
October 2026 | Medical Practice Cybersecurity Salt Lake City | Cybersecurity Awareness Month | HIPAA Security Myths
October is Cybersecurity Awareness Month — a good time to take stock of what you actually know versus what you think you know about protecting your Salt Lake City medical practice. Between HIPAA requirements, EHR systems like Epic, Cerner, Athenahealth and eClinicalWorks, and a waiting room that never slows down, it's easy for outdated advice to go unquestioned. Some of it has circulated for so long that it sounds like fact even when it's flat-out wrong.
When bad advice goes unchallenged, it creates blind spots. And blind spots are exactly what cybercriminals look for. Knowledge gaps and comfortable assumptions are what make medical practices easy targets — and in healthcare, the stakes aren't just financial. A security incident can interrupt patient care and put protected health information (PHI) at risk.
The good news is that these gaps are simple to close once you know where they are. Here are six myths we hear from practice owners and office managers regularly, along with the truth behind each one.
Myth 1: "Cybercriminals Won't Care About Our Practice"
This is the most dangerous myth in healthcare, because the opposite is true: healthcare is the number one ransomware target of any industry. Patient records sell for far more on the dark web than stolen credit card numbers, because a medical record contains everything — names, birthdates, Social Security numbers, insurance details and clinical history that can't be canceled or reissued like a card.
It doesn't matter what specialty you're in or how quiet your practice seems. If you have exposed accounts, an unpatched EHR workstation or a vulnerable remote-access connection, bad actors will take advantage. Every practice holds valuable PHI, billing access and entry points to insurance networks and referral partners.
Fact: Hackers choose targets based on opportunity, not profile — and PHI is the most valuable data they can steal.
Myth 2: "Our Staff Will Recognize a Phishing Email"
The days of obvious phishing emails full of typos from suspicious senders are gone. Today's attacks arrive looking like the messages your front desk team handles all day: a referral from another provider with a "patient records" attachment, an insurance prior authorization request that needs a login, or a lab portal notification asking someone to reset a password.
Thanks to AI, it's become harder to catch a scam from the text alone. Instead, your clinical staff and front desk team need to think about sender behavior. Ask whether the supposed sender would:
- Send an unexpected referral or records request from an unfamiliar address
- Change payment or remittance instructions
- Request patient information or login credentials by email
- Send a new or unusual link to an EHR, lab or insurance portal
If anything seems off, double-check by phone before clicking or responding.
Fact: A convincing email can still be a scam — even one that looks like a referral or insurance authorization.
Myth 3: "MFA Fully Protects Our EHR"
Multi-factor authentication (MFA) is important — and for systems that touch PHI, it should be considered mandatory. But it isn't invulnerable. Hackers use MFA fatigue to their advantage, counting on busy staff approving requests out of habit. "Prompt bombing," for example, floods a phone with requests in hopes someone will approve access to your EHR or billing platform just to make them stop.
MFA is a tool, not a shield. Attackers are finding ways around weaker authentication methods, which is why MFA on your Epic, Athenahealth or AdvancedMD logins needs support from the security controls around it — monitoring, access reviews and staff who know that an unexpected prompt is a red flag, not an annoyance.
Fact: MFA should be part of a broader, HIPAA-aligned security strategy — not the whole plan.
Myth 4: "Our Backups Have Us Covered"
Ask yourself: if your practice was hit with a ransomware attack tomorrow, could you actually restore your patient records? How long would your EHR be down? Could you see patients safely in the meantime?
A backup is great when you know it's going to work. An untested PHI backup isn't something you can rely on during an incident — and EHR downtime doesn't just cost money, it disrupts appointments, delays prescriptions and forces your clinical staff back to paper. Knowing how long your practice would realistically be down, and verifying that restores actually work, can save you days of interrupted patient care.
Fact: Having backups is not the same as being able to recover — test your PHI restores before you need them.
Myth 5: "Cybersecurity Is Only IT's Responsibility"
Your IT support does a lot to keep your practice safe, but they can't control every click. Security decisions happen at the front desk, in the billing office and in the exam room — and it takes only one bad click on a fake referral to expose your systems.
In healthcare, there's an extra layer: HIPAA makes safeguarding PHI a legal obligation for everyone in the practice, not just the IT provider. Employee security awareness training isn't optional box-checking — it's part of the administrative safeguards HIPAA expects you to have. When everyone from providers to the front desk team knows what to look for and when to ask for help, they become part of your defenses instead of the gap in them.
Fact: Training your staff to make good decisions strengthens your security posture — and supports your HIPAA compliance.
Myth 6: "We Know What to Do If Something Happens"
It's Tuesday morning. Your front desk can't open the schedule, and providers can't access charts. Many practices discover in that exact moment that nobody has answered the basic questions:
- Should staff shut down their workstations?
- Who calls IT — and who moves the practice to downtime procedures so patients can still be seen?
- What do you do if phones and email are down?
- When do the insurance company and your attorney get involved?
- Who determines whether PHI was exposed, and who notifies patients?
That last question matters more in healthcare than anywhere else. HIPAA's Breach Notification Rule sets legal deadlines for notifying affected patients and the Department of Health and Human Services. Winging it isn't an option — miss the timeline and the incident gets more expensive and more public.
Don't rely on memory in the moment. Have a documented incident response plan that includes clinical downtime procedures and breach notification steps.
Fact: Your recovery plan shouldn't debut during an incident — especially when patient care and HIPAA deadlines are on the line.
Frequently Asked Questions
Do you offer HIPAA-compliant IT services for medical practices in Salt Lake City?
Yes. Qual IT provides HIPAA-compliant IT services for Salt Lake City medical practices, including security risk analysis support, EHR and network security, encrypted PHI backup and recovery, email security, staff security awareness training, MFA implementation and incident response planning built around HIPAA's breach notification requirements.
What is the biggest cybersecurity mistake medical practices make?
Assuming they're covered without verifying it. Untested PHI backups, unexamined assumptions about staff readiness and security tools nobody monitors create a false sense of protection — which is often more dangerous than a known gap, and harder to defend in a HIPAA audit.
How do I know if my practice's cybersecurity is actually working?
Through testing and review: verified backup restores of your EHR and patient records, simulated phishing exercises for your staff, and a periodic security risk analysis by a qualified IT partner who understands medical practice cybersecurity and HIPAA requirements.
Cybersecurity Awareness Starts With the Facts
Cybersecurity Awareness Month is about making sure the assumptions guiding your decisions are correct. Myths are comfortable — they let you feel covered without digging deeper. But in a medical practice, security gaps rarely come from a missing product. They come from believing you've already got it handled when you don't.
We work with Salt Lake City medical practices to protect patient data and maintain HIPAA compliance. If any of these myths sound familiar, it's time to take a closer look at where your practice stands — from your EHR to your backups to your front desk inbox.
Schedule a free 10-minute discovery call with Qual IT and we'll help you separate what's protecting your patients from what's only giving you peace of mind. Book your discovery call here.

