Ponemon Institute Publishes 2016 Cost of Data Breach Study
For the past 11 years, the Ponemon Institute has conducted an annual benchmark study on the cost of data breaches. This week, the Ponemon Institute published the results of its 2016 Cost of Data Breach Study, which shows the cost of breach resolution continues to rise. The IBM-sponsored study indicates the average total cost of the breach response and resolution has increased to $7.01 million from $6.53 million last year: A rise of 7% year on year. Ponemon puts the average cost per compromised record at $221: A rise of 2% from last year’s figures or $4 per record. The 2016 cost of data breach study was conducted on organizations around the world, including companies based in Australia, Brazil, Canada, France, Germany, India, Italy, Japan, Saudi Arabia, the United Arab Emirates, and the United Kingdom. The global average data breach cost increased from $154 per record to $158 per record, with the total cost increasing from $3.8 million to $4 million per data breach. 383 companies took part in the global study. 64 U.S. companies took part in this year’s benchmark study and 16...
NIST Cybersecurity Framework to be Updated
In 2014, the National Institute of Standards and Technology (NIST) published its Cybersecurity Framework. The Framework details a set of standards, procedures, and processes that can be adopted by organizations to help them align their policy, business, and technological approaches to deal with cybersecurity risks. In December 2015, NIST issued a request for information (RFI) seeking feedback on use of the Cybersecurity Framework. NIST also asked for comments regarding long-term governance of the Framework and suggestions on how best practices for use should be shared. 105 responses were received. Further feedback was sought from stakeholders at an April 6-7 workshop in Gaithersburg, MD, specifically on best practice sharing, case studies, further development of the Framework, and comment on the NIST Roadmap for Improving Critical Infrastructure Cybersecurity. The feedback received from the RFI and the workshop indicated the Framework had proved to be a useful organization and system level tool, and that it has proved to be valuable for coordinating cybersecurity. Organizations...
FDA Issues Guidance for Medical Device Makers to Facilitate Data Sharing with Patients
The Food and Drug Administration (FDA) has issued new draft guidance for medical device manufacturers offering recommendations to facilitate the sharing of medical device data with patients. The FDA believes that sharing medical data such as oximetry data, heart electrical activity, and cardiac rhythms with patients will help to empower them to become more engaged in their own healthcare, and will help them to make sound medical decisions. In the guidance, the FDA explains that while the data recorded by these devices is primarily for physicians and hospitals, device manufacturers should make the data recorded by their devices available to patients. The data included in the FDA’s definition of patient-specific information include, but are not limited to, healthcare provider inputs, device usage/output statistics, incidences of alarms, records of device malfunctions or failures, or any data recorded by the devices. Device manufacturers have previously suggested that FDA approval would be necessary before they provide medical device data to patients. The FDA has issued the guidance...
Kern County Mental Health Department Announces Privacy Breach
Kern County Mental Health Department, CA., (KCMH) has reported a breach of protected health information which occurred during the relocation of its administrative department in April, 2016. The breach involved the exposure of a limited amount of protected health information of patients who had previously received care from KCMH between September 1, and September 30, 2006. When the administrative department relocated, the former offices were renovated. A single document was left behind in the offices and could potentially have been viewed by construction workers. The document was discovered by a KCMH staff member upon return to the offices. During the time that the report was left unprotected, staff members did not have access to the area. The report contained patients’ full names, internal record numbers, service codes, and the unit where treatment was provided. While patients could have been identified as having previously received treatment from KCMH and/or its contractors, the mental health services received were only identifiable by their codes. KCMH confirmed that highly...
Two More Healthcare Organizations Inform Patients of Bizmatics Breach
Two more healthcare organizations have started notifying patients that their protected health information was exposed when a hacker infiltrated the PrognoCIS application of third party vendor, Bizmatics Inc. Earlier this year, Bizmatics started notifying some of its clients that its systems had been infiltrated by a hacker, who may have accessed and copied clients’ data from its PrognoCIS electronic medical record (EMR) database. An attacker had succeeded in installing malware on its systems in January 2015, although the malicious software was discovered almost a year later toward the end of 2015. Many of the healthcare organizations affected by the breach were notified in March 2016. The latest two U.S. healthcare providers to announce that their patients had been affected by the Bizmatics breach are the California Health & Longevity Institute, based in Westlake Village near Los Angeles, and the Grand Junction, CO-based Vincent Vein Center. California Health & Longevity Institute submitted a breach report to the Department of Health and Human Services’ Office for Civil...



