Healthcare IT NewsHealthcare IT News
TwitterFacebookLinkedInHealthcareITNews International
  • Home
  • Topics
    • Business Intelligence
    • Claims Processing
    • Data Warehousing
    • EDIS
    • Election 2012
    • Electronic Health Records
    • Enterprise Content Management
    • Enterprise Resource Planning
    • ePrescribing
    • Financial/Revenue Cycle Management
    • Health Information Exchange (HIE)
    • ICD-10
    • Meaningful Use
    • Mobile/Wireless
    • Network Infrastructure
    • Policy and Legislation
    • Privacy and Security
    • Quality and Safety
    • RIS and PACS
    • RTLS
    • Telehealth
    • Workforce Management
  • Issues
    • May 2012
    • April 2012
    • March 2012
    • February 2012
    • January 2012
    • December 2011
  • Blog
  • Webinars
    • Upcoming Webinars
    • On Demand Webinars
  • White Papers
  • Events
  • HIMSS JobMine
  • Press Releases
  • Slideshows
  • Videos
  • Podcasts
  • Supplements
  • Survey Analyses
  • Newsletters
  • Advertise
  • Login
  • Register
  • SUBSCRIBE
    • Newspaper
    • Email Newsletter
Home » News » Electronic Health Records | Mobile/Wireless | Privacy and Security
Receive News By Email

  • del.icio.us
  • Digg
  • StumbleUpon
  • Reddit
  • Facebook
  • Google
  • RSS Icon
  

Report: More than 6M affected since breach notification rule

February 10, 2011 | Molly Merrill, Associate Editor

Suggested Content

  • Health data breaches up 97 percent in 2011

Related Resources

  • The Healthcare IT Innovation Imperative: Harnessing the Power of Technology for 21st Century Care Models
  • The 4Cs of Global Healthcare Reform
  • Defining an EMR and HIE Strategy for Medical Imaging
  • June 5th @ 1PM ET--Get Control of Your Medical Images with a Cloud-Based Vendor-Neutral Archive
  • Enabling Collaborative Healthcare Delivery: Care Coordination Strategies with 21st Century Technology

CARPINTERIA, CA – Electronically protected health information (ePHI) has become a target for malicious attack, according to a recent report by Redspin, Inc., a provider of HIPAA risk analysis and IT security assessment services.

The report was conducted between August 2009 – when the HITECH breach notification interim final rule (IFR) went into effect - and the end of 2010. The findings were based on 225 security breaches affecting 6,067,751 individuals.

Redspin's analysis focuses on single breaches affecting more than 500 people. Such large scale breaches must be reported on a timely basis to individuals, the media and the HHS Secretary according to the HHS Office of Civil Rights' regulations. The regulations also require business associates of covered entities to notify the covered entity of such breaches at or by the business associate.

[See also: Missing files highlight need for tighter security]

Selected findings from the report include:

  • 43 states, plus D.C. and Puerto Rico have suffered at least one breach affecting more than 500 individuals.
  • 27,000 individuals, on average, are affected by a breach.
  • 78 percent of all records breached are the result of 10 incidents, five of which are the result of theft of common storage media e.g. desktop computers, network servers, and portable devices.
  • 61 percent of breaches are a result of malicious intent.
  • 66,000 individuals, on average, are affected by a single breach of portable media.
  • 40 percent of records breached involved business associates.

"Redspin is committed to helping covered entities and business associates properly safeguard private health information," said John Abraham, president and CEO of Redspin. "We hope that by highlighting these findings we can help healthcare organizations proactively address areas of highest risk."

[See also: Are you ready for a data breach?]

Redspin makes the following recommendations in its report for preventing breaches around four key areas:

  • Incident Detection and Response: Implement an incident detection and response program to ensure all incidents are detected and responded to in a timely manner.
  • System Security Plan: During the development of the next IT project develop a system security plan that documents each component of the new system, including external connections, where sensitive data is stored, who has access, what vulnerabilities exist with the system, and how to prevent those vulnerabilities from being exploited.
  • Portable Media Policy: Rather than try to restrict where sensitive information is taken, take a data-driven view and focus on protecting data wherever it is stored. A mobile device security policy that includes management, operational and technical controls must be defined and implemented.
  • Business Associate Oversight: Ensure your business associate oversight program includes a review of contractual language that requires business associates to take as much care with your protected health information as you do.

Read the full report here.

Related Topics:
  • Carpinteria
  • Redspin Inc.
  • Electronic Health Records
  • Mobile/Wireless
  • Privacy and Security

Reader Comments (0)Login to Post a Comment

Most Popular

Latest Headlines
Most Popular
  • 6 reasons physicians need to be on social media
  • Lawsuit seeks Allscripts CEO's removal
  • 6 things patients want from social media
  • FCC gives green light to wireless medical devices
  • Tablet adoption by docs soars
  • Lawsuit seeks Allscripts CEO's removal
  • Web First: Q&A with Allscripts CEO Glen Tullman
  • 6 reasons physicians need to be on social media
  • Oregon to implement new statewide HIE
  • Tablet adoption by docs soars
more news

WEBINARS AND WHITE PAPERS

  • UPCOMING WEBINARS
    June 6th @ 2PM ET--Healthcare Best Practices: 4 Critical IT Strategies to Avoid Data Breaches
  • WHITE PAPERS
    Business Intelligence for Hospitals: Empowering Healthcare Providers to Make Informed Decisions
  • WHITE PAPERS
    Sharp HealthCare: Growing Content Management into an Enterprise Strategy
  • ON DEMAND WEBINARS
    A Smarter Approach to Healthcare PC Virtualization
  • WHITE PAPERS
    Mobility Advantage: Health Care Made Easier
More Resources
Syndicate content

HIMSS JOBMINE

  • Clinical Informatics Physician - Epic - Verona, WI
  • Regional Senior Quality Analyst - Memorial Medical Center - Modesto, CA
  • Network Engineer II - Carilion Clinic - Roanoke, VA
  • EMR Implementation - Project Manager Rothman Specialty Hospital - Rothman Specialty Hospital - Bensalem, PA
  • Director of Information Systems - Mission Regional Medical Center - Mission, Texas
more jobs

Marketplace

Follow Healthcare IT News on TwitterFan Healthcare IT News on FacebookJoin Healthcare IT News on LinkedInRSS Subscriptions
Digital EditionBlogEvents
JobsMobile SiteMobile App
 
Healthcare Finance News Government Health IT EHRWatch Healthcare Payer News HITECHWatch ICD10Watch mHIMSS PhysBizTech NHINWatch
©2012 MedTech Media Healthcare IT News is a publication of MedTech Media
Subscribe Advertise About Us Privacy Policy