Local: (805)-371-3680 | Toll Free: (800) 240-CHIV
Facebook
LinkedIn
Chivaroli Insurance Services
  • INSURANCE COVERAGE
    • Medical Professional Liability
    • Commercial Auto Insurance
    • Errors & Omissions Insurance
    • Commercial General Liability
    • Business Owners Policy (BOP)
    • Representations & Warranties
    • Directors’ & Officers’ Liability
    • Fiduciary Liability Insurance
    • Terrorism Risk Insurance
    • Commercial Property
    • Commercial Crime
    • Difference in Conditions
    • Workers Compensation
    • Employment Practices Liability
    • Stop Loss Insurance
    • Security & Privacy (Cyber) Liability
    • Products Liability
    • Personal Lines Insurance
  • OTHER SERVICES
    • Alternatives
    • Consulting Services
    • Credentialing Requests
    • Risk Management
    • Wholesale Brokerage
  • RESOURCES
    • Healthcare Resources
    • Insurance Resources
    • Terms & Definitions
  • NEWS
  • ABOUT
  • CONTACT

Finding the Blind Spots: Latest Ponemon Study Shows New Vulnerability Zones in PHI Security

March 24, 2014Chivaroli and Associates Insurance ServicesArticle Archives

As seen on idexperts.com:

date breachesA new study from the Ponemon Institute shows that healthcare providers have made progress in implementing protected health information (PHI) security policies and processes. According to the Fourth Annual Benchmark Study on Patient Privacy and Data Security by Ponemon Institute, slightly more than half (55 percent) of organizations surveyed agree they have the policies and procedures that effectively prevent or quickly detect unauthorized patient data access, loss or theft, a perception supported by the finding that the number and cost of data breaches has declined slightly from past years. Unfortunately, a year after the HIPAA Final Rule went into effect, the other half of organizations surveyed do not feel they have adequate policies and procedures in place to effectively prevent or detect PHI security incidents. The overall picture is still sobering. Healthcare organizations are threatened by large and evolving security blind spots, from the ongoing issue of employee behavior to growing criminal activity—criminal attacks rose 100 percent over last year, in fact—as organizations drive full speed ahead into a rapidly changing healthcare landscape.

Signs of Improvement

While the total number of data breaches has declined slightly over previous years, 90 percent of healthcare organizations are still experiencing breaches, and 38 percent report that they have had more than five incidents in the last two years (a slight decrease from last year’s report, in which 45 percent reported more than five breaches). Ponemon calculates the average economic impact of reported data breaches over the past two years at $2.0 million per organization, however data breaches are still costing healthcare organizations an estimated $5.6 billion annually.

There are hopeful signs, but many organizations are still struggling with incident management, compliance with the myriad of regulations, and how to cope with changes in the security environment. Dr. Larry Ponemon, chairman and founder of the Ponemon Institute, sums up the situation: “Healthcare organizations are getting better at implementing security measures, but attacks and threats are getting stronger and more persistent. The combination of insider and outsider threats presents a multi-level challenge, and healthcare organizations are lacking the resources to address this reality.”

Shining Light on the Blind Spots

The shifting healthcare environment creates security blind spots for healthcare organizations: they know there will be threats from business associates, mobile devices, new healthcare exchanges, etc., but they don’t have the visibility to avoid those threats. The new Ponemon study outlines several key areas of concern.

Employee negligence: As in past Ponemon surveys, human error emerged this year as the biggest vulnerability in PHI security. Although the majority of surveyed organizations expressed confidence in their breach detection policies and procedures, 75 percent reported employee negligence as their biggest worry, and insider negligence was the root of most data breaches reported in the study. Exacerbating concerns about employee negligence is the use of insecure mobile devices: 88 percent of organizations permit employees and medical staff to use their own mobile devices to connect to the organization’s networks or enterprise systems, even though more than half of organizations are not confident that employees’ mobile devices are secure, and 38 percent don’t take steps to secure the devices or prevent them from accessing sensitive information.

Security gaps with business associates: Healthcare organizations are increasingly reliant on business associates (BAs) for IT services, claims processing, benefits management, and other services, yet most don’t trust their third parties or business associates with sensitive patient information. BAs have access to patient information, but many are still struggling to comply with the HIPAA Final Rule. Seventy-three percent of organizations surveyed by Ponemon are somewhat confident (33 percent) or not confident (40 percent) that their business associates would be able to detect, perform an incident risk assessment, and notify the organization in the event of a data breach incident as required under the business associate agreement. Only 30 percent are confident that their business associates are appropriately safeguarding patient data as required under the HIPAA Final Rule.

Evolving criminal threats: Dr. Larry Ponemon says that the most sobering finding of the study is the rise in criminal activity directed against PHI: “The latest trend we are seeing is the uptick in criminal attacks on hospitals, which have increased a staggering 100 percent since the first study four years ago. As millions of new patients enter the U.S. healthcare system under the Affordable Care Act, patient records have become a smorgasbord for criminals.” This year, 40 percent of organizations surveyed report criminal attacks to PHI security, as opposed to 20 percent in 2010, a 100 percent increase. Cybercriminals are constantly changing and revising their tactics, and staying ahead of the criminal threat is a major challenge for healthcare organizations.

New vulnerabilities under the Affordable Care Act: The Affordable Care Act promotes the use of electronic medical records as a means to lower healthcare costs, but nearly 70 percent of respondents in the Ponemon survey believe that it has increased the risk to millions of patients due to inadequate security. The primary concerns include insecure exchange of patient information between healthcare providers and government, patient data on insecure databases, and patient registration on insecure websites. Survey participants also had strong reservations about the security of Health Information Exchanges (HIEs): a third said they don’t plan to participate in HIEs because they are not confident enough in the security and privacy of patient data shared on the exchanges.

A Bucket of Trouble

There are glimmers of good news in this year’s Ponemon report, but this is no time for any healthcare organization to rest on its laurels. “It’s been one year since the HIPAA Final Rule was enforced and we have seen healthcare organizations make some good progress towards complying with federal privacy and security guidelines and better safeguarding patient information. However, because the threats and risks are shifting, organizations are in a constant state of catch up,” Rick Kam, president and co-founder of ID Experts, explains. “It’s like a bucket filled with water and holes. The water keeps spurting out, and every time you go to patch a hole, a new hole forms. The whole process of patching old and new holes is overwhelming.”

Right now, healthcare organizations need to double down on their efforts to assess risks, achieve consistency in security processes and procedures, and to prepare for emerging threats. This shift in focus from an incident-based process to a culture of compliance is what’s necessary to get ahead of the shifting sands of security risks. According to Ponemon, organizations should look for opportunities to instill business operations that include tools, software and processes that will both automate and streamline the practice of managing the disclosure of regulated data.

For more information contact Chivaroli & Associates.

Chivaroli and Associates Insurance Services
Chivaroli & Associates Insurance Services is a full-service brokerage and consulting firm that specializes in the custom design and placement of property and casualty insurance and alternative risk funding solutions for healthcare organizations.
Previous post Hacking Incidents Prompt Universities to Rethink Balance between Openness / Security Next post A Spinal Implant Loophole Costs the State of California Millions in Workers Compensation
Sign up for Chivaroli & Associates Newsletter
* = required field
unsubscribe from list

Categories

  • Article Archives
  • General Article
  • Private
  • Uncategorized

Archives

  • February 2025
  • December 2024
  • November 2024
  • October 2024
  • August 2024
  • July 2024
  • June 2024
  • May 2024
  • April 2024
  • March 2024
  • January 2024
  • December 2023
  • November 2023
  • October 2023
  • September 2023
  • August 2023
  • July 2023
  • June 2023
  • April 2023
  • March 2023
  • February 2023
  • January 2023
  • December 2022
  • October 2022
  • September 2022
  • August 2022
  • July 2022
  • June 2022
  • May 2022
  • April 2022
  • March 2022
  • February 2022
  • January 2022
  • November 2021
  • September 2021
  • August 2021
  • July 2021
  • June 2021
  • May 2021
  • April 2021
  • March 2021
  • February 2021
  • January 2021
  • November 2020
  • October 2020
  • September 2020
  • August 2020
  • July 2020
  • June 2020
  • May 2020
  • April 2020
  • March 2020
  • February 2020
  • January 2020
  • August 2019
  • July 2019
  • June 2019
  • March 2019
  • February 2019
  • January 2019
  • December 2018
  • November 2018
  • August 2018
  • July 2018
  • June 2018
  • May 2018
  • April 2018
  • March 2018
  • February 2018
  • December 2017
  • November 2017
  • October 2017
  • August 2017
  • July 2017
  • June 2017
  • May 2017
  • April 2017
  • March 2017
  • February 2017
  • January 2017
  • November 2016
  • October 2016
  • September 2016
  • August 2016
  • July 2016
  • June 2016
  • May 2016
  • April 2016
  • March 2016
  • February 2016
  • December 2015
  • November 2015
  • October 2015
  • September 2015
  • August 2015
  • July 2015
  • June 2015
  • April 2015
  • February 2015
  • January 2015
  • December 2014
  • November 2014
  • October 2014
  • September 2014
  • August 2014
  • July 2014
  • June 2014
  • May 2014
  • April 2014
  • March 2014
  • February 2014
  • January 2014

Chivaroli and Associates Insurance Services is a full-service brokerage firm specializing in the custom-design and placement of insurance and alternative risk funding solutions for your healthcare organization.

Facebook
Twitter
LinkedIn
YouTube

Contact Us Today

Address:
200 North Westlake Blvd., Suite 101
Westlake Village, CA 91362
Phone:
805-371-3680
E-mail:
mail@chivarolitr.wpengine.com

Resources

Health Care
Insurance
Terms & Definitions
News
About

Policies

Cookie Policy
Disclaimer

Recent News

  • Premium Hikes Continued in Q4 2024, Latest Survey Shows 
  • ‘Nuclear’ Medical Malpractice Verdicts on the Rise
  • Pay Now, Deliver Later: Some Women Are Prepaying for Their Baby
  • Fidelity Bonds vs. Commercial Crime Insurance: Which is Right for You?
© 2025 All rights reserved. Powered By Insurance Agency Website by Stratosphere