Healthcare IT NewsHealthcare IT News
TwitterFacebookLinkedInHealthcareITNews International
  • Home
  • Topics
    • Business Intelligence
    • Claims Processing
    • Data Warehousing
    • EDIS
    • Election 2012
    • Electronic Health Records
    • Enterprise Content Management
    • Enterprise Resource Planning
    • ePrescribing
    • Financial/Revenue Cycle Management
    • Health Information Exchange (HIE)
    • ICD-10
    • Meaningful Use
    • Mobile/Wireless
    • Network Infrastructure
    • Policy and Legislation
    • Privacy and Security
    • Quality and Safety
    • RIS and PACS
    • RTLS
    • Telehealth
    • Workforce Management
  • Issues
    • May 2012
    • April 2012
    • March 2012
    • February 2012
    • January 2012
    • December 2011
  • Blog
  • Webinars
    • Upcoming Webinars
    • On Demand Webinars
  • White Papers
  • Events
  • HIMSS JobMine
  • Press Releases
  • Slideshows
  • Videos
  • Podcasts
  • Supplements
  • Survey Analyses
  • Newsletters
  • Advertise
  • Login
  • Register
  • SUBSCRIBE
    • Newspaper
    • Email Newsletter
Home » News » Electronic Health Records | Mobile/Wireless | Network Infrastructure | Privacy and Security | Quality and Safety
Receive News By Email

  • del.icio.us
  • Digg
  • StumbleUpon
  • Reddit
  • Facebook
  • Google
  • RSS Icon
  

Costly healthcare data breaches jump 32 percent

December 01, 2011 | Chris Anderson, Contributing Editor

Related Resources

  • Redefining Value and Success in Healthcare: Charting the Path to the Future
  • Ensure Performance and Availability of Your Epic Application
  • Executing Best Practices for EMR Implementation
  • Maple Grove Hospital: Building Innovative Healthcare Communications From the Ground Up
  • Architecting the Hospital of the Future

TRAVERSE CITY, MI – The frequency of data breaches in healthcare have increased 32 percent in the past year and cost an estimated $6.5 billion annually according to a new study by the Ponemon Institute. Among the chief culprits: sloppy employee handling of data and the ever-increasing use of mobile devices.

Forty-one percent of healthcare executive surveyed attributed data breaches related to protected health information (PHI) to employee mistakes, while half of the respondents said their organization does nothing to protect the information contained on mobile devices. In all, 80 percent of healthcare organizations use mobile devices that collect, store and/or transmit some form of PHI.

[See also: $1B suit filed against Sutter Health over data breach]

While total data breaches are up 32 percent, the increases in some areas was even higher. Compromised patient records in benchmarked organizations increased an average of 46 percent and 55 percent of healthcare organizations say they have little or no confidence they are able to detect all privacy incidents. In fact, 61 percent of organizations are not confident they know where their patient data is physically located.

Third-party mistakes, including those by business associates, account for 46 percent of data breaches reported in the study. According to 49 percent of respondents, lost or stolen computing or data devices are the reason for healthcare data breach incidents.

As data breaches become an increasing problem in health, there is little evidence that providers have the appropriate resources to stem the tide. Seventy-three percent of respondents reported lacking sufficient resources to prevent or detect unauthorized patient data access, loss or theft and 53 percent said lack of budget is their biggest weakness in preventing data breaches.

[See also: Room for improvement on security, HIMSS survey shows]

"Healthcare data beaches are an epidemic," said Dr. Larry Ponemon, chairman and founder, Ponemon Institute, in an announcement of the study results. "These problems are a direct result of our national economy. Healthcare organizations – especially not-for-profit hospitals and small clinics – have thin margins, are trimming staff and resources and are lacking sufficient security and privacy budgets needed to adequately protect patients. I don't see this getting better anytime soon."

Rick Kam, president and co-founder of study sponsor ID Experts, said healthcare organizations can minimize their data breach risks with three basic steps:

  1. Take an inventory of PHI/PII. An inventory provides a complete accounting of every element of personally identifiable information (PII) and PHI that an organization holds, in either paper or electronic format. It helps determine how an organization collects, uses, stores and disposes of its PHI. A PHI inventory reveals the risks for a data breach, so organizations can strategically protect PHI data and best plan for a response based on real information.
  2. Develop an Incident Response Plan (IRP). An IRP is an effective, cost-efficient means for helping organizations meet HIPAA and HITECH requirements and develop guidelines related to data breach incidents. The IRP designates roles and provides guidelines for the response team's responsibilities and actions.
  3. Review contracts and agreements with business associates. Business associates are a growing cause of data breaches. These contracts between healthcare organizations and business associates authorize and define business associates' use of the PHI they share with healthcare providers. Keeping these contracts up-to-date demonstrates compliance to regulators and helps maintain consistency in how PHI is managed in a healthcare ecosystem.

"Identity theft and medical identity theft resulting from data breach exposure are commonplace, causing patients financial harm, frustration and embarrassment," said Kam, in a press release. "Hospitals must vaccinate against data breach risks in order to take better care of patients and their data."

[See also: PwC: Health industry under-prepared to protect privacy]
Chris Anderson
Editor of Healthcare Payer News
Follow Chris on Twitter @HPN_Editor
Related Topics:
  • Chris Anderson
  • mobile devices
  • Ponemon Institute
  • Traverse City
  • Electronic Health Records
  • Mobile/Wireless
  • Network Infrastructure
  • Privacy and Security
  • Quality and Safety

Reader Comments (0)Login to Post a Comment

Most Popular

Latest Headlines
Most Popular
  • 6 reasons physicians need to be on social media
  • Lawsuit seeks Allscripts CEO's removal
  • Tablet adoption by docs soars
  • FCC to vote on broadband space for patient monitoring
  • Computing cluster speeds targeted treatments for childhood cancer
  • Lawsuit seeks Allscripts CEO's removal
  • Web First: Q&A with Allscripts CEO Glen Tullman
  • 6 reasons physicians need to be on social media
  • Oregon to implement new statewide HIE
  • Tablet adoption by docs soars
more news

WEBINARS AND WHITE PAPERS

  • WHITE PAPERS
    Business Intelligence for Hospitals: Empowering Healthcare Providers to Make Informed Decisions
  • UPCOMING WEBINARS
    June 5th @ 1PM ET--Get Control of Your Medical Images with a Cloud-Based Vendor-Neutral Archive
  • WHITE PAPERS
    Mobility Advantage: Health Care Made Easier
  • ON DEMAND WEBINARS
    A Smarter Approach to Healthcare PC Virtualization
  • WHITE PAPERS
    The Christ Hospital Case Study: Improving Operations and Ensuring the Best Possible Patient Care with ECM
More Resources
Syndicate content

HIMSS JOBMINE

  • Network Engineer II - Carilion Clinic - Roanoke, VA
  • EMR Implementation - Project Manager Rothman Specialty Hospital - Rothman Specialty Hospital - Bensalem, PA
  • Director of Information Systems - Mission Regional Medical Center - Mission, Texas
  • Biostatistician II - Saudi Aramco - Dhahran, Saudi Arabia
  • Chief Information Officer - West Virginia - InfoPartners, Inc. - West Virginia
more jobs

Marketplace

Follow Healthcare IT News on TwitterFan Healthcare IT News on FacebookJoin Healthcare IT News on LinkedInRSS Subscriptions
Digital EditionBlogEvents
JobsMobile SiteMobile App
 
Healthcare Finance News Government Health IT EHRWatch Healthcare Payer News HITECHWatch ICD10Watch mHIMSS PhysBizTech NHINWatch
©2012 MedTech Media Healthcare IT News is a publication of MedTech Media
Subscribe Advertise About Us Privacy Policy