06/04/2023
Medical records are the most sought after type of personal record by hackers as they can fetch up to $1,000 on dark web marketplaces. This is roughly 20 times the price of stolen credit card data and 50 times the price of an email list.
Why is the price so high for medical data? Medical records are a treasure trove of personal information as healthcare institutions collect extensive profile information on patients. Quite often this data include a patient's full name, address history, DOB, financial information, social security numbers, insurance card no's and medical conditions. This is enough information for hackers to take out a loan, set up a line of credit under patients' names or file false insurance claims.
How do hackers obtain this type of information? Hackers primarily exploit human risk factors when attacking healthcare institutions and their affiliates. These risk factors include targeted phishing emails, social engineering (phone calls & impersonation), unsecured laptops, inappropriate sharing of personal health information and other risks.
What can be done by employers to reduce the risks? Training is a key component of a strategy to mitigate risks in healthcare, particularly in the privacy space. Healthcare rules such as HIPPA's privacy rule, HITECH act and Omnibus rule place an onus on the healthcare provider to train their staff on privacy and security risks. Other rules such as state privacy laws, GDPR, UK-GDPR also make specific mention to health data and training in their statutes.
It's up to you, as the employer to ensure that this training occurs regularly for all staff.
How can DPO Solutions help? We have a range of privacy training solutions on our online store ( https://data-privacy.io/shop ) along with useful advice on our blog ( https://data-privacy.io/data-privacy-blog ) and main page ( https://data-privacy.io ).
Reach us at [email protected] for more information.