| Literature DB >> 31984315 |
Jay G Ronquillo1, J Erik Winterholler1, Kamil Cwikla1, Raphael Szymanski1, Christopher Levy1.
Abstract
OBJECTIVE: The rapid adoption of health information technology (IT) coupled with growing reports of ransomware, and hacking has made cybersecurity a priority in health care. This study leverages federal data in order to better understand current cybersecurity threats in the context of health IT.Entities:
Keywords: clinical informatics; cybersecurity; electronic health records; hacking; ransomware
Year: 2018 PMID: 31984315 PMCID: PMC6951874 DOI: 10.1093/jamiaopen/ooy019
Source DB: PubMed Journal: JAMIA Open ISSN: 2574-2531
Characteristics of reported data breaches of protected health information by covered entity, 2013–2017
| Characteristic | 2013 | 2014 | 2015 | 2016 | 2017 |
|---|---|---|---|---|---|
| Reported data breaches, | |||||
| Health plan | 17 (6.1) | 38 (12.1) | 62 (23.0) | 51 (15.6) | 47 (14.5) |
| Health care provider | 184 (66.2) | 180 (57.3) | 194 (72.1) | 256 (78.3) | 259 (79.9) |
| Other | 77 (27.7) | 96 (30.6) | 13 (4.8) | 20 (6.1) | 18 (5.6) |
| Patient records affected, | |||||
| Health plan | 88549 (1.3) | 2135600 (16.8) | 102919905 (90.9) | 880455 (5.3) | 330728 (6.8) |
| Health care provider | 5773597 (83.2) | 2051214 (16.2) | 6392806 (5.6) | 12213969 (73.3) | 4328916 (88.9) |
| Other | 1078487 (15.5) | 8496026 (67.0) | 3954463 (3.5) | 3560666 (21.4) | 209876 (4.3) |
P < .001.
Figure 1.Number of breaches (A) and records breached (B) per million residents by state and quartile, 2013–2017.
Figure 2.Number of breaches (A) and records breached (B) per thousand physicians by state and quartile, 2013–2017.
Breakdown of hacking and EMR-related breaches
| Breaches, | Records affected, | |
|---|---|---|
| Hacking-related breaches by media type | ||
| Portable electronic device or laptop | 1 (0.3) | 1911 (0.0) |
| Desktop, email, or EMR | 106 (29.2) | 1984418 (1.5) |
| Network server | 192 (52.9) | 119590428 (91.5) |
| Multiple types | 48 (13.2) | 8822024 (6.7) |
| Other/unknown | 16 (4.4) | 303597 (0.2) |
| EMR-related breaches by breach category | ||
| Theft | 21 (16.4) | 146496 (3.0) |
| Unauthorized access or disclosure | 66 (51.6) | 377088 (7.7) |
| Hacking or IT incident | 34 (26.6) | 4240218 (87.1) |
| Multiple categories | 5 (3.9) | 102614 (2.1) |
| Other/unknown | 2 (1.6) | 1504 (0.0) |
Abbreviations: EMR: electronic medical record; IT: information technology.