{"id":4011,"date":"2015-03-18T09:27:40","date_gmt":"2015-03-18T13:27:40","guid":{"rendered":"http:\/\/www.khpi.org\/blog\/?p=4011"},"modified":"2015-03-18T09:47:30","modified_gmt":"2015-03-18T13:47:30","slug":"another-major-data-breach-for-a-health-insurer","status":"publish","type":"post","link":"http:\/\/www.khpi.org\/blog\/another-major-data-breach-for-a-health-insurer\/","title":{"rendered":"Another Major Data Breach for a Health Insurer."},"content":{"rendered":"<p>Hackers breached whatever firewalls and security measures were present at Premera Blue Cross based in Washington state.\u00a0\u00a0 The personal, financial, and now even medical information of some <a href=\"http:\/\/www.modernhealthcare.com\/article\/20150317\/NEWS\/150319904?utm_source=modernhealthcare&amp;utm_medium=email&amp;utm_content=externalURL&amp;utm_campaign=am\" target=\"_blank\">11 million past- and present customers were accessed.<\/a> The breach may have occurred last May, was detected on January 29, but not disclosed to either the public or regulators until a few days ago.\u00a0 Nice job on the accountability front.<\/p>\n<p>I<a title=\"Breach of Personal Healthcare Information at Anthem.\" href=\"http:\/\/www.khpi.org\/blog\/breach-of-personal-healthcare-information-at-anthem\/\" target=\"_blank\"> recently wrote abou<\/a>t an even larger breach of security at Anthem where the personal information of almost 80 million people was penetrated.\u00a0 It was not thought that medical information was compromised then, but how can one know for sure?\u00a0\u00a0\u00a0 I predicted we would be seeing more attacks on medical record and insurance databases but it is disappointing to see them coming on so rapidly.\u00a0 There are at least two driving forces or enablers.\u00a0 The first follows from Willie Sutton\u2019s law explaining his reason for robbing banks\u2014because that is where the money is.\u00a0 Some 18% of our gross national product fuels the healthcare industry\u2014 that is where the real money is.\u00a0 Medical fraud is part of that big business.<!--more--><\/p>\n<p>The industry enabler is that accessing medical information seems to be so easy.\u00a0 If banks, other financial organizations, or for that matter governments cannot keep their digital records secure, why should we assume for a moment that our medical information will be any less vulnerable to prying eyes?\u00a0 Much has been promised about the value of having our computerized medical records available to us and everyone who takes care of us. We are told that \u201cbig data,\u201d the analysis of massive data sets, will revolutionize medicine and save us a fortune.\u00a0 More and more information is being collected with the goal of providing safe and effective medical care of high value and to reduce fraud. The assembly\u00a0and analysis of medical data is now a big business of its own.\u00a0 Everybody and their uncle wants access to the data\u2013 me included.\u00a0 There are any number of business \u201cpartners\u201d willing to comb through an institution\u2019s medical data for research, marketing, or business purposes. But to accomplish the above means making it transportable or available and there\u2019s the rub!<\/p>\n<p>Take computerized medical records.\u00a0 I never had to use them as a doctor, and there are many providers that love them, but we are getting more and more pushback from patients and providers alike as the downsides of switching to the digital medical encounter emerge. To make their use practical, providers can access medical records from home or their cell phones.\u00a0 If they can do it, so too can your geeky 14 year-old nephew let-alone a well financed medical voyeur. A major complaint about existing electronic medical record systems is that they do not talk very well to each other or to the insurers and regulators demanding information. \u00a0Attempts to expand accessibility for some runs the risk of further security comprise for all.<\/p>\n<p>To boast about my sagacity, I predict here and now, that we will have another multimillion-record breach of digital medical information security within 6 months.\u00a0 To demonstrate my confidence in this likelihood, I will accept the wager of a Martini in your favorite Louisville bar or mine.\u00a0 Alas, even if I win, we all lose!<\/p>\n<p>Peter Hasselbacher, MD<br \/>\nPresident, KHPI<br \/>\nMarch 18, 2015<\/p>\n<div class=\"sharedaddy sd-sharing-enabled\"><div class=\"robots-nocontent sd-block sd-social sd-social-icon-text sd-sharing\"><h3 class=\"sd-title\">Share this:<\/h3><div class=\"sd-content\"><ul><li><a href=\"#\" class=\"sharing-anchor sd-button share-more\"><span>Share<\/span><\/a><\/li><li class=\"share-end\"><\/li><\/ul><div class=\"sharing-hidden\"><div class=\"inner\" style=\"display: none;\"><ul><li class=\"share-facebook\"><a rel=\"nofollow noopener noreferrer\" data-shared=\"sharing-facebook-4011\" class=\"share-facebook sd-button share-icon\" href=\"http:\/\/www.khpi.org\/blog\/another-major-data-breach-for-a-health-insurer\/?share=facebook\" target=\"_blank\" title=\"Click to share on Facebook\" ><span>Facebook<\/span><\/a><\/li><li class=\"share-linkedin\"><a rel=\"nofollow noopener noreferrer\" data-shared=\"sharing-linkedin-4011\" class=\"share-linkedin sd-button share-icon\" href=\"http:\/\/www.khpi.org\/blog\/another-major-data-breach-for-a-health-insurer\/?share=linkedin\" target=\"_blank\" title=\"Click to share on LinkedIn\" ><span>LinkedIn<\/span><\/a><\/li><li class=\"share-end\"><\/li><li class=\"share-twitter\"><a rel=\"nofollow noopener noreferrer\" data-shared=\"sharing-twitter-4011\" class=\"share-twitter sd-button share-icon\" href=\"http:\/\/www.khpi.org\/blog\/another-major-data-breach-for-a-health-insurer\/?share=twitter\" target=\"_blank\" title=\"Click to share on Twitter\" ><span>Twitter<\/span><\/a><\/li><li class=\"share-email\"><a rel=\"nofollow noopener noreferrer\" data-shared=\"\" class=\"share-email sd-button share-icon\" href=\"mailto:?subject=%5BShared%20Post%5D%20Another%20Major%20Data%20Breach%20for%20a%20Health%20Insurer.&body=http%3A%2F%2Fwww.khpi.org%2Fblog%2Fanother-major-data-breach-for-a-health-insurer%2F&share=email\" target=\"_blank\" title=\"Click to email a link to a friend\" data-email-share-error-title=\"Do you have email set up?\" data-email-share-error-text=\"If you&#039;re having problems sharing via email, you might not have email set up for your browser. You may need to create a new email yourself.\" data-email-share-nonce=\"94767e25f5\" data-email-share-track-url=\"http:\/\/www.khpi.org\/blog\/another-major-data-breach-for-a-health-insurer\/?share=email\"><span>Email<\/span><\/a><\/li><li class=\"share-end\"><\/li><li class=\"share-end\"><\/li><\/ul><\/div><\/div><\/div><\/div><\/div>","protected":false},"excerpt":{"rendered":"<p>Hackers breached whatever firewalls and security measures were present at Premera Blue Cross based in Washington state.\u00a0\u00a0 The personal, financial, and now even medical information of some 11 million past- and present customers were accessed. The breach may have occurred last May, was detected on January 29, but not disclosed to either the public or &hellip; <a href=\"http:\/\/www.khpi.org\/blog\/another-major-data-breach-for-a-health-insurer\/\" class=\"more-link\">Continue reading<span class=\"screen-reader-text\"> &#8220;Another Major Data Breach for a Health Insurer.&#8221;<\/span><\/a><\/p>\n<div class=\"sharedaddy sd-sharing-enabled\"><div class=\"robots-nocontent sd-block sd-social sd-social-icon-text sd-sharing\"><h3 class=\"sd-title\">Share this:<\/h3><div class=\"sd-content\"><ul><li><a href=\"#\" class=\"sharing-anchor sd-button share-more\"><span>Share<\/span><\/a><\/li><li class=\"share-end\"><\/li><\/ul><div class=\"sharing-hidden\"><div class=\"inner\" style=\"display: none;\"><ul><li class=\"share-facebook\"><a rel=\"nofollow noopener noreferrer\" data-shared=\"sharing-facebook-4011\" class=\"share-facebook sd-button share-icon\" href=\"http:\/\/www.khpi.org\/blog\/another-major-data-breach-for-a-health-insurer\/?share=facebook\" target=\"_blank\" title=\"Click to share on Facebook\" ><span>Facebook<\/span><\/a><\/li><li class=\"share-linkedin\"><a rel=\"nofollow noopener noreferrer\" data-shared=\"sharing-linkedin-4011\" class=\"share-linkedin sd-button share-icon\" href=\"http:\/\/www.khpi.org\/blog\/another-major-data-breach-for-a-health-insurer\/?share=linkedin\" target=\"_blank\" title=\"Click to share on LinkedIn\" ><span>LinkedIn<\/span><\/a><\/li><li class=\"share-end\"><\/li><li class=\"share-twitter\"><a rel=\"nofollow noopener noreferrer\" data-shared=\"sharing-twitter-4011\" class=\"share-twitter sd-button share-icon\" href=\"http:\/\/www.khpi.org\/blog\/another-major-data-breach-for-a-health-insurer\/?share=twitter\" target=\"_blank\" title=\"Click to share on Twitter\" ><span>Twitter<\/span><\/a><\/li><li class=\"share-email\"><a rel=\"nofollow noopener noreferrer\" data-shared=\"\" class=\"share-email sd-button share-icon\" href=\"mailto:?subject=%5BShared%20Post%5D%20Another%20Major%20Data%20Breach%20for%20a%20Health%20Insurer.&body=http%3A%2F%2Fwww.khpi.org%2Fblog%2Fanother-major-data-breach-for-a-health-insurer%2F&share=email\" target=\"_blank\" title=\"Click to email a link to a friend\" data-email-share-error-title=\"Do you have email set up?\" data-email-share-error-text=\"If you&#039;re having problems sharing via email, you might not have email set up for your browser. You may need to create a new email yourself.\" data-email-share-nonce=\"94767e25f5\" data-email-share-track-url=\"http:\/\/www.khpi.org\/blog\/another-major-data-breach-for-a-health-insurer\/?share=email\"><span>Email<\/span><\/a><\/li><li class=\"share-end\"><\/li><li class=\"share-end\"><\/li><\/ul><\/div><\/div><\/div><\/div><\/div>","protected":false},"author":21,"featured_media":0,"comment_status":"open","ping_status":"open","sticky":false,"template":"","format":"standard","meta":{"spay_email":"","jetpack_publicize_message":"","jetpack_is_tweetstorm":false,"jetpack_publicize_feature_enabled":true},"categories":[3],"tags":[],"jetpack_publicize_connections":[],"jetpack_featured_media_url":"","jetpack_sharing_enabled":true,"jetpack_shortlink":"https:\/\/wp.me\/p5mRQe-12H","_links":{"self":[{"href":"http:\/\/www.khpi.org\/blog\/wp-json\/wp\/v2\/posts\/4011"}],"collection":[{"href":"http:\/\/www.khpi.org\/blog\/wp-json\/wp\/v2\/posts"}],"about":[{"href":"http:\/\/www.khpi.org\/blog\/wp-json\/wp\/v2\/types\/post"}],"author":[{"embeddable":true,"href":"http:\/\/www.khpi.org\/blog\/wp-json\/wp\/v2\/users\/21"}],"replies":[{"embeddable":true,"href":"http:\/\/www.khpi.org\/blog\/wp-json\/wp\/v2\/comments?post=4011"}],"version-history":[{"count":2,"href":"http:\/\/www.khpi.org\/blog\/wp-json\/wp\/v2\/posts\/4011\/revisions"}],"predecessor-version":[{"id":4013,"href":"http:\/\/www.khpi.org\/blog\/wp-json\/wp\/v2\/posts\/4011\/revisions\/4013"}],"wp:attachment":[{"href":"http:\/\/www.khpi.org\/blog\/wp-json\/wp\/v2\/media?parent=4011"}],"wp:term":[{"taxonomy":"category","embeddable":true,"href":"http:\/\/www.khpi.org\/blog\/wp-json\/wp\/v2\/categories?post=4011"},{"taxonomy":"post_tag","embeddable":true,"href":"http:\/\/www.khpi.org\/blog\/wp-json\/wp\/v2\/tags?post=4011"}],"curies":[{"name":"wp","href":"https:\/\/api.w.org\/{rel}","templated":true}]}}