Government  Health IT
TwitterFacebookLinkedIn
  • Home
  • Topics
    • Cloud Computing
    • Election 2012
    • Electronic Health Record
    • ePrescribing
    • Health Information Exchange (HIE)
    • Meaningful Use
    • Medicaid
    • Medicare
    • Military Health
    • Mobile/ Wireless
    • NHIN
    • Policy & Legislation
    • Population Health
    • Privacy and Security
    • Quality and Safety
    • Telehealth
    • Workforce Management
  • Issues
    • Sept/Oct 2011
    • July/August 2011
    • May/June 2011
    • March/April 2011
    • Jan/Feb 2011
    • Nov/Dec 2010
  • Webinars
    • Upcoming Webinars
    • On Demand Webinars
  • White Papers
  • Blog
  • Events
  • Jobs
  • RSS
  • Slideshows
  • Videos
  • Podcasts
  • Newsletters
  • Advertise
  • LOGIN
  • REGISTER
  • SUBSCRIBE
Home » News » Privacy and Security
Receive News
By Email

  • del.icio.us
  • Digg
  • Facebook
  • Google
  • Reddit
  • StumbleUpon
  • RSS Icon
  

Tweet

A glimpse inside the $234 billion world of medical fraud

February 08, 2012 | Rick Kam, President and CEO, ID Experts and Christine Arevalo, director of healthcare identity management, ID Experts

Suggested Content

  • HHS to award $300 million across states for delivery reform
  • Maine tops states for provider rate of EHRs, meaningful use
  • 12 states file insurance exchange blueprints early
  • Results of state legislatures, ballot initiatives could spark conflict with feds
  • Most states engaged in Medicaid care coordination efforts
  • 6 states receive $181M health insurance exchange funds

Related Resources

  • Delivering the Future of Healthcare: Maintain Compliance, Improve Efficiency and Continuity of Care...Virtually Anywhere
  • Futureproofing Healthcare with Converged Medical Infrastructure
  • Medical Imaging in the Cloud
  • Case Study: Blood Systems Expands Remote Access Connectivity to Prepare for Disaster
  • Ten Things to Ask Your SAAS Vendor Before Entering the Cloud

Healthcare fraud is costing American taxpayers up to $234 billion annually, based on estimates from the FBI. It’s no wonder that a stolen medical identity has a $50 street value, according to the World Privacy Forum – whereas a stolen social security number, on the other hand, only sells for $1.

One form of healthcare fraud, known as medical identity theft, has its own staggering statistics: 1.42 million Americans were victims of medical identity theft in 2010, according to a 2011 study on patient data privacy and security by the Ponemon Institute. The report estimates the annual economic impact of medical identity theft to be $30.9 billion.

[See also: How politics distort Americans' perception of health reform.]

Medical identity theft occurs when a person uses someone else’s medical record to obtain medical goods or services or to bill for medical goods and services that the patient did not receive. Thieves will also use a person’s social security number to obtain medical services or health insurance.

The harm medical identity theft causes patients
With its serious health risks, medical identity theft is far more dangerous than the more well-known consumer or financial identity theft. When a victim’s records are merged with a thief using the same identity, for instance, that record becomes “polluted,” and the victim may be denied treatment or be misdiagnosed based on this inaccurate information. In addition, patients may be denied life insurance or billed for services not rendered. A few real-world examples illustrate the dangers:

  • In Oregon, a pregnant woman delivered a baby addicted to crack using another woman’s social security number—and then abandoned the baby. Police arrested the victim and put her children into protective custody.
  • A hospital’s billing department notified a pregnant woman in Washington that someone had used her social security number to be treated for a crack overdose at the ER of the same facility where she was about to deliver her baby.
  • A patient in Texas used a California man’s medical identity to obtain radiation treatment and other care. When the thief’s records and the patient’s records merge, healthcare providers will think the patient has a condition he doesn’t have.
  • One woman used her sister’s medical ID to receive treatment for a serious sports injury. When chronic problems arose, she was denied coverage for further treatment because there was no record of her initial treatment.
  • Another woman couldn’t get physical therapy following neck surgery because a Miami clinic that she had never visited claimed her insurance benefits had been maxed out.
  • A teenager was denied the opportunity to give blood because the Red Cross flagged her social security number as belonging to a person who had tested positive for HIV. Another person had used her social security number at a free AIDS clinic in another state, and the clinic did not ask for physical copies of identification.

Data breaches — A major source of medical I.D. theft
Whether caused by theft, loss, human error, or hacking, data breaches put patient data at risk for medical identity theft. The number of healthcare data breaches has risen dramatically, increasing the likelihood for medical identity theft; in 2011, more than 18 million patients were listed on the HHS’ “Wall of Shame” as having their protected health information (PHI) breached. Tighter privacy laws, increased scrutiny from the HHS’ Office for Civil Rights (OCR), and the potential for costly fines make medical identity theft a problem for all healthcare organizations.

[Q&A: How a health 'data spill' could be more damaging than what BP did to the Gulf.]

Three tips for protecting patient data 
Preparation is the best defense for mitigating the chances of a data breach and the costly consequences of medical identity theft. To start preparing now, we recommend that healthcare organizations:

  1. Take an inventory of PHI/PII. An inventory provides a complete accounting of every element of personally identifiable information (PII) and PHI that an organization holds, in either paper or electronic format. It helps determine how an organization collects, uses, stores and disposes of its PHI. By revealing the risks for a data breach, a PHI inventory helps an organization protect PHI data and best plan for a response based on real information.
  2. Develop an Incident Response Plan (IRP). An IRP is an effective, cost-efficient means for helping organizations meet HIPAA and HITECH requirements and develop guidelines related to data breach incidents. The IRP designates roles and provides guidelines for the response team's responsibilities and actions.
  3. Review contracts and agreements with business associates. Business associates are a growing cause of data breaches. These contracts authorize and define business associates' use of the PHI they share with healthcare providers. Keeping these contracts up-to-date demonstrates compliance to regulators and helps maintain consistency in how PHI is managed in a healthcare ecosystem.

With its combined financial and health risks, medical identity theft has greater consequences for victims than more traditional forms of identity theft. Healthcare organizations, therefore, have a greater obligation to step up their privacy and security efforts to safeguard their patients’ health information. Protecting a patient’s physical – and financial – well being is, after all, the best form of caring.
 

Rick Kam, CIPP, is president and co-founder of ID Experts. Rick is also chairing the “PHI Project,” a seminal research effort to measure financial risk and implications of data breach in healthcare, led by the American National Standards Institute (ANSI), via its Identity Theft Prevention and Identity Management Standards Panel (IDSP), in partnership with the Shared Assessments Program and the Internet Security Alliance (ISA).

Christine Arevalo is director of healthcare identity management and a founding employee of ID Experts. She has experience managing risk assessments, complex crisis communication strategies, and data breach response for healthcare organizations.

Related Topics:
  • Online Only
  • Privacy and Security
  • Miami
  • Washington
  • BP
  • ID Experts
  • Internet Security Alliance
  • Shared Assessments Program
  • USD
  • Person Career
  • A hospital
  • American National Standards Institute
  • Ponemon Institute
  • healthcare
  • AIDS
  • California
  • Christine Arevalo
  • Federal Bureau of Investigation
  • HIV
  • injury
  • neck surgery
  • OCR
  • Oregon
  • physical therapy
  • radiation
  • radiation treatment
  • Red Cross
  • Rick Kam
  • Texas

Reader Comments (0)Login to Post a Comment

Most Popular

Latest Headlines
Most Popular
  • Deloitte: Docs underutilize various health technologies
  • Expert predicts 'meaningful use fatigue' in 2015
  • Commentary: How data sharing between AHLTA and VistA is possible
  • NYeC PHR design winners to shape public portal
  • First HIE launching in greater Philadelphia
  • 10 health reform benefits at risk in the election
  • Would Romney kill meaningful use?
  • CMS circulates final 2014 MU clinical quality measures
  • HIE is critical public utility in Sandy disaster
  • HIMSS: The intangibles of HIT employee retention
more news

WEBINARS AND WHITE PAPERS

  • WHITE PAPERS
    Key Benefits to a Secure & Elastic Private Cloud
  • WHITE PAPERS
    The VNA Strategy: Balancing Workflow and Enterprise Imaging Management
  • WHITE PAPERS
    Enterprise-class API Patterns for Cloud & Mobile
  • WHITE PAPERS
    When Evolution Drives Revolution: The Cloud as a Business Model
  • WHITE PAPERS
    New World Order: Effectively Securing Healthcare Data Through Secure Information Exchanges
More Resources
Syndicate content

HIMSS JOBMINE

  • Director of Clinical Applications - MidMichigan Health - Midland, MI
  • Information Services Director - Central Peninsula Hospital - Soldotna, AK
  • Director, Marketing and Business Development - Vermont Information Technology Leaders, Inc. - Burlington, VT
  • CIO - Bend Memorial Clinic - Bend, Oregon
  • Director of Clinical Transformation - Agnesian Healthcare - Fond du Lac, WI
more jobs
receive news by email

Marketplace

  • Home
  • Resource Central
  • Blog
  • Events
  • Jobs
  • Mobile Site
  • Advertise
  • RSS
  • About
  • Site map
  • Privacy Policy
Follow Government Health IT on TwitterLike Government Health IT on FacebookJoin Government Health IT on LinkedInRSS Subscriptions
BlogEvents
JobsMobile SiteMobile App
 
Healthcare IT NewsHealthcare Finance NewsHealthcare Payer NewsHIEWatch ICD10Watch mHIMSS PhysBizTech
©2013 MedTech Media Government Health IT is a publication of MedTech Media
Advertise About Us Privacy Policy