Sep 23, 2026
News
Protecting Your Practice's Digital Assets: What Actually Works in 2026



Every medical practice has digital assets worth protecting — patient records, billing systems, scheduling software, the practice management platform that keeps the whole office running. The question isn't whether those assets need protecting. It's whether the protection you have actually works against the threats hitting South Florida medical offices right now.
The Numbers Behind the Threat
804 large healthcare data breaches were reported in 2025 — averaging more than two a day nationwide.
Healthcare has been the costliest industry for data breaches for 14 straight years running, averaging $7.42 million per breach in 2025.
It now takes healthcare organizations 279 days on average to identify and contain a breach — about five weeks longer than the cross-industry median.
When ransomware is involved, attackers demanded an average of $5.08 million in disclosed 2025 cases.
These aren't hospital-system numbers only. They come from a healthcare sector where small and mid-size practices increasingly make up the target list.
Why Small Practices Are the Ones Getting Hit
In 2022, more than half of the financial penalties issued by HHS's Office for Civil Rights — 55% — landed on small medical practices, not hospital systems. Not because small practices cause more harm when something goes wrong, but because they're easier to break into and slower to notice when someone has.
2025 saw 534 healthcare-specific data compromises nationally, part of a 79% increase in healthcare breaches over five years. And 16% of healthcare email breaches trace back to a third-party vendor or business associate — a billing company, a lab, an IT contractor — not the practice itself.
Most of these breaches don't start with a sophisticated hack. They start with a misconfiguration: MFA that was never turned on for one account, a vendor integration nobody's reviewed since it was installed, a login left exposed because "we'll fix that later."
What This Means for a South Florida Practice
Palm Beach, Broward, and Miami-Dade medical offices carry the same target profile as everywhere else — patient records, insurance data, scheduling and billing systems — plus a few local complications. Hurricane season pushes practices toward rushed, under-secured remote work setups every year. And the dense concentration of small independent practices and specialty groups in South Florida means many share vendors, EMRs, and IT resources with each other. If one link in that chain gets breached, it rarely stays contained to just one office.
Practical Takeaways
Turn on multi-factor authentication everywhere PHI lives — email, EMR, practice management software, remote access. No exceptions for accounts that are "just for scheduling."
Encrypt backups and keep at least one copy somewhere ransomware can't reach — offline or immutable, not just a second folder on the same network.
Review every vendor and business associate agreement (BAA) that touches patient data. A vendor's weak security becomes your breach.
Put a written incident response plan in place before you need it — who calls whom, in what order, within the first hour of discovering a problem.
Train staff to recognize phishing and social engineering attempts specifically, not with a generic annual video nobody remembers by March.
Get a real risk assessment, not a checkbox one. Most breaches trace back to gaps nobody had actually looked for.
Not sure where your practice stands? Take our free 2-minute HIPAA Risk Assessment to see which of these gaps apply to you.
Get expert clarity
Frequently asked questions
Can my staff use the free version of ChatGPT or Claude at work?
Yes, for tasks with no patient information at all, like drafting a generic handout or a job posting. Never for anything touching a patient’s chart or PHI, per both companies’ own consumer terms.
What is a BAA and why does it matter for AI tools?
A Business Associate Agreement is a signed contract required under HIPAA before any vendor can touch PHI on your behalf. Anthropic and OpenAI only offer BAAs on business-tier or API plans, and it must be separately executed, not assumed from a paid subscription.
Does paying for ChatGPT Plus or Claude Pro make it HIPAA-compliant?
No. Both companies state that even paid individual consumer accounts (Plus, Pro, Max) are not covered by a BAA and PHI should not be entered into them.
What should our practice do before letting staff use AI with patient information?
Confirm a business-tier account is provisioned with an executed BAA, set a written policy distinguishing PHI from non-PHI use cases, and fold AI access into your existing audit-logging and access-review process.
How does UpsiteGroup help with this?
We confirm which AI tools your staff can access, verify a BAA is actually on file (not just technically available), and manage AI access controls alongside your EHR’s existing security configuration.

