Revisit: 5 Qs On Data Security
Editor’s Note: BHM posted a data security article this past May and we felt the topic was covered for six months or so. August uncovered at least three significant data breach-related examples. This post reflects on the recent exposures. Here at BHM, security is first. One-click and let our experts explain how.
Three stories caught my eye this month, from Becker’s Hospital Review:
- August 3: Banner Health suffers year’s largest data breach; 3.7M affected
- August 15: Bon Secours vendor breach affects 655K patients
- August 22: OCR to investigate more breaches affecting 500 or fewer individuals
As much as the details differ between the three stories, one worry comes true: cybersecurity threats are growing.
August 3: Cyberattackers gained access to “a limited number” of Banner Health computer servers, including the servers that process payment card information where food and beverages are sold at the Phoenix-based health system. Overall, 3.7 million patients, Banner health plan members and beneficiaries, food and beverage customers and providers may be affected, making it the largest healthcare data breach of 2016.
August 15: On June 14, the health system discovered R-C Healthcare Management, a vendor providing data reporting optimization services, inadvertently left patient information available online while adjusting its computer network settings from April 18 through April 21.
August 22: HHS’ Office for Civil Rights is increasing data breach investigation efforts and is making a concerted push to look into smaller breaches affecting fewer than 500 people.
These don’t even touch on ransomware. A recent AHC Media article reports that the FBI has recognized ransomware attacks as a serious threat, and some experts predict more will follow the February incident in which Hollywood Presbyterian Medical Center in Los Angeles paid $17,000 to hackers who took over its systems.
Next Steps for Data Security
Before IT starts pulling the covers over their heads, processes and options keep pace with these new attacks. Learn more about the Health Information Trust Alliance (HITRUST) and the HITRUST certification for organizations working and sharing data throughout the healthcare system.
Choosing third-party vendors carefully may lower exposure risk, if the right questions are included in the vetting process.
News of data breaches and cyberattacks has been ruling the headlines. As cyberattacks become more common, it’s crucial for healthcare organizations to learn how to protect themselves, and their patients’ data, from breaches and attacks.
A recent press release from the National Association of Insurance Commissioners (NAIC) identifies hacking as the most common type of data breach, with one-third of all data breaches that occurred in 2015 tracked back to hacking.
According to NAIC President John Huff, with millions of data records stolen each day, cybersecurity is more important now than ever, and it is imperative that consumers learn their options for defending themselves against growing threats.
Data security has become a very important issue for C-suite level executives in the healthcare industry. Whether you are a health plan or hospital, here are five important questions to ask about data security within your organization:
- How is your organization encouraging minimal access to records?
- How are you enforcing protocols set in place to ensure no one accesses a record unnecessarily?
- Does your organization have a zero-tolerance policy for breaches within your organization?
- How are records protected, and are they encrypted? Emails or other computer-based communications should be encrypted as well. Have these encryptions been tested?
- How are breaches reported? What is the timeline for investigation?
The National Association of Insurance Commissioners (NAIC) is the U.S. standard-setting and regulatory support organization created and governed by the chief insurance regulators from the 50 states, the District of Columbia and five U.S. territories. You can read the full press release here.
Partner with BHM Healthcare Solutions
With over 20 years in the industry, BHM Healthcare Solutions is committed to providing consulting and review services that help streamline clinical, financial, and operational processes to improve care delivery and organizational performance.
We bring the expertise, strategy, and capacity that healthcare organizations need to navigate today’s challenges – so they can focus on helping others.
Are you ready to make the shift to a more effective process?