When the Threat Wears a Badge: Healthcare's Insider Risk Crisis Demands Executive Ownership
- Rick Moore

- Aug 4
- 5 min read
A new HIPAA Journal report documents what many of us in healthcare security have been tracking for years: a sustained surge in malicious insider incidents, running alongside a rise in mega data breaches, with 2026 on track to set records across both categories. For health system executives and boards still treating insider threat as an IT checkbox, this data demands a fundamentally different response.
The Structural Problem Healthcare Cannot Outspend
Healthcare's insider threat exposure is built into its operating model. Large, distributed workforces require broad access to sensitive patient data as a condition of doing their jobs. Clinicians, billing staff, vendor partners, and IT administrators all hold legitimate access to systems that, in any other industry, would be tightly compartmentalized. That access is operationally necessary. It is also the primary attack surface for insider incidents.
Cloud adoption has made this worse. Over the past five years, health systems have migrated significant workloads to cloud platforms without rethinking their access governance models. The result is an access footprint often inherited from legacy role structures, one that traditional data loss prevention tools cannot adequately see or control.
The HIPAA Security Rule has required workforce security standards under 45 CFR § 164.308(a)(3) for over two decades, including documented procedures for granting, modifying, and terminating access. What the rule requires and what health systems actually implement are, across my experience advising health plans, providers, and federal agencies, very different things. OCR's 2023 resolution agreement with Montefiore Medical Center, resulting in a $4.75 million penalty, arose from a former employee stealing and selling patient data over multiple years. The access was never flagged. The behavioral monitoring was never triggered. The program was simply not designed to detect it.
What Most Healthcare Organizations Are Getting Wrong
The most consequential failure in healthcare insider threat programs is conflating malicious and negligent insider risk. These are distinct threat categories, and they require distinct control sets.
Negligent insider incidents, a workforce member emailing a PHI-containing spreadsheet to a personal account or misconfiguring a cloud storage bucket, are addressable through security awareness training, data classification, and basic DLP configuration. Most health systems invest heavily here because the controls are visible, auditable, and relatively inexpensive to deploy. It is the path of least organizational resistance.
Malicious insider incidents are a different problem entirely. A disgruntled employee exfiltrating patient records for financial gain, or a privileged IT administrator abusing system access with deliberate intent, requires behavioral analytics, user and entity behavior analysis, privileged access monitoring, and a rapid response capability that brings HR, Legal, and Security into alignment before the damage compounds. Most health systems have none of that cross-functional structure in place.
The CISO owns the monitoring tools. HR owns the workforce policies. Legal owns the investigation protocols. Nobody owns the program end-to-end. CISA's Insider Threat Mitigation Guide identifies this governance gap as the primary reason technically capable organizations still suffer preventable malicious insider breaches.
The external threat picture compounds this further. Attackers increasingly gain initial access by weaponizing legitimate insider credentials: service accounts, vendor access pathways, privileged user sessions. The Verizon 2024 Data Breach Investigations Report identified credential theft as the leading initial access vector in healthcare. When an attacker is operating inside your environment on a legitimate credential, perimeter controls are irrelevant. What matters is whether your behavioral baselines and access governance are tight enough to detect anomalous activity regardless of how the session was authenticated. This is the privileged access governance problem that PAM tools alone cannot solve.

What This Means at the Executive and Board Level
The financial exposure from insider-related breaches is substantial and routinely underestimated. OCR settlements for access control failures and workforce security deficiencies have ranged from hundreds of thousands to multiple millions of dollars. That is before accounting for state attorney general actions, class action litigation, and the operational disruption that follows a large-scale PHI disclosure requiring notification to tens of thousands of individuals.
For health systems and plans operating under value-based care arrangements, the reputational dimension matters as well. Payers and CMS partners increasingly evaluate cybersecurity governance as part of network participation and contract criteria. A high-profile insider breach signals executive-level governance failure, not a technical misconfiguration.
Boards carry meaningful exposure here. Governance expectations around material cyber risk have shifted significantly, driven by SEC disclosure requirements for public companies and increasing HHS scrutiny of health system governance practices. Healthcare boards that cannot articulate their insider threat program maturity, who owns it, how it is resourced, and how improvement is measured, are poorly positioned for that environment.
Strategic leaders recognize that insider threat is fundamentally a workforce governance problem with a security technology layer, not the reverse. Getting the governance model right is the precondition for technology investment to deliver any lasting value.
What Leaders Should Do Now
Separate your malicious and negligent insider risk programs. Conduct an honest assessment of where current investment is concentrated. If the answer is awareness training and endpoint DLP, your program is almost certainly underinvested in the behavioral analytics and privileged access governance capabilities that actually detect malicious insiders before a breach occurs. HITRUST CSF Control Category 09.aa and the NIST CSF 2.0 Govern function both provide frameworks for making this separation operationally clear.
Assign cross-functional program ownership with real authority. The CISO cannot own insider threat alone. Designate explicit joint accountability between Security, HR, and Legal. Define escalation protocols before an incident forces improvisation. Run tabletop exercises that bring all three functions into the same room. My years leading enterprise health IT, at NCQA and in the DoD health IT environment, reinforced this repeatedly: the programs that worked were the ones where ownership was documented before the incident, not assembled during one.
Audit your cloud access footprint. Cloud adoption has quietly expanded the insider threat surface in ways legacy DLP tools were never designed to address. A role lifecycle audit, covering who holds access, whether that access is still appropriate to their current role, and whether separation-of-duties controls are enforced in cloud environments, is foundational work. HHS 405(d) HICP Technical Volume 1 addresses cloud access governance directly and is an underutilized resource in most health system security programs.
Give your board a maturity framework, not a status report. Boards are asking whether insider threat monitoring exists. The right questions are who owns the program end-to-end, whether it is resourced as a cross-functional initiative, and how progress is being measured and reported over time. A board-ready maturity scorecard anchored in CISA Insider Threat guidance and HIPAA's workforce security standards is a deliverable most health system boards need and few currently have.
The Margin for Getting This Wrong Is Gone
The organizations that build credible insider threat programs are not those with the most sophisticated tooling. They are the ones where the CIO and CHRO agreed on program ownership before an incident forced the conversation. Experience has taught me that the distance between knowing these frameworks and actually operationalizing them is where most health systems lose ground, and where the bulk of OCR enforcement actions are ultimately rooted.
MTC Group works with health systems, health plans, and health IT organizations to build insider threat programs that are operationally credible, board-ready, and grounded in HIPAA, HITRUST, and NIST CSF 2.0. If your organization is ready to move from compliance posture to operational capability, I welcome the conversation.
Sources & Further Reading
HHS OCR Breach Portal, U.S. Department of Health & Human Services, Office for Civil Rights
HIPAA Security Rule, HHS Office for Civil Rights
Insider Threat Mitigation Guide, Cybersecurity and Infrastructure Security Agency (CISA)
2024 Data Breach Investigations Report, Verizon Business
NIST SP 800-53 Rev. 5: Security and Privacy Controls for Information Systems and Organizations, National Institute of Standards and Technology



Comments