Government  Health IT
TwitterFacebookLinkedIn
  • Home
  • Topics
    • Cloud Computing
    • Election 2012
    • Electronic Health Record
    • ePrescribing
    • Health Information Exchange (HIE)
    • Meaningful Use
    • Medicaid
    • Medicare
    • Military Health
    • Mobile/ Wireless
    • NHIN
    • Policy & Legislation
    • Population Health
    • Privacy and Security
    • Quality and Safety
    • Telehealth
    • Workforce Management
  • Issues
    • Sept/Oct 2011
    • July/August 2011
    • May/June 2011
    • March/April 2011
    • Jan/Feb 2011
    • Nov/Dec 2010
  • Webinars
    • Upcoming Webinars
    • On Demand Webinars
  • White Papers
  • Blog
  • Events
  • Jobs
  • RSS
  • Slideshows
  • Videos
  • Podcasts
  • Newsletters
  • Advertise
  • LOGIN
  • REGISTER
  • SUBSCRIBE
Home » News » Privacy and Security
Receive News
By Email

  • del.icio.us
  • Digg
  • Facebook
  • Google
  • Reddit
  • StumbleUpon
  • RSS Icon
  

3 steps to minimize 'data breach epidemic'

December 01, 2011 | Chris Anderson, Senior Editor, Healthcare Payer News

Suggested Content

  • A glimpse inside the $234 billion world of medical fraud
  • 7 health data privacy and security trends to track in 2012
  • Year in review: Top 10 trends in healthcare data privacy and security
  • 4 data breach response best practices
  • OCR will train state AGs to enforce HIPAA
  • Mass General pays $1M to settle potential privacy violations
  • 8 security questions to ask your business partners
  • Year-end: 3 security threats and 4 tips for protecting health data
  • Why HAI health IT should fall under meaningful use
  • Q&A: How a health 'data spill' could be more damaging than what BP did to the Gulf

Related Resources

  • Better Outcomes in Healthcare IT | Key Lessons from an IT Leader
  • Delivering the Future of Healthcare: Maintain Compliance, Improve Efficiency and Continuity of Care...Virtually Anywhere
  • Proactive Security and Privacy Monitoring for Modern Healthcare Networks
  • Best Practices to Deploy ECM Technologies: Ensure Decisions are Made Based on all the Information, not a Portion of it
  • Secure Physician Mobile Access to Patient Data with Virtualization

The frequency of data breaches in healthcare have increased 32 percent in the past year and cost the industry an estimated $6.5 billion annually according to the second annual benchmarking study conducted by the Ponemon Institute.

Among the chief culprits responsible for data security breaches were sloppy employee handling of data and the ever-increasing use of mobile devices in the healthcare setting. Forty-one percent of healthcare executive surveyed attributed data breaches related to protected health information (PHI) to employee mistakes, while half of the respondents said their organization does nothing to protect the information contained on mobile devices. In all, 80 percent of healthcare organizations use mobile devices that collect, store and/or transmit some form of PHI.

[Four-part series: 3 tips for surviving an OCR audit, 4 data breach response best practices, 9 steps to take during an OCR data breach investigation, and a look at why privacy compliance needn’t be so scary.]

While total data breaches are up 32 percent, the increases in some areas was even higher. Compromised patient records in benchmarked organizations increased an average of 46 percent and 55 percent of healthcare organizations say they have little or no confidence they are able to detect all privacy incidents. In fact, 61 percent of organizations are not confident they know where their patient data is physically located.

Third-party mistakes, including those by business associates, account for 46 percent of data breaches reported in the study. According to 49 percent of respondents, lost or stolen computing or data devices are the reason for healthcare data breach incidents.

As data breaches become an increasing problem in health, there is little evidence that providers have the appropriate resources to stem the tide. Seventy-three percent of respondents reported lacking sufficient resources to prevent or detect unauthorized patient data access, loss or theft and 53 percent said lack of budget is their biggest weakness in preventing data breaches.

"Healthcare data beaches are an epidemic," said Dr. Larry Ponemon, chairman and founder, Ponemon Institute, in an announcement of the study results. "These problems are a direct result of our national economy. Healthcare organizations – especially not-for-profit hospitals and small clinics – have thin margins, are trimming staff and resources and are lacking sufficient security and privacy budgets needed to adequately protect patients. I don't see this getting better anytime soon."

Rick Kam, president and co-founder of study sponsor ID Experts, said healthcare organizations can minimize their data breach risks with three basic steps:

  1. Take an inventory of PHI/PII. An inventory provides a complete accounting of every element of personally identifiable information (PII) and PHI that an organization holds, in either paper or electronic format. It helps determine how an organization collects, uses, stores and disposes of its PHI. A PHI inventory reveals the risks for a data breach, so organizations can strategically protect PHI data and best plan for a response based on real information.
  2. Develop an Incident Response Plan (IRP). An IRP is an effective, cost-efficient means for helping organizations meet HIPAA and HITECH requirements and develop guidelines related to data breach incidents. The IRP designates roles and provides guidelines for the response team's responsibilities and actions.
  3. Review contracts and agreements with business associates. Business associates are a growing cause of data breaches. These contracts between healthcare organizations and business associates authorize and define business associates' use of the PHI they share with healthcare providers. Keeping these contracts up-to-date demonstrates compliance to regulators and helps maintain consistency in how PHI is managed in a healthcare ecosystem.

"Identity theft and medical identity theft resulting from data breach exposure are commonplace, causing patients financial harm, frustration and embarrassment," said Kam, in a press release. "Hospitals must vaccinate against data breach risks in order to take better care of patients and their data."

Chris Anderson
Editor of Healthcare Payer News
Follow Chris on Twitter @HPN_Editor
Related Topics:
  • Online Only
  • Privacy and Security
  • USD
  • Person Career
  • Quotation
  • Ponemon Institute
  • computing
  • healthcare
  • Larry Ponemon
  • mobile devices
  • OCR
  • Rick Kam

Reader Comments (0)Login to Post a Comment

Most Popular

Latest Headlines
Most Popular
  • Why telemedicine, health IT camps need each other
  • Top 9 fraud and abuse areas big data tools can target
  • CMS posts names of Medicare EHR payments recipients
  • Report: HIEs failing at true interoperability
  • VA's 7 steps to protect VLER data
  • 6 states receive $181M health insurance exchange funds
  • Nebraska advances insurance exchange despite politicians' health reform view
  • Q&A: 3M on how Open HDD and VA, DoD iEHR will trigger innovation
  • HIMSS calling all health IT pros!
  • HHS tool to track nation's healthcare performance

WEBINARS AND WHITE PAPERS

  • ON DEMAND WEBINARS
    Solving Healthcare Compliance and eDiscovery with Intelligent, Adaptive and Converged Information Management
  • UPCOMING WEBINARS
    May 31st @ 1PM ET--Hospital Case Study: Overcome Data Protection Challenges, Increase Retention & Restore Data in Seconds
  • ON DEMAND WEBINARS
    Proactive Security and Privacy Monitoring for Modern Healthcare Networks
  • ON DEMAND WEBINARS
    Secure Physician Mobile Access to Patient Data with Virtualization
  • WHITE PAPERS
    The State of EHR Adoption: On The Road to Improving Patient Safety
More Resources
Syndicate content

HIMSS JOBMINE

  • McKesson Paragon Consultant - Beacon Partners - Massachusetts
  • Soarian Clinicals Consultants $5K Sign on Bonus! - Beacon Partners - MA
  • ICD-10 PMO Support Team Member - Rainmakers Government Solutions - Columbia, MD
  • Business Intelligence Consultant - Healthcare - Dimensional Insight - Coral Springs, FL
  • MEDITECH BAR & General Financials, Contract/FT Consultant - Beacon Partners - Nationwide Travel, MA
more jobs
receive news by email

Marketplace

  • Home
  • Issues
  • Resource Central
  • Blog
  • Events
  • Jobs
  • Mobile Site
  • Mobile App
  • Subscribe
  • Advertise
  • Rss
  • About
  • Site map
  • Privacy Policy
Follow Government Health IT on TwitterFan Government Health IT on FacebookJoin Government Health IT on LinkedInRSS Subscriptions
Digital EditionBlogEvents
JobsMobile SiteMobile App
 
Healthcare IT NewsHealthcare Finance News EHRWatch Healthcare Payer News HITECHWatch ICD10Watch mHIMSS PhysBizTech NHINWatch
©2012 MedTech Media Government Health IT is a publication of MedTech Media
Subscribe Advertise About Us Privacy Policy