News
Aesto Health AWS Breach Hits HHS Portal at 9.54 Million Patients Across 30 Provider Clients, Including Everside Health · Data BreachTheGentlemen Ransomware Group Threatens Nutex Health's 27-Hospital Network; Class Action Filed Days After SEC Disclosure · Data BreachOCR Settles with California Eye Care Provider Azul Vision for Failure to Provide Timely Patient Record Access — 55th Right of Access Enforcement Action · OCR EnforcementShinyHunters Claims Leak of 7.1 Million Baxter International Salesforce Records Including Patient PII · Data BreachCareCloud EHR Vendor Breach Exposes Medical and Financial Data of 345,000 Patients · Data BreachOptalis Management Solutions and Other HIPAA-Regulated Entities Disclose Patient Data Breaches Affecting Thousands · Data BreachFive Small Healthcare Organizations Disclose Patient Data Breaches: Family Medical Associates of Raleigh, Arkansas Oral & Maxillofacial Surgeons, Alpine Agency of the Midlands, Princeton Family Eye Care, and Others · Data BreachAesto Health AWS Breach Hits HHS Portal at 9.54 Million Patients Across 30 Provider Clients, Including Everside Health · Data BreachTheGentlemen Ransomware Group Threatens Nutex Health's 27-Hospital Network; Class Action Filed Days After SEC Disclosure · Data BreachOCR Settles with California Eye Care Provider Azul Vision for Failure to Provide Timely Patient Record Access — 55th Right of Access Enforcement Action · OCR EnforcementShinyHunters Claims Leak of 7.1 Million Baxter International Salesforce Records Including Patient PII · Data BreachCareCloud EHR Vendor Breach Exposes Medical and Financial Data of 345,000 Patients · Data BreachOptalis Management Solutions and Other HIPAA-Regulated Entities Disclose Patient Data Breaches Affecting Thousands · Data BreachFive Small Healthcare Organizations Disclose Patient Data Breaches: Family Medical Associates of Raleigh, Arkansas Oral & Maxillofacial Surgeons, Alpine Agency of the Midlands, Princeton Family Eye Care, and Others · Data Breach
Beginnerfront deskpractice managerprovidervendor

HIPAA and Computers: Passwords, Locks, and Shared Desks

Why screen locks and individual logins matter more than expensive gadgets.

TL;DR

Use unique logins, automatic screen locks, and least-privilege access. Most breaches start with simple gaps, not Hollywood hacking.

Updated 2026-04-21

Security does not have to mean complicated. For most practices, the basics prevent the majority of mishaps.

Lock screens

Set computers to lock after a few minutes of inactivity. An open EHR in a hallway is an invitation for snooping or accidental disclosure.

Individual accounts

Shared passwords are a red flag. They make audits impossible and training pointless. Everyone should have their own login with permissions matched to their job.

Physical safety

Position monitors so patients cannot read them at check-in. Cover sheets on desks during lunch breaks.

For vendors

If you host apps for clinics, enforce MFA, rotate keys, and log admin actions. Your customers will ask for proof during procurement.

Not legal advice. Educational overview only; consult qualified counsel for your situation.