Hacking Accounted for 98 Percent of Healthcare Data Breaches in 2015, Report Says | Healthcare Informatics Magazine | Health IT | Information Technology Skip to content Skip to navigation

Hacking Accounted for 98 Percent of Healthcare Data Breaches in 2015, Report Says

February 1, 2016
by Heather Landi
| Reprints
Click To View Gallery

While lost and theft of employee devices accounted for the majority (68 percent) of healthcare data breaches in 2014, last year was a different story, with 98 percent of breaches due to hacking and IT-related incidents, according to a Bitglass Healthcare Breach Report.

The report cites a series of large-scale hacks in the healthcare industry last year as one reason for the shift from device loss to hacking as the primary source for breaches. Those large breaches include the Premera Blue Cross breach involving 11 million customers and the Anthem hack that resulted in 78.8 million leaked customer records. According to the report, even if the six breaches that occurred last year that affected more than 1 million individuals were excluded, hacking and IT-related incidents would still account for the majority of leaked healthcare records in 2015.

In 2015, only 97 breaches were due to the loss or theft of a device, down from 140 in 2014. By contrast, there have been 56 breaches due to hacking in 2015, up from 31 in 2014, and those 56 breaches affected more than 111 million individuals’ data.

As has been previously reported in Healthcare Informatics, protected health information (PHI), which includes such sensitive information as Social Security numbers, medical record numbers and date of birth, is very valuable on the black market. The average cost per lost or stolen record that includes PHI is $154, and that number skyrockets to $363 on average for healthcare organizations, according to a Ponemon Institute report.

According to the Bitglass report, at least one administrator’s credentials were compromised in the Anthem breach by means of a phishing attack where hackers used a technique called domain spoofing.  As the report explains, according to an investigation, hackers registered variations on the real domains and phishing emails were sent to employees to bait them onto the spoofed sites. Once employees log into the fake site with their credentials, hackers gain access to those credentials and employees are then logged into the real Premera or Anthem site, unaware that they have just been subject to a phishing attack.

In the case of the Anthem breach, that company’s healthcare data was targeted by hackers in China, an investigation revealed, and access to those credentials provided the hackers with access to customer names, dates of birth, Social Security numbers, healthcare ID numbers and income data. With the Premera breach, bank account and medical claims information also were potentially leaked.

In light of the major breaches in 2015, the report also cites the need for healthcare organizations to have a HIPAA-compliant, comprehensive, data-centric solution. As previously reported by HCI, healthcare organizations are looking at a number of innovative data security solutions, such as behavioral pattern auditing and, in the case of Dallas-based Texas Health Resources, a sophisticated risk management-based approach to information security.

Get the latest information on Health IT and attend other valuable sessions at this two-day Summit providing healthcare leaders with educational content, insightful debate and dialogue on the future of healthcare and technology.

Learn More



Analysis: Healthcare Ransomware Attacks Decline in First Half of 2018

In the first half of 2018, ransomware events in major healthcare data breaches diminished substantially compared to the same time period last year, as cyber attackers move on to more profitable activities, such as cryptojacking, according to a new report form cybersecurity firm Cryptonite.

Dignity Health, UCSF Health Partner to Improve the Digital Patient Experience

Dignity Health and UCSF Health are collaborating to develop a digital engagement platform that officials believe will provide information and access to patients when and where they need it as they navigate primary and preventive care, as well as more acute or specialty care.

Report: Digital Health VC Funding Surges to Record $4.9 Billion in 2018

Global venture capital funding for digital health companies in the first half of 2018 was 22 percent higher year-over-year (YoY) with a record $4.9 billion raised in 383 deals compared to the $4 billion in 359 deals in the same time period last year, according to Mercom Capital Group’s latest report.

ONC Roundup: Senior Leadership Changes Spark Questions

The Office of the National Coordinator for Health IT (ONC) has continued to experience changes within its upper leadership, leading some folks to again ponder what the health IT agency’s role will be moving forward.

Media Report: Walmart Hires Former Humana Executive to Run Health Unit

Reigniting speculation that Walmart and insurer Humana are exploring ways to forge a closer partnership, Walmart Inc. has hired a Humana veteran to run its health care business, according to a report from Bloomberg.

Value-Based Care Shift Has Halted, Study Finds

A new study of 451 physicians and health plan executives suggests that progress toward value-based care has stalled. In fact, it may have even taken a step backward over the past year, the research revealed.