The data set is unusually rich. Health information, Social Security numbers, Medicare and Medicaid identifiers, insurance details, and often bank or trust account information for residents. That combination supports both medical identity theft and financial fraud, and the resident population is a preferred target for both.
Care does not pause. A retailer with encrypted systems loses sales. A skilled nursing facility with an encrypted electronic health record still has to administer medications, document assessments and respond to call lights, on paper, with staff who may never have done it that way. The downtime procedure is a clinical safety issue rather than an inconvenience, and gaps in it produce medication errors that become liability claims.
Notification obligations attach to health information under HIPAA and to personal information under state breach laws, and the two do not align. A single incident can trigger both, on different timetables.
Business associate agreements mean the pharmacy, the therapy contractor, the billing vendor and the electronic health record host all handle your residents data. A breach at any of them can become your notification obligation and your reputational event.
The workforce profile creates phishing exposure: high turnover, shared workstations, personal devices used for scheduling and communication, and limited security training budget.