NY Hospital Security Breach Shows Vulnerabilities in Healthcare Cybersecurity

NY Hospital Security Breach Shows Vulnerabilities in Healthcare Cybersecurity

SUNY Upstate Hospital announced a former employee inappropriately accessed more than 1,200 patient records.

So far this year, 359 healthcare breaches at hospitals, health insurers and other organizations related to healthcare have been reported to the federal government. According to the Journal of the American Medical Association, nearly 176.4 million health records were breached between 2010 and 2017. 

Included in this year's breaches is SUNY Upstate University Hospital - which announced 1,216 patient records were inappropriately accessed by an employee between Nov. 3, 2017 and Oct. 23, 2017 without having a legitimate reason to do so. 

The hospital recorded the breach to the U.S. Department of Health and Human Services Office for Civil Rights, which investigates violations of the Health Insurance Portability and Accountability Act, or HIPPA, a federal law that safeguards medical information. 

Upstate could face federal fines ranging from $100 to $50,000 per violation if an investigation shows it was negligent. 

The breach included patient names, ages, diagnoses and services received. The hospital does not believe that any of the information accessed by the employee, who has not been charged with a crime, was misused in any way. Social Security numbers, insurance identification numbers, credit card information and other types of personal data often used by identity thieves were were not compromised. 

Patient data breaches have been rising as the cost of a medical record goes up on the black market. These days, a data thief could pay anywhere between $500 to $800. This information can be used to submit fraudulent insurance claims, obtain medical devices, get prescription drugs and blackmail people. 

Hospitals and healthcare organizations are not making it anymore difficult for thieves to get this information, however. Organizations are not taking the time to lay out proper procedures and put policies and controls in place to protect medical records.


About the Author

Sydny Shepard is the Executive Editor of Campus Security & Life Safety.

Featured

  • MetLife Stadium Uses Custom Surveillance Solution from Axis Communications

    Axis Communications, provider of video surveillance and network devices, today announced the implementation of a custom surveillance solution developed in collaboration with the MetLife Stadium security team. This new, tailored solution will help the venue augment its security capabilities, providing high-quality video at unprecedented distances and allowing the security team to identify details from anywhere in the venue. Read Now

  • U.S. Cyber Trust Mark Launches for Consumer Internet-Connected Devices

    The White House recently announced the launch of a cybersecurity label for internet-connected devices, known as the U.S. Cyber Trust Mark, completing public notice and input over the last 18 months. During that time, FCC Commissioners decided in a bipartisan and unanimous vote to authorize the program and adopt final rules, as well as the trademarked, distinct shield logo that will be applied to products certified for the U.S. Cyber Trust Mark label. Read Now

  • Motorola Solutions Expands its Retail Portfolio with Theatro Labs Acquisition

    Motorola Solutions has entered into a definitive agreement to acquire Theatro Labs, Inc., maker of AI and voice-powered communication and digital workflow software for frontline workers, based in Richardson, Texas. Read Now

  • FAST Announces National Security Technician Day Jan. 23

    The Foundation for Advancing Security Talent (FAST) has announced the third annual National Security Technician Day, an annual commemorative day held on Jan. 23 to honor security technicians across the country. Read Now

Featured Cybersecurity

Webinars

New Products

  • 4K Video Decoder

    3xLOGIC’s VH-DECODER-4K is perfect for use in organizations of all sizes in diverse vertical sectors such as retail, leisure and hospitality, education and commercial premises. 3

  • ResponderLink

    ResponderLink

    Shooter Detection Systems (SDS), an Alarm.com company and a global leader in gunshot detection solutions, has introduced ResponderLink, a groundbreaking new 911 notification service for gunshot events. ResponderLink completes the circle from detection to 911 notification to first responder awareness, giving law enforcement enhanced situational intelligence they urgently need to save lives. Integrating SDS’s proven gunshot detection system with Noonlight’s SendPolice platform, ResponderLink is the first solution to automatically deliver real-time gunshot detection data to 911 call centers and first responders. When shots are detected, the 911 dispatching center, also known as the Public Safety Answering Point or PSAP, is contacted based on the gunfire location, enabling faster initiation of life-saving emergency protocols. 3

  • AC Nio

    AC Nio

    Aiphone, a leading international manufacturer of intercom, access control, and emergency communication products, has introduced the AC Nio, its access control management software, an important addition to its new line of access control solutions. 3