HEALTHCARE BREACHES Andrew Kuebler MIS 534 April 15, 2015
Outline The Forecast for 2015 Why are EMR’s & PHI Being Targeted? How are Hackers Succeeding? Top 10 Healthcare Breaches 3 rd - TRICARE 2 nd – Premera BCBS 1 st – Anthem BCBS Conclusion
The Forecast “2015 is already the year of the health-care hack — and it’s only going to get worse.” -The Washington Post, March 2015 “Healthcare to be 'plagued' by data breaches in 2015.” -Healthcare IT News, December 2014 “MEDICAL DATA HAS BECOME THE NEXT CYBERSECURITY TARGET” -NextGov, March 2015
Why are EMR’s & PHI Being Targeted?
How are Hackers Succeeding? “81% had a root cause in employee negligence. The most common issue was the loss of administrative credentials – user name and password – but also included lost media, firewall left open, lost laptop etc.” -Michael Bruemmer, VP of Consumer Protection at Experian “Employees and negligence are the leading cause of security incidents but remain the least reported issue.” -Experian’s 2015 Second Annual Data Breach Industry Forecast
Top 10 Healthcare Breaches 1. Anthem Inc., 80 Million Records 2. Premera Blue Cross,11 Million Records 3. TRICARE Management Activity, 4.9 Million Records 4. Community Health Systems, 4.5 Million Records 5. Advocate Health Care, 4.03 Million Records 6. Health Net Inc., 1.9 Million Records 7. New York City Health & Hospitals Corporation's North Bronx Healthcare Network, 1.7 Million Records 8. Montana Dept. of Public Health and Human Services, 1.3 Million Records 9. AvMed Inc., 1.22 Million Records 10. The Nemours Foundation, 1.06 Million Records
TRICARE Management Activity 4.9 Million Records WHO: TRICARE, a provider of health benefits for the military, military retirees, and dependents WHEN: September 14, 2011 HOW: Loss of backup tapes RESOLUTION: Free credit monitoring through FTC, Incident Response Call Center
Premera BCBS Premera BCBS 11 Million Records WHO: Premera, a BCBS Health Insurance Company WHEN: May 5, 2014 HOW: A “sophisticated cyber attack” RESOLUTION: Two years of free credit monitoring and identity theft protection, call center Premera Update
Anthem BCBS Anthem BCBS 80 Million Records WHO: Anthem, a BCBS Health Insurance Company WHEN: December 2014 HOW: A cyber attack that involved breaking in to servers RESOLUTION: Two years of free credit monitoring and identity theft protection, call center Anthem Update
Conclusion Predictions of healthcare breaches are making headlines for 2015 EMRs & PHI contain a valuable plethora of information that hackers can use for identity theft The number one cause of breaches: HUMAN ERROR The top three breaches of all time: TRICARE, 4.9 Million Records Premera BCBS, 11 Million Records Anthem BCBS, 80 Million Records
References and-its-only-going-to-get-worse/ and-its-only-going-to-get-worse/ software-systems/d/d-id/ ? software-systems/d/d-id/ ?