Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

Health Data Losses: Don't Blame Hackers

Physical theft and lost computing devices are responsible for most of the health data that has been compromised, not hacking, according to U.S. Dept. of Health and Human Services.

10 Massive Security Breaches
(click image for larger view)
Slideshow: 10 Massive Security Breaches
While patients and doctors often worry about medical records being hacked by cybercriminals and Internet snoops, the most common cause of health data breaches is physical theft of computing gear, according to reports by the U.S. Dept of Health and Human Services.

Under the HITECH Act, HHS is required to post a list of incidents involving breaches and unsecured protected health information affecting 500 or more people. The HHS listing of the incidents reveals the top causes of breaches to be theft, not hacking of data.

Of the 288 HIPAA breaches listed on the HHS site, physical theft is at the root of more than 49% of the violations, according to analysis by software research and consulting firm, Software Advisor.

Meanwhile, human error and careless or accidental physical losses--such as losing a laptop with patient data--accounted for 14% of the incidents; unauthorized access and disclosure was involved in 16% of the cases; and improper disposal was the root of 5% of the incidents.

Despite common fears by patients and healthcare providers about of intrusions by black hats, hacking was involved in just 6% of the incidents.

Approximately 9% of the incidents involved a combination of breaches.

According the HHS, the largest data breach of all involved the theft of portal disk drive stolen from Health Net Inc. in California. The January 2011 incident affected 1.9 million individuals.

As for data breaches that involved lost computing gear, the largest incident occurred at South Shore Hospital in South Weymouth, Mass, affecting 800,000 individuals.

The January 2010 incident involved outdated patient data that was stored in e-medical records and on portable electronic devices that had been shipped by the hospital to Archive Data Solutions (formerly called Iron Mountain Data Products) for disposal.

However, a number of the boxes containing the records reportedly never arrived at the third-party data management company. The South Shore Hospital event was the fifth largest data breach incident reported in the HHS list.

Meanwhile, the largest breach involving hacking occurred last November and involved health data at Seacoast Radiology PA in New Hampshire. The incident affected 231,400 individuals.

Among some of the other larger health data breaches was a hacking incident in February 2010 involving records of the University of Texas in Arlington. The breach of prescription records--which included names of patients, diagnostic codes, medications names and some social security numbers--involved a network file server and affected approximately 27,000 individuals, according the HHS report.

In the new, all-digital InformationWeek Healthcare: iPads are leading a new wave of devices into the exam room. Are security, tech support, and infection control up to the task? Download it now. (Free registration required.)

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
SOC 2s & Third-Party Assessments: How to Prevent Them from Being Used in a Data Breach Lawsuit
Beth Burgin Waller, Chair, Cybersecurity & Data Privacy Practice , Woods Rogers PLC,  12/5/2019
Navigating Security in the Cloud
Diya Jolly, Chief Product Officer, Okta,  12/4/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: "This is the last time we hire Game of Thrones Security"
Current Issue
Navigating the Deluge of Security Data
In this Tech Digest, Dark Reading shares the experiences of some top security practitioners as they navigate volumes of security data. We examine some examples of how enterprises can cull this data to find the clues they need.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-19230
PUBLISHED: 2019-12-09
An unsafe deserialization vulnerability exists in CA Release Automation (Nolio) 6.6 with the DataManagement component that can allow a remote attacker to execute arbitrary code.
CVE-2013-0342
PUBLISHED: 2019-12-09
The CreateID function in packet.py in pyrad before 2.1 uses sequential packet IDs, which makes it easier for remote attackers to spoof packets by predicting the next ID, a different vulnerability than CVE-2013-0294.
CVE-2014-0242
PUBLISHED: 2019-12-09
mod_wsgi module before 3.4 for Apache, when used in embedded mode, might allow remote attackers to obtain sensitive information via the Content-Type header which is generated from memory that may have been freed and then overwritten by a separate thread.
CVE-2015-3424
PUBLISHED: 2019-12-09
SQL injection vulnerability in Accentis Content Resource Management System before the October 2015 patch allows remote attackers to execute arbitrary SQL commands via the SIDX parameter.
CVE-2015-3425
PUBLISHED: 2019-12-09
Cross-site scripting (XSS) vulnerability in Accentis Content Resource Management System before October 2015 patch allows remote attackers to inject arbitrary web script or HTML via the ctl00$cph_content$_uig_formState parameter.