More Americans trust the healthcare industry with their data than trust the government. But with a sharp rise in healthcare data breaches in 2016, there are steps that providers and the public should take to be safe.
Cybersecurity breaches are a growing issue in healthcare. As our contributor Lee Barrett reported earlier this year, a person’s healthcare record is 5 times more valuable on the black market because it contains much more information than someone’s credit card.
Healthcare, of course, isn’t the only part of the economy worried about cybersecurity. To call attention to the need for education and better security measures, the National Cyber Security Alliance (NCSA) celebrates Data Privacy Day each year on January 28.
To highlight Data Privacy Day, The American Journal of Managed Care® (AJMC®) spoke with Dan Konzen, campus chair for the College of Information Systems and Technology at the University of Phoenix. Konzen's center just conducted a poll that found 52% of Americans feel less secure today about their information than they did 5 years ago, and 47% have experienced a breach. When it comes to healthcare cybersecurity, here are 5 things to know:
1. Cybersecurity breaches are increasing each year
Konzen said the number of attacks is increasing, but, fortunately, “As the number of exposures occurs in and out of healthcare, people are more aware.” The best measure of the growing cybersecurity problem can be found on the HHS reporting site, where breaches that affect more than 500 people must be recorded under the HITECH (Health Information Technology for Economic and Clinical Health) Act. Last year saw 316 reportable breaches, which is 17.4% of the total since reporting began in 2009.
2. Training is essential to avoid breaches
Konzen said the best hardware and software won’t prevent an attack if staff are not taught what to look for—especially when using e-mail. But there are other ways security is breached, such as leaving charts where other can see them, or using a sign-in system that leaves patient signatures visible. For patients, Konzen said, these are things to look for to gauge whether your provider has good cybersecurity practices.
3. Cybersecurity is not a “do it yourself” task
For most healthcare providers and systems, Konzen said cybersecurity “is not their wheelhouse.” Most use a third party for their electronic health records (EHR) or for other security training and services. Konzen said a key step after staff training is to have a third party “test” the system to see if employees know what to do when they get a suspicious e-mail. Most breaches, he said, happen due to errors by health system employees, not a breach of the third-party vendor. That said, Konzen recommends a thorough vetting of EHR or other security vendors before health systems sign a contract. Barrett, who is executive director of the Electronic Healthcare Network Accreditation Commission, reports that underwriters are increasingly looking for third-party accreditation.
4. Have a response plan
As Barrett noted recently, the sharp rise in breaches in 2016 means that more and more providers have been affected by them, and he notes that 80% of breaches are discovered by outside groups or audits. Konzen said healthcare providers and health systems must have a response plan in place. Some notification requirements are spelled out by law, but others—both technical steps and efforts to restore public confidence—are not. Right now, the University of Phoenix poll finds 70% of Americans trust the healthcare industry with their data, compared with 41% who trust the government.
5. Join AJMC® to learn more about cybersecurity
The May 4-5, 2017, meeting of the ACO & Emerging Healthcare Delivery Coalition, taking place in Scottsdale, Arizona, will feature a session on cybersecurity issues in healthcare. To learn more about the meeting and to register, visit the ACO Coalition website here. To learn more about the NCSA and Data Privacy day, visit here.
ACOs’ Focus on Rooting Out Fraud Aligns With CMS Vision Under Oz
April 23rd 2025Accountable care organizations (ACOs) are increasingly playing the role of data sleuths as they identify and report trends of anomalous billing in hopes of salvaging their shared savings. This mission dovetails with that of CMS, which under the new administration plans to prioritize rooting out fraud, waste, and abuse.
Read More
New Research Challenges Assumptions About Hospital-Physician Integration, Medicare Patient Mix
April 22nd 2025On this episode of Managed Care Cast, Brady Post, PhD, lead author of a study published in the April 2025 issue of The American Journal of Managed Care®, challenges the claim that hospital-employed physicians serve a more complex patient mix.
Listen
Personalized Care Key as Tirzepatide Use Expands Rapidly
April 15th 2025Using commercial insurance claims data and the US launch of tirzepatide as their dividing point, John Ostrominski, MD, Harvard Medical School, and his team studied trends in the use of both glucose-lowering and weight-lowering medications, comparing outcomes between adults with and without type 2 diabetes.
Listen
Upadacitinib Shows Promise for Hard-to-Treat Crohn Disease
April 23rd 2025Upadacitinib showed promising results in achieving clinical and endoscopic remission in people with moderate to severe Crohn disease, including those previously treated with advanced therapies, offering a potential second-line treatment option with a manageable safety profile.
Read More
Higher Weight-Adjusted Waist Index Tied to Greater Mortality Risk in Patients With Osteoarthritis
April 23rd 2025Researchers consider the weight-adjusted waist index a more precise predictor of mortality risk in patients with osteoarthritis than traditional obesity measures, like body mass index.
Read More