Skip to content Skip to navigation

Survey: Majority of Americans Underestimate the Threat of Stolen Medical Data

October 30, 2015
by Heather Landi
| Reprints

Despite widespread media attention about recent large security breaches at healthcare organizations, most Americans don’t recognize the threat posed by stolen medical records, according to a Vormetric survey.

Vormetric, a data security vendor, in conjunction with Wakefield, surveyed consumers about the types of account information they are most concerned about in the event of a data breach. The survey found that 89 percent of Americans polled did not include medical records in their top three selections of personal data they would be most concerned to have lost in a data breach. And, the survey indicated that Americans are still most concerned about the security of financial account information and social security numbers.

According to the survey, 84 percent of consumers surveyed said they were concerned about security of social security numbers, 73 percent cited credit card data and 71 percent in financial account information.

Cybersecurity experts have learned that black market prices for personal health information (PHI) can be four to 12 times higher than for credit card data, which makes healthcare data a prime target for hackers.

“Healthcare data sets contain extremely detailed personal information. Enough to not only apply for credit cards or loans, but also to generate huge sums from fraudulent medical charges,” Tina Stewart, vice president of marketing for Vormetric, said in a statement. “The public’s lack of awareness of their potential exposure to this is troubling. Few seem to realize that having their medical data lost is much more dangerous to their financial health than a stolen credit card number and address.”

And as Healthcare Informatics Senior Editor Rajiv Leventhal pointed out in his blog post, medical identity theft can result in a significant financial loss for patients, on average about $13,500 per victim.

The survey found 91 percent of Americans polled said they would still be worried if their personal data was stored in an encrypted file that was stolen as a result of a hack.

Stewart said encryption combined with strong access control was perhaps the most effective way to protect sensitive data given today’s threat environment. However, information security leaders interviewed by Healthcare Informatics have indicated that other techniques can effectively protect data. Many information security leaders have said that a solid risk analysis of healthcare databases is needed to determine the best security strategy.



EHNAC and HITRUST Combine HIPAA Security Criteria, CSF Framework

The Electronic Healthcare Network Accreditation Commission (EHNAC) and the Health Information Trust Alliance (HITRUST) announced plans to streamline their accreditation and certification programs.

Halamka on MACRA Final Rule: “CMS is Listening and I Thank Them”

Health IT notable expert John Halamka, M.D., CIO of Beth Israel Deaconess Medical Center in Boston, recently weighed in on the Medicare Access and CHIP Reauthorization Act (MACRA) final rule.

Texas Patient Care Clinic Hit with Ransomware Attack

Grand Prairie, Texas-based Rainbow Children's Clinic was the victim of a ransomware attack on its IT systems in August, affecting more than 33,000 patients, according to multiple news media reports this week.

Healthcare Organizations Again Go to Bat for AHRQ

Healthcare organizations are once again urging U.S. Senate and House leaders to protect the Department of Health and Human Services’ Agency for Healthcare Research and Quality (AHRQ) from more budget cuts for 2017.

ONC Pilot Projects Focus on Using, Sharing Patient-Generated Health Data

Accenture Federal Services (AFS) has announced two pilot demonstrations with the Office of the National Coordinator for Health Information Technology (ONC) to determine how patient-generated health data can be used by care teams and researchers.

Is it Unethical to Identify Patients as “Frequent Flyers” in Health IT Systems?

Several researchers from the University of Pennsylvania addressed the ethics of behavioral health IT as it relates to “frequent flyer” icons and the potential for implicit bias in an article published in JAMA.