Share this
Compliance ≠ Security: Healthcare Organizations’ Biggest Threats
by Rebecca Gazda on Jul 26, 2022 12:00:00 AM
Compliance and security are not the same. And in healthcare, this difference is incredibly important. Checking off compliance boxes will not ensure patient data is fully secure.
It is a start, sure. But true security in your organization requires much more than compliance standards might suggest.
Security and Compliance in Healthcare: What’s the Difference?
Compliance is the first step to achieving security. Healthcare compliance can be defined as the ongoing process of meeting or exceeding the legal, ethical, and professional standards applicable to a particular healthcare organization or provider. This is especially important for healthcare organizations because the data they possess is classified as Protected Health Information (PHI) under HIPAA.
Security is the product, solutions, and/or process in place to do the work. A secure organization not only follows all of the rules outlined by the compliance guidelines, but also:
- Ensures there are no gaps in security
- Trains all employees in what they can do to maintain security
- Ensures that all possible use cases are covered
To simplify: Compliance is the checklist. Security is the ongoing, ever-evolving process.
Special Considerations in Healthcare Security
Healthcare organizations have to protect the most vulnerable and personal types of information. If they are affected by an attack, real human lives can be at stake.
However, healthcare organizations can struggle with training a workforce made up of vastly different backgrounds, technical skill levels, understanding of cybersecurity, and willingness to comply with cybersecurity guidelines.
DNSFilter Healthcare Customer Data

Looking at data collected from DNSFilter healthcare customers in the past month, the highest threat category encountered was Proxy & Filter Avoidance. Proxy & Filter Avoidance are sites that provide information or a means to circumvent DNS based content filtering, including VPN and anonymous surfing services.
For healthcare organizations, the biggest threat seen in DNS queries is employees trying to get around DNSFilter and other security tools. This speaks volumes to the need for more training and clarification around what cybersecurity tools are in place, and why they are necessary.
Also visible in this data:
Defined as: Fraudulent websites that aim to trick users into handing over personal or financial information. Phishing and deception websites can open up a “can of worms.”
If employees click the links inside of them, they open the organization up to malware, ransomware, botnets, and personal login information being stolen and used.
Defined as: Malicious software, including drop servers and compromised websites, that can be accessed via any application, protocol, or port. This also includes drive-by downloads and adware.
A huge issue here is ransomware attacks. Healthcare providers are much more likely to be forced to pay a ransomware attacker to get their data or systems back online because literal lives may be at stake.
- Translation Sites
Defined as: Sites that perform translation from one language to another, usually performed by a computer. May also be used as a means to circumvent content filters.
- New Domains
Defined as: Domains which have been registered in the last 30 days. These have a high probability of serving malicious resources.
- Botnet
Defined as: Command and Control botnet hosts. Prevents receiving commands for already infected machines and also helps to identify infected machines.
- Very New Domains
Defined as: Domains which have been registered in the last 24 hours. These have a high probability of serving malicious resources.
An Education Problem, and also a Configuration Problem

Digging deeper into the data from above, it’s clear that healthcare threats are not only an issue of employees clicking the links, but also an issue around security measures that are put in place by administrators.
Of the threats identified above, not all were blocked by DNSFilter because some customers have opted not to block all security/threat categories. Of course, this is an organizational choice.
However, DNSFilter advises caution and urges organizations to take careful consideration around the policies created within our tool.
Share this
Categories
- Featured (136)
- Cybersecurity & IT (45)
- DNS (32)
- Cyber Threats (22)
- DNSFilter Updates (19)
- Product & Features (15)
- DNSFilter Community (14)
- IndyCar (7)
- Protective DNS (6)
- Content Filtering (4)
- Public Wi-Fi (4)
- AI (3)
- IT (3)
- IT Challenges (3)
- MSP (3)
- Staying Ahead of Cyber Threats (3)
- Machine Learning (2)
- Phishing (2)
- Cybersecurity Brief (1)
- Events (1)
- Malware (1)
- Ransomware (1)
- Team (1)

The Old-School Operations Role: Backbone or Bottleneck?
In the early days of IT, the operations team was the unsung hero—the silent, and often siloed, force that kept everything running. They were responsible for the infrastructure: Servers, databases, and networks that powered the business. They managed deployments, monitored systems, and ensured uptime. If it was working, no one noticed them. If it wasn't? Well, then the questions started: "Wha...

When Vintage Goes Viral (In All the Wrong Ways)
Remember that time you found your old Tamagotchi and thought, "Hey, this could be fun again"? Well, cybercriminals are having a similar nostalgic moment, but instead of resurrecting digital pets, they're breathing new life into outdated malware and long-forgotten data breaches. Welcome to the world of recycled cyber threats, where everything old is terrifyingly new again.

The Growing Threat of Malicious Domains in Cybersecurity
As cybercriminals continue to evolve their tactics, domain-based attacks like cybersquatting, typosquatting, and other malicious domains have become a significant threat to businesses and individuals alike. These attacks are designed to exploit trust, impersonate brands, and mislead users into handing over sensitive information—often resulting in financial losses, data breaches, and reputat...