Survey: Half of Americans Concerned That Electronic Health Records Will Negatively Impact Privacy

CDW Healthcare, part of the public sector subsidiary of CDW LLC, recently announced the results of a national survey on patient perceptions of electronic health records (EHRs) and the security of personal health information (PHI).

The report, “Elevated Heart Rates:  EHR and IT Security,” found that while patients trust their doctors to protect their information, 49 percent believe that EHRs will have a negative impact on the privacy of their PHI and health data.

As healthcare organizations transition to EHRs, they will be responsible for maintaining and protecting a significant amount of personal data electronically.  According to the survey, patients not only require that PHI be held securely, but also believe that healthcare organizations are responsible for protecting financial information (86 percent), personally identifiable information (93 percent) and any information provided about a patient’s family (94 percent).

“The new era of EHR brings with it a whole new set of requirements for healthcare organizations -- particularly in the area of IT security,” said Bob Rossi, vice president of CDW Healthcare.  “Digital files are not inherently less secure than paper files, but they do require a completely different set of technologies, processes and internal policies for protection.”

In fact, recent research from CDW Healthcare indicates that many physician practices have not yet prioritized IT security.  According to CDW Healthcare’s Physician Practice EHR Price Tag, 30 percent of physician practices report that they lack basic anti-virus software and 34 percent report that they do not use network firewalls.  Both elements are considered basic steps in developing a minimum IT security profile.

According to the U.S. Department of Health and Human Services, patients should expect significant benefits from the PHI included in EHRs, including:

  • The reduction of adverse drug events, medical errors and redundant tests and procedures when used in conjunction with e-prescribing.
  • The regular use of preventive services such as health screenings, which can help reduce health care costs.
  • Improved communication between patients and providers, giving patients better access to timely information.
  • The reduction of office waiting time by improving office efficiency.

Both the Health Insurance Portability and Accountability Act (HIPAA) of 1996 and the Health Information Technology for Economic and Clinical Health (HITECH) Act set standards for protecting PHI and create penalties for any violations.  Beyond those formal penalties, however, patients may respond to any breach of trust with a changed business relationship. 

For survey respondents who were notified of a breach of their personal data from any business or organization in the past, 33 percent changed their relationship with the offending organization, including 9 percent that severed the relationship, 12 percent that reduced spending and 12 percent that no longer trust that organization.

Ultimately, survey respondents put responsibility for the protection of their information directly on physician practices.  When asked who they hold primarily responsible for the privacy and security of their health information, 84 percent of respondents cited either a staff member at the doctors’ office by role, or the medical practice as a whole.

“For physician practices, IT security must be a primary part of any EHR,” said Rossi.  “Right now, patients trust their doctors more than anyone else to protect their personal information.  But like any relationship based upon trust, even one breach can fundamentally change the dynamic.”

CDW Healthcare conducted a survey of 1,000 respondents across the United States from January 24 to January 31.  The age and gender distribution of the survey sample match that of the overall U.S. population.  All survey respondents had been to both a doctors’ office and hospital/outpatient clinic in the previous 18 months.

A full copy of CDW Healthcare’s Elevated Heart Rates:  EHR and IT Security Report is available at http://www.cdw.com/HeartRates

 

Featured

  • Maximizing Your Security Budget This Year

    Perimeter Security Standards for Multi-Site Businesses

    When you run or own a business that has multiple locations, it is important to set clear perimeter security standards. By doing this, it allows you to assess and mitigate any potential threats or risks at each site or location efficiently and effectively. Read Now

  • New Research Shows a Continuing Increase in Ransomware Victims

    GuidePoint Security recently announced the release of GuidePoint Research and Intelligence Team’s (GRIT) Q1 2024 Ransomware Report. In addition to revealing a nearly 20% year-over-year increase in the number of ransomware victims, the GRIT Q1 2024 Ransomware Report observes major shifts in the behavioral patterns of ransomware groups following law enforcement activity – including the continued targeting of previously “off-limits” organizations and industries, such as emergency hospitals. Read Now

  • OpenAI's GPT-4 Is Capable of Autonomously Exploiting Zero-Day Vulnerabilities

    According to a new study from four computer scientists at the University of Illinois Urbana-Champaign, OpenAI’s paid chatbot, GPT-4, is capable of autonomously exploiting zero-day vulnerabilities without any human assistance. Read Now

  • Getting in Someone’s Face

    There was a time, not so long ago, when the tradeshow industry must have thought COVID-19 might wipe out face-to-face meetings. It sure seemed that way about three years ago. Read Now

    • Industry Events
    • ISC West

Featured Cybersecurity

Webinars

New Products

  • A8V MIND

    A8V MIND

    Hexagon’s Geosystems presents a portable version of its Accur8vision detection system. A rugged all-in-one solution, the A8V MIND (Mobile Intrusion Detection) is designed to provide flexible protection of critical outdoor infrastructure and objects. Hexagon’s Accur8vision is a volumetric detection system that employs LiDAR technology to safeguard entire areas. Whenever it detects movement in a specified zone, it automatically differentiates a threat from a nonthreat, and immediately notifies security staff if necessary. Person detection is carried out within a radius of 80 meters from this device. Connected remotely via a portable computer device, it enables remote surveillance and does not depend on security staff patrolling the area. 3

  • Luma x20

    Luma x20

    Snap One has announced its popular Luma x20 family of surveillance products now offers even greater security and privacy for home and business owners across the globe by giving them full control over integrators’ system access to view live and recorded video. According to Snap One Product Manager Derek Webb, the new “customer handoff” feature provides enhanced user control after initial installation, allowing the owners to have total privacy while also making it easy to reinstate integrator access when maintenance or assistance is required. This new feature is now available to all Luma x20 users globally. “The Luma x20 family of surveillance solutions provides excellent image and audio capture, and with the new customer handoff feature, it now offers absolute privacy for camera feeds and recordings,” Webb said. “With notifications and integrator access controlled through the powerful OvrC remote system management platform, it’s easy for integrators to give their clients full control of their footage and then to get temporary access from the client for any troubleshooting needs.” 3

  • EasyGate SPT and SPD

    EasyGate SPT SPD

    Security solutions do not have to be ordinary, let alone unattractive. Having renewed their best-selling speed gates, Cominfo has once again demonstrated their Art of Security philosophy in practice — and confirmed their position as an industry-leading manufacturers of premium speed gates and turnstiles. 3