Skip to content
StudyDex
Health & Medicine

Which of the following are common causes of breaches?

Quick answer

Common causes of HIPAA breaches include lost or stolen devices, unauthorized access by insiders, phishing and other cyberattacks, improper disposal of protected health information, and inadequate staff training. On most exams the correct choice is 'all of the above.'

The answer

When a question lists causes of health-information (HIPAA) breaches and offers an 'all of the above' option, that is almost always the correct choice, because breaches stem from many overlapping causes, not a single one. The most common categories are:

  • Lost or stolen devices — unencrypted laptops, phones, and USB drives holding protected health information (PHI).
  • Unauthorized access — employees or insiders viewing records they have no business reason to see (snooping), or credentials being misused.
  • Phishing and cyberattacks — hacking, ransomware, and malware, frequently launched through a deceptive email that tricks a staff member into revealing a password.
  • Improper disposal of PHI — throwing paper charts in regular trash or discarding drives without wiping them.
  • Inadequate training / human error — misdirected emails, faxes to the wrong number, and staff who simply do not know the safeguards.

Because each of these is a documented, frequent cause, a well-written MCQ collapses them into 'all of the above.'

Why the distractors are 'wrong' only in isolation

The trap in this question is that each individual option is a real cause — so choosing just one (say, only 'hacking') is incorrect not because it is false but because it is incomplete. Test-takers who pick a single answer are usually pattern-matching to the most publicized cause (cyberattacks) and forgetting that, historically, a large share of reported breaches come from lost/stolen devices and simple human error, not glamorous hacks. Ruling out the single-item options therefore comes down to recognizing that the question asks for common causes (plural) and that the listed items are not mutually exclusive.

The bigger picture: cause-to-safeguard mapping

What most quiz pages omit is that every breach cause maps to a specific safeguard — which is exactly how you both answer the question and prevent the event. Encryption defeats lost-device breaches; role-based access and audit logs defeat snooping; email filtering and staff awareness defeat phishing; shredding and drive-wiping defeat disposal breaches; and ongoing training defeats human error. Under HIPAA, a breach is generally an impermissible use or disclosure of unsecured PHI that compromises its security or privacy, and covered entities must perform a risk assessment and, when required, notify affected individuals, HHS, and sometimes the media. Understanding the pairing of cause and control is the durable knowledge behind the exam answer.

Lost or stolen deviceUnencrypted laptop taken from a carFull-disk encryption + remote wipe
Unauthorized access / snoopingStaff viewing a celebrity's chartRole-based access + audit logs
Phishing / cyberattackRansomware from a fake login emailEmail filtering + security training
Improper disposalPaper charts in normal trashShredding + certified drive wiping
Inadequate training / human errorEmail sent to the wrong patientOngoing HIPAA awareness training

Frequently asked

What is the most common cause of HIPAA breaches?

Historically, lost or stolen unencrypted devices and human error (such as misdirected emails and faxes) account for a very large share of reported breaches, though hacking and IT incidents have risen sharply in recent years. There is no single dominant cause — several categories each contribute heavily.

How can HIPAA breaches be prevented?

Prevention pairs each cause with a control: encrypt devices, enforce role-based access with audit logs, filter email and train staff against phishing, shred or wipe media before disposal, and run ongoing awareness training. Layered technical, physical, and administrative safeguards are the HIPAA standard.

What is considered a HIPAA breach?

A breach is generally an impermissible use or disclosure of unsecured protected health information that compromises its security or privacy. Unless a low-probability risk assessment shows otherwise, the covered entity must treat it as a breach and follow notification rules.

What should you do after a data breach?

Contain the incident, perform a risk assessment, and document everything. If the PHI was unsecured and compromised, notify affected individuals without unreasonable delay (within 60 days), notify HHS, and, for large breaches, notify prominent media as required by the Breach Notification Rule.

Start freeLog in