Study finds occurrences of large personal data breaches in hospitals

NewsGuard 100/100 Score

Lying in a hospital bed, the last thing you should have to worry about is a personal data breach. Yet recent research co-authored by a Michigan State University business scholar found nearly 1,800 occurrences of large data breaches in patient information over a seven-year period.

The study, by Xuefeng "John" Jiang, MSU associate professor of accounting, and colleagues from Johns Hopkins and Ball State universities, is published in JAMA Internal Medicine. The data breaches occurred in health care facilities ranging from UC Davis Medical Center in California to Henry Ford Hospital in Michigan.

"Our findings underscore the critical need for increased data protection in the health care industry," Jiang said. "While the law requires health care professionals and systems to cross-share patient data, the more people who can access data, the less secure it is."

The researchers examined Department of Health and Human Services data for the period October 2009-December 2016. By law, hospitals covered by the Health Insurance Portability and Accountability Act, or HIPPA, must notify HHS of any breach affecting 500 or more individuals within 60 days from the discovery of the breach.

What they found was alarming:

  • Healthcare providers reported 1,225 of the 1,798 recorded breaches, while business associates, health plans and healthcare clearinghouses reported the rest.
  • 257 breaches reported by 216 hospitals.
  • 33 hospitals experienced more than one breach - many of which are large, major teaching hospitals.

This research reinforces the critical trade-off patients face: healthcare systems having access to information they need, versus a hacker planning to spend your savings at Best Buy.

Comments

The opinions expressed here are the views of the writer and do not necessarily reflect the views and opinions of News Medical.
Post a new comment
Post

While we only use edited and approved content for Azthena answers, it may on occasions provide incorrect responses. Please confirm any data provided with the related suppliers or authors. We do not provide medical advice, if you search for medical information you must always consult a medical professional before acting on any information provided.

Your questions, but not your email details will be shared with OpenAI and retained for 30 days in accordance with their privacy principles.

Please do not ask questions that use sensitive or confidential information.

Read the full Terms & Conditions.

You might also like...
Feeling lonely? It may affect how your brain reacts to food, new research suggests