A Security Policy Only Works If You Follow It

safe workplace security policy

Your company probably has a lot of cybersecurity rules. For example, use multi-factor authentication. Don’t click suspicious links. Report strange emails. Keep sensitive information in approved systems.

It can be tempting to think of those rules as recommendations, especially when you’re busy and taking a shortcut seems harmless.

A recent federal enforcement action provides a good reminder that cybersecurity procedures aren’t just paperwork, though. When sensitive information is involved, failing to follow these rules can become a very serious cyber-compliance problem.

What Happened Recently?

On September 17, 2026, the U.S. Department of Health and Human Services (HHS) announced a settlement with genetic testing company Ambry Genetics over potential violations of the HIPAA Security Rule.

The investigation stemmed from a phishing attack that compromised an employee’s email account, which contained a lot of sensitive information.

According to HHS, threat actors exposed the Protected Health Information (PHI) of 225,370 people including names, addresses, dates of birth, some Social Security or driver’s license numbers, financial information, diagnoses, lab results, medications, and treatment information. HHS ultimately reached a $2.25M settlement with Ambry Genetics over the violation.

The incident involved healthcare data, but the lesson applies to practically every workplace. It also highlights the very real financial and litigation costs that come from failing to comply with data privacy regulations.

Writing a Policy Isn’t the Same as Following It

Most companies have cybersecurity policies…but what happens after those policies are written?

Does everyone understand them? Are employees actually following them? Does the company regularly review whether its security measures still work? A document sitting in a policy folder doesn’t protect anything by itself.

That’s why most cyber-compliance regulations require organizations to put safeguards in practice and employees to follow the procedures that protect sensitive information. Whether you’re handling PHI, Personally Identifiable Information (PII), financial records, customer information, or confidential company data, you still have to follow those documented procedures.

Your Email Account May Hold More Than You Realize

One reason phishing attacks can become so serious is the sheer amount of information sitting inside the average work mailbox.

Think about yours.

You may have years of conversations, attachments, customer information, invoices, spreadsheets, internal documents, meeting invitations, and links to other company systems.

That makes your email account much more than a communication tool. It’s potentially a doorway into a large collection of company information, too.

If an attacker steals your credentials, they may not need to break into dozens of separate systems. Your inbox could already contain valuable information that you wouldn’t want getting out.

This Is Why “Just This Once” Is a Dangerous Mindset

Cybersecurity procedures can feel inconvenient.

Maybe MFA adds another step when you sign in. Reporting a suspicious email takes time. Verifying an unexpected request means stopping what you’re doing.

Those extra steps exist because attackers depend on people skipping them.

The same is true for compliance procedures.

If company policy says sensitive information belongs in a secure system rather than email, use the secure system. If you’re required to verify someone’s identity before releasing information, verify them every time.

Don’t bypass the process because you recognize the person or the request seems urgent.

Training Only Works If You Use It

Most employees have probably sat through cybersecurity training at some point. Knowing the right answer on a training quiz is easy in the moment, but remembering it when you’re juggling emails, meetings, deadlines, and phone calls is much harder.

That’s where good security habits come in.

  • Slow down before clicking unexpected links.
  • Look carefully at login pages before entering credentials.
  • Never approve an MFA request you didn’t initiate
  • Report suspicious activity immediately.

If you make a mistake, report that quickly, too! Hiding an accidental click because you’re embarrassed only gives an attacker more time to work their scam.

Compliance Is Something You Do

The case with Ambry Genetics involved HIPAA, but every industry has information it needs to protect.

A law firm may hold confidential client documents. Financial companies may have Social Security numbers and banking information. Retailers may have customer records. Your own company may handle information you don’t think twice about seeing every day.

Someone still has to protect it. Technology can help, but security ultimately depends on people following the controls surrounding that information.

Conclusion

The Ambry Genetics settlement is a useful reminder that compliance isn’t something a company achieves by writing a policy and putting it in a folder.

It’s something employees practice every day.

Every time you verify a request, report a suspicious message, use an approved system, or follow a security procedure instead of taking a shortcut, you’re helping protect the information your organization has been trusted to handle.

Policies tell us what we’re supposed to do.

Compliance happens when we actually do it.

More Articles & Posts