The short answer is lack of good cybersecurity hygiene and not taking proactive measures to improve the security of the organization. HIPAA Security Risk Assessments and penetration tests that are done proactively, will show what gaps are open. The solution is to fix the gaps and re-perform the HIPAA Security Risk Assessments and penetration tests at least annually to stay ahead.