Posted in

5 Best Practices to Avoid Data Breaches in the Healthcare Industry

Data breaches are common and can occur at almost every type of organization or company, but they are particularly troublesome and widespread in the healthcare industry. Patients sensitive medical records are constantly at risk, whether the organization is large or small, affecting individuals at every level of data breach.

The U.S. Department of Health and Human Services maintains an online database of healthcare breaches affecting over 500 individuals, but many smaller breaches occur each year as well. According to Forbes, over 112 million records were compromised by data breaches in 2015 aloneand 90% of the top ten breaches were related to hacking or IT incidents.

The average cost of a breach continues to rise, and in 2014, that average stood at $5.9 million. With the high prevalence of cybercrime still rising, the healthcare industry must take steps to reduce the number and impact of data breaches, which lead to the compromise of sensitive data and financial consequences. Healthcare organizations should follow cyber security best practices to minimize the risk of a breach. These steps include:

1. Educating Employees on Security Risks

Healthcare organizations may have stellar employees, but human error can always lead to security issues. Proper training on regulations, security protocolsand support for employees using mobile devicescan help reduce these errors and improve overall security. Employees should only have the data necessary to perform the functions of their jobthe fewer places data is stored, the more secure it is. As Brian Lapidus of Kroll points out, Thieves can’t steal what you don’t have. Data minimization is a powerful element of preparedness. When employees leave the organization, human resource procedures should include suspending access to sensitive data.

2. Keeping Systems Patched

Patches are necessary to keep systems running at optimal levels. They are used as a method for keeping data secure because unpatched versions of systems may no longer be supported. Without a patch, hackers find weak spots they can exploit, making breaches more likely. Unfortunately, many systems do not have automatic patching in place which require more time and resources to update. Patching systems continue to be an ongoing maintenance issue that can be costly, but is far less expensive compared to a data breach.

3. Choosing Vendors Carefully

Many healthcare organizations use offsite data storage systems that work with third party vendors who are responsible for the organizations records. Choosing partners who follow best practices are essential to keeping data safe. When an organization does not have direct control over the data, the security precautions must be just as strict as if the data was stored in-house.

4. Be Careful Implementing Bring Your Own Device Policies

Norwich University notes that a staggering 96% of healthcare organizations have had lost or stolen device incidents. Aside from these statistics, Bring Your Own Device (BYOD) policies have caused even more risks for healthcare organizations. It is difficult to implement the same security measures on personal devices as it is for company-owned devices. While BYOD can be attractive to employers, saving about $900 a year per employee, 73% of organizations feel that there are greater security risks involved with this type of policy. In 2013, 25% of workers who used their own devices for work claimed to have had security issues during the past year. With breaches so common in the healthcare industry, BYOD may be a poor fit for these organizations.

5. Assessing Vulnerabilities and Creating Policies

Periodic assessments from an impartial, third-party expert is recommended for organizations to understand where their security focus should be. Additionally, these assessments allow healthcare groups to create new policies for incident response, should a breach occur. Having formal procedures can reduce the impact of a security breach, and allow everyone involved to act immediately, without uncertainty about the correct steps to take.

Best Practices are the Best Defense

Unfortunately, its not always possible to prevent a data breach. By following best practices, however, healthcare organizations can minimize the risk of a breach and be better equipped to handle a one in the future. Preventing a breach may require quite a bit of preparation, but it can save money in the long run and prevent patients sensitive data from falling into the wrong hands. 

Consultant. Speaker. Writer. Andrew Deen is always happy to share his knowledge about developing news stories in big data, IoT and business. He has been a consultant in almost every industry from retail to medical devices and everything in between. He implements lean methodology and currently writing a book about scaling up businesses. Feel free to reach out to him on Twitter

Privacy Overview

This website uses cookies so that we can provide you with the best user experience possible. Cookie information is stored in your browser and performs functions such as recognising you when you return to our website and helping our team to understand which sections of the website you find most interesting and useful.