3 Cybersecurity Gaps HHS Keeps Citing in Small Fairfax County Medical Practices, and What to Fix First

HIPAA cybersecurity gaps for Fairfax County medical practices

A five-provider medical practice in Fairfax may not have the IT department of a regional hospital. Under HIPAA, that does not make electronic protected health information any less important.

Small healthcare organizations are dealing with the same ransomware, phishing, credential theft, outdated software, and unauthorized-access risks facing larger healthcare systems, usually with fewer internal cybersecurity resources.

HHS explicitly recognizes this reality. Its Health Industry Cybersecurity Practices (HICP) resources include guidance specifically for small healthcare organizations, including single-physician practices and small clinics with limited or outsourced IT resources. HHS also warns that attackers increasingly target smaller healthcare organizations, not just large health systems.

For medical practices in Fairfax County, the question is therefore not simply: “Are we HIPAA compliant?”

A more useful question is: “If HHS Office for Civil Rights looked at our environment tomorrow, could we show how we identify cybersecurity risks, control access to patient information, monitor our systems, and address vulnerabilities?”

Across recent OCR enforcement actions and Security Rule guidance, three cybersecurity gaps repeatedly deserve attention.

1. No Accurate, Organization-Wide HIPAA Security Risk Analysis

If your practice fixes only one thing first, start here.

The HIPAA Security Rule requires regulated entities to conduct an accurate and thorough assessment of potential risks and vulnerabilities affecting the confidentiality, integrity, and availability of electronic protected health information, or ePHI.

OCR describes risk analysis as foundational to Security Rule compliance. And this is not simply an old requirement sitting in a compliance manual. OCR continues to enforce it.

In April 2025, OCR settled a ransomware investigation involving a small neurology practice after finding that the organization had failed to conduct an accurate and thorough risk analysis. The ransomware incident encrypted the practice’s IT network and potentially affected information belonging to 6,800 individuals. The practice agreed to a $25,000 settlement and a two-year corrective action plan.

By April 2026, OCR reported 13 completed investigations under its Risk Analysis Initiative.

For a practical checklist of the security controls and areas your practice should review, see our HIPAA cybersecurity checklist for medical practices.

What does a HIPAA risk assessment for a small medical practice actually cover?

It should go beyond completing a questionnaire. A cybersecurity risk assessment should identify where ePHI exists and how it moves throughout your practice.

That can include:

  • Electronic health record systems
  • Practice management and billing platforms
  • Employee laptops and workstations
  • Email accounts
  • Cloud storage
  • Patient portals
  • Remote access
  • Mobile devices
  • Local servers
  • Backup systems
  • Connected medical equipment
  • Third-party vendors with access to ePHI

HHS guidance states that the scope should include all ePHI the organization creates, receives, maintains, or transmits, regardless of where that information resides.

For a Fairfax medical practice, a risk analysis should ultimately answer four questions: Where is our patient information? Who can access it? What could compromise it? What are we doing about those risks?

What to fix first

Create an inventory of every system that creates, receives, stores, or transmits ePHI. Then identify vulnerabilities, document risk levels, assign remediation priorities, and create a risk management plan.

Do not treat the assessment as a document you complete once and file away. HHS describes risk analysis as an ongoing process. It should be revisited when technology, personnel, operations, threats, or the practice itself materially changes. HIPAA does not prescribe one universal annual frequency for every organization.

2. Weak Access Controls, Authentication and System Visibility

Consider a common scenario. An employee leaves your Fairfax practice on Friday. Their Microsoft 365 account remains active.

  • They still have remote access
  • A shared login continues to work
  • Nobody reviews the authentication logs
  • Nothing happens for three months.

Is the practice secure simply because no breach has been discovered? No.

The HIPAA Security Rule requires technical policies and procedures that limit access to ePHI to authorized users. It also requires authentication procedures and audit controls capable of recording and examining activity in systems containing or using ePHI.

For small practices, the gaps can be surprisingly ordinary:

  • Shared user accounts
  • Former employees who still have access
  • Administrative privileges given to people who do not need them
  • Weak remote-access controls
  • Systems generating logs nobody reviews
  • Inconsistent authentication across applications.

The problem is not simply whether a security tool exists. The practice needs to know who has access to patient information and have mechanisms for identifying suspicious activity.

What to fix first

Start with identity and access. Review every employee and vendor account that can reach systems containing ePHI.

Remove inactive accounts, restrict administrator permissions, use unique user identities, strengthen authentication, review remote access and confirm that access can be terminated quickly when an employee leaves.

Then make sure relevant system activity is being logged and reviewed.

OCR specifically recommends audit controls, regular reviews of system activity, and authentication mechanisms to help ensure that only authorized users access ePHI. For a small practice without an internal security team, this is an area where medical practice IT support in Fairfax County can become particularly important. Security controls need someone responsible for configuring, monitoring, and maintaining them after the initial HIPAA project is finished.

3. Known Technical Risks That Stay Unfixed

A practice can have HIPAA policies sitting in a folder while its actual technology remains exposed. That disconnect matters.

In its January 2026 cybersecurity guidance, OCR specifically highlighted risks associated with unpatched software. HHS recommends measures including vulnerability scanning, monitoring authoritative vulnerability sources, and implementing security measures that reduce identified risks to a reasonable and appropriate level.

For a small medical office, technical gaps might include:

  • Unsupported operating systems
  • Delayed security patches
  • Poorly secured remote access
  • Unprotected endpoints
  • Inadequate backups
  • Missing vulnerability scans
  • Weak network configurations
  • Patient information stored unnecessarily on local devices
  • Insufficient monitoring
  • Poorly configured cloud applications

The issue is not whether your practice can build a cybersecurity program identical to a hospital’s. HIPAA is designed to consider factors including an organization’s size, complexity, capabilities, technical infrastructure, costs, and risks.

But identifying a serious risk and simply leaving it unresolved can create a much harder compliance position.

What to fix first

Turn the findings from your HIPAA risk analysis into a prioritized remediation plan. Start with vulnerabilities that could expose large amounts of ePHI or allow an attacker deeper access to your environment.

For many small practices, that means addressing identity and access weaknesses, critical software vulnerabilities, endpoint protection, backups, email security, and remote-access exposure before lower-risk IT improvements.

What Should a Fairfax County Medical Practice Fix First?

What Should a Fairfax County Medical Practice Fix First

Trying to “become HIPAA compliant” as one giant project makes the work harder than it needs to be. A better approach is to prioritize.

First: Know Your Risk

Complete an accurate, documented HIPAA risk assessment for your small medical practice. You cannot prioritize risks you have not identified.

Second: Lock Down Access

Review who can access ePHI, how users authenticate, which accounts have elevated privileges, and whether former employees or unnecessary third parties retain access.

Third: Fix High-Risk Technical Weaknesses

Patch critical vulnerabilities, secure endpoints, review remote access, protect backups, strengthen email security, and address other high-risk findings from the assessment.

Fourth: Make Monitoring Routine

Logging, access reviews, vulnerability management, patching, backups, and employee changes should become ongoing IT processes.

Fifth: Document What You Are Doing

A technical control that nobody can explain or document can create problems when your practice needs to demonstrate its security program. The goal is not a binder full of policies. The goal is an IT environment where the documented policies and the actual security controls tell the same story.

Why Small Fairfax Medical Practices Cannot Assume They Are Too Small for OCR

Small practice does not mean small responsibility. In May 2025, OCR announced an enforcement settlement involving a small healthcare provider whose unsecured server exposed medical images belonging to 21,778 individuals. HHS explicitly titled its announcement: “Small Health Care Providers Also Must Comply with the HIPAA Rules.”

OCR has also increased its focus on cybersecurity. Its 2024–2025 HIPAA Audit Program selected 50 covered entities and business associates to review compliance with Security Rule provisions particularly relevant to hacking and ransomware. The lesson for an independent physician office, dental practice, behavioral health clinic, specialist practice, or outpatient provider in Fairfax County is straightforward:

Your cybersecurity program should be built before an incident gives OCR a reason to examine it.

What HHS 405(d) Means for Small Medical Practices

HIPAA tells healthcare organizations what security obligations they have. HHS’s 405(d) Program provides healthcare-focused cybersecurity resources that can help organizations put practical safeguards in place.

The program developed Health Industry Cybersecurity Practices, or HICP, specifically with healthcare organizations in mind. HICP identifies five major cybersecurity threat categories and ten cybersecurity practices designed to help mitigate them. HHS also provides material specifically for small healthcare organizations because these practices may have limited internal IT resources.

For a small Fairfax County practice, HICP can provide a useful framework for strengthening areas such as:

  • Email security
  • Endpoint protection
  • Access management
  • Data protection
  • Network management
  • Vulnerability management
  • Incident response
  • Cybersecurity policies
  • Employee security awareness
  • Cybersecurity risk assessment and governance

It is particularly useful when your practice knows cybersecurity needs improvement but does not know where to begin.

HIPAA Compliance Is Not a One-Time IT Project

Your practice can complete a risk assessment today and introduce a new vulnerability six months later.

  • A new physician joins
  • Someone leaves
  • You change EHR vendors
  • A billing company gets access
  • Staff begin working remotely
  • A new cloud application gets introduced
  • A server reaches end of life
  • A newly discovered vulnerability affects software you already use

This is why HIPAA compliance for small medical practices should connect compliance work with ongoing IT management.

For medical practices across Fairfax County and Northern Virginia, CMIT Solutions NOVA South can help assess cybersecurity risks, identify technology gaps, prioritize remediation, strengthen security controls, and provide ongoing IT support around the systems that handle sensitive patient information.

The objective is not simply to prepare for an audit. It is to make the practice harder to compromise in the first place.

Need to Know Where Your Practice Stands?

If you are unsure whether your current IT environment would stand up to a HIPAA security review, start with the fundamentals. CMIT Solutions NOVA South provides cybersecurity solutions in Fairfax County and IT support for local medical practices that need help identifying and addressing security risks around ePHI.

FAQs:

What are the most common HIPAA cybersecurity violations HHS finds in small medical practices?

There is no official HHS “top three violations for small practices” list. However, OCR enforcement actions and guidance repeatedly emphasize failures involving comprehensive risk analysis, risk management, appropriate access controls, system monitoring, and other safeguards required to protect ePHI.

Risk analysis is particularly important. OCR has established a specific Risk Analysis Initiative and continues to resolve investigations involving organizations that failed to conduct an accurate and thorough assessment of risks to ePHI.

How often does HHS actually audit small medical practices?

OCR does not publish a fixed schedule under which every small medical practice will receive a routine HIPAA audit.

However, small organizations can be subject to audits and investigations, and OCR’s 2024–2025 audit initiative selected 50 covered entities and business associates for review of Security Rule provisions related to hacking and ransomware. OCR can also investigate after complaints and reported breaches.

What is a HIPAA risk assessment and how often should a Fairfax County medical practice run one?

A HIPAA Security Rule risk analysis assesses potential risks and vulnerabilities affecting the confidentiality, integrity, and availability of all ePHI an organization creates, receives, maintains, or transmits.

HIPAA does not prescribe a single fixed frequency such as “once every 12 months” for every practice. HHS describes risk analysis as an ongoing process and says organizations should update their analysis as circumstances change, including changes in technology, operations, personnel, or security threats.

What are the HIPAA penalties for a small medical practice?

HIPAA enforcement can result in corrective action requirements, settlements, or civil monetary penalties depending on the circumstances. The outcome can depend on factors including the nature and extent of the violation, harm involved, compliance history, and corrective action.

Being a small practice does not create an automatic exemption. Recent OCR enforcement actions have specifically involved small healthcare providers.

Does HIPAA require encryption for patient data?

Encryption is an “addressable” implementation specification under the HIPAA Security Rule, which does not mean it can simply be ignored. A regulated entity must assess whether encryption is reasonable and appropriate. If it does not implement encryption, it must document the decision and, where reasonable and appropriate, implement an equivalent alternative measure.

What should a small medical practice do first to close HIPAA cybersecurity gaps?

Start with an accurate and thorough HIPAA Security Rule risk analysis covering all systems that create, receive, maintain, or transmit ePHI.

Use the findings to prioritize remediation based on likelihood and potential impact. Access controls, critical vulnerabilities, endpoint security, backups, authentication, system monitoring, and workforce security practices may emerge as priorities depending on the practice’s environment.

Are small medical practices actually targeted by ransomware?

Yes. HHS specifically warns small healthcare organizations that cyber threats are real and that attackers increasingly target smaller organizations, not only major hospitals. OCR has also brought ransomware-related enforcement actions involving smaller healthcare providers, including a small neurology practice.

Does cyber insurance cover HIPAA violations?

It depends on the policy.

Cyber insurance may cover certain costs associated with a cybersecurity incident, such as incident response, forensic investigation, legal expenses, notification, business interruption, or other covered losses. Coverage for regulatory investigations, fines, or penalties varies by policy and applicable law.

Insurance should therefore complement a HIPAA cybersecurity program, not replace one.

How much does HIPAA-compliant IT support cost for a small medical practice in Fairfax County?

There is no standard price because cost depends on the number of users and locations, existing infrastructure, EHR and cloud environment, cybersecurity controls, compliance gaps, support requirements, and the amount of remediation required.

A cybersecurity risk assessment can help establish the scope before a practice commits to unnecessary tools or services.

What is the HHS 405(d) program and does it apply to small practices?

The HHS 405(d) Program is a public-private initiative designed to strengthen cybersecurity across the healthcare and public health sector.

Its Health Industry Cybersecurity Practices resources specifically include guidance for small healthcare organizations, giving smaller practices practical cybersecurity measures designed around their resources and operating environments.

Back to Blog

Share:

Related Posts

AI-generated phishing attacks Prince William County

AI-generated phishing is now harder to spot for Prince William County SMBs

In July 2025, Clorox filed a $380 million lawsuit against Cognizant, the…

Read More
ransomware recovery for financial firms in Prince William County

Ransomware Recovery for Prince William County Financial Firms: What It Really Costs

For a financial firm, a ransomware attack is not simply an IT…

Read More