The largest health care data breach in U.S. history started with a login that had no second lock on the door. The February 2024 ransomware attack on Change Healthcare eventually reached 192.7 million people, and former UnitedHealth Group CEO Andrew Witty later told Congress that attackers walked in through a system that lacked multifactor authentication.
That failure was not exotic. Across 2025, large health care breaches were reported at a rate of more than two a day, and the year's incidents exposed well over 100 million records. Small and midsize practices are not spared. They are targeted precisely because attackers assume the security is thin and no one is watching closely.
Regulators are moving to close the openings. A proposed overhaul of the HIPAA Security Rule would make multifactor authentication, encryption and several other controls mandatory rather than "addressable," and while the final rule has slipped past its spring 2026 target, the enforcement environment already rewards practices that act now. Here are 10 places to start.