Plugin vulnerabilities and PHI exposure
Most WordPress security incidents start with an unpatched plugin. On a healthcare site with HIPAA-compliant contact forms or patient intake elements, a vulnerability in any plugin that touches those components creates direct PHI exposure, a reportable breach event under HIPAA.