81% of U.S. Healthcare Organizations Have Increased Security Spending in 2017
The 2017 Thales data threat report published earlier this week shows the healthcare industry is responding to the increased threat of data breaches and cyberattacks by committing more funds to improving cybersecurity defenses. After two record breaking years of healthcare data breaches – 2015 in terms of the number of records exposed or stolen, and 2016 in terms of the number of breaches reported – it is clear that the healthcare industry is under attack. 2016 also saw a record number of settlements reached with the Department of Health and Human Services’ Office for Civil Rights. Last year there were 12 HIPAA settlements and one Civil Monetary Penalty issued to resolve HIPAA violations discovered during healthcare data breach investigations. Healthcare organizations are certainly feeling the heat. In the US, 90% of healthcare organizations feel vulnerable to data threats. There was also a 2% increase in the number of healthcare organizations that experienced a data breach in the past 12 months. 20% said they had a data breach in the past 12 months and 55% of healthcare...
Theft, Hacking, Ransomware and Improper Accessing of ePHI – Attacks Coming from All Angles
Theft, hacking, ransomware, and improper ePHI access by employees – The past few days have seen a diverse range of healthcare data breaches reported. St. Joseph’s Hospital and Medical Center in Arizona, Family Service Rochester of Minnesota, and the University of North Carolina have all reported potential breaches of patients’ ePHI, while Lexington Medical Center in South Carolina has announced that the sensitive data of its employees have been viewed. University of North Carolina Reports Theft of Dental Patients’ ePHI A laptop computer and a SD memory card from a digital camera have been stolen from the car of a postgrad dental resident of the University of North Carolina School of Dentistry. While the devices should have had a number of security measures installed to prevent improper data access, UNC has been unable to confirm whether that was the case. The breach may have resulted in the exposure of around 200 patients’ personal information including full face photographs (without any other PHI), names, dates of birth, dental record numbers, treatment plans, dental and health...
Small Healthcare Data Breach Notification Deadline: March 1, 2017
The Health Insurance Portability and Accountability Act’s Breach Notification Rule requires all covered entities to report breaches of unsecured electronic protected health information to the Department of Health and Human Services’ Office for Civil Rights. While large data breaches – those impacting 500 or more individuals – must be reported to OCR within 60 days of the discovery of the breach, covered entities can delay the reporting of smaller data breaches. While patients must be notified of any breach of their ePHI within 60 days – regardless of the number of individuals affected by the breach – notifications of security incidents are not required by OCR until 60 days after the end of the calendar year in which the data breaches were discovered. The deadline for reporting 2016 healthcare data breaches impacting fewer than 500 individuals is March 1, 2017. As with larger data breaches, all smaller incidents must be submitted via the OCR breach reporting tool. While smaller data breaches can be reported together, each breach must be entered into the breach reporting tool...
A Quarter of Americans Have Been Impacted by a Healthcare Data Breach
Given the volume of healthcare records that have been exposed or stolen over the past two years, it comes as little surprise that 26% of Americans believe their health data have been stolen. The figures come from a recent survey conducted by Accenture. The survey was conducted on 2,000 U.S. adults and more than a quarter said that their medical information has been stolen as a result of a healthcare data breach. Healthcare information is attractive for cybercriminals as the information in health records does not expire. Credit card numbers can only be used for an extremely limited time before cards are blocked. However, Social Security numbers can be used for a lifetime and health insurance information can similarly be used for extended periods. The information can also be used for a multitude of nefarious activities such as tax fraud, identity and medical identity theft, and insurance fraud. It is also unsurprising that many victims of healthcare data breaches have reported suffering losses as a result of the theft of their data. According to Accenture, half of the individuals who...
Healthcare Industry Threat Landscape Explored by Trend Micro
Trend Micro has issued a new report that explores the healthcare industry threat landscape, the new risks that have been introduced by the inclusion of a swathe of IoT devices, and how cybercriminals are stealing and monetizing health data. Cybercriminals are attacking healthcare organizations with increased vigor. More attacks occurred last year than any other year, while 2015 saw a massive increase in stolen healthcare records. While the health data of patients is an attractive target, health records are not always being sold for big bucks on underground marketplaces. Health insurance cards can cost as little as $1, while EHR records start at around $5 per record set. However, cybercriminals are now increasing their profits by processing and packaging the stolen data. Data are used to obtain government-issued iDs such as driver’s licenses, passwords and birth certificates. Farmed identities of individuals who have died are being sold, which can see prices of more than $1,000 charged per identity, or even more if IDs are also supplied. A large haul of health data from an EHR...



