- HIPAA Insider
- Posts
- Lock the Digital Doors Before Hackers Walk In
Lock the Digital Doors Before Hackers Walk In
š„ New Episode: Beyond the Surface: Understanding Different Types of Vulnerability Scans
by HIPAA Vault
Think of vulnerability scans as a cybersecurity checkupābecause leaving your systems unchecked is like leaving your office unlocked overnight. These automated scans identify weak spots in servers, apps, and networks before attackers do.
There are different levels:
URL/Unauthenticated scans show whatās visible to the outside world.
Credentialed scans dig deeper, uncovering misconfigurations and outdated software.
Penetration tests go even further, simulating real hacker exploits.
š Donāt wait for a breachārequest a vulnerability scan today and strengthen your security posture while staying HIPAA compliant.
HIPAA Compliance Tip of the Week
Donāt Just Check the BoxāCheck for Vulnerabilities
HIPAA requires more than policies on paperāit demands proof youāre actively protecting ePHI. Vulnerability scans are a practical way to show auditors that youāre identifying risks, remediating them, and staying compliant.
Action Steps:
š” Perform authenticated scans to detect hidden weaknesses inside your systems
š Fix critical vulnerabilities first, then document remediation efforts
š Classify risks by severity and keep detailed reports for HIPAA audits
āļø Schedule scans throughout developmentānot just after deployment
āSecurity is usually forgotten during development and considered last minute. Thatās always bad. You should include it at each step.ā
ā Henri Alfonso, Compliance Manager, HIPAA Vault
Industry News Roundup
July Makes It a Hot Month for Healthcare BreachesāBut In a Good Way?
Good news: healthcare data breaches in the U.S. dropped significantly in July 2025. HIPAA-regulated entities reported just 48 breaches affecting 500+ individuals, down from the 12-month average of about 60āmarking a 34.1% month-over-month decline. Even better, the number of people impacted shrank by 44.5%, with roughly 4.4 million individuals affectedāthanks in part to an absence of mega-incidents like last yearās Change Healthcare breach.
Still, two major cyberattacksāat Anne Arundel Dermatology (MD) and Radiology Associates of Richmond (VA)āaccounted for 75% of the total exposure. Hacking remained the top culprit, driving 83% of Julyās breaches. Final totals may still rise as investigations wrap up.
ā Want the full breakdown? Read the HIPAA Journalās July breach report here.
Morris Hospital Is Cutting a Check
Morris Hospital & Healthcare Centers has agreed to pay $1.36 million to settle a class-action lawsuit after a 2023 cyberattack exposed data on nearly 249,000 patients. While the hospital isnāt admitting any wrongdoing, affected individuals could get up to $5,000 for documented out-of-pocket lossesāor a smaller cash payout with no paperwork. The clockās ticking: claims must be filed by October 28, objections by September 29, and a final court approval is set for October 24. The breach stemmed from a ādata security incidentā that gave hackers access to sensitive health info.
ā Read the full story on HIPAA Journal here.
Close Security Gaps Before They Become Breaches
HIPAA Vault makes it easy to protect ePHI with scans that go beyond the basics. From surface-level checks to deep authenticated assessments, we help you uncover risks before attackers do.
Our team delivers:
š Automated scans + detailed remediation reports
š Compliance-focused testing (HIPAA, PCI-DSS, GDPR)
š Executive summaries for audits and IT teams
š Continuous monitoring and re-scans to verify fixes