Crime Leading HIPAA Breach Cause Says Ponemon Data Security Study
The threat to the healthcare industry from hackers is growing. Hacking and network server incidents are now the main cause of HIPAA data breaches, according to the OCR “wall of shame”. Yesterday, the Ponemon Institute released data from a new Privacy and Security which confirms that criminals are now the major cause of HIPAA breaches. The new study – the Fifth Annual Benchmark Study on Privacy and Security of Healthcare Data – shows that criminal activity is behind 45% of all healthcare data breaches, be that the theft of equipment or records with intent to use or sell the data, hacking incidents, malware, phishing and theft by malicious insiders. The loss of laptop computers and other unencrypted devices, accidental disclosures, and administration errors have traditionally been the major cause of data breaches over the past few years, including in 2014. This is the first time that carelessness and negligence have not been the leading breach cause. This is unlikely to change in the near future, especially considering criminal activity has increased by 125% over the course of the...
Hacking Tops List of 2015 Data Breach Causes
An analysis of breach reports during the first 5 months of the year shows that the main cause of 2015 HIPAA breaches is still hacking, which continue to expose patient health records in the millions. The colossal data breach at Anthem Inc., exposed 78.8 million member records while the HIPAA breach at Premera Health was potentially more serious. While 11 million records were obtained by hackers – considerably less than in the Anthem hacking incident – the data stolen was more substantial, and included medical information, personal identifiers and Social Security numbers; everything thieves need to commit fraud on a huge scale. Hacking Main Cause of HIPAA Breaches and Exposes Most Records HIPAA-covered entities are required – under the Breach Notification Rule – to report data breaches involving more than 500 individuals to the Department of Health and Human Services’ Office for Civil Rights. These breach reports must be made within 60 days of the discovery of a data breach. The two mega data breaches certainly stand out in the breach report lists due to the volume of records...
Almost Three Quarters of Companies Unprepared for Data Breaches
A day after the Department of Justice released new guidelines for responding to data breaches, the results of a survey conducted by EiQ Networks, a provider of security, risk, and compliance solutions, confirm the need for assistance. Nearly three-quarters (72%) of respondents claimed they were not prepared for a data breach. The survey was conducted on 168 IT decision-makers, with the sample including respondents from a range of industries. The data suggests IT staff do not have much confidence in either the defenses they have employed or how their organizations will deal with a data breach when it occurs. There were numerous problems highlighted by the survey, with a general lack of resources cited as one of the main issues. IT departments simply do not have the staffing levels required to safeguard systems and prevent data breaches, but 62% if respondents claimed their main concern was a lack of process – or only a partial process – to protect their company. There were inadequate checks being conducted to determine whether a security incident had actually occurred, and a...
Department of Justice Releases Breach Response Best Practice Guide
The Cybersecurity Unit of the U.S. Department of Justice (DOJ) has produced a new set of guidelines to help organizations with preparing for data breaches to enable them to take prompt action to mitigate damage and address security vulnerabilities. The DOJ felt that smaller organizations were unsure about the correct breach response, and aimed its guidance at these companies rather than large corporations and healthcare providers which are likely to have already implemented appropriate policies and procedures. A step-by-step guide is also included to help organizations prepare for the inevitable and the guidelines detail the steps that must be taken directly after the breach to minimize continuing damage along with a useful section covering actions that must not be taken, such as continuing to use an infected system to communicate. Unfortunately, while the steps are listed, not all will be appropriate for every organization. It is therefore essential that companies develop their own breach policies and procedures to match their own infrastructures. The guide points out certain...
The Cost of HIPAA Non-Compliance
The Security Rule of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) demands that all covered entities implement the appropriate administrative, physical and technical safeguards to keep PHI secure. Failure to implement those basic minimum standards and provide HIPAA training can lead to more than just a fine from the Department of Health and Human Services’ Office for Civil Rights (OCR). The cost of HIPAA non-compliance is considerable. The True Cost of HIPAA Non-Compliance Since the HIPAA Enforcement Act, the OCR has been able to fine organizations that fail to implement the appropriate controls to protect healthcare data and the privacy of patients. Fines of up to $1.5 million can be issued for HIPAA violations, with that number multiplied by the number of years each violation has been allowed to persist. Multimillion dollar financial penalties have already been issued for non-compliance, but a HIPAA-violation penalty is one of the smaller costs covered entities have to cover. Organizations experiencing even relatively small data breaches can see the cost...



