The Costs of a Data Breach in the Healthcare Sector and its Privacy Compliance Implications

Healthcare Data Breach

Share This Post

About a year ago we covered the 2022 Cost of a Data Breach Report by IBM. The 2022 report had surfaced that the cost was highest in the healthcare and financial industry, followed by pharmaceuticals and technology. In 2023 this was equally so as the latest report shows. In fact, the cost in the healthcare data breach rose again from an average of USD 10.10 million in 2022 to USD 10.93 million in 2023. Over the past 3 years, this number has increased by a whopping 53.3 percent. 

In addition, the number of breaches recorded in the healthcare industry has more than doubled since 2017, the HIPAA Journal reports in its December 2023 Healthcare Data Breach Report

This article covers the effects of data breaches on the healthcare sector, the value of health data, the cost of noncompliance with data protection laws, and how companies can avoid it.

The Devastating Effects of Data Breaches in the Health Sector

Healthcare Data Breach sector can have devastating effects. Even the bad guys know it. Only in December of 2022, the then-largest ransomware operation LockBit which operates a Ransomware as a Service model apologized to Sick Kids Hospital in Toronto, Canada for its affiliate breaking the rules LockBit imposes as conditions for the use of its services and attacking healthcare service providers using LockBits ransomware encryption variant. Of course this does not mean that healthcare as an industry is off-limits. In November 2023, a LockBit-affiliated threat actor stated during the attack of a US healthcare service provider: “We purposely didn’t encrypt this hospital so as not to interfere with patient care. We just stole over 10 million files.” 

Then in February 2024 the arguably worst ransomware attack on the US healthcare sector ever hit UnitedHealth subsidiary Change Healthcare and exposed how fragile the healthcare system is. For context, Change Healthcare is the largest clearinghouse for insurance billing and payments in the States with thousands of healthcare providers depending on their system to obtain insurance approval for any prescribed services, including drugs, and to get paid for them. So it’s not that the hackers directly disabled the provision of healthcare services but they put the pressure on to make Change Healthcare meet their ransom demands by causing healthcare providers to scramble for funds to keep their doors open. 

The Value of Health Data

For this reason, it is obvious why healthcare service providers are such a popular target for hackers: they are likely willing to pay as the stakes are particularly high with the lives of patients quite literally on the line.

But a second, less obvious reason is that health records bring the biggest bang for buck on the black market. Reportedly, medical records sell for USD 60 while a Social Security number only brings in USD 15 and USD 3 can be charged for a credit card. Why are health records so valuable? It’s because they have a long lifespan compared to a credit card number or other financial data, misuse is harder to detect, they allow for impersonation to obtain prescription drugs, commit tax fraud, phishing attacks, extortion, blackmail and more.

So far it remains unclear whether Protected Health Information (PHI) has been affected by the Change Healthcare breach and if so how. The HHS Office for Civil Rights (OCR), the entity tasked with enforcing the Health Insurance Portability and Accountability Act’s (HIPAA) security, privacy, and breach notification rules, has launched an investigation to determine whether Change Healthcare has been HIPAA compliant and whether PHI was breached. 

The Cost of Noncompliance

Non-compliance is an important cost factor, driving up the total cost of a data breach in highly regulated industries including healthcare by 23 percent or USD 1.03 million compared to industries subject to few or no regulations. This number is down from 50.9 percent in 2022. But non-compliance remains the third most impactful cost amplifier, according to the 2023 IBM Report, which was the same in 2022. The first two are security skill shortage and security system complexity.

Effective Cost Mitigation

The wisdom these days dictates that it is not a question of whether but when a security breach of an organization will occur. Preventing a breach is of course the best strategy, but since that is unlikely to be successful against all attacks ever launched against and organization, efforts should also be undertaken to shorten the data breach lifecycle (the time from discovery to resolution of a breach) and to ensure compliance with data protection laws and regulations.

The 2023 Cost of a Data Breach Report recommends the following top three strategies:

  • Build security into every stage of software development and deployment—and test regularly
  • Modernize data protection across hybrid cloud
  • Use security AI and automation to increase speed and accuracy
  • Strengthen resiliency by knowing your attack surface and practicing incident response

How We Can Help

Focusing on the first recommendation, here is how Private AI can help make software development and deployment safer. If you are using vast amounts of data to develop software components such as algorithms best practice and data protection laws and regulation dictate that you only include the minimum amount of personal data necessary to achieve your goal. Private AI can redact and replace personally identifiable information in unstructured datasets with great accuracy. The safest data to use is the one that does not contain valuable data at all and the most expensive one is personal data including health records.

2023 Cost of a Data Breach Report by IBM

Following the fourth recommendation on how to save costs in the context of healthcare data breach, knowing your attack surface and practicing incident response, can also be facilitated using Private AI’s tech. First of all, when you can easily determine where in your systems the largest amount and the most valuable information is located, you know where hackers are more likely to attack. Private AI has the ability to produce a precise report indicating the location and type of personal data in your systems, helping you make this determination particularly when unstructured data is concerned. 

Having the ability to determine where your valuable data is located and what it includes exactly is also a must for incident response strategies, one aspect of which is breach reporting. 

Private AI can be used to produce a precise report indicating the location and type of personal data in the data affected by the breach, which can save a considerable amount of time. This is particularly important in cases where there are tight deadlines for reporting data breaches. The GDPR requires reporting “without undue delay and, where feasible, not later than 72 hours after having become aware of it.” Under HIPAA, reporting of breaches affecting 500 or more individuals must occur “without unreasonable delay and in no case later than 60 days following a breach.” 

Given that in 2023 it took organizations an average of 73 days to contain a data breach resulting from stolen or compromised credentials according to the 2023 IBM Report even a 60-day reporting period can seem short, given the competing demands on everyone’s time during data breach incidents. Having tools to aid with the issuing of the report can be instrumental in avoiding significant fines.

Conclusion

In conclusion, the healthcare sector faces mounting challenges from escalating data breach costs and their profound implications. According to the 2023 Cost of a Data Breach Report, healthcare data breach-related expenses surged by 53.3 percent over three years, reaching an average of USD 10.93 million. The frequency of breaches has more than doubled since 2017, underscoring the urgency of addressing this critical issue. Beyond financial losses, breaches jeopardize patient safety and privacy, as seen in recent ransomware attacks on healthcare institutions. 

Compliance with data protection laws is crucial, given the high value of health data on the black market. Noncompliance remains costly, driving up breach expenses and emphasizing the need for proactive risk mitigation measures. By implementing strategies outlined in the report, such as integrating security into software development and leveraging AI and automation, organizations can strengthen their defenses. Solutions like those offered by Private AI, which facilitate data redaction and streamline incident response, play a vital role in minimizing breach impact. Collaboration between industry stakeholders and innovative technologies will be essential in safeguarding patient data and mitigating the devastating consequences of breaches in the healthcare sector. Try our web demo to see for yourself, or talk to an expert today.

Subscribe To Our Newsletter

Sign up for Private AI’s mailing list to stay up to date with more fresh content, upcoming events, company news, and more! 

More To Explore

Privacy Management
Blog

End-to-end Privacy Management

End-to-end privacy management refers to the process of protecting sensitive data throughout its entire lifecycle, from the moment it is collected to the point where

Read More »

Download the Free Report

Request an API Key

Fill out the form below and we’ll send you a free API key for 500 calls (approx. 50k words). No commitment, no credit card required!

Language Packs

Expand the categories below to see which languages are included within each language pack.
Note: English capabilities are automatically included within the Enterprise pricing tier. 

French
Spanish
Portuguese

Arabic
Hebrew
Persian (Farsi)
Swahili

French
German
Italian
Portuguese
Russian
Spanish
Ukrainian
Belarusian
Bulgarian
Catalan
Croatian
Czech
Danish
Dutch
Estonian
Finnish
Greek
Hungarian
Icelandic
Latvian
Lithuanian
Luxembourgish
Polish
Romanian
Slovak
Slovenian
Swedish
Turkish

Hindi
Korean
Tagalog
Bengali
Burmese
Indonesian
Khmer
Japanese
Malay
Moldovan
Norwegian (Bokmål)
Punjabi
Tamil
Thai
Vietnamese
Mandarin (simplified)

Arabic
Belarusian
Bengali
Bulgarian
Burmese
Catalan
Croatian
Czech
Danish
Dutch
Estonian
Finnish
French
German
Greek
Hebrew
Hindi
Hungarian
Icelandic
Indonesian
Italian
Japanese
Khmer
Korean
Latvian
Lithuanian
Luxembourgish
Malay
Mandarin (simplified)
Moldovan
Norwegian (Bokmål)
Persian (Farsi)
Polish
Portuguese
Punjabi
Romanian
Russian
Slovak
Slovenian
Spanish
Swahili
Swedish
Tagalog
Tamil
Thai
Turkish
Ukrainian
Vietnamese

Rappel

Testé sur un ensemble de données composé de données conversationnelles désordonnées contenant des informations de santé sensibles. Téléchargez notre livre blanc pour plus de détails, ainsi que nos performances en termes d’exactitude et de score F1, ou contactez-nous pour obtenir une copie du code d’évaluation.

99.5%+ Accuracy

Number quoted is the number of PII words missed as a fraction of total number of words. Computed on a 268 thousand word internal test dataset, comprising data from over 50 different sources, including web scrapes, emails and ASR transcripts.

Please contact us for a copy of the code used to compute these metrics, try it yourself here, or download our whitepaper.