Skip to main content

Main menu

  • Home
  • Content
    • Current issue
    • Past issues
    • Early releases
    • Collections
    • Sections
    • Blog
    • Infographics & illustrations
    • Podcasts
    • COVID-19 Articles
  • Authors & Reviewers
    • Overview for authors
    • Submission guidelines
    • Submit a manuscript
    • Forms
    • Editorial process
    • Editorial policies
    • Peer review process
    • Publication fees
    • Reprint requests
    • Open access
    • Patient engagement
  • Members & Subscribers
    • Benefits for CMA Members
    • CPD Credits for Members
    • Subscribe to CMAJ Print
    • Subscription Prices
    • Obituary notices
  • Alerts
    • Email alerts
    • RSS
  • JAMC
    • À propos
    • Numéro en cours
    • Archives
    • Sections
    • Abonnement
    • Alertes
    • Trousse média 2023
  • CMAJ JOURNALS
    • CMAJ Open
    • CJS
    • JAMC
    • JPN

User menu

Search

  • Advanced search
CMAJ
  • CMAJ JOURNALS
    • CMAJ Open
    • CJS
    • JAMC
    • JPN
CMAJ

Advanced Search

  • Home
  • Content
    • Current issue
    • Past issues
    • Early releases
    • Collections
    • Sections
    • Blog
    • Infographics & illustrations
    • Podcasts
    • COVID-19 Articles
  • Authors & Reviewers
    • Overview for authors
    • Submission guidelines
    • Submit a manuscript
    • Forms
    • Editorial process
    • Editorial policies
    • Peer review process
    • Publication fees
    • Reprint requests
    • Open access
    • Patient engagement
  • Members & Subscribers
    • Benefits for CMA Members
    • CPD Credits for Members
    • Subscribe to CMAJ Print
    • Subscription Prices
    • Obituary notices
  • Alerts
    • Email alerts
    • RSS
  • JAMC
    • À propos
    • Numéro en cours
    • Archives
    • Sections
    • Abonnement
    • Alertes
    • Trousse média 2023
  • Visit CMAJ on Facebook
  • Follow CMAJ on Twitter
  • Follow CMAJ on Pinterest
  • Follow CMAJ on Youtube
  • Follow CMAJ on Instagram
News

Medical privacy breaches rising

Roger Collier
CMAJ March 06, 2012 184 (4) E215-E216; DOI: https://doi.org/10.1503/cmaj.109-4116
Roger Collier
  • Find this author on Google Scholar
  • Find this author on PubMed
  • Search for this author on this site
  • Article
  • Responses
  • Metrics
  • PDF
Loading

Privacy concerns influence where and when patients seek care, as well how much personal information they disclose to their caregivers, and it appears people have good reason to be worried. The use of portable electronic devices, many of which lack encryption, is increasing in hospitals and that, among other factors, is leading to more breaches of protected health information.

In the United States, there was a whopping 97% increase in the number of health records breached from 2010 to 2011, according to a new report from Redspin, a US company that assesses information technology security (www.redspin.com/docs/Redspin_PHI_2011_Breach_Report.pdf).

“That’s a trend going in the wrong direction,” says Daniel Berger, Redspin’s president and CEO, who worries that breaches are hurting the entire US health care system. “The adoption and implementation and usage of information technology are foundational elements of transforming the whole system. The problem with security is a threat to that.”

The number of patient records accessed in each breach has also increased substantially, from 26 968 (in 2010) to 49 394 (in 2011). Since August 2009, when the US government regulated that any breach affecting more than 500 patients be publicly disclosed, a total of 385 breaches, involving more than 19 million records, have been reported to the Department of Health and Human Services. A large portion of those breaches, 39%, occurred because of a lost, stolen or otherwise compromised portable electronic device — a problem that will likely only get worse as iPads, smartphones and other gadgets become more common in hospitals.

“A lot more of this data is now stored on devices that can walk out of your building every night,” says Berger.

Are breaches of protected health information as big a problem in Canada as in the US? Nobody knows, as there is no federal law requiring health care providers to disclose that information — and that’s a problem, says Khaled El Emam, Canada Research Chair in electronic health information at the University of Ottawa in Ontario and chief executive officer of Privacy Analytics, an Ottawa-based company that creates software to protect individual privacy with respect to sensitive data.

Figure

Increased use of portable electronic devices, such as computer tablets, by physicians and hospitals is contributing to rise of medical privacy breaches.

Image courtesy of © 2012 Thinkstock

“All of these breaches are having an impact on patients and on health care providers. As a starting point, it would be really helpful to have data to understand how often it happens,” says El Emam.

Anecdotally, however, breaches involving mobile devices also appear to be a problem in Canada, says El Emam, who suggests that health care providers could adopt certain practices to reduce the risk of that occurring. “One is to encrypt all mobile devices and to enforce that,” says El Emam. “Another could be not to put any health information onto mobile devices, or to anonymize the data that goes on the devices. A key one, though, would be training the staff. If you do all these things, your risk will be low.”

In the US, the government has taken several steps to encourage health care providers to improve the security of their information technology systems. In addition to requiring public disclosure of breaches — an incentive in the form of the proverbial “wall of shame” — the US government will be dropping in on some health care providers to kick the tires of their security practices. The Department of Health and Human Services’ Office for Civil Rights will conduct 150 audits by Dec. 31, 2012, to check compliance with privacy requirements listed in the Health Insurance Portability and Accountability Act. Under the act, health organizations are required to have conducted a risk analysis and implemented policies to protect patient privacy. The maximum annual penalty for violating the act is US$1.5 million.

Canada has not yet followed the US down the road of strict enforcement and stiff penalties, and perhaps it doesn’t have to, suggests El Emam, but that is impossible to determine without national data on privacy breaches. “For us, the first step is to have the data. Once we look at the data, if the numbers are low, we might not have to do anything.”

But patients in Canada appear to be concerned about the privacy of their health information. A recent online survey of 1002 Canadian patients indicated that 43.2% have withheld or would withhold information from their health care provider because of privacy concerns, while 31.3% of Canadian patients have or would postpone care over privacy concerns, and 42.9% would seek care outside their communities for the same reason.

“Any friction in the free flow of information between care providers and patients, such as that caused by privacy concerns, prevents the patient from receiving the best possible care,” states the survey, Canada: How Privacy Considerations Drive Patient Decisions and Impact Patient Care Outcomes, conducted by FairWarning, a US company that provides privacy auditing solutions for electronic health records (www.fairwarning.com/documents/Canada/2011-CanadaSurvey.pdf).

“We are entering an era where the information the patient provides has more impact than ever before on the nature of the care they receive. There has to be trust between the patient and the care provider,” says Kurt Long, FairWarning’s CEO. “Health care providers need to begin viewing privacy not only as a legal, ethical and moral obligation, but as a serious part of patient treatment and care.”

PreviousNext
Back to top

In this issue

Canadian Medical Association Journal: 184 (4)
CMAJ
Vol. 184, Issue 4
6 Mar 2012
  • Table of Contents
  • Index by author

Article tools

Respond to this article
Print
Download PDF
Article Alerts
To sign up for email alerts or to access your current email alerts, enter your email address below:
Email Article

Thank you for your interest in spreading the word on CMAJ.

NOTE: We only request your email address so that the person you are recommending the page to knows that you wanted them to see it, and that it is not junk mail. We do not capture any email address.

Enter multiple addresses on separate lines or separate them with commas.
Medical privacy breaches rising
(Your Name) has sent you a message from CMAJ
(Your Name) thought you would like to see the CMAJ web site.
CAPTCHA
This question is for testing whether or not you are a human visitor and to prevent automated spam submissions.
Citation Tools
Medical privacy breaches rising
Roger Collier
CMAJ Mar 2012, 184 (4) E215-E216; DOI: 10.1503/cmaj.109-4116

Citation Manager Formats

  • BibTeX
  • Bookends
  • EasyBib
  • EndNote (tagged)
  • EndNote 8 (xml)
  • Medlars
  • Mendeley
  • Papers
  • RefWorks Tagged
  • Ref Manager
  • RIS
  • Zotero
‍ Request Permissions
Share
Medical privacy breaches rising
Roger Collier
CMAJ Mar 2012, 184 (4) E215-E216; DOI: 10.1503/cmaj.109-4116
Digg logo Reddit logo Twitter logo Facebook logo Google logo Mendeley logo
  • Tweet Widget
  • Facebook Like

Jump to section

  • Article
  • Responses
  • Metrics
  • PDF

Related Articles

  • No related articles found.
  • PubMed
  • Google Scholar

Cited By...

  • No citing articles found.
  • Google Scholar

More in this TOC Section

  • Should alcohol carry a warning label?
  • Could bringing the hospital home expand acute care capacity?
  • Can Ontario offload surgeries to private clinics without undermining public health care?
Show more News

Similar Articles

Collections

  • Topics
    • Patient safety & quality improvement
    • Respiratory medicine

 

View Latest Classified Ads

Content

  • Current issue
  • Past issues
  • Collections
  • Sections
  • Blog
  • Podcasts
  • Alerts
  • RSS
  • Early releases

Information for

  • Advertisers
  • Authors
  • Reviewers
  • CMA Members
  • CPD credits
  • Media
  • Reprint requests
  • Subscribers

About

  • General Information
  • Journal staff
  • Editorial Board
  • Advisory Panels
  • Governance Council
  • Journal Oversight
  • Careers
  • Contact
  • Copyright and Permissions
  • Accessibiity
  • CMA Civility Standards
CMAJ Group

Copyright 2023, CMA Impact Inc. or its licensors. All rights reserved. ISSN 1488-2329 (e) 0820-3946 (p)

All editorial matter in CMAJ represents the opinions of the authors and not necessarily those of the Canadian Medical Association or its subsidiaries.

To receive any of these resources in an accessible format, please contact us at CMAJ Group, 500-1410 Blair Towers Place, Ottawa ON, K1J 9B9; p: 1-888-855-2555; e: cmajgroup@cmaj.ca

Powered by HighWire