Research finds the kind of data hackers get about you from hospitals

0
202
data hackers
data hackers

Summary:New research has uncovered the specific data leaked through hospital breaches, sounding alarm bells for nearly 170 million people.

When hospitals are hacked, the public hears about the number of victims — but not what information the cybercriminals stole. New research from Michigan State University and Johns Hopkins University is the first to uncover the specific data leaked through hospital breaches, sounding alarm bells for nearly 170 million people.

“The major story we heard from victims was how compromised, sensitive information caused financial or reputation loss,” said John (Xuefeng) Jiang, lead author and MSU professor of accounting and information systems. “A criminal might file a fraudulent tax return or apply for a credit card using the social security number and birth dates leaked from a hospital data breach.”

Until now, researchers have not been able to classify the kind or amount of public health information leaked through breaches; thus, never getting an accurate picture of breadth or consequences.

The findings, published in Annals of Internal Medicine, encompass 1,461 breaches that happened between Oct. 2009 and July 2019.

Jiang and co-author Ge Bai, associate professor of accounting at Johns Hopkins Carey Business School and Bloomberg School of Public Health, discovered that 169 million people have had some form of information exposed because of hackers.

To uncover what specific information was exposed, the researchers classified data into three categories: demographic, such as names, email addresses and other personal identifiers; service or financial information, which included service date, billing amount, payment information; and medical information, such as diagnoses or treatment.

“We further classified social security and driver’s license numbers and birth dates as sensitive demographic information, and payment cards and banking accounts as sensitive financial information. Both types can be exploited for identity theft or financial fraud,” Jiang said. “Within medical information, we classified information related to substance abuse, HIV, sexually transmitted diseases, mental health and cancer as sensitive medical information because of their substantial implications for privacy.”

Over 70% of the breaches compromised sensitive demographic or financial data that could lead to identity theft or financial fraud. More than 20 breaches compromised sensitive health information, which affected 2 million people.

“Without understanding what the enemy wants, we cannot win the battle,” Bai said. “By knowing the specific information hackers are after, we can ramp up efforts to protect patient information.”

With a newfound understanding of what explicit data was leaked — and how many over the last decade were affected — the researchers offer hospitals and health providers suggestions on how to better protect patients’ sensitive information.

The researchers suggest that the Department of Health and other regulators formally collect the types of information compromised in a data breach to help the public assess the potential damages. Hospitals and other healthcare providers, Jiang said, could effectively reduce data breach risks by focusing on securing information if they have limited resources. For example, implementing separate systems to store and communicate sensitive demographic and financial information.

Jiang noted that the Department of Health and Human Services and Congress recently proposed rules that encourage more data-sharing, which increases the risks for breaches. He said that he and Bai plan to work with lawmakers and industries by providing practical guidance and advice using their academic findings.

More: Science Daily

Previous articleNaresh Pal Gangwar IAS transferred as Commissioner & Principal Secretary- Agriculture, Rajasthan
Next articleMd Majnur Hussain IAS given addl charge as Secretary- Secretariat Administration Dept, Assam
Saurabh
Saurabh Sinha, Editor of IndianBureaucracy.com, is known for his credible, precise and insightful coverage of governance, civil services and administrative developments in India. Under his leadership, the portal has grown into a trusted national platform for accurate updates, appointments and policy movements within the bureaucratic ecosystem. Saurabh’s strong professional networking and deep understanding of government functioning enable him to present timely, reliable and well-contextualised information to readers across sectors. As a thought-driven editor, he promotes informed dialogue on governance reforms while maintaining high editorial standards. His calm, consistent and detail-oriented approach continues to strengthen the portal’s reputation. इंडियनब्यूरोक्रेसी.कॉम के संपादक सौरभ सिन्हा देश की नौकरशाही, शासन व्यवस्था और प्रशासनिक गतिविधियों की विश्वसनीय तथा संतुलित रिपोर्टिंग के लिए जाने जाते हैं। उनके नेतृत्व में यह पोर्टल नियुक्तियों, नीतिगत बदलावों और प्रशासनिक खबरों का एक भरोसेमंद राष्ट्रीय स्रोत बन चुका है। शासन तंत्र की गहरी समझ और मजबूत पेशेवर नेटवर्क के कारण सौरभ पाठकों को समयबद्ध, सटीक और संदर्भित जानकारी प्रदान करते हैं। एक विचारशील संपादक के रूप में वे सुशासन, पारदर्शिता और सुधारों पर सकारात्मक संवाद को बढ़ावा देते हैं। उनकी शांत, सूक्ष्म और पेशेवर संपादकीय शैली पोर्टल की प्रतिष्ठा को लगातार मजबूत कर रही है।