About a year ago we covered the 2022 Cost of a Data Breach Report by IBM. The 2022 report had surfaced that the cost was highest in the healthcare and financial industry, followed by pharmaceuticals and technology. In 2023 this was equally so as the latest report shows. In fact, the cost in the healthcare data breach rose again from an average of USD 10.10 million in 2022 to USD 10.93 million in 2023. Over the past 3 years, this number has increased by a whopping 53.3 percent.
In addition, the number of breaches recorded in the healthcare industry has more than doubled since 2017, the HIPAA Journal reports in its December 2023 Healthcare Data Breach Report.
This article covers the effects of data breaches on the healthcare sector, the value of health data, the cost of noncompliance with data protection laws, and how companies can avoid it.
The Devastating Effects of Data Breaches in the Health Sector
Healthcare Data Breach sector can have devastating effects. Even the bad guys know it. Only in December of 2022, the then-largest ransomware operation LockBit which operates a Ransomware as a Service model apologized to Sick Kids Hospital in Toronto, Canada for its affiliate breaking the rules LockBit imposes as conditions for the use of its services and attacking healthcare service providers using LockBits ransomware encryption variant. Of course this does not mean that healthcare as an industry is off-limits. In November 2023, a LockBit-affiliated threat actor stated during the attack of a US healthcare service provider: “We purposely didn’t encrypt this hospital so as not to interfere with patient care. We just stole over 10 million files.”
Then in February 2024 the arguably worst ransomware attack on the US healthcare sector ever hit UnitedHealth subsidiary Change Healthcare and exposed how fragile the healthcare system is. For context, Change Healthcare is the largest clearinghouse for insurance billing and payments in the States with thousands of healthcare providers depending on their system to obtain insurance approval for any prescribed services, including drugs, and to get paid for them. So it’s not that the hackers directly disabled the provision of healthcare services but they put the pressure on to make Change Healthcare meet their ransom demands by causing healthcare providers to scramble for funds to keep their doors open.
The Value of Health Data
For this reason, it is obvious why healthcare service providers are such a popular target for hackers: they are likely willing to pay as the stakes are particularly high with the lives of patients quite literally on the line.
But a second, less obvious reason is that health records bring the biggest bang for buck on the black market. Reportedly, medical records sell for USD 60 while a Social Security number only brings in USD 15 and USD 3 can be charged for a credit card. Why are health records so valuable? It’s because they have a long lifespan compared to a credit card number or other financial data, misuse is harder to detect, they allow for impersonation to obtain prescription drugs, commit tax fraud, phishing attacks, extortion, blackmail and more.
So far it remains unclear whether Protected Health Information (PHI) has been affected by the Change Healthcare breach and if so how. The HHS Office for Civil Rights (OCR), the entity tasked with enforcing the Health Insurance Portability and Accountability Act’s (HIPAA) security, privacy, and breach notification rules, has launched an investigation to determine whether Change Healthcare has been HIPAA compliant and whether PHI was breached.
The Cost of Noncompliance
Non-compliance is an important cost factor, driving up the total cost of a data breach in highly regulated industries including healthcare by 23 percent or USD 1.03 million compared to industries subject to few or no regulations. This number is down from 50.9 percent in 2022. But non-compliance remains the third most impactful cost amplifier, according to the 2023 IBM Report, which was the same in 2022. The first two are security skill shortage and security system complexity.
Effective Cost Mitigation
The wisdom these days dictates that it is not a question of whether but when a security breach of an organization will occur. Preventing a breach is of course the best strategy, but since that is unlikely to be successful against all attacks ever launched against and organization, efforts should also be undertaken to shorten the data breach lifecycle (the time from discovery to resolution of a breach) and to ensure compliance with data protection laws and regulations.
The 2023 Cost of a Data Breach Report recommends the following top three strategies:
- Build security into every stage of software development and deployment—and test regularly
- Modernize data protection across hybrid cloud
- Use security AI and automation to increase speed and accuracy
- Strengthen resiliency by knowing your attack surface and practicing incident response
How We Can Help
Focusing on the first recommendation, here is how Private AI can help make software development and deployment safer. If you are using vast amounts of data to develop software components such as algorithms best practice and data protection laws and regulation dictate that you only include the minimum amount of personal data necessary to achieve your goal. Private AI can redact and replace personally identifiable information in unstructured datasets with great accuracy. The safest data to use is the one that does not contain valuable data at all and the most expensive one is personal data including health records.
2023 Cost of a Data Breach Report by IBM
Following the fourth recommendation on how to save costs in the context of healthcare data breach, knowing your attack surface and practicing incident response, can also be facilitated using Private AI’s tech. First of all, when you can easily determine where in your systems the largest amount and the most valuable information is located, you know where hackers are more likely to attack. Private AI has the ability to produce a precise report indicating the location and type of personal data in your systems, helping you make this determination particularly when unstructured data is concerned.
Having the ability to determine where your valuable data is located and what it includes exactly is also a must for incident response strategies, one aspect of which is breach reporting.
Private AI can be used to produce a precise report indicating the location and type of personal data in the data affected by the breach, which can save a considerable amount of time. This is particularly important in cases where there are tight deadlines for reporting data breaches. The GDPR requires reporting “without undue delay and, where feasible, not later than 72 hours after having become aware of it.” Under HIPAA, reporting of breaches affecting 500 or more individuals must occur “without unreasonable delay and in no case later than 60 days following a breach.”
Given that in 2023 it took organizations an average of 73 days to contain a data breach resulting from stolen or compromised credentials according to the 2023 IBM Report even a 60-day reporting period can seem short, given the competing demands on everyone’s time during data breach incidents. Having tools to aid with the issuing of the report can be instrumental in avoiding significant fines.
Conclusion
In conclusion, the healthcare sector faces mounting challenges from escalating data breach costs and their profound implications. According to the 2023 Cost of a Data Breach Report, healthcare data breach-related expenses surged by 53.3 percent over three years, reaching an average of USD 10.93 million. The frequency of breaches has more than doubled since 2017, underscoring the urgency of addressing this critical issue. Beyond financial losses, breaches jeopardize patient safety and privacy, as seen in recent ransomware attacks on healthcare institutions.
Compliance with data protection laws is crucial, given the high value of health data on the black market. Noncompliance remains costly, driving up breach expenses and emphasizing the need for proactive risk mitigation measures. By implementing strategies outlined in the report, such as integrating security into software development and leveraging AI and automation, organizations can strengthen their defenses. Solutions like those offered by Private AI, which facilitate data redaction and streamline incident response, play a vital role in minimizing breach impact. Collaboration between industry stakeholders and innovative technologies will be essential in safeguarding patient data and mitigating the devastating consequences of breaches in the healthcare sector. Try our web demo to see for yourself, or talk to an expert today.