2019 Data Breach Barometer Report Shows Massive Increase in Exposed Healthcare Records
Protenus has released its 2019 Breach Barometer report: An analysis of healthcare data breaches reported in 2018. The data for the report came from Databreaches.net, which tracks data breaches reported in the media as well as HIPAA breach notifications sent to the Department of Health and Human Services’ Office for Civil Rights and state attorneys general. The report shows there was a small annual increase in the number of healthcare data breaches but a tripling of the number of healthcare records exposed in data breaches. According to the report, there were 503 healthcare data breaches reported in 2018, up from 477 in 2017. 2017 was a relatively good year in terms of the number of healthcare records exposed – 5,579,438 – but the number rose to 15,085,302 exposed healthcare records in 2018. In 2017, March was the worst month of the year in terms of the number of records exposed and there was a general downward trend in exposed records throughout the rest of the year. In 2018, there was a general increase in exposed records as the year progressed. The number of exposed records...
ONC and CMS Propose New Rules on Patient Access and Information Blocking
On Monday, February 11, 2019, the HHS’ Office of the National Coordinator for Health Information Technology (ONC) and the Centers for Medicare and Medicaid Services (CMS) released new rules covering patient data access and information blocking. The aim of the new rules is to advance interoperability and support the meaningful exchange and use of health information. The rules are intended to increase competition, encourage innovation, and give patients control over their health data. One of the main goals is to make health information accessible via application programming interfaces (APIs). Currently consumers use a wide range of smartphone apps for paying bills and accessing information. It should be just as easy to gain access to healthcare data through apps and for healthcare data to be provided electronically at no cost. One of the main requirements of the new rules is for healthcare providers and health plans to implement data sharing technologies that support the transition of care to new healthcare providers and health plans. Whenever a patient wishes to start seeing a new...
HIMSS Cybersecurity Survey: Phishing and Legacy Systems Raise Grave Concerns
Each year, HIMSS conducts a survey to gather information about security experiences and cybersecurity practices at healthcare organizations. The survey provides insights into the state of cybersecurity in healthcare and identifies attack trends and common security gaps. 166 health information security professionals were surveyed for the 2019 HIMSS Cybersecurity Survey, which was conducted from November to December 2018. This year’s survey revealed security incidents are a universal phenomenon in healthcare. Almost three quarters (74%) of healthcare organizations experienced a significant security breach in the past 12 months. 22% said they had not experienced a significant security incident in the past year. The figures are in line with the 2018 HIMSS Cybersecurity Survey, when 21% of respondents said they had not experienced a significant security incident. In 2018, 82% of hospital systems reported a significant security incident, as did almost two thirds of non-acute and vendor organizations. The most common actors implicated in security incidents were online scam artists (28%)...
7,000 Patients Notified About Pawnee County Memorial Hospital Malware Attack
Pawnee County Memorial Hospital in Pawnee City, Nebraska, is alerting 7,038 patients that some of their protected health information has potentially been accessed by a hacker. On November 29, 2018, the hospital learned that malware had been installed which allowed an unauthorized individual to gain access to its email system. Malware was injected into the hospital’s email system when an employee opened a malicious email attachment. According to Pawnee County Memorial Hospital’s substitute breach notice, the email appeared to have been sent from a trusted source and the email attachment seemed genuine. Assisted by a third-party computer forensics expert, the hospital determined that the email attachment had been opened on November 16, 2018. The hacker was able to access employees’ email accounts from November 16 to November 24. The compromised email accounts contained a range of business reports, clinical reports, clinical summaries, and other internal documents. Those documents contained patients’ full names along with one or more of the following data elements: Date of birth,...
Is Smartsheet HIPAA Compliant?
There are many different types of project management platforms available for Covered Entities and Business Associates to manage workflows, but are project management platforms such as Smartsheet HIPAA compliant? Smartsheet is a Software-as-a-Service project management platform Covered Entities and Business Associates can use to assign tasks, track progress, manage calendars, and share documents. It is an effective solution for facilitating collaboration between workforce members; but, when any collaboration involves uses and disclosures of PHI, it is important PHI is protected. The HIPAA Security Rule details how PHI should be protected while in use, in transit, or at rest; and – via its Enterprise Plan – Smartsheet provides the necessary security controls for Covered Entities and Business Associates to comply with the Security Rule standards. However, Covered Entities and Business Associates are responsible for configuring the security controls correctly. The Smartsheet Business Associate Agreement In order to make Smartsheet HIPAA compliant, Covered Entities and Business...



