Nuviun
Register with nuviun FREE Log in
Register with nuviun Log in
  • digital health
    • Big Data
    • eHealth
    • EHR - EMR
    • Gamification
    • Health 2.0-Social Media in Healthcare
    • Health and Wellness Apps
    • Health IT
    • Interoperability
    • Medical Imaging
    • mHealth
    • Personal Genomics
    • Quantified Self
    • Sensors and Wearables
    • Telehealth/Telemedicine/Connected Health
    • Betting Sites UK
  • content library
    • Series
  • dashboard
  • directory
    • people
    • companies
  • events
nuviun
Content library
Privacy and Security Breach Concerns Growing in Healthcare Industry

Privacy and Security Breach Concerns Growing in Healthcare Industry

Published 09/11/2014 at 00:00 Shiva Gopal Reddy, MA eHealth Electronic Health Records (EHRs) Electronic Medical Records (EMRs) Security Privacy 0 comments

With data breaches being reported almost on a weekly basis, healthcare organizations are struggling to plug holes in information security leaks.

By the end of October, 2014, the US Department of Health and Human Services, Office for Civil Rights (OCR), had reported 1,140 breaches affecting 38.7 million individuals on its breach notifications page—also known as the ‘Wall of Shame’. And more incidents are being added to the list every day.

The sheer numbers reflect the extensive range of threats healthcare organizations face in preventing data privacy and security breaches. As healthcare data proliferates, threats to security will increase and organizations will need to adopt a multi-pronged approach to fight them.

Breach Trends

Hacking, Distributed Denial-of-Service (DDoS) attacks, loss or theft of unencrypted computing devices, and insider threats such as unauthorized access or disclosure of information are some of the major causes behind security breaches in healthcare organizations.

Hacking

Hacking has been the cause of at least 95 major security breaches since 2009. With each health record fetching up to $1,000 in the underground market as compared to 25 cents for a social security number and $1 for a credit card number, health data is a hot commodity in the black market, says John Halamka, CIO at Beth Israel Deaconess Medical Center (BIMDC) in Boston.

The FBI estimates that $80 billion of the $2.2 trillion spent each year on healthcare in the United States is associated with fraud, with half of that fraud related to medical identity theft. 

“In the past, hackers were MIT freshmen who attacked the Harvard network for fun. Today it's a totally different kind of attack—highly sophisticated, organized criminals attempting to get medical Identities," says Halamka.

The hacking at the Montana Department of Public Health and Human Resources is one of the largest breaches reported in the healthcare sector, affecting 1.3 million individuals.

Insider Threats

Nearly 270 breaches related to improper disposal of paper records and unauthorized access/disclosure of information by insiders have been reported to date by HHS. With healthcare organizations increasingly adopting computerization of patient information, the threat of inappropriate access by insiders is expected to increase.

A former employee bypassed security systems and accessed the personal information of nearly 97,000 patients of New York-based NRAD Medical Associates in April this year.

Breaches due to improper handling of information were also reported. A clerical error at St. Vincent Breast Cancer Hospital led to sending letters containing personal health information to nearly 63,000 wrong recipients.

Lack of Encryption

Breaches due to loss or theft of computing devices is the probably the most predominant source of data security worries. HHS reported more than 500 major breaches by the end of October, 2014.

In February this year, eight unencrypted computers containing personal information of patients were stolen from Los Angeles County departments of health services and public services. The breach affected 168,500 individuals. Similarly, a laptop stolen from Beth Israel Deaconess Medical Center (BIDMC) in Boston had unencrypted personal information of more than 3,900 patients.

Preventing Breaches

Despite the persistent threat of breaches and the hefty resolution amounts organizations have to pay for them, much of the healthcare sector is still behind the learning curve in plugging security holes when compared to other vulnerable industries—such as financial services and information technology. Many healthcare organizations still devote inadequate resources to secure and safeguard their information systems.

According to the 2014 Healthcare Information Security Today Survey, more than half of all healthcare organizations spend less than 3 percent of their IT budgets to protect data, and almost half do not have a full-time CISO or Chief Information Security Manager.

Experts and practitioners recommend a multipronged approach of ‘deterrence, prevention, detection and response’ to build a strong mechanism to counter security breaches and call on healthcare organizations to devote more resources to:

  1. Improve regulatory compliance by making it an organizational priority;
  2. Improve security awareness/education for physicians, staff, executives and board;
  3. Prevent and detect breaches through persistent risk analysis, mitigation and continuous learning;
  4. Monitor HIPAA compliance; and
  5. Encrypt all computing devices, including mobile devices.

Until necessary resources are allocated for breach prevention, healthcare organizations will continue to be vulnerable to increasing cyber security threats.

Shiva Gopal Reddy has a Bachelor's degree in Physics and a Master's in Applied Psychology and writes frequently on the latest research, impact, happenings and trends in digital health technology.

Log in or register for FREE for full access to ALL site features

As a member of the nuviun community, you can benefit from:

  • 24/7 unlimited access to the content library
  • Full access to the company and people directories
  • Unlimited discussion and commenting privileges
  • Your own searchable professional profile

Not yet a member?

Register now

Already a member?

Log in for immediate access:

Login failed, check your credentials and try again.

Author:

Shiva Gopal Reddy, MA View profile
Categorised:

Categorised:

  • eHealth
  • Electronic Health Records (EHRs)
  • Electronic Medical Records (EMRs)
  • Security
  • Privacy
Share with friends and colleagues
Discuss this post You must be logged in to comment on this post.
  • Most popular
  • Most recent
  • Oculus Rift in the Operating Room

  • One way healthcare providers can use big data to generate revenue fast

  • Why 2015 is the pivotal year for #digitalhealth

  • Talent to Task: The Digital Health Accelerator Dilemma

  • 7 Best Gamification Fitness Apps For 2015

  • 90 Healthcare Leaders Discuss Opportunities in Digital Health

  • nuvi & mo episode 9

  • Mitigating Hope and Hype: The Evolving Role of the Physician in the Era of eHealth

  • “You Click, We Care.” Profile in Digital Health: Raouf Khalil, CEO of Mobile Doctors 24/7

  • Solving the Innovation Puzzle with Partnerships: Our Second Day in India

  • The gaping privacy hole in healthcare data is not where you think

  • “Make them use it” is not a valid EMR adoption strategy

More by this author
  • Privacy and Security Breach Concerns Growing in Healthcare Industry

    This Ultrasound-on-a-Chip Technology May Disrupt Medical Imaging with Smartphone-Sized Scanners

  • Privacy and Security Breach Concerns Growing in Healthcare Industry

    Digital Health in Action: mHealth Tools Can Enhance Clinical Trial Process

  • Privacy and Security Breach Concerns Growing in Healthcare Industry

    Telemedicine Adoption Picking Up Pace among Hospital Executives, Survey Says

  • Privacy and Security Breach Concerns Growing in Healthcare Industry

    Study: Significant Medication Adherence Outcomes Can Be Achieved With Low Cost Automated Reminders

  • Privacy and Security Breach Concerns Growing in Healthcare Industry

    Virtual Reality-Based Therapy Can Help Overcome PTSD and Other Disorders

Related posts
  • Privacy and Security Breach Concerns Growing in Healthcare Industry

    The gaping privacy hole in healthcare data is not where you think

  • Privacy and Security Breach Concerns Growing in Healthcare Industry

    “Make them use it” is not a valid EMR adoption strategy

  • Privacy and Security Breach Concerns Growing in Healthcare Industry

    Digital Health Rounds: Editor’s Progress Notes—March2015, Friday #2

  • Privacy and Security Breach Concerns Growing in Healthcare Industry

    4 High-Tech Medical Management Apps for Seniors

  • Privacy and Security Breach Concerns Growing in Healthcare Industry

    Oculus Rift in the Operating Room

  • Privacy and Security Breach Concerns Growing in Healthcare Industry

    What you don’t know about digital health in Canada can help you

Digital Health Live 2015

Dubai World Trade Center

May 5th - 7th 2015

Doctors 2.0 and you - Paris 4th and 5th of June 2015
Explore nuviun
  • Home
  • About nuviun
  • Join our team
  • Contact nuviun
  • Site map
  • Privacy and cookies
  • Terms and conditions
Dashboard
  • Dashboard
  • Content Library
  • Subscriptions
  • Directory
  • Edit profile
  • My account
Connect with us
facebook linkedin twitter
© 2015 Nuviun. All rights reserved. MintTwist CMS Websites

nuviun.com uses cookies to enhance your experience. By using this site you agree to have cookies placed on your computer. To learn more, please see our cookies policy and privacy policy pages. Thanks for reading.

Apologies

These features are reserved for registered users of nuviun.com. Registration is FREE.

It's simple to:

  • log in if you've already registered
  • or super quick to register a new account if you don't have one yet.
Log inRegister with nuviun

You have unfavourited the article [title]