We use cookies to give you the best online experience. By using our website you agree to our use of cookies in accordance with our cookie policy. Learn more here.Close Me
Navigant recently published the latest update of
its comprehensive Information Security and Data Breach Report,
which adds yet another analytic view of the data breach picture.
And the view is not a pretty one. You can get a copy of the report
here.
Some of the "highlights":
Healthcare entities again accounted for the largest percentage
of the data reaches identified in either quarter (Q3: 39% vs. Q4:
40%), but it is unclear if that spike is a result of enhanced
reporting or whether this is an indicator of more actual
breaches.
There was an 88.5% increase in the number of records breached
from quarter to quarter (Q3: 1.02 million records vs. Q4: 1.93
million records)
Healthcare entities showed the largest increase in the number
of days between discovery and disclosure of a data breach, from 51
days to 94 days (and that is in spite of the legal requirement that
breaches be disclosed in 60 days) . The report also reveals that
the number of physician offices experiencing a breach in Q3 was 4%,
while in Q4, that number increased dramatically to 38%.
50% of hacking incidents targeted corporate entities in Q3,
while 67% targeted corporate entities in Q4.
The average number of records breached per incident increased
71% from quarter to quarter. In Q3, the average number of records
per incident was 18,253, but that number skyrocketed in Q4 to
31,069.
The content of this article is intended to provide a general
guide to the subject matter. Specialist advice should be sought
about your specific circumstances.
To print this article, all you need is to be registered on Mondaq.com.
Click to Login as an existing user or Register so you can print this article.
The 2010 theft of an unencrypted laptop containing confidential health care information made front-page news in 2013, not because a huge number of patients were affected, but for the exact opposite reason.
Identity theft is a serious threat. In 2012, more than 12.6 million adults became victims of identity theft in the U.S.1 And the costs have been astronomical.
On April 22 Verizon released its 2013 Data Breach Investigations Report (DBIR), which has since 2008 become a leading annual survey of data breaches, with participants across the globe.
Increasingly, privacy is a big concern in app development. California and other jurisdictions are ramping up enforcement efforts around existing privacy laws.
Understanding the complexities of the Health Insurance Portability and Accountability Act of 1996 (HIPAA) Privacy and Security Rules is often a challenge for health care providers and consumers.
Any company that collects personal data from consumers should take proactive steps to have appropriate legal counsel review its data security practices, as well as its terms of service or privacy practices, to identify any potential problem areas.
The U.S. Department of Health and Human Services (HHS) Office for Civil Rights (OCR) published on its website a series of factsheets designed to educate consumers unfamiliar with their rights under the Health Insurance Portability and Accountability Act’s (HIPAA) Privacy and Security Rules.