Exploring the Causes of Healthcare Data Breaches

BCLP
Contact

Pursuant to the Health Insurance Portability and Accountability Act of 1996 (“HIPAA”), covered entities (e.g. healthcare providers and health plans) must notify the Department of Health and Human Services (“HHS”) of breaches of unsecured protected health information (“PHI”).1  The information provided to HHS provides organizations with a high level of insight concerning the types of breaches that occur in the healthcare industries.

The data collected by HHS concerning breaches affecting 500 or more individuals in 2014 shows that low-tech breaches remain the most common form of data loss in the health sector – surpassing more publicized hacking events. 

Things to consider when reviewing your information security program in light of HHS data:

  1. Are all laptops encrypted?
  2. Is laptop encryption full-disk (e.g., does it apply to the entire hard drive)?
  3. Is laptop encryption also file-level (e.g., would it apply if files were removed from the hard drive)?
  4. Do you permit other types of portable media in your environment like USB drives?
  5. If so, are those devices encrypted at the disk or file-level?
  6. Are passwords enforced on laptops and other types of portable media?

The following provides a snapshot of information concerning healthcare data breaches.

46%

The quantity of breaches caused by theft of hardware of all types.2

34%

The quantity of theft involving stolen laptops.3

9%

The quantity of breaches caused by hacking/IT intrusions.4

3%

The quantity of breaches caused by improper disposal.5

 

[1] 45 C.F.R. §164.408(a)-(b).

[2] U.S. Dep't of Health and Human Servs. Office for Civ. Rights, Breaches Affecting 500 or More Individuals, https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf

[3] Id.

[4] Id.

[5] Id.

[View source.]

DISCLAIMER: Because of the generality of this update, the information provided herein may not be applicable in all situations and should not be acted upon without specific legal advice based on particular situations.

© BCLP | Attorney Advertising

Written by:

BCLP
Contact
more
less

PUBLISH YOUR CONTENT ON JD SUPRA NOW

  • Increased visibility
  • Actionable analytics
  • Ongoing guidance

BCLP on:

Reporters on Deadline

"My best business intelligence, in one easy email…"

Your first step to building a free, personalized, morning email brief covering pertinent authors and topics on JD Supra:
*By using the service, you signify your acceptance of JD Supra's Privacy Policy.
Custom Email Digest
- hide
- hide