Survey: Half of Americans Concerned That Electronic Health Records Will Negatively Impact Privacy

CDW Healthcare, part of the public sector subsidiary of CDW LLC, recently announced the results of a national survey on patient perceptions of electronic health records (EHRs) and the security of personal health information (PHI).

The report, “Elevated Heart Rates:  EHR and IT Security,” found that while patients trust their doctors to protect their information, 49 percent believe that EHRs will have a negative impact on the privacy of their PHI and health data.

As healthcare organizations transition to EHRs, they will be responsible for maintaining and protecting a significant amount of personal data electronically.  According to the survey, patients not only require that PHI be held securely, but also believe that healthcare organizations are responsible for protecting financial information (86 percent), personally identifiable information (93 percent) and any information provided about a patient’s family (94 percent).

“The new era of EHR brings with it a whole new set of requirements for healthcare organizations -- particularly in the area of IT security,” said Bob Rossi, vice president of CDW Healthcare.  “Digital files are not inherently less secure than paper files, but they do require a completely different set of technologies, processes and internal policies for protection.”

In fact, recent research from CDW Healthcare indicates that many physician practices have not yet prioritized IT security.  According to CDW Healthcare’s Physician Practice EHR Price Tag, 30 percent of physician practices report that they lack basic anti-virus software and 34 percent report that they do not use network firewalls.  Both elements are considered basic steps in developing a minimum IT security profile.

According to the U.S. Department of Health and Human Services, patients should expect significant benefits from the PHI included in EHRs, including:

  • The reduction of adverse drug events, medical errors and redundant tests and procedures when used in conjunction with e-prescribing.
  • The regular use of preventive services such as health screenings, which can help reduce health care costs.
  • Improved communication between patients and providers, giving patients better access to timely information.
  • The reduction of office waiting time by improving office efficiency.

Both the Health Insurance Portability and Accountability Act (HIPAA) of 1996 and the Health Information Technology for Economic and Clinical Health (HITECH) Act set standards for protecting PHI and create penalties for any violations.  Beyond those formal penalties, however, patients may respond to any breach of trust with a changed business relationship. 

For survey respondents who were notified of a breach of their personal data from any business or organization in the past, 33 percent changed their relationship with the offending organization, including 9 percent that severed the relationship, 12 percent that reduced spending and 12 percent that no longer trust that organization.

Ultimately, survey respondents put responsibility for the protection of their information directly on physician practices.  When asked who they hold primarily responsible for the privacy and security of their health information, 84 percent of respondents cited either a staff member at the doctors’ office by role, or the medical practice as a whole.

“For physician practices, IT security must be a primary part of any EHR,” said Rossi.  “Right now, patients trust their doctors more than anyone else to protect their personal information.  But like any relationship based upon trust, even one breach can fundamentally change the dynamic.”

CDW Healthcare conducted a survey of 1,000 respondents across the United States from January 24 to January 31.  The age and gender distribution of the survey sample match that of the overall U.S. population.  All survey respondents had been to both a doctors’ office and hospital/outpatient clinic in the previous 18 months.

A full copy of CDW Healthcare’s Elevated Heart Rates:  EHR and IT Security Report is available at http://www.cdw.com/HeartRates

 

Featured

  • Facing Facts for Facilities

    Despite the proliferation of constantly evolving security solutions, there remains a troubling trend among many facility operators who often neglect the most important security assets within their organization. Keys and shared devices like radios, laptops and tablets are crucial to successful operations, yet many operators are managing them haphazardly through outdated storage systems like pegboards and notebooks. Read Now

  • Report Reveals Security Training Reduces Global Phishing Click Rates by 86%

    KnowBe4, the cybersecurity platform that comprehensively addresses human risk management, today launched its “Phishing by Industry Benchmarking Report 2025” which measures an organization’s Phish-prone Percentage (PPP) — the percentage of employees likely to fall for social engineering or phishing attacks, indicating the organization’s overall susceptibility to phishing threats. This year’s report found a global average baseline PPP of 33.1%, meaning a third of employees interact with phishing simulations before taking part in best-practice security awareness training (SAT).COVER 2025-PIB-NA-Report_EN-US Read Now

  • TSA Begins REAL ID Full Enforcement Today

    Today, the Transportation Security Administration (TSA) announced the imminent implementation of its REAL ID enforcement measures at TSA checkpoints nationwide. Read Now

  • Body-Worn Cameras on the Rise

    On the evening of Oct. 29, 2024, the owner of 300 Guard based in Houston, was shot while on duty at a convenience store. He returned fire. He was wearing a plated vest and thankfully recovered in the hospital. Read Now

  • Brazil Port Enhances Surveillance and Supports Wildlife Conservation with Sustainable Technology

    Ferroport, which operates the iron ore terminal at the Port of Açu in São João da Barra, Rio de Janeiro, Brazil, has deployed state-of-the-art video surveillance cameras from Axis Communications to enhance nighttime security and visibility, while decreasing environmental impact and prioritizing sustainability. With cutting-edge technology, the port now has precise surveillance cameras that capture high-quality nighttime images, while reducing the amount of artificial lighting that negatively impacts the surrounding ecosystem. Read Now

New Products

  • A8V MIND

    A8V MIND

    Hexagon’s Geosystems presents a portable version of its Accur8vision detection system. A rugged all-in-one solution, the A8V MIND (Mobile Intrusion Detection) is designed to provide flexible protection of critical outdoor infrastructure and objects. Hexagon’s Accur8vision is a volumetric detection system that employs LiDAR technology to safeguard entire areas. Whenever it detects movement in a specified zone, it automatically differentiates a threat from a nonthreat, and immediately notifies security staff if necessary. Person detection is carried out within a radius of 80 meters from this device. Connected remotely via a portable computer device, it enables remote surveillance and does not depend on security staff patrolling the area.

  • FEP GameChanger

    FEP GameChanger

    Paige Datacom Solutions Introduces Important and Innovative Cabling Products GameChanger Cable, a proven and patented solution that significantly exceeds the reach of traditional category cable will now have a FEP/FEP construction.

  • AC Nio

    AC Nio

    Aiphone, a leading international manufacturer of intercom, access control, and emergency communication products, has introduced the AC Nio, its access control management software, an important addition to its new line of access control solutions.