Report: Electronic Health Information Under Attack
Redspin report finds two-thirds of all records breached resulted from laptops or other portable media devices
February 10, 2011
PRESS RELEASE
CARPINTERIA, Calif., Feb. 9, 2011 /PRNewswire/ -- Redspin, a leading provider of HIPAA risk analysis and IT security assessment services, today released an analysis of all protected health information breaches publicly recorded between August 2009 and the end of 2010, as per the interim final breach notification of the HITECH Act. The findings were based on 225 security breaches affecting 6,067,751 individuals.
Redspin's analysis focuses on single breaches affecting more than 500 people. Such large scale breaches must be reported on a timely basis to individuals, the media and the HHS Secretary according to the HHS Office of Civil Rights' regulations. The regulations also require business associates of covered entities to notify the covered entity of such breaches at or by the business associate.
Selected findings from the report include:
-- 43 states, D.C. and Puerto Rico have suffered at least one breach affecting over 500 individuals. -- ~27,000 individuals, on average, are affected by a breach. -- 78% of all records breached are the result of 10 incidents, five of which are the result of theft of common storage media e.g. desktop computers, network servers, and portable devices. -- 61% of breaches are a result of malicious intent. -- ~66,000 individuals, on average, are affected by a single breach of portable media. -- 40% of records breached involved business associates.
"Redspin is committed to helping covered entities and business associates properly safeguard private health information," said John Abraham, President and CEO of Redspin. "We hope that by highlighting these findings we can help healthcare organizations proactively address areas of highest risk."
A full copy of the report is available at http://www.redspin.com
About Redspin, Inc.
Redspin delivers comprehensive security testing, risk management and compliance solutions. For hospitals and other covered entities, Redspin provides HIPAA risk analysis and IT security assessment services that meet the security requirements of the EHR meaningful use incentive program. Most importantly, Redspin helps keep protected health information safe and critical IT systems secure. The company's expertise, objectivity and business acumen have made Redspin a trusted partner to healthcare and other industries for over a decade.
You May Also Like
How to Evaluate Hybrid-Cloud Network Policies and Enhance Security
September 18, 2024DORA and PCI DSS 4.0: Scale Your Mainframe Security Strategy Among Evolving Regulations
September 26, 2024Harnessing the Power of Automation to Boost Enterprise Cybersecurity
October 3, 202410 Emerging Vulnerabilities Every Enterprise Should Know
October 30, 2024
State of AI in Cybersecurity: Beyond the Hype
October 30, 2024[Virtual Event] The Essential Guide to Cloud Management
October 17, 2024Black Hat Europe - December 9-12 - Learn More
December 10, 2024SecTor - Canada's IT Security Conference Oct 22-24 - Learn More
October 22, 2024