- HIPAA Insider
- Posts
- Building healthcare software? Start with security
Building healthcare software? Start with security
Encryption, MFA, supported technology, and strong internal controls should be considered from day one.
HIPAA Compliance Requires More Than a Secure Application
by HIPAA Vault
A healthcare application can function perfectly and still expose an organization to serious security and compliance risks.
A major healthcare breach reported in 2024 affected more than 2.35 million individuals, illustrating the potential scale of harm when sensitive patient information is exposed.
While public information does not establish that outdated application code caused that incident, legacy software remains a significant concern. Applications built with unsupported languages, frameworks, or plugins may contain known vulnerabilities—and moving them to a modern hosting environment can reveal compatibility problems that require development work.
Healthcare applications should incorporate safeguards such as:
Encryption for sensitive information
Multi-factor authentication
Supported languages and frameworks
Regular security updates
Appropriate access controls
Secure hosting and infrastructure
Employee training and security policies
Encryption and MFA are strongly recommended safeguards. However, under the HIPAA Security Rule currently in effect, encryption is an addressable implementation specification, and MFA is not explicitly required in every situation. Each organization must evaluate its risks and document the safeguards it chooses.
HIPAA obligations apply to covered entities and business associates—not to an application or hosting platform in isolation. Secure technology cannot compensate for weak policies, poor access management, exposed workstations, or inadequate employee training.
Build security into the complete application lifecycle, keep the technology supported, and treat HIPAA compliance as an ongoing organization-wide responsibility.

Is Your Healthcare Application Properly Protected?
HIPAA Vault can help evaluate your hosting environment, application security controls, and shared compliance responsibilities—then identify practical steps for addressing potential gaps.
Quote of the Week
"Compliance is at the company level."
— Gil Vidals, HIPAA Vault founder
A secure application is important, but compliance also depends on administrative, physical, and technical safeguards throughout the organization.
Catch the full conversation! → 📺 Watch on YouTube - 🎧 Listen on Spotify
HIPAA Compliance Tip of the Week
A Working App Isn't Necessarily a Secure App.
Just because a healthcare application still functions doesn't mean it's safe. Unsupported frameworks, outdated libraries, and unpatched code can introduce security and compliance risks—even when everything appears to be working normally.
Vibe Coding a Healthcare App? Don’t Improvise the Security.
AI tools can help you build and launch applications faster—but speed can also introduce hidden risks.
Generated code may include insecure dependencies, weak access controls, exposed credentials, or configurations that were never designed for sensitive patient information. And even well-written code still needs secure infrastructure, monitoring, updates, backups, and clearly assigned compliance responsibilities.
HIPAA Vault provides fully managed hosting environments for healthcare applications, helping developers and organizations build on a stronger security foundation.
Vibe code the idea. Let HIPAA Vault help secure the environment.
Review your healthcare application with a HIPAA hosting specialist
Industry News Roundup
23andMe’s $18M DNA Bill
Turns out, "your password123" wasn't the only problem.
23andMe will pay $18 million to settle a multistate lawsuit brought by 42 state attorneys general over the 2023 data breach that exposed the personal information of 6.9 million customers. While the company initially blamed users for reusing passwords in a credential stuffing attack, investigators concluded that 23andMe failed to implement basic cybersecurity protections that could have stopped—or at least detected—the attack much sooner.
Where things went wrong
The investigation found several glaring security gaps:
No password blocklists to prevent the use of previously breached credentials.
No mandatory multifactor authentication (MFA).
No rate limiting or intrusion prevention to slow credential stuffing attacks.
Poor logging and monitoring, allowing attackers to operate undetected for five months.
Failure to investigate suspicious spikes in login attempts or address known vulnerabilities.
More than just a settlement
The agreement requires 23andMe—now operating as the 23andMe Research Institute under TTAM Research—to implement stronger cybersecurity controls moving forward. The $18 million will be distributed among the participating states, with New York receiving more than $705,000.
This isn't the company's first financial hit. 23andMe has already:
Agreed to pay $46.75 million to settle customer claims.
Been fined $2.75 million in Spain and $3.1 million in the UK over the same breach.
Faced a separate lawsuit from California, though a bankruptcy judge recently ruled the state cannot pursue monetary damages due to the company's Chapter 11 reorganization.
Credential stuffing starts with reused passwords—but regulators made it clear that companies can't shift all the blame to users. Basic safeguards like MFA, password screening, and attack monitoring are now considered table stakes, especially when you're entrusted with customers' genetic data.
Centers Lab Hit by Breach Affecting 542,000 Patients
Another healthcare provider is dealing with the fallout of a major cyberattack.
Centers Lab NJ, a New Jersey-based diagnostic testing laboratory, disclosed that 542,377 individuals had their protected health information exposed following a cybersecurity incident discovered in August 2025. Investigators found that an unauthorized third party accessed the company's systems between August 9 and August 14, exfiltrating files containing sensitive patient data before the intrusion was detected.
What was exposed?
The compromised information varies by individual but may include:
Names
Dates of birth
Social Security numbers
Passport numbers
Driver's license or state ID numbers
Medical information
Health insurance information
After completing a forensic investigation and reviewing the impacted data, Centers Lab recently finished validating the affected records and has begun notifying patients.
What's being done?
Centers Lab says it has implemented additional security measures to strengthen its defenses, while noting that cybersecurity controls were already in place before the attack. Affected individuals are being offered 12 to 24 months of complimentary credit monitoring and identity theft protection.
Although the company did not identify the attackers, the WorldLeaks ransomware group has claimed responsibility and reportedly published the stolen data on its dark web leak site.
When highly sensitive medical and identity data is stolen—and potentially leaked online—the risk doesn't end when the breach is disclosed. Anyone notified should enroll in the free identity protection services and closely monitor their financial and healthcare accounts for suspicious activity.
Unsupported frameworks, unpatched vulnerabilities, weak configurations, and unclear security responsibilities can expose sensitive patient information—even when the application appears to be working perfectly.
HIPAA Vault provides fully managed hosting environments designed for healthcare applications and the sensitive data they handle. Our team helps manage the infrastructure surrounding your application, including monitoring, vulnerability scanning, remediation, backups, and security support.
Whether you are launching a new healthcare platform or moving a legacy application to a modern environment, we can help you identify the right hosting architecture and clarify which security responsibilities belong to your organization.
Talk with a HIPAA hosting specialist → Get a HIPAA Hosting Quote
Your application deserves more than a place to run. It needs an environment built to protect it.
