Electronic Health Records Security Controls Assessment
This assessment re-analyzes a published study of electronic health record security as though the hospital were a U.S. organization subject to HIPAA and HITECH. It concludes that the existing controls are not effective as an overall program, because physical security works while administrative and technical controls are inconsistent or missing, and it recommends moving to a managed security program.
By Sean Richard · Project date 2026
At a glance
- Scenario
- A hospital EHR environment (Wanyonyi et al., 2017) re-analyzed as a U.S.-based organization subject to HIPAA, HITECH, and the Breach Notification Rule.
- Method
- Apply U.S. laws, policies, standards, and baselines, evaluate the study's proposed controls, and judge overall control effectiveness.
- Finding
- Physical security works (97% rated effective), but administrative and technical controls are inconsistent or missing. The program is not effective as a whole.
- Outcome
- Move to a managed security program: RBAC and MFA, encryption at rest and in transit, centralized logging, tested backups, and recurring assessment.
The U.S. laws, policies, and standards applied
| Layer | Applied |
|---|---|
| Laws | HIPAA Privacy Rule, HIPAA Security Rule, HITECH Act, and the HIPAA Breach Notification Rule |
| Policies | Access control, authentication and passwords, workforce security and termination, training, audit logging, incident response, backup and contingency, media disposal, configuration and patching, and physical and environmental security |
| Standards and baselines | NIST CSF 2.0, NIST SP 800-53 Rev. 5 (tailored moderate baseline), and NIST SP 800-66 Rev. 2 |
The HIPAA Security Rule requires reasonable and appropriate administrative, physical, and technical safeguards to preserve the confidentiality, integrity, and availability of electronic protected health information. The Privacy Rule adds limits on uses and disclosures, including the minimum-necessary principle. HITECH and the Breach Notification Rule add accountability and notification requirements if unsecured PHI is compromised.
A tailored moderate-impact baseline is an appropriate starting point, because compromise of EHR confidentiality, integrity, or availability could cause serious harm to patients and operations. The assessment is careful on one point: the NIST baseline is used as a security benchmark, not as a claim that every private U.S. hospital is legally required to adopt NIST SP 800-53.
Are the existing controls effective?
No. Some individual controls work, particularly physical security, which 97% of respondents viewed as effective. The EHR environment still remains exposed. The study reported these threats and gaps by share of respondents:
| Threat or gap | Share of respondents |
|---|---|
| Unauthorized access | 93.5% |
| Social engineering | 87.2% |
| Theft of records | 80.8% |
| Lack of file encryption | 79.7% |
| Lack of backups | 64.2% |
| Unassigned access permissions | 52.9% |
| Lack of multifactor authentication | 50.8% |
The study also found that basic safeguards had not been fully implemented, including a security professional, proper access-right allocation, removal of former users, and power backup. Effectiveness ratings were weak for automatic logoff, password implementation, and multifactor authentication. A control should be judged on measured effectiveness, not on the fact that it exists.
Evaluating the study's proposed controls, and what to add
The controls proposed in the study are appropriate because they address weaknesses the study actually measured: media disposal, privileged-account ownership, frequent system audits, stronger identification and authentication, proper configuration, automated off-site backups, improved physical and environmental controls, power backup, maintenance, and personnel security. Six additions make the program more complete:
- Role-based access control and least privilege, with periodic access reviews and immediate deprovisioning when employees leave or change roles.
- Multifactor authentication required for EHR access, especially for privileged and remote accounts.
- ePHI encrypted both at rest and in transit.
- Centralized audit logging and security monitoring to detect abnormal access to patient records and privileged accounts.
- A formal vulnerability and patch-management process, tested incident-response procedures, and regularly tested encrypted backups.
- Recurring security-awareness training and phishing or social-engineering exercises.
From isolated controls to a managed security program
The central recommendation is structural: documented requirements, assigned control owners, measurable baselines, and recurring assessments.
- Identity and access management: least privilege, role-based access, MFA, strong password rules, periodic access recertification, and immediate account removal on termination or transfer.
- Technical controls: encryption, secure configuration, endpoint protection, patching, vulnerability management, centralized logging, alerting, and routine audit review.
- Operational resilience: automated off-site backups, restoration testing, UPS and generator capacity, environmental monitoring, and a tested contingency plan.
- Administrative controls: recurring risk analysis, workforce training, incident-response exercises, personnel screening, and sanctions for policy violations.
The hospital should then reassess the controls on a schedule using defined performance measures, which is consistent with HIPAA's requirement to protect ePHI and with NIST guidance for ongoing control assessment.
What this project demonstrates
- Applying HIPAA, HITECH, and NIST guidance to a healthcare environment.
- Judging control effectiveness from measured evidence instead of control existence.
- Distinguishing a legal requirement from a security benchmark.
- Recommending a managed program across identity, technical, resilience, and administrative controls.
Read the full document
Portfolio edition of coursework completed for the B.S. in Cyber/Computer Forensics & Counterterrorism at Full Sail University. The organization and scenario are a course case study, and this page summarizes the full document.