The Healthcare Breach Nobody Talks About: Insider Threats and How to Address Them
- sonali negi
- Aug 13
- 5 min read
Updated: Aug 17

Every healthcare cybersecurity conversation focuses on the same threats. Ransomware. Phishing. Third-party vendor access. These are real risks, and they deserve the attention they receive.
But 30% of healthcare data breaches involve someone who already has legitimate access to the systems and data being compromised.
Not an external attacker who circumvented security controls. An insider.
This figure, drawn consistently from Verizon's annual Data Breach Investigations Report, represents one of the largest and most consistently underaddressed security risks in healthcare. The reason it receives less attention than ransomware is partly that it is less dramatic, and partly because it is more uncomfortable. Addressing external threats requires better technology. Addressing insider threats requires acknowledging that people your organisation employs and trusts are involved.
Both of those realities make the problem easier to defer.
What Insider Threat Actually Looks Like
The term insider threat conjures a specific image. A disgruntled employee downloading patient records before resigning. A clinician selling prescription data. These cases exist, and they are serious. But they represent a fraction of the actual insider threat landscape in healthcare.
The majority of healthcare insider incidents are not malicious. They are accidental.
A nurse accesses the medical record of a family member who is receiving care in another unit. A physician views the records of a high-profile patient out of curiosity rather than clinical necessity. A billing coordinator exports a patient dataset to a personal device to work from home, and the device is later lost or stolen. An employee clicks a link in a phishing email and credentials are compromised.
These incidents do not involve criminal intent. They involve access that the organisation's systems permitted, used in ways the organisation's policies prohibited. The distinction matters for the response. Technology controls are the primary tool for accidental insider incidents. Behavioural investigation and legal action may be required for malicious ones.
Healthcare has the highest insider threat rate of any industry, according to the Ponemon Institute's 2023 study on insider risk. This is not because healthcare workers are more likely to be malicious. It is because healthcare environments have the widest gap between the access people legitimately need to do their jobs and the access controls that govern how that access is used.
The Access Problem
Healthcare is an environment where broad access is genuinely necessary for clinical function. A physician covering an emergency department overnight may need to access the records of any patient in the building. A care coordinator managing complex patients may need to access records across multiple specialties and sites. A billing professional resolving a complex claim may need access to detailed clinical documentation.
This clinical necessity creates an access landscape that is extremely difficult to govern without impeding care. The result in most health systems is that access controls err heavily on the side of permissiveness. People have more access than their current clinical activity requires, because building access models that precisely match individual access needs to clinical roles and patient populations at any given time is technically and administratively complex.
The consequence is that when an insider incident occurs, whether accidental or intentional, the blast radius tends to be larger than it would be in an environment with more granular access controls. The nurse who accessed a family member's record without clinical justification did not just see one record. Depending on how access was configured, they may have been able to access many others.
Addressing this requires implementing least privilege access principles consistently across clinical systems. This means building access models that grant access to the patients and records that each role actually needs rather than granting access to everything and auditing after the fact. It is technically more demanding than broad role-based access. It is also substantially more effective at limiting the impact of both accidental and malicious insider incidents.
What a Genuine Insider Threat Programme Requires
Most healthcare organisations do not have an insider threat programme. They have security monitoring that generates logs, and an HR process for handling employees who are reported to have behaved inappropriately with patient data. These are not the same thing.
A genuine insider threat programme has four components.
The first is user and entity behaviour analytics. This technology monitors access patterns across clinical and administrative systems and surfaces anomalies that deviate from expected behaviour. For example, a physician who suddenly begins accessing records in departments where they have no current patients. A billing analyst who begins running large data exports outside normal working hours. An administrator whose credential is used to access systems from a location they have never previously worked from. UEBA does not determine whether intent is malicious. It surfaces activity that warrants investigation before a situation escalates.
The second is privileged access management. Not all access is equal. Administrative credentials, database access, and system-level permissions carry substantially more risk than standard clinical access. These credentials should be governed through dedicated privileged access management controls that require additional authentication, limit session duration, record sessions for audit purposes, and generate alerts when privileged credentials are used in unexpected ways.
The third is a response process. When an insider incident is identified, the response needs to be coordinated across security, HR, legal, and clinical leadership. Most healthcare organisations have not pre-planned this process and discover the gaps when they need it. Having a defined response playbook, including who has authority to revoke access, what evidence needs to be preserved, when legal counsel must be involved, and how the incident is documented for potential regulatory reporting, needs to be in place before an incident occurs.
The fourth is a security awareness programme that addresses insider risk specifically. Most healthcare security awareness training focuses on phishing. It rarely addresses the specific situations, accessing records without clinical justification, handling data on personal devices, sharing credentials for convenience- that are most common in healthcare insider incidents. Training that names these scenarios explicitly and connects them to real consequences for patients and the organisation is more effective than generic phishing simulations.
Building a Culture Alongside Technology
Technology controls can detect and limit insider incidents. They cannot prevent the underlying human behaviours that lead to them. Building a healthcare security culture where staff understand why data access controls exist and feel personally invested in protecting patient data requires more than training compliance checkboxes.
The organisations that do this well treat privacy and security as clinical values rather than IT requirements. They connect data protection to patient dignity. They recognise staff who report potential incidents or ask for guidance when they are uncertain whether an access is appropriate. And they build governance structures where clinical leadership owns the security culture alongside the security team rather than delegating it entirely to IT.
This is not soft. It is the part of insider threat management that technology cannot replace.
The external threat is increasingly sophisticated. The perimeter is increasingly difficult to maintain. The organisations that build genuine security cultures alongside their technical controls are the ones that close the gap the tools alone cannot reach.
The Conversation Worth Having
Insider threat is uncomfortable to discuss because it requires acknowledging that the risk is partly internal. But the 30% figure does not go away by not discussing it.
The health systems that are addressing this risk are doing it quietly and systematically. They are implementing behaviour analytics and privileged access management. They are building response processes before they need them. They are training staff on the specific scenarios that lead to incidents rather than the generic threats that training programmes are designed around.
They are not waiting for the incident that makes the conversation unavoidable.
Tamamie designs secure and future-proof infrastructure for healthcare providers, pharmaceutical organisations, and infrastructure leaders. Visit tamamie.com





Comments