BT
Benjamin Taylor LSU • Information Systems
← Back to Hub
🏆 Spotlight
10:08 AM
Featured Cybersecurity Project • LSU ISDS

HHS Data Breach Analysis &
Healthcare Sector Cyber Risk Assessment

A team-based, data-driven cybersecurity risk assessment examining the U.S. Department of Health and Human Services (HHS) breach repository. Utilizing the NIST SP 800-30 Risk Assessment Framework, our team modeled critical threat vectors, evaluated breach likelihood and operational impact, and formulated strategic defense-in-depth mitigations for healthcare organizations.

Domain & Focus
Cyber Risk & Healthcare IT
Standard Framework
NIST SP 800-30
Telemetry & Tooling
Microsoft Excel & Data Viz
Academic Base
LSU E.J. Ourso College of Business
View All Projects on Resume → Discuss This Project with Benjamin
700+
Healthcare Breach Incidents Evaluated
NIST SP 800-30
Standardized Risk Assessment Framework
Top 3 Vectors
Network Hacking, Ransomware & Insider Risk
Assessment Framework

NIST Risk Assessment Lifecycle Implementation

Our evaluation systematically transitioned from raw breach data extraction to quantitative threat likelihood scoring, vulnerability correlation, and actionable mitigation roadmaps aligned with federal compliance mandates.

Threat Source Characterization Vulnerability Identification Likelihood Determination Impact Severity Matrix Risk Remediation
Context & Challenge

The Vulnerability of U.S. Healthcare Infrastructure

The healthcare sector represents one of the most targeted critical infrastructure sectors in the United States. Under HIPAA requirements, covered entities and business associates must report breaches affecting 500 or more individuals to the U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR).

Healthcare organizations handle deeply sensitive Protected Health Information (PHI) while frequently operating on fragmented electronic health record (EHR) platforms, legacy medical devices, and decentralized vendor supply chains. Our team was tasked with examining empirical HHS breach records to diagnose root cause vulnerabilities and deliver prioritized mitigation strategies.

Analytical Methodology

Data Cleaning & Quantitative Analysis in Excel

Using advanced Microsoft Excel functionalities — including pivot tables, multi-parameter conditional lookups, and categorical aggregation — our team cleansed and parsed historical HHS breach records:

  • Categorization by Breach Type: Segmented incidents into Hacking/IT Incidents, Unauthorized Access/Disclosure, Theft, Loss, and Improper Disposal.
  • Location of Breached Information: Mapped breaches across Network Servers, Email Accounts, Electronic Medical Records (EMR), Laptops, and Paper/Films.
  • Entity Profiling: Differentiated breach trends among Healthcare Providers, Business Associates, Health Plans, and Healthcare Clearinghouses.
Critical Findings

Most Prominent Attack Vectors Discovered

Network Server Ransomware

Hacking incidents targeting centralized network servers and EMR databases represented the vast majority of exposed patient records and operational paralysis.

Email Phishing & Credential Theft

Compromised employee credentials via spear-phishing served as the predominant entry point into corporate networks and clinical communication systems.

Third-Party Business Associates

Vendor supply chain vulnerabilities exposed massive quantities of aggregated PHI when billing, claims processing, or IT contractors suffered security failures.

Unencrypted Portable Endpoints

Laptops, storage drives, and medical devices lacking mandatory full-disk encryption frequently contributed to non-compliance disclosures upon theft or loss.

Defensive Architecture

Proposed Risk Mitigation Strategies

Applying defensive controls recommended in NIST publications, our team designed an actionable remediation strategy prioritizing low-overhead, high-impact defense mechanisms:

✔ Zero Trust & Strict IAM Enforcement:

Mandate phishing-resistant Multi-Factor Authentication (MFA) across all email and network portals, utilizing conditional access policies (e.g., Azure Entra ID) and strict least-privilege role boundaries.

✔ Network Segmentation & EDR:

Isolate clinical IoT devices and patient monitoring systems from general staff networks to prevent lateral movement during ransomware outbreaks, backed by automated Endpoint Detection & Response.

✔ Immutable Air-Gapped Backups:

Establish offline, immutable backup repositories to guarantee prompt system restoration without capitulating to extortion attempts.

✔ Continuous Security Awareness:

Implement recurring phishing simulations and role-tailored security awareness education for clinical and administrative staff.

Executive Briefing

Formal Presentation & Stakeholder Briefing

Our team synthesized these analytical insights into a formal executive presentation delivered to course faculty and fellow students at LSU's E.J. Ourso College of Business. The presentation emphasized translating complex cyber telemetry into quantifiable financial and patient safety risk metrics that hospital boardrooms can prioritize.

Additional Portfolio Work

More Projects by Benjamin

Car Dealership Data Modeling

Designed an ERD model, Relational Data Model, and SQL schema for an automotive dealership database, including full metadata and data dictionary.

SQL ERD Data Modeling

Static Website Creation

Built a responsive static website using VS Code, GitHub, Anaconda Prompt, and Zurb templates, configured with Cloudflare DNS & security routing.

GitHub Cloudflare VS Code