SlideShare a Scribd company logo
1 of 30
CTEK SUMMIT
2020
CTEK SUMMIT
2020
2
Privacy Threats in Healthcare
It Could Happen to You
CTEK SUMMIT
2020
3
Nick Culbertson
CEO & Co-Founder
CTEK SUMMIT
2020
Agenda
4
• Health data security threat landscape & emerging trends in
2019
• Practical steps your team can use now to protect patient
privacy
• How to leverage Healthcare Compliance Analytics
CTEK SUMMIT
2020
5
41 million patient
records affected in
2019
CTEK SUMMIT
2020
6
CTEK SUMMIT
2020
2019 Findings
7
CTEK SUMMIT
2020
8
Number of Health Records Breached
CTEK SUMMIT
2020
9
Total Disclosed Incidents
CTEK SUMMIT
2020
10
State Frequency
CTEK SUMMIT
2020
11
Single Largest Breach:
Affected 20,949,600
patient records, with
11,900,000 affected
records from just one
client.
CTEK SUMMIT
2020
12
2019 Type of Incidents
CTEK SUMMIT
2020
13
Total Hacking Incidents
CTEK SUMMIT
2020
14
2019 Total Hacking Incidents
CTEK SUMMIT
2020
1
5
Insider incidents continue to decrease,
showing promise with adoption of
healthcare compliance analytics.
CTEK SUMMIT
2020
16
Total Insider-Related Incidents
CTEK SUMMIT
2020
17
Patient Records Breached by Insiders
CTEK SUMMIT
2020
18
4+ years
CTEK SUMMIT
2020
19
Average Number of Days to Discovery
CTEK SUMMIT
2020
20
Why is privacy monitoring so important?
CTEK SUMMIT
2020
21
Most breaches go unnoticed
CTEK SUMMIT
2020
22
Building an Effective Privacy Monitoring Program
Effective privacy
monitoring is geared
towards educating
workforce and preventing
violations.
CTEK SUMMIT
2020
23
Centralize All Audit Log Data
Bring disparate audit log
data from across the
enterprise together under
a ‘single pane of glass.’
CTEK SUMMIT
2020
24
Increase Efficiency and Resolve Cases Faster
Leverage the data at your
fingertips to speed up
investigations and close
more cases in less time.
CTEK SUMMIT
2020
25
Protect VIPs Patients
Automatically review
publicly available news
and social media to
predict threats and catch
them as they happen.
CTEK SUMMIT
2020
26
Healthcare Compliance Analytics
let’s you see the entire picture.
CTEK SUMMIT
2020
Agenda
27
• Health data security threat landscape
• Practical steps to protect patient privacy
• How to leverage Healthcare Compliance Analytics
Key Takeaways
CTEK SUMMIT
2020
2
8
https://www.protenus.com/brea
ch-barometer
OR
Google “Breach Barometer”
28
CTEK SUMMIT
2020
29
Questions?
CTEK SUMMIT
2020
THANK YOU
• Nick@Protenus.com
• www.Protenus.com
30

More Related Content

Similar to Privacy Threats in Healthcare - It Could Happen to You

Emerging Markets Digital Health Outlook 2023.pdf
Emerging Markets Digital Health Outlook 2023.pdfEmerging Markets Digital Health Outlook 2023.pdf
Emerging Markets Digital Health Outlook 2023.pdfScallionRice
 
MPG Life Sciences Software Market Snapshot October 2020
MPG Life Sciences Software Market Snapshot October 2020MPG Life Sciences Software Market Snapshot October 2020
MPG Life Sciences Software Market Snapshot October 2020Madison Park Group
 
Cyber risk reporting aicpa framework
Cyber risk reporting aicpa frameworkCyber risk reporting aicpa framework
Cyber risk reporting aicpa frameworkJames Deiotte
 
mHealth israel_Medical Coding Bootcamp_Melanie Endicott
mHealth israel_Medical Coding Bootcamp_Melanie EndicottmHealth israel_Medical Coding Bootcamp_Melanie Endicott
mHealth israel_Medical Coding Bootcamp_Melanie EndicottLevi Shapiro
 
Cyber Security: Threat and Prevention
Cyber Security: Threat and PreventionCyber Security: Threat and Prevention
Cyber Security: Threat and Preventionfmi_igf
 
Tech scouting in Banking & Insurance Project.pptx
Tech scouting in Banking & Insurance Project.pptxTech scouting in Banking & Insurance Project.pptx
Tech scouting in Banking & Insurance Project.pptxGiorgia Zunino
 
Canada Digital Health Market Analysis Sample Report
Canada Digital Health Market Analysis Sample ReportCanada Digital Health Market Analysis Sample Report
Canada Digital Health Market Analysis Sample ReportInsights10
 
The state of cyber resilience in the UK
The state of cyber resilience in the UKThe state of cyber resilience in the UK
The state of cyber resilience in the UKIpsos UK
 
Aon - Cyber Insurance in the World of Cyber Criminals
Aon - Cyber Insurance in the World of Cyber CriminalsAon - Cyber Insurance in the World of Cyber Criminals
Aon - Cyber Insurance in the World of Cyber CriminalsCSNP
 
Wardell, Future of Digital Health, Leerink Research 2014-10
Wardell, Future of Digital Health, Leerink Research 2014-10Wardell, Future of Digital Health, Leerink Research 2014-10
Wardell, Future of Digital Health, Leerink Research 2014-10Steven Wardell
 
2020.01.12 OECD STI Outlook launch - Impacts of COVID-19: How STI systems res...
2020.01.12 OECD STI Outlook launch - Impacts of COVID-19: How STI systems res...2020.01.12 OECD STI Outlook launch - Impacts of COVID-19: How STI systems res...
2020.01.12 OECD STI Outlook launch - Impacts of COVID-19: How STI systems res...innovationoecd
 
Canada Digital Health Market Analysis
Canada Digital Health Market AnalysisCanada Digital Health Market Analysis
Canada Digital Health Market AnalysisInsights10
 
CTEK-Investor-Presentation-May-2021-1.pptx
CTEK-Investor-Presentation-May-2021-1.pptxCTEK-Investor-Presentation-May-2021-1.pptx
CTEK-Investor-Presentation-May-2021-1.pptxZharfanHanif
 
Canada Telemedicine Market Analysis Sample Report
Canada Telemedicine Market Analysis Sample ReportCanada Telemedicine Market Analysis Sample Report
Canada Telemedicine Market Analysis Sample ReportInsights10
 
Final Thoughts: Yours, Mine, & Ours
Final Thoughts: Yours, Mine, & OursFinal Thoughts: Yours, Mine, & Ours
Final Thoughts: Yours, Mine, & OursSophiaPalmira
 
COVID-19 Data and Analytics: Survey Reveals Long- and Short-Term Healthcare I...
COVID-19 Data and Analytics: Survey Reveals Long- and Short-Term Healthcare I...COVID-19 Data and Analytics: Survey Reveals Long- and Short-Term Healthcare I...
COVID-19 Data and Analytics: Survey Reveals Long- and Short-Term Healthcare I...Health Catalyst
 
Big Data London Meetup on Customer Experience
Big Data London Meetup on Customer ExperienceBig Data London Meetup on Customer Experience
Big Data London Meetup on Customer ExperienceChristos Hadjinikolis
 
Exploring The 2020 Digital Health Sector
Exploring The 2020 Digital Health SectorExploring The 2020 Digital Health Sector
Exploring The 2020 Digital Health SectorWhite Star Capital
 
Webinar: Digital Health Strategy: Leveraging Emerging Technologies in Healthcare
Webinar: Digital Health Strategy: Leveraging Emerging Technologies in HealthcareWebinar: Digital Health Strategy: Leveraging Emerging Technologies in Healthcare
Webinar: Digital Health Strategy: Leveraging Emerging Technologies in HealthcareIntellectsoft
 
Moving Forward: Setting The Direction - A Findings Review of CTEK’s 2020 Annu...
Moving Forward: Setting The Direction - A Findings Review of CTEK’s 2020 Annu...Moving Forward: Setting The Direction - A Findings Review of CTEK’s 2020 Annu...
Moving Forward: Setting The Direction - A Findings Review of CTEK’s 2020 Annu...SophiaPalmira
 

Similar to Privacy Threats in Healthcare - It Could Happen to You (20)

Emerging Markets Digital Health Outlook 2023.pdf
Emerging Markets Digital Health Outlook 2023.pdfEmerging Markets Digital Health Outlook 2023.pdf
Emerging Markets Digital Health Outlook 2023.pdf
 
MPG Life Sciences Software Market Snapshot October 2020
MPG Life Sciences Software Market Snapshot October 2020MPG Life Sciences Software Market Snapshot October 2020
MPG Life Sciences Software Market Snapshot October 2020
 
Cyber risk reporting aicpa framework
Cyber risk reporting aicpa frameworkCyber risk reporting aicpa framework
Cyber risk reporting aicpa framework
 
mHealth israel_Medical Coding Bootcamp_Melanie Endicott
mHealth israel_Medical Coding Bootcamp_Melanie EndicottmHealth israel_Medical Coding Bootcamp_Melanie Endicott
mHealth israel_Medical Coding Bootcamp_Melanie Endicott
 
Cyber Security: Threat and Prevention
Cyber Security: Threat and PreventionCyber Security: Threat and Prevention
Cyber Security: Threat and Prevention
 
Tech scouting in Banking & Insurance Project.pptx
Tech scouting in Banking & Insurance Project.pptxTech scouting in Banking & Insurance Project.pptx
Tech scouting in Banking & Insurance Project.pptx
 
Canada Digital Health Market Analysis Sample Report
Canada Digital Health Market Analysis Sample ReportCanada Digital Health Market Analysis Sample Report
Canada Digital Health Market Analysis Sample Report
 
The state of cyber resilience in the UK
The state of cyber resilience in the UKThe state of cyber resilience in the UK
The state of cyber resilience in the UK
 
Aon - Cyber Insurance in the World of Cyber Criminals
Aon - Cyber Insurance in the World of Cyber CriminalsAon - Cyber Insurance in the World of Cyber Criminals
Aon - Cyber Insurance in the World of Cyber Criminals
 
Wardell, Future of Digital Health, Leerink Research 2014-10
Wardell, Future of Digital Health, Leerink Research 2014-10Wardell, Future of Digital Health, Leerink Research 2014-10
Wardell, Future of Digital Health, Leerink Research 2014-10
 
2020.01.12 OECD STI Outlook launch - Impacts of COVID-19: How STI systems res...
2020.01.12 OECD STI Outlook launch - Impacts of COVID-19: How STI systems res...2020.01.12 OECD STI Outlook launch - Impacts of COVID-19: How STI systems res...
2020.01.12 OECD STI Outlook launch - Impacts of COVID-19: How STI systems res...
 
Canada Digital Health Market Analysis
Canada Digital Health Market AnalysisCanada Digital Health Market Analysis
Canada Digital Health Market Analysis
 
CTEK-Investor-Presentation-May-2021-1.pptx
CTEK-Investor-Presentation-May-2021-1.pptxCTEK-Investor-Presentation-May-2021-1.pptx
CTEK-Investor-Presentation-May-2021-1.pptx
 
Canada Telemedicine Market Analysis Sample Report
Canada Telemedicine Market Analysis Sample ReportCanada Telemedicine Market Analysis Sample Report
Canada Telemedicine Market Analysis Sample Report
 
Final Thoughts: Yours, Mine, & Ours
Final Thoughts: Yours, Mine, & OursFinal Thoughts: Yours, Mine, & Ours
Final Thoughts: Yours, Mine, & Ours
 
COVID-19 Data and Analytics: Survey Reveals Long- and Short-Term Healthcare I...
COVID-19 Data and Analytics: Survey Reveals Long- and Short-Term Healthcare I...COVID-19 Data and Analytics: Survey Reveals Long- and Short-Term Healthcare I...
COVID-19 Data and Analytics: Survey Reveals Long- and Short-Term Healthcare I...
 
Big Data London Meetup on Customer Experience
Big Data London Meetup on Customer ExperienceBig Data London Meetup on Customer Experience
Big Data London Meetup on Customer Experience
 
Exploring The 2020 Digital Health Sector
Exploring The 2020 Digital Health SectorExploring The 2020 Digital Health Sector
Exploring The 2020 Digital Health Sector
 
Webinar: Digital Health Strategy: Leveraging Emerging Technologies in Healthcare
Webinar: Digital Health Strategy: Leveraging Emerging Technologies in HealthcareWebinar: Digital Health Strategy: Leveraging Emerging Technologies in Healthcare
Webinar: Digital Health Strategy: Leveraging Emerging Technologies in Healthcare
 
Moving Forward: Setting The Direction - A Findings Review of CTEK’s 2020 Annu...
Moving Forward: Setting The Direction - A Findings Review of CTEK’s 2020 Annu...Moving Forward: Setting The Direction - A Findings Review of CTEK’s 2020 Annu...
Moving Forward: Setting The Direction - A Findings Review of CTEK’s 2020 Annu...
 

More from SophiaPalmira

Network Connected Medical Devices - A Case Study
Network Connected Medical Devices - A Case StudyNetwork Connected Medical Devices - A Case Study
Network Connected Medical Devices - A Case StudySophiaPalmira
 
What Has Changed Since COVID-19?
What Has Changed Since COVID-19?What Has Changed Since COVID-19?
What Has Changed Since COVID-19?SophiaPalmira
 
The Next Normal: CTEK's New Services to Support Adapting in 2020 & Beyond
The Next Normal: CTEK's New Services to Support Adapting in 2020 & BeyondThe Next Normal: CTEK's New Services to Support Adapting in 2020 & Beyond
The Next Normal: CTEK's New Services to Support Adapting in 2020 & BeyondSophiaPalmira
 
Say What!? Yes, Security & Privacy Can Work Together
Say What!? Yes, Security & Privacy Can Work TogetherSay What!? Yes, Security & Privacy Can Work Together
Say What!? Yes, Security & Privacy Can Work TogetherSophiaPalmira
 
Opening Keynote: How a Pandemic Can Inform Our Response to a Major Cyber Secu...
Opening Keynote: How a Pandemic Can Inform Our Response to a Major Cyber Secu...Opening Keynote: How a Pandemic Can Inform Our Response to a Major Cyber Secu...
Opening Keynote: How a Pandemic Can Inform Our Response to a Major Cyber Secu...SophiaPalmira
 

More from SophiaPalmira (6)

Network Connected Medical Devices - A Case Study
Network Connected Medical Devices - A Case StudyNetwork Connected Medical Devices - A Case Study
Network Connected Medical Devices - A Case Study
 
What Has Changed Since COVID-19?
What Has Changed Since COVID-19?What Has Changed Since COVID-19?
What Has Changed Since COVID-19?
 
The Next Normal: CTEK's New Services to Support Adapting in 2020 & Beyond
The Next Normal: CTEK's New Services to Support Adapting in 2020 & BeyondThe Next Normal: CTEK's New Services to Support Adapting in 2020 & Beyond
The Next Normal: CTEK's New Services to Support Adapting in 2020 & Beyond
 
Ted's Talk
Ted's TalkTed's Talk
Ted's Talk
 
Say What!? Yes, Security & Privacy Can Work Together
Say What!? Yes, Security & Privacy Can Work TogetherSay What!? Yes, Security & Privacy Can Work Together
Say What!? Yes, Security & Privacy Can Work Together
 
Opening Keynote: How a Pandemic Can Inform Our Response to a Major Cyber Secu...
Opening Keynote: How a Pandemic Can Inform Our Response to a Major Cyber Secu...Opening Keynote: How a Pandemic Can Inform Our Response to a Major Cyber Secu...
Opening Keynote: How a Pandemic Can Inform Our Response to a Major Cyber Secu...
 

Recently uploaded

MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRLMONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRLSeo
 
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...Sheetaleventcompany
 
Katrina Personal Brand Project and portfolio 1
Katrina Personal Brand Project and portfolio 1Katrina Personal Brand Project and portfolio 1
Katrina Personal Brand Project and portfolio 1kcpayne
 
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service AvailableDipal Arora
 
0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdf0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdfRenandantas16
 
Cracking the Cultural Competence Code.pptx
Cracking the Cultural Competence Code.pptxCracking the Cultural Competence Code.pptx
Cracking the Cultural Competence Code.pptxWorkforce Group
 
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...amitlee9823
 
Call Girls In Noida 959961⊹3876 Independent Escort Service Noida
Call Girls In Noida 959961⊹3876 Independent Escort Service NoidaCall Girls In Noida 959961⊹3876 Independent Escort Service Noida
Call Girls In Noida 959961⊹3876 Independent Escort Service Noidadlhescort
 
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876dlhescort
 
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...lizamodels9
 
John Halpern sued for sexual assault.pdf
John Halpern sued for sexual assault.pdfJohn Halpern sued for sexual assault.pdf
John Halpern sued for sexual assault.pdfAmzadHosen3
 
Falcon's Invoice Discounting: Your Path to Prosperity
Falcon's Invoice Discounting: Your Path to ProsperityFalcon's Invoice Discounting: Your Path to Prosperity
Falcon's Invoice Discounting: Your Path to Prosperityhemanthkumar470700
 
Dr. Admir Softic_ presentation_Green Club_ENG.pdf
Dr. Admir Softic_ presentation_Green Club_ENG.pdfDr. Admir Softic_ presentation_Green Club_ENG.pdf
Dr. Admir Softic_ presentation_Green Club_ENG.pdfAdmir Softic
 
Value Proposition canvas- Customer needs and pains
Value Proposition canvas- Customer needs and painsValue Proposition canvas- Customer needs and pains
Value Proposition canvas- Customer needs and painsP&CO
 
Famous Olympic Siblings from the 21st Century
Famous Olympic Siblings from the 21st CenturyFamous Olympic Siblings from the 21st Century
Famous Olympic Siblings from the 21st Centuryrwgiffor
 
How to Get Started in Social Media for Art League City
How to Get Started in Social Media for Art League CityHow to Get Started in Social Media for Art League City
How to Get Started in Social Media for Art League CityEric T. Tung
 
Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...Roland Driesen
 
Uneak White's Personal Brand Exploration Presentation
Uneak White's Personal Brand Exploration PresentationUneak White's Personal Brand Exploration Presentation
Uneak White's Personal Brand Exploration Presentationuneakwhite
 
Insurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageInsurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageMatteo Carbone
 

Recently uploaded (20)

MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRLMONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
MONA 98765-12871 CALL GIRLS IN LUDHIANA LUDHIANA CALL GIRL
 
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
Chandigarh Escorts Service 📞8868886958📞 Just📲 Call Nihal Chandigarh Call Girl...
 
Forklift Operations: Safety through Cartoons
Forklift Operations: Safety through CartoonsForklift Operations: Safety through Cartoons
Forklift Operations: Safety through Cartoons
 
Katrina Personal Brand Project and portfolio 1
Katrina Personal Brand Project and portfolio 1Katrina Personal Brand Project and portfolio 1
Katrina Personal Brand Project and portfolio 1
 
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service AvailableCall Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
Call Girls Pune Just Call 9907093804 Top Class Call Girl Service Available
 
0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdf0183760ssssssssssssssssssssssssssss00101011 (27).pdf
0183760ssssssssssssssssssssssssssss00101011 (27).pdf
 
Cracking the Cultural Competence Code.pptx
Cracking the Cultural Competence Code.pptxCracking the Cultural Competence Code.pptx
Cracking the Cultural Competence Code.pptx
 
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
Call Girls Electronic City Just Call 👗 7737669865 👗 Top Class Call Girl Servi...
 
Call Girls In Noida 959961⊹3876 Independent Escort Service Noida
Call Girls In Noida 959961⊹3876 Independent Escort Service NoidaCall Girls In Noida 959961⊹3876 Independent Escort Service Noida
Call Girls In Noida 959961⊹3876 Independent Escort Service Noida
 
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
Call Girls in Delhi, Escort Service Available 24x7 in Delhi 959961-/-3876
 
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
Call Girls From Pari Chowk Greater Noida ❤️8448577510 ⊹Best Escorts Service I...
 
John Halpern sued for sexual assault.pdf
John Halpern sued for sexual assault.pdfJohn Halpern sued for sexual assault.pdf
John Halpern sued for sexual assault.pdf
 
Falcon's Invoice Discounting: Your Path to Prosperity
Falcon's Invoice Discounting: Your Path to ProsperityFalcon's Invoice Discounting: Your Path to Prosperity
Falcon's Invoice Discounting: Your Path to Prosperity
 
Dr. Admir Softic_ presentation_Green Club_ENG.pdf
Dr. Admir Softic_ presentation_Green Club_ENG.pdfDr. Admir Softic_ presentation_Green Club_ENG.pdf
Dr. Admir Softic_ presentation_Green Club_ENG.pdf
 
Value Proposition canvas- Customer needs and pains
Value Proposition canvas- Customer needs and painsValue Proposition canvas- Customer needs and pains
Value Proposition canvas- Customer needs and pains
 
Famous Olympic Siblings from the 21st Century
Famous Olympic Siblings from the 21st CenturyFamous Olympic Siblings from the 21st Century
Famous Olympic Siblings from the 21st Century
 
How to Get Started in Social Media for Art League City
How to Get Started in Social Media for Art League CityHow to Get Started in Social Media for Art League City
How to Get Started in Social Media for Art League City
 
Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...Ensure the security of your HCL environment by applying the Zero Trust princi...
Ensure the security of your HCL environment by applying the Zero Trust princi...
 
Uneak White's Personal Brand Exploration Presentation
Uneak White's Personal Brand Exploration PresentationUneak White's Personal Brand Exploration Presentation
Uneak White's Personal Brand Exploration Presentation
 
Insurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usageInsurers' journeys to build a mastery in the IoT usage
Insurers' journeys to build a mastery in the IoT usage
 

Privacy Threats in Healthcare - It Could Happen to You

Editor's Notes

  1. Nick’s bio: Nick Culbertson is the Co-Founder and CEO of Protenus. In 2014, Nick and his co-founder Robert Lord developed the initial prototype and algorithms that launched Protenus, fulfilling a critical need to advance health data security and better protect patient data. 
  2. In this session, we will examine how data breaches affected the healthcare industry, according to the 2020 Breach Barometer, and what steps you can take to protect your institution now. Our agenda will include the current health data security threat landscape and the emerging trends from 2019, practical steps your team can use to protect patient privacy and an understanding of healthcare compliance analytics and how it is used to monitor, detect, and prevent health data breaches.
  3. One shocking statistic from the 2020 Breach Barometer is that 41 million patient records were affected in 2019 as hacking incidents continue to escalate.
  4. You might be wondering what Tom Hanks, Idris Elba and Boris Johnson have in common. All of these gentleman had COVID-19 and their medical information was made public. It’s not a matter of if but when you will be hit with a breach whether it is a famous VIP or a normal patient.
  5. Our analysis is based on 572 health data breaches reported to the U.S. Department of Health and Human Services (HHS), the media, or some other source during 2019. As in years past, we do not have numbers for every incident in 2019, but for those 481 incidents for which we have data, 41,404,022 patients were impacted.
  6. Comparing those numbers with those of years prior, you can see the staggering increase in the number of affected patient records. In 2019, the number almost tripled compared to the 2018 data.
  7. Despite innovations in healthcare compliance analytics, the healthcare industry has continued to experience an increase in the number of reported health data breaches, year over year, since Protenus started compiling statistics in 2016. This is an alarming trend which should change as more organizations deploy advanced patient privacy monitoring systems that can prevent future incidents.
  8. Forty-eight states (96%) are represented in the 570 incidents for which we had location data. Texas had the most reported incidents with 59, followed by California with 49. Please note that numbers for some states are inflated because the analysis uses the state where the BA/vendor is located, not where the client is located.
  9. The single largest breach reported in 2019 was the result of the hacking of a Business Associate. It involved one of the country’s largest patient collections recovery agencies that had its patient information accessed by an unauthorized party. The breach was discovered when analysts found personal identifiable information (PII), including date of birth (DOB), Social Security Numbers, and physical addresses for sale on the dark web. Hackers appeared to gain access to patient information through the online patient portal over the course of several months, beginning in September 2018 and continuing until March 2019. This hacking incident affected 20,949,600 patient records, with 11,900,000 affected records from just one client.
  10. This graph shows the types of incidents. In 2019 there were incidents of hackers attempting to extort money from the breached patients, not just the affected healthcare organizations. In one incident in Florida, the hackers gained access to patient information and made the typical ransom demand of the breached organization. In a new malicious move, the hackers also sent ransom demands to a number of the affected patients, “threatening the public release of their photos and personal information unless unspecified ransom demands are negotiated and met.” The FBI is currently investigating this incident.
  11. The healthcare industry experienced yet another alarming increase in hacking incidents in 2019.The increase is consistent with a worrisome year over year trend since 2016.
  12. Hacking incidents were relatively constant throughout the year, with a total of 330 incidents in 2019, comprising 58% of all 2019 breaches. It appears hacking incidents, particularly ransomware incidents, are on the rise; hackers are getting more creative in how they exploit healthcare organizations and patients alike. In contrast to previous hacking incidents, current ransomware threat actors have taken to naming victims who do not pay the ransom demands, and then publicly dumping the data if they refuse to pay.
  13. Overall, the number of insider-related incidents has decrease year over year since 2016. This is largely due to the adoption of healthcare compliance analytics in health systems across the country and improved employee education on how to prevent privacy violations.
  14. Even with the decrease in the number of insider incidents, they still pose a significant threat with one insider-related incident going undetected for over seven years. In this particular incident, sensitive patient information was viewable to external audiences outside their system network. Potentially exposed information included patient name, medical record number, insurance information, appointment times, and procedure information. At this time, it does not appear this data has been used maliciously and the organization has corrected the system configuration. Several other insider-related incidents went undiscovered for three or more years, putting significant amounts of patient data at risk.
  15. While there were substantially fewer patient records breached by insider-wrongdoing, they are often more dangerous since employees with legitimate access to patient information can abuse their access with malicious intent, often undetected. In one recent case from 2019, a nurse is suspected of gaining access to patient information and providing the data to a third-party for fraudulent purposes. The Maryland-based healthcare organization discovered the breach when law enforcement reached out after the employee’s associate was arrested for an unrelated matter. It is estimated that 16,542 patients could have been affected over the course of almost two years (644 days) before discovery. Based on information provided by state and local law enforcement, the organization fired this employee and reported the incident to the Board of Nursing. The investigation is still ongoing. In addition to the loss of patient trust, this entity may now face substantial post-breach costs that have been estimated to be close to $10M per breach.
  16. Several insider incidents took more than 4 years to discover. Overall, the number of insider-related incidents has decrease year over year since 2016. This is largely due to the adoption of healthcare compliance analytics in health systems across the country and improved employee education on how to prevent privacy violations.
  17. While hacking incidents may be discovered more quickly than insider incidents, they also tend to have longer gaps between the discovery of the breach and reporting it. This may be due to ransomware attacks making it more difficult to determine what may have been accessed or exfiltrated, making it harder to identify who to notify.
  18. Given the last several slides, you can see why privacy monitoring is so important. Especially, in the current COVID-19 environment.
  19. While the breach barometer reports on publicly disclosed incidents, it’s just the tip of the iceberg, most data breaches go unnoticed because of the legacy systems and the manual audits that still occur across the country. With the sheer volume of the medical events that happen across the EHR you are asking the compliance team to do the impossible - manually detect these breaches before they happen.
  20. Let’s talk about some steps your organization can take to protect patient privacy. An effective privacy monitoring program is always geared toward educating workforce and preventing violations.
  21. It is best to centralize all audit log data and bring your disparate systems across the enterprise together under a ‘single pane of glass’
  22. You can reduce time spent on investigations if you leverage the data at your fingertips, allowing your team to resolve more cases in less time.
  23. Also, you need to think outside the box and get ahead of publicly available news and social media to predict threats and catch them before a breach happens.
  24. There has been an increase in adoption in HCA that allows you to use AI to see everything in a single pane of glass. All of your EHR data or peripheral applications will be at your fingertips allowing you to do more with less. The AI will be able to distinguished abnormal vs normal events in the EHR automatically.
  25. Let’s review what we discussed today, you learned how data breaches affect the healthcare industry with more than 41 million patient records affected, we discussed the practical steps your team can use to protect patient privacy by creating an effective privacy monitoring program and how to use AI to leverage Healthcare Compliance Analytics within your EHR.
  26. We have a lot more data available in our Breach Barometer. Please visit the url on the screen to secure a copy.
  27. Does anyone have any questions? Please utilize the Q&A and chat features on the right-hand side of your screen to submit a question.