA |
| Business Email Compromise | Impersonation for financial fraud | Financial losses, vendor relationship damage | Payment verification procedures, awareness |
| Insider Threats | Misuse by employees/contractors | Privacy breaches, data theft | Access controls, monitoring, audit logs |
| Medical Device Attacks | Exploitation of connected devices | Patient safety, network compromise | Segmentation, patching, vendor management |
| Supply Chain Attacks | Compromise through third parties | Widespread access, difficult detection | Vendor assessment, monitoring, SBOM review |
Consider a hospital facing a ransomware attack that has encrypted key clinical systems including the electronic health record. The attackers demand payment, but paying may fund criminal organisations and encourage future attacks. Meanwhile, clinicians cannot access medication lists, allergy information, or recent test results. How should leadership weigh the immediate patient safety concerns against the broader ethical implications of paying ransoms?
Security Controls and Best Practices
Imagine a medieval castle designed to withstand siege. The moat creates distance from attackers. The outer wall forces them to breach heavy fortifications. Arrow slits let defenders attack while remaining protected. The inner keep provides a final refuge even if outer defences fall. Each layer serves a purpose, and the failure of any single defence does not mean total defeat. This principle, defence in depth, guides modern cybersecurity just as it guided medieval fortification.
Healthcare organisations cannot rely on any single security measure, no matter how sophisticated. Firewalls fail. Passwords get stolen. Employees click malicious links despite training. Individual defences will eventually be breached; what matters is whether the organisation has enough layers that an attacker who defeats one control faces another, and another, until the attack becomes too costly or too slow to succeed. Effective security requires controls that prevent attacks from succeeding, detect when prevention fails, and enable rapid response to limit damage (HHS ASPR, 2024).
The first line of defence is controlling who can access what. Consider what happens when a nurse logs into the electronic health record. That nurse should see patients on her unit, not patients hospital-wide. She should see clinical information, not billing details. She should be able to document care, not modify physician orders. This is the principle of least privilege: grant only the minimum access necessary for each person's specific role. When a ransomware attack compromises a single user's credentials, least privilege limits the damage to what that user could access. Ideally, this is a small subset of organisational data rather than everything.
Implementing least privilege at scale requires role-based access control, where permissions attach to job functions rather than individuals. A "bedside nurse" role might include access to unit census, medication administration, and vital signs documentation. A "charge nurse" role adds scheduling functions. A "nurse manager" role adds performance reviews and staffing data. When someone changes positions, updating their role automatically adjusts their permissions without requiring manual review of every individual access right.
But passwords alone, even with perfect role assignments, remain dangerously vulnerable. Phishing campaigns harvest credentials constantly. Employees reuse passwords across personal and professional accounts, so a breach at a completely unrelated service can compromise healthcare credentials. Multi-factor authentication changes this calculus by requiring multiple verification types: something you know (password), something you have (phone or hardware token), or something you are (fingerprint or facial recognition). An attacker who steals a password still cannot access systems without also possessing the second factor.
Even properly authenticated users transmitting sensitive data across networks face interception risks. Encryption addresses this by rendering data mathematically unreadable to anyone without the decryption key. Data in transit (moving across networks from browser to server, from hospital to laboratory, from clinic to pharmacy) should travel through encrypted channels using transport layer security (TLS). Data at rest (sitting on server hard drives, in databases, on portable devices) should be encrypted so that a stolen laptop or improperly disposed hard drive does not become a breach. Encryption carries a notable benefit under HIPAA: encrypted data that is lost or stolen may not require breach notification because it remains unintelligible to attackers.
Network architecture itself provides defensive depth. Rather than a flat network where any connected device can communicate with any other, segmentation divides the environment into zones with controlled boundaries. Clinical systems occupy one segment, administrative systems another, medical devices a third. Firewalls between segments filter traffic based on rules. A registration workstation has no legitimate reason to communicate with the pacemaker programmer, so that traffic gets blocked. When attackers compromise one segment, they face additional barriers before reaching others. The ransomware that encrypts billing workstations may never reach the electronic health record if network segmentation prevents lateral movement.
Modern networks generate large volumes of data (connection logs, authentication events, system alerts, application messages), far too much for human review. Security information and event management (SIEM) systems aggregate this data, correlating events across sources to identify attack patterns. A single failed login might be unremarkable. But a failed login from an unusual geographic location, followed by a successful login, followed by large data downloads at 3 a.m., triggers an alert. Intrusion detection systems watch network traffic for signatures of known attacks; intrusion prevention systems go further by automatically blocking detected threats.
Individual devices (the "endpoints" where users interact with systems) require their own protections. Traditional antivirus software recognises known malware by matching files against databases of threat signatures, but novel malware evades signature detection. Endpoint detection and response (EDR) solutions add behavioural analysis: software that starts encrypting files rapidly, or that establishes unusual network connections, triggers investigation regardless of whether it matches known signatures. For mobile devices that employees carry between home and hospital, mobile device management (MDM) enforces security configurations and enables remote wiping if devices are lost.
Attackers actively scan for vulnerabilities: unpatched software, misconfigured systems, and known weaknesses. Organisations must find these vulnerabilities first. Vulnerability management programmes run regular automated scans, identifying known weaknesses and prioritising remediation based on risk. A high-severity vulnerability in an internet-facing system demands immediate attention; a low-severity issue on an isolated internal system can wait. Patch management (applying security updates from software vendors) requires balancing urgency against operational disruption, since patches occasionally cause compatibility problems. Penetration testing goes beyond automated scanning by engaging specialists to attack systems as real adversaries would, finding weaknesses that automated tools miss.
Technology alone cannot secure healthcare. The human element (every employee who might click a phishing link, reuse a password, or tailgate through a secure door) remains both a significant vulnerability and an important defence. Security awareness training teaches staff to recognise threats: suspicious emails, social engineering tactics, physical security risks, proper data handling. But one-time training fades from memory. Effective programmes reinforce lessons continuously through simulated phishing campaigns that identify employees who need additional coaching and through regular reminders that keep security awareness present in daily work.
When prevention fails (and eventually it will), incident response determines whether a security event becomes a minor disruption or a major crisis. Response plans developed before incidents strike define who does what. They specify who leads the response team, who communicates with executives and the board, who handles media inquiries, who coordinates with law enforcement, and who manages technical containment and recovery. Tabletop exercises test these plans by walking teams through realistic scenarios before real incidents occur. After each incident, post-mortems identify root causes and drive improvements. The goal is to ensure the organisation learns from every breach.
Can you answer these questions?
What are the key differences between HIPAA's Privacy Rule and Security Rule, and what types of safeguards does each require?
How does encryption protect health information, and why does it provide "safe harbour" from breach notification requirements?
What steps should an organisation take immediately upon discovering a potential data breach?
How do the principles of "least privilege" and "defence in depth" work together to protect health information systems?
Summary
The regulatory frameworks governing health data - HIPAA in the United States, GDPR across the European Union, and the UK GDPR supplemented by Caldicott Principles and common law duties - share a common premise: that patients share sensitive information because they trust it will be protected, and that violating this trust undermines the therapeutic relationship. These frameworks differ in scope and mechanism (HIPAA is sector-specific; GDPR applies to all personal data) but converge on requiring organisations to demonstrate, not merely claim, that they handle health data responsibly.
The cybersecurity threats facing healthcare are serious, growing, and increasingly consequential for patient safety. Ransomware attacks have diverted ambulances, delayed surgeries, and disrupted medication dispensing. Supply chain compromises create systemic risk because critical services concentrate in single intermediaries: when the Change Healthcare breach took one company in the payment path of pharmacies, hospitals, and insurers offline, prescription processing and claims submission stalled across the United States. No combination of technical controls can eliminate these threats entirely, which is why the defence-in-depth approach - layered controls where the failure of any single measure does not mean total compromise - remains the organising principle for healthcare security. The human element, from the employee who recognises a phishing attempt to the executive who funds security investment, is as important as any technology.
Key Takeaways
HIPAA establishes the primary US framework for health information privacy and security, with Privacy and Security Rules defining requirements for covered entities and business associates.
GDPR provides comprehensive data protection requirements affecting any organisation processing EU residents' data, with substantial penalties for non-compliance.
Healthcare faces significant cybersecurity threats including ransomware, phishing, insider threats, and medical device vulnerabilities requiring layered security approaches.
Effective security combines technical controls including access management, encryption, network security, endpoint protection, and vulnerability management within comprehensive security programmes.
Security requires organisational commitment including leadership support, risk management, third-party oversight, workforce training, and incident response preparation.
References
- American Hospital Association (2024). Congress Urged to Help Hospitals Impacted by Change Healthcare Cyberattack. American Hospital Association.
- Autoriteit Persoonsgegevens (2019). Haga Hospital fined for failing to adequately protect patient records. Autoriteit Persoonsgegevens (Dutch Data Protection Authority).
- European Data Protection Board (2023). European Data Protection Board - GDPR Guidelines on Health Data. European Data Protection Board.
- Garante per la Protezione dei Dati Personali (2023). Ordinanza ingiunzione nei confronti dell'Azienda Sanitaria Locale Napoli 3 Sud (28 settembre 2023, doc. web n. 9941232). Garante per la Protezione dei Dati Personali.
- HHS Administration for Strategic Preparedness and Response (2024). Healthcare and Public Health Sector Cybersecurity Performance Goals (HPH CPGs). U.S. Department of Health and Human Services.
- HHS Office for Civil Rights (2024). HIPAA for Professionals. U.S. Department of Health and Human Services.
- HHS Office for Civil Rights (2025). HHS Breach Portal. U.S. Department of Health and Human Services.
- National Institute of Standards and Technology (2024). NIST Special Publication 800-66: Implementing HIPAA Security Rule. NIST.
- Patrick Howell O'Neill (2020). Ransomware Did Not Kill a German Hospital Patient. MIT Technology Review.
- Ronda B. Goldfein, Sarah R. Schalman-Bergen (2010). From the Streets of Philadelphia: The AIDS Law Project of Pennsylvania's How-To Primer on Mitigating Health Disparities. Temple Law Review, Vol. 82.
- Sophos (2024). The State of Ransomware in Healthcare 2024. Sophos.
- US Government Accountability Office (2022). Cybersecurity: Federal Response to SolarWinds and Microsoft Exchange Incidents (GAO-22-104746). US Government Accountability Office.
- William Ralston (2020). The Untold Story of a Cyberattack, a Hospital and a Dying Woman. Wired UK.