Government  Health IT
TwitterFacebookLinkedIn
  • Home
  • Topics
    • Cloud Computing
    • Election 2012
    • Electronic Health Record
    • ePrescribing
    • Health Information Exchange (HIE)
    • Meaningful Use
    • Medicaid
    • Medicare
    • Military Health
    • Mobile/ Wireless
    • NHIN
    • Policy & Legislation
    • Population Health
    • Privacy and Security
    • Quality and Safety
    • Telehealth
    • Workforce Management
  • Issues
    • Sept/Oct 2011
    • July/August 2011
    • May/June 2011
    • March/April 2011
    • Jan/Feb 2011
    • Nov/Dec 2010
  • Webinars
    • Upcoming Webinars
    • On Demand Webinars
  • White Papers
  • Blog
  • Events
  • Jobs
  • RSS
  • Slideshows
  • Videos
  • Podcasts
  • Newsletters
  • Advertise
  • LOGIN
  • REGISTER
  • SUBSCRIBE
Home » News » Privacy and Security
Receive News
By Email

  • del.icio.us
  • Digg
  • Facebook
  • Google
  • Reddit
  • StumbleUpon
  • RSS Icon
  

Tweet

3 steps to minimize 'data breach epidemic'

December 01, 2011 | Chris Anderson, Senior Editor, Healthcare Payer News

Suggested Content

  • Former UConn employee breached health records
  • OCR's message in HIPAA settlement: Encrypt your data
  • OCR looking for 'high level of sensitivity' in data breaches
  • Q&A: Health orgs don't protect patient data for reasons going 'back to the industrial revolution'
  • A glimpse inside the $234 billion world of medical fraud
  • 7 health data privacy and security trends to track in 2012
  • Year in review: Top 10 trends in healthcare data privacy and security
  • 4 data breach response best practices
  • OCR will train state AGs to enforce HIPAA
  • Mass General pays $1M to settle potential privacy violations

Related Resources

  • Better Patient Care: Virtually There
  • The Need for Data Loss Prevention Now
  • Palomar Health Choses EXTENSION's Alert Management Software Solution
  • Top Ten Government Healthcare IT Security Commandments
  • Connect to Care Interactive Map: Public Sector Healthcare Innovation

The frequency of data breaches in healthcare have increased 32 percent in the past year and cost the industry an estimated $6.5 billion annually according to the second annual benchmarking study conducted by the Ponemon Institute.

Among the chief culprits responsible for data security breaches were sloppy employee handling of data and the ever-increasing use of mobile devices in the healthcare setting. Forty-one percent of healthcare executive surveyed attributed data breaches related to protected health information (PHI) to employee mistakes, while half of the respondents said their organization does nothing to protect the information contained on mobile devices. In all, 80 percent of healthcare organizations use mobile devices that collect, store and/or transmit some form of PHI.

[Four-part series: 3 tips for surviving an OCR audit, 4 data breach response best practices, 9 steps to take during an OCR data breach investigation, and a look at why privacy compliance needn’t be so scary.]

While total data breaches are up 32 percent, the increases in some areas was even higher. Compromised patient records in benchmarked organizations increased an average of 46 percent and 55 percent of healthcare organizations say they have little or no confidence they are able to detect all privacy incidents. In fact, 61 percent of organizations are not confident they know where their patient data is physically located.

Third-party mistakes, including those by business associates, account for 46 percent of data breaches reported in the study. According to 49 percent of respondents, lost or stolen computing or data devices are the reason for healthcare data breach incidents.

As data breaches become an increasing problem in health, there is little evidence that providers have the appropriate resources to stem the tide. Seventy-three percent of respondents reported lacking sufficient resources to prevent or detect unauthorized patient data access, loss or theft and 53 percent said lack of budget is their biggest weakness in preventing data breaches.

"Healthcare data beaches are an epidemic," said Dr. Larry Ponemon, chairman and founder, Ponemon Institute, in an announcement of the study results. "These problems are a direct result of our national economy. Healthcare organizations – especially not-for-profit hospitals and small clinics – have thin margins, are trimming staff and resources and are lacking sufficient security and privacy budgets needed to adequately protect patients. I don't see this getting better anytime soon."

Rick Kam, president and co-founder of study sponsor ID Experts, said healthcare organizations can minimize their data breach risks with three basic steps:

  1. Take an inventory of PHI/PII. An inventory provides a complete accounting of every element of personally identifiable information (PII) and PHI that an organization holds, in either paper or electronic format. It helps determine how an organization collects, uses, stores and disposes of its PHI. A PHI inventory reveals the risks for a data breach, so organizations can strategically protect PHI data and best plan for a response based on real information.
  2. Develop an Incident Response Plan (IRP). An IRP is an effective, cost-efficient means for helping organizations meet HIPAA and HITECH requirements and develop guidelines related to data breach incidents. The IRP designates roles and provides guidelines for the response team's responsibilities and actions.
  3. Review contracts and agreements with business associates. Business associates are a growing cause of data breaches. These contracts between healthcare organizations and business associates authorize and define business associates' use of the PHI they share with healthcare providers. Keeping these contracts up-to-date demonstrates compliance to regulators and helps maintain consistency in how PHI is managed in a healthcare ecosystem.

"Identity theft and medical identity theft resulting from data breach exposure are commonplace, causing patients financial harm, frustration and embarrassment," said Kam, in a press release. "Hospitals must vaccinate against data breach risks in order to take better care of patients and their data."

Chris Anderson
Editor of Healthcare Payer News
Follow Chris on Twitter @HPN_Editor
Related Topics:
  • Online Only
  • Privacy and Security
  • USD
  • Person Career
  • Quotation
  • Ponemon Institute
  • computing
  • healthcare
  • Larry Ponemon
  • mobile devices
  • OCR
  • Rick Kam

Reader Comments (0)Login to Post a Comment

Most Popular

Latest Headlines
Most Popular
  • Deloitte: Docs underutilize various health technologies
  • Commentary: How data sharing between AHLTA and VistA is possible
  • NYeC PHR design winners to shape public portal
  • Why modernizing state IT infrastructures is crucial for HIX
  • First HIE launching in greater Philadelphia
  • 10 health reform benefits at risk in the election
  • Would Romney kill meaningful use?
  • CMS circulates final 2014 MU clinical quality measures
  • HIE is critical public utility in Sandy disaster
  • HIMSS: The intangibles of HIT employee retention
more news

WEBINARS AND WHITE PAPERS

  • WHITE PAPERS
    When Evolution Drives Revolution: The Cloud as a Business Model
  • WHITE PAPERS
    Your Cloud in Healthcare - How to Use the Cloud to Achieve Greater Business Agility
  • WHITE PAPERS
    Enterprise-class API Patterns for Cloud & Mobile
  • WHITE PAPERS
    HIE Interoperability case study: Health-e-cITi-NJ
  • WHITE PAPERS
    The VNA Strategy: Balancing Workflow and Enterprise Imaging Management
More Resources
Syndicate content

HIMSS JOBMINE

  • Director of Clinical Applications - MidMichigan Health - Midland, MI
  • Information Services Director - Central Peninsula Hospital - Soldotna, AK
  • Director, Marketing and Business Development - Vermont Information Technology Leaders, Inc. - Burlington, VT
  • CIO - Bend Memorial Clinic - Bend, Oregon
  • Director of Clinical Transformation - Agnesian Healthcare - Fond du Lac, WI
more jobs
receive news by email

Marketplace

  • Home
  • Resource Central
  • Blog
  • Events
  • Jobs
  • Mobile Site
  • Advertise
  • RSS
  • About
  • Site map
  • Privacy Policy
Follow Government Health IT on TwitterLike Government Health IT on FacebookJoin Government Health IT on LinkedInRSS Subscriptions
BlogEvents
JobsMobile SiteMobile App
 
Healthcare IT NewsHealthcare Finance NewsHealthcare Payer NewsHIEWatch ICD10Watch mHIMSS PhysBizTech
©2013 MedTech Media Government Health IT is a publication of MedTech Media
Advertise About Us Privacy Policy