• HIPAA Insider
  • Posts
  • Building healthcare software? Start with security

Building healthcare software? Start with security

Encryption, MFA, supported technology, and strong internal controls should be considered from day one.

HIPAA Compliance Requires More Than a Secure Application
by HIPAA Vault

A healthcare application can function perfectly and still expose an organization to serious security and compliance risks.

A major healthcare breach reported in 2024 affected more than 2.35 million individuals, illustrating the potential scale of harm when sensitive patient information is exposed.

While public information does not establish that outdated application code caused that incident, legacy software remains a significant concern. Applications built with unsupported languages, frameworks, or plugins may contain known vulnerabilities—and moving them to a modern hosting environment can reveal compatibility problems that require development work.

Healthcare applications should incorporate safeguards such as:

  • Encryption for sensitive information

  • Multi-factor authentication

  • Supported languages and frameworks

  • Regular security updates

  • Appropriate access controls

  • Secure hosting and infrastructure

  • Employee training and security policies

Encryption and MFA are strongly recommended safeguards. However, under the HIPAA Security Rule currently in effect, encryption is an addressable implementation specification, and MFA is not explicitly required in every situation. Each organization must evaluate its risks and document the safeguards it chooses.

HIPAA obligations apply to covered entities and business associates—not to an application or hosting platform in isolation. Secure technology cannot compensate for weak policies, poor access management, exposed workstations, or inadequate employee training.

Build security into the complete application lifecycle, keep the technology supported, and treat HIPAA compliance as an ongoing organization-wide responsibility.

Is Your Healthcare Application Properly Protected?

HIPAA Vault can help evaluate your hosting environment, application security controls, and shared compliance responsibilities—then identify practical steps for addressing potential gaps.

Quote of the Week

"Compliance is at the company level."
— Gil Vidals, HIPAA Vault founder

A secure application is important, but compliance also depends on administrative, physical, and technical safeguards throughout the organization.


Catch the full conversation!  📺 Watch on YouTube - 🎧 Listen on Spotify

HIPAA Compliance Tip of the Week

A Working App Isn't Necessarily a Secure App.

Just because a healthcare application still functions doesn't mean it's safe. Unsupported frameworks, outdated libraries, and unpatched code can introduce security and compliance risks—even when everything appears to be working normally.

Vibe Coding a Healthcare App? Don’t Improvise the Security.

AI tools can help you build and launch applications faster—but speed can also introduce hidden risks.

Generated code may include insecure dependencies, weak access controls, exposed credentials, or configurations that were never designed for sensitive patient information. And even well-written code still needs secure infrastructure, monitoring, updates, backups, and clearly assigned compliance responsibilities.

HIPAA Vault provides fully managed hosting environments for healthcare applications, helping developers and organizations build on a stronger security foundation.

Vibe code the idea. Let HIPAA Vault help secure the environment.

Review your healthcare application with a HIPAA hosting specialist

Industry News Roundup

23andMe’s $18M DNA Bill

Turns out, "your password123" wasn't the only problem.

23andMe will pay $18 million to settle a multistate lawsuit brought by 42 state attorneys general over the 2023 data breach that exposed the personal information of 6.9 million customers. While the company initially blamed users for reusing passwords in a credential stuffing attack, investigators concluded that 23andMe failed to implement basic cybersecurity protections that could have stopped—or at least detected—the attack much sooner.

Where things went wrong

The investigation found several glaring security gaps:

  • No password blocklists to prevent the use of previously breached credentials.

  • No mandatory multifactor authentication (MFA).

  • No rate limiting or intrusion prevention to slow credential stuffing attacks.

  • Poor logging and monitoring, allowing attackers to operate undetected for five months.

  • Failure to investigate suspicious spikes in login attempts or address known vulnerabilities.

More than just a settlement

The agreement requires 23andMe—now operating as the 23andMe Research Institute under TTAM Research—to implement stronger cybersecurity controls moving forward. The $18 million will be distributed among the participating states, with New York receiving more than $705,000.

This isn't the company's first financial hit. 23andMe has already:

  • Agreed to pay $46.75 million to settle customer claims.

  • Been fined $2.75 million in Spain and $3.1 million in the UK over the same breach.

  • Faced a separate lawsuit from California, though a bankruptcy judge recently ruled the state cannot pursue monetary damages due to the company's Chapter 11 reorganization.

Credential stuffing starts with reused passwords—but regulators made it clear that companies can't shift all the blame to users. Basic safeguards like MFA, password screening, and attack monitoring are now considered table stakes, especially when you're entrusted with customers' genetic data.

Centers Lab Hit by Breach Affecting 542,000 Patients

Another healthcare provider is dealing with the fallout of a major cyberattack.

Centers Lab NJ, a New Jersey-based diagnostic testing laboratory, disclosed that 542,377 individuals had their protected health information exposed following a cybersecurity incident discovered in August 2025. Investigators found that an unauthorized third party accessed the company's systems between August 9 and August 14, exfiltrating files containing sensitive patient data before the intrusion was detected.

What was exposed?

The compromised information varies by individual but may include:

  • Names

  • Dates of birth

  • Social Security numbers

  • Passport numbers

  • Driver's license or state ID numbers

  • Medical information

  • Health insurance information

After completing a forensic investigation and reviewing the impacted data, Centers Lab recently finished validating the affected records and has begun notifying patients.

What's being done?

Centers Lab says it has implemented additional security measures to strengthen its defenses, while noting that cybersecurity controls were already in place before the attack. Affected individuals are being offered 12 to 24 months of complimentary credit monitoring and identity theft protection.

Although the company did not identify the attackers, the WorldLeaks ransomware group has claimed responsibility and reportedly published the stolen data on its dark web leak site.

When highly sensitive medical and identity data is stolen—and potentially leaked online—the risk doesn't end when the breach is disclosed. Anyone notified should enroll in the free identity protection services and closely monitor their financial and healthcare accounts for suspicious activity.

Your Application Works. But Is the Environment Protecting It?

A healthcare application can perform exactly as intended and still contain hidden security risks.

Unsupported frameworks, unpatched vulnerabilities, weak configurations, and unclear security responsibilities can expose sensitive patient information—even when the application appears to be working perfectly.

HIPAA Vault provides fully managed hosting environments designed for healthcare applications and the sensitive data they handle. Our team helps manage the infrastructure surrounding your application, including monitoring, vulnerability scanning, remediation, backups, and security support.

Whether you are launching a new healthcare platform or moving a legacy application to a modern environment, we can help you identify the right hosting architecture and clarify which security responsibilities belong to your organization.

Talk with a HIPAA hosting specialist → Get a HIPAA Hosting Quote

Your application deserves more than a place to run. It needs an environment built to protect it.