By David Cruz
Correspondent
It seems to happen so frequently that we’ve all become immune to the headlines about another breach of personal medical information. Since 2009 more than 255 reported data breaches affected more than 112 million individual medical records, at huge hospitals and smaller so-called business associates from dentists to MRI providers.
“It’s definitely an epidemic,” said Art Gross, CEO at HIPAA Secure Now, a company that helps patients, doctors and other health care organizations protect patient records. “I mean when you look at the large breaches, insurance companies, over 80 million patient records breached, so yes, we definitely have an epidemic.”
HIPAA — the Health Insurance Portability and Accountability Act — calls for health care providers and others to secure your medical records. It’s a law that’s been around since 1996 to no great effect, says Gross. But the Health and Human Services Department’s Office for Civil Rights is now auditing the medical industry to see how they’re doing keeping your records safe.
“HIPAA’s been around for years, and it hasn’t been enforced,” noted Gross. “It’s been largely ignored. And the other piece is that the health care industry has ignored security. It’s one of the weakest sectors in terms of security, so you put that together and there’s no wonder why there’s so many patient records breaches.”
And that means hackers have been stealing critical information, not only about what your medical history is — which is bad enough — but your name, address, Social Security number, etc. with which they can not only get medical services and stick you with the bill, but can use all that other personal data to steal your identity to get loans and other credit.
“Since 2009, the government has incentivized health care organizations to move from paper-based records to electronic records,” added Gross.
President Obama included the incentive as part of the economic stimulus package in 2009, saying, “We will make sure that every doctor’s office and hospital in this country is using cutting-edge technology and electronic medical records so that we can cut red tape, prevent medical mistakes and help saves billions of dollars each year.”
“In fact, the government incentivized these health care organizations,” added Gross. “They gave out over $30 billion to move from paper to electronic and the result now has been the 100 million plus records that have been breached.”
The latest HIPAA enforcement effort — Phase II audits — is already underway. Providers — and there are literally millions of these — should be on the lookout for a letter like this, which asks them to identify their primary contact person, after which an expanded, but, as yet, unidentified number of them will get visits from federal investigators. Gross says the main goal is compliance, but failure to comply could also hurt.
“Well, not complying with HIPAA regulations could give you a fine of $1.5 million, per year, per occurrence, so the fines could theoretically be very large,” he said.
But not as large as the billions of dollars lost in fraud every year when someone steals your medical records and sells them on the black market, where the going rate for medical records is 50 times that for other stolen data. It’s enough to make you wish for the good old analog days.