From 2012 to 2013 healthcare data breaches have doubled. A quick look at the numbers will make any healthcare security professional concerned, and ready to take action so that security in 2014 doesn’t live the same fate as last year’s.
Why are breaches rising?
With healthcare data moving toward a complete online system (a perfect example: EHRs) this creates bulks of personal information that can be accessed by anyone who is looking to penetrate the area where data is stored (devices, networks, clouds, data centers).
In addition to the challenge of having big pools of data in one location and potentially accessible to unauthorized individuals, we find another six healthcare information security concerns.
- Device theft
- Insider threat
- Business associates
- Lack of IT staff to adopt new security solutions and with the needed level of expertise
- EHR vendors can’t always deliver new offerings in a timely manner
Six suggestions to help healthcare facilities prepare for the above challenges, as well as work towards a stronger security posture (long term), can come in handy.
- Be ready to identify, analyze and report on security incidents at all times.
- Verify that staff and business associates are consistent with the terms of agreement and meeting compliance standards.
- Continued compliance with applicable federal and state laws, rules, and regulations across your facility and your business associates.
- Comply and maintain internal security policies and procedures in loco, and ensure your business partners do the same.
- Have an individual or team of security professionals who can coordinate security activities such as business associate relationships, audits and the monitoring process.
- Improve implementation of encryption.
Lastly, keep in mind that with the new HIPAA report requirements a rise in healthcare data breach reports is inevitable. Reporting plays a huge role in the repercussions for a healthcare facility’s reputation and the patient’s sense of security.
Learning from the breach lessons that took place in 2013 and acting in a timely manner will allow the healthcare industry to show their patients that they can be counted on to keep sensitive data secure.
Healthcare executives and security professionals taking action will also give hope that 2014 will not turn out to be so dark and full of data breaches as this past year.
What steps are you taking to increase your healthcare facility’s security posture in 2014?
Photo courtesy of Fotos GOVBA