DEC 6, 2012 11:51am ET

Related Links

Coalition to Senate: Time to ‘Re-do’ Meaningful Use
May 20, 2013
Rule Sets Pre-existing Coverage Rates
May 20, 2013
Medical Loss Ratio Rules Finalized for Medicare Advantage & Drug Programs
May 20, 2013
AHA to Senators: EHR Concerns Understandable, but Don’t Pause Meaningful Use
May 20, 2013
California Developing Guidance for Patient Consent of HIE
May 17, 2013
Quick Turnaround on Breach Notification
May 17, 2013
Tableau Sold as “DATA” in Stock Market Debut
May 17, 2013

Survey Finds Breach Incidents Continue to Increase

Print
Reprints
Email

The third year of a benchmark survey to assess progress in protecting health information finds the percentage of health care organizations reporting a breach has continued to increase since the first study in 2010.

That’s one of many sobering reminders in the survey that much of protected health information remains unprotected three years after the HIPAA breach notification rule became effective. Ninety-four percent of provider organization respondents reported at least one data breach during the past two years, and 45 percent said they had more than five. The average number for respondents was four breaches over two years.

Ponemon Institute, a privacy and security research firm, conducted the survey with sponsorship from data breach and remediation firm ID Experts. Eighty organizations, ranging from delivery systems to standalone hospitals and clinics, participated in the survey with 324 interviews conducted. Other survey results include:

* Fifty-two percent of respondents had one or more incidents of medical identity theft, and only one-third have controls to detect theft;

* Eighty-one percent permit employees and medical staff to use their own mobile devices and, on average, 51 percent of the work force brings their devices to work;

* Ninety-one percent of respondents use cloud services, but nearly half are not confident that information in the cloud is secure; and

* Nearly all breaches are discovered by an audit or assessment, or by employees.

Ponemon estimates the average cost of responding organizations dealing with breaches is $2.4 million over two years, compared with $2.1 million in the 2010 survey. The report, “Third Annual Benchmark Study on Patient Privacy & Data Security,” is available here.


Comments (0)

Be the first to comment on this post using the section below.

Add Your Comments:
You must be registered to post a comment.
Not Registered?
You must be registered to post a comment. Click here to register.
Already registered? Log in here
Please note you must now log in with your email address and password.
Twitter
Facebook
LinkedIn

As the feds ramp up enforcement of privacy and security rules, providers look to fill protection gaps.

Login  |  My Account  |  White Papers  |  Web Seminars  |  Events |  Newsletters |  eBooks
FOLLOW US
Already a subscriber? Log in here
Please note you must now log in with your email address and password.