For a small practice (a dental office with eight workforce members, a chiropractic clinic with twelve, a behavioral health group with three providers), the news about healthcare cybersecurity in 2024 and early 2025 was easy to dismiss as a story about somebody else. The breaches that made headlines were enormous. Change Healthcare. Ascension. Kaiser. Hospital systems and clearinghouses with thousands of users and the kind of attack surface a six-person practice doesn't have.

But the public record of those breaches, filed where HIPAA requires it to be filed and analyzed in real time by the trade press, teaches the same handful of lessons over and over. And the lessons travel. The practice with eight workforce members has every one of the same exposures the headline-grabbing breaches had: just in smaller numbers and with fewer people watching.

Here's what the 2024 and first-half 2025 breach record actually teaches, in plain English, for the practices that don't have a Chief Information Security Officer to translate it.

Most healthcare breaches now come through someone else.

The single most consistent lesson from the OCR Breach Portal in 2024 and 2025 is that the typical healthcare breach isn't directly against the covered entity anymore. It's against a business associate (a clearinghouse, a transcription service, an EHR vendor, a billing company, an analytics platform) that then exposes the covered entity's PHI.

The Change Healthcare attack is the canonical example. On February 21, 2024, a BlackCat / ALPHV ransomware group accessed a Change Healthcare Citrix portal where multi-factor authentication had not been enabled. From that single point of entry, the attackers ultimately exposed protected health information for approximately 192.7 million individuals: close to half the U.S. population. The downstream wave of HIPAA breach notifications that hit covered entities was not because the covered entities themselves were attacked. It was because their business associate was.

The HIPAA Journal's running statistics from OCR data confirm the pattern as a multi-year trend: hacking and IT-related incidents now drive the overwhelming majority of breach reports by volume, and a substantial share of those incidents involve business associates rather than the covered entities themselves.

For a small practice, the operational lesson is simple. Your HIPAA exposure is not just your own controls. It is also the security posture of every business associate that touches your PHI: the cloud-based EHR, the transcription service, the billing platform, the patient communications vendor, the marketing tool that has access to demographic data. The Business Associate Agreement is not a formality. The BAA is the contractual instrument that defines what happens when one of those vendors gets compromised. And in 2024 and 2025, plenty of them did.

Identity is still the front door.

The Change Healthcare breach has another lesson that doesn't depend on the size of the organization. The initial access vector was a remote-access portal where MFA had not been enabled. In an organization with thousands of users and a sophisticated security operation, a single missing MFA configuration was sufficient to produce one of the largest healthcare breaches in U.S. history.

The implication for a small practice is uncomfortable but actionable. The same control gap (MFA missing on a remote-access entry point, a service account, a legacy authentication path) is the gap an attacker will find in any environment, and the practice's smaller size doesn't make the gap less exploitable. It just makes the exposure smaller in absolute terms when the gap gets exploited.

The 2026 HIPAA Security Rule update will eliminate the "addressable" classification that has historically given practices room to argue MFA was optional in some contexts. But the underlying lesson is already in the public record: where MFA is missing, attackers find it. The argument for enforcement everywhere is no longer theoretical. It's been documented at the scale of 192 million people.

Ransomware against healthcare is not slowing down.

The American Hospital Association's cybersecurity hub flagged a specific trend through 2025: the FBI named healthcare the top target for ransomware. The pattern is not new (healthcare has been a ransomware target for years), but the intensity through 2024 and into 2025 has been consistent enough that even industry bodies that don't usually issue stark warnings are issuing stark warnings.

The lesson for small practices is not that ransomware will inevitably hit them. Most won't be directly attacked. The lesson is that when a ransomware event hits the healthcare ecosystem, it doesn't stay where it started. Clearinghouses go down and the practice's claim cycle stops. EHR vendors get compromised and the practice's records access stops. Pharmacy systems get compromised and prescription fulfillment stops. The practice doesn't have to be the target of the attack to bear the operational consequences of the attack.

The two controls that limit exposure to ransomware in the practice's own environment are the same ones the HIPAA Security Rule already names: endpoint detection and response across workstations, and immutable backups that have been tested for restoration. Both are explicitly mentioned in carrier cyber insurance applications. Both are now expected to be in place rather than being on a remediation roadmap.

The lessons that travel from the big breaches to the small practices.

Pulling the threads together, the public record of 2024 and 2025 teaches four lessons that scale down cleanly from a 100,000-user hospital system to a six-person practice:

  1. Inventory your business associates and know which ones touch PHI. When one of them gets breached, you will need to know which patients were potentially exposed.
  2. Verify MFA enforcement at every remote-access point, every administrative account, and every legacy authentication path. The Change Healthcare entry point was a single Citrix portal. Yours might be a remote desktop, a cloud EHR admin account, a vendor portal, an email account with legacy auth still enabled.
  3. Confirm your backups are immutable and have been restored from in the last 90 days. Most ransomware encrypts both production data and reachable backups. Both have to be assumed compromised in an incident; only immutable, separately-controlled backups survive.
  4. Document the controls now, while you have time. When OCR opens an investigation, which it will, eventually, for many practices in the next compliance cycle, the first document requested is the Security Risk Analysis. The practice that has one ready is in a fundamentally different conversation than the practice that is trying to assemble one under pressure.

The largest healthcare breaches of 2024 and 2025 are not stories about somebody else. They are case studies in the controls that should already be in place at every scale of healthcare practice. The OCR portal is the public ledger that records what happens when they aren't.