Cybersecurity Case Study · Govern & Comply

Electronic Health Records Security Controls Assessment

This assessment re-analyzes a published study of electronic health record security as though the hospital were a U.S. organization subject to HIPAA and HITECH. It concludes that the existing controls are not effective as an overall program, because physical security works while administrative and technical controls are inconsistent or missing, and it recommends moving to a managed security program.

By Sean Richard · Project date 2026

At a glance

Scenario
A hospital EHR environment (Wanyonyi et al., 2017) re-analyzed as a U.S.-based organization subject to HIPAA, HITECH, and the Breach Notification Rule.
Method
Apply U.S. laws, policies, standards, and baselines, evaluate the study's proposed controls, and judge overall control effectiveness.
Finding
Physical security works (97% rated effective), but administrative and technical controls are inconsistent or missing. The program is not effective as a whole.
Outcome
Move to a managed security program: RBAC and MFA, encryption at rest and in transit, centralized logging, tested backups, and recurring assessment.

The U.S. laws, policies, and standards applied

Regulatory and standards basis applied to the EHR case study
LayerApplied
LawsHIPAA Privacy Rule, HIPAA Security Rule, HITECH Act, and the HIPAA Breach Notification Rule
PoliciesAccess control, authentication and passwords, workforce security and termination, training, audit logging, incident response, backup and contingency, media disposal, configuration and patching, and physical and environmental security
Standards and baselinesNIST CSF 2.0, NIST SP 800-53 Rev. 5 (tailored moderate baseline), and NIST SP 800-66 Rev. 2

The HIPAA Security Rule requires reasonable and appropriate administrative, physical, and technical safeguards to preserve the confidentiality, integrity, and availability of electronic protected health information. The Privacy Rule adds limits on uses and disclosures, including the minimum-necessary principle. HITECH and the Breach Notification Rule add accountability and notification requirements if unsecured PHI is compromised.

A tailored moderate-impact baseline is an appropriate starting point, because compromise of EHR confidentiality, integrity, or availability could cause serious harm to patients and operations. The assessment is careful on one point: the NIST baseline is used as a security benchmark, not as a claim that every private U.S. hospital is legally required to adopt NIST SP 800-53.

Are the existing controls effective?

No. Some individual controls work, particularly physical security, which 97% of respondents viewed as effective. The EHR environment still remains exposed. The study reported these threats and gaps by share of respondents:

Reported threats and gaps, share of respondents (Wanyonyi et al., 2017)
Threat or gapShare of respondents
Unauthorized access93.5%
Social engineering87.2%
Theft of records80.8%
Lack of file encryption79.7%
Lack of backups64.2%
Unassigned access permissions52.9%
Lack of multifactor authentication50.8%

The study also found that basic safeguards had not been fully implemented, including a security professional, proper access-right allocation, removal of former users, and power backup. Effectiveness ratings were weak for automatic logoff, password implementation, and multifactor authentication. A control should be judged on measured effectiveness, not on the fact that it exists.

Evaluating the study's proposed controls, and what to add

The controls proposed in the study are appropriate because they address weaknesses the study actually measured: media disposal, privileged-account ownership, frequent system audits, stronger identification and authentication, proper configuration, automated off-site backups, improved physical and environmental controls, power backup, maintenance, and personnel security. Six additions make the program more complete:

  1. Role-based access control and least privilege, with periodic access reviews and immediate deprovisioning when employees leave or change roles.
  2. Multifactor authentication required for EHR access, especially for privileged and remote accounts.
  3. ePHI encrypted both at rest and in transit.
  4. Centralized audit logging and security monitoring to detect abnormal access to patient records and privileged accounts.
  5. A formal vulnerability and patch-management process, tested incident-response procedures, and regularly tested encrypted backups.
  6. Recurring security-awareness training and phishing or social-engineering exercises.

From isolated controls to a managed security program

The central recommendation is structural: documented requirements, assigned control owners, measurable baselines, and recurring assessments.

  • Identity and access management: least privilege, role-based access, MFA, strong password rules, periodic access recertification, and immediate account removal on termination or transfer.
  • Technical controls: encryption, secure configuration, endpoint protection, patching, vulnerability management, centralized logging, alerting, and routine audit review.
  • Operational resilience: automated off-site backups, restoration testing, UPS and generator capacity, environmental monitoring, and a tested contingency plan.
  • Administrative controls: recurring risk analysis, workforce training, incident-response exercises, personnel screening, and sanctions for policy violations.

The hospital should then reassess the controls on a schedule using defined performance measures, which is consistent with HIPAA's requirement to protect ePHI and with NIST guidance for ongoing control assessment.

What this project demonstrates

  • Applying HIPAA, HITECH, and NIST guidance to a healthcare environment.
  • Judging control effectiveness from measured evidence instead of control existence.
  • Distinguishing a legal requirement from a security benchmark.
  • Recommending a managed program across identity, technical, resilience, and administrative controls.
HIPAA/HITECHNIST CSFNIST SP 800-53EHR securityIAMEncryptionResilience

Read the full document

Portfolio edition of coursework completed for the B.S. in Cyber/Computer Forensics & Counterterrorism at Full Sail University. The organization and scenario are a course case study, and this page summarizes the full document.

Related work

Ready to build the system behind your growth?

Tell me what you're operating.