What is a healthcare data breach?
A healthcare data breach is an unauthorized access, use, or disclosure of protected health information (PHI) as defined by HIPAA. Breaches affecting 500 or more individuals must be reported to the HHS Office for Civil Rights (OCR), state attorneys general, and affected patients within 60 days of discovery.
How many healthcare data breaches happen each year?
The HHS OCR Breach Portal reports an average of 600-700 large breaches (500+ records) annually, affecting tens of millions of patient records. In 2023, over 133 million records were exposed in healthcare breaches, more than doubling the previous year. The frequency and scale of breaches continues to increase year over year.
What should I do if my healthcare data was breached?
Immediately place a fraud alert or credit freeze with the three major credit bureaus (Equifax, Experian, TransUnion). Monitor your explanation of benefits (EOB) statements for services you did not receive. Enroll in any free credit monitoring offered by the breached organization. Report suspicious activity to the FTC at IdentityTheft.gov and your state attorney general.
What are the most common causes of healthcare data breaches?
Hacking and IT incidents account for approximately 75% of healthcare breaches, with ransomware being the leading attack vector. Unauthorized access or disclosure by insiders causes about 15% of breaches. Lost or stolen devices, improper disposal of records, and business associate failures account for the remainder.
Can I sue if my healthcare data was breached?
Yes. You may be able to join a class action lawsuit or file an individual claim against the breached organization. Most healthcare data breach settlements range from $100-$1,000 per affected individual for basic claims, with higher amounts for documented identity theft or financial harm. Many cases settle for $5-50 million total.
What penalties do healthcare organizations face for data breaches?
HIPAA violations carry penalties of $100-$50,000 per violation (up to $1.5 million per year per violation category). The HHS OCR can also require corrective action plans. State attorneys general can levy additional fines. In 2023, OCR settlements and penalties exceeded $4 million, with individual cases reaching $1.25 million.
How long does credit monitoring last after a healthcare breach?
Most breached organizations offer 12-24 months of free credit monitoring and identity theft protection. Some major breaches (like the Anthem breach) offered longer monitoring periods. After the free monitoring expires, consider maintaining your own credit monitoring through annualcreditreport.com or a paid service if your Social Security number was exposed.
What types of information are exposed in healthcare breaches?
Healthcare breaches can expose names, dates of birth, Social Security numbers, health insurance information, medical record numbers, diagnosis and treatment details, prescription information, and financial data. Healthcare records are particularly valuable to criminals because they contain both identity and medical information, selling for $250-1,000 per record on the dark web.
Are telehealth platforms subject to the same breach notification rules?
Yes. Telehealth platforms that handle PHI are covered entities or business associates under HIPAA and must comply with the same breach notification rules. The FTC Health Breach Notification Rule also applies to health apps and telehealth services not covered by HIPAA, requiring them to notify users of unauthorized disclosures.
How do I check if my information was part of a specific healthcare breach?
Search the HHS OCR Breach Portal (ocrportal.hhs.gov) to verify reported breaches. Breached organizations are required to send individual notification letters to affected patients. You can also contact the organization directly to ask if your records were involved. State attorney general websites often maintain breach notification databases with additional details.