Video: Every Case Tells a Story| Webinar: ACR/CHEST ILD Guidelines in Practice

An official publication of the ACR and the ARP serving rheumatologists and rheumatology professionals

  • Conditions
    • Axial Spondyloarthritis
    • Gout and Crystalline Arthritis
    • Myositis
    • Osteoarthritis and Bone Disorders
    • Pain Syndromes
    • Pediatric Conditions
    • Psoriatic Arthritis
    • Rheumatoid Arthritis
    • Sjögren’s Disease
    • Systemic Lupus Erythematosus
    • Systemic Sclerosis
    • Vasculitis
    • Other Rheumatic Conditions
  • FocusRheum
    • ANCA-Associated Vasculitis
    • Axial Spondyloarthritis
    • Gout
    • Psoriatic Arthritis
    • Rheumatoid Arthritis
    • Systemic Lupus Erythematosus
  • Guidance
    • Clinical Criteria/Guidelines
    • Ethics
    • Legal Updates
    • Legislation & Advocacy
    • Meeting Reports
      • ACR Convergence
      • Other ACR meetings
      • EULAR/Other
    • Research Rheum
  • Drug Updates
    • Analgesics
    • Biologics/DMARDs
  • Practice Support
    • Billing/Coding
    • EMRs
    • Facility
    • Insurance
    • QA/QI
    • Technology
    • Workforce
  • Opinion
    • Patient Perspective
    • Profiles
    • Rheuminations
      • Video
    • Speak Out Rheum
  • Career
    • ACR ExamRheum
    • Awards
    • Career Development
  • ACR
    • ACR Home
    • ACR Convergence
    • ACR Guidelines
    • Journals
      • ACR Open Rheumatology
      • Arthritis & Rheumatology
      • Arthritis Care & Research
    • From the College
    • Events/CME
    • President’s Perspective
  • Search

Healthcare Data Hacking May Lead to Identity Thefts

Linda Carroll  |  September 25, 2019

(Reuters Health)—More than 70% of healthcare data breaches in the U.S. have involved sensitive demographic or financial information that could fuel identity theft, a new study suggests.

When a healthcare company is hacked, criminals gain access not only to health information, but also to demographic and financial data that could compromise patients’ privacy and financial security, researchers from the Michigan State and Johns Hopkins report.

ad goes here:advert-1
ADVERTISEMENT
SCROLL TO CONTINUE

Media reports often focus on the numbers of patients affected by these breaches, but what may be more important is the kind of data that has been stolen, they write in Annals of Internal Medicine, online Sept 23.1

Theft of medical data may not affect patients much because there isn’t a big market for it, said the study’s lead author, Xuefeng Jiang, a professor of accounting and information systems at the Eli Broad College of Business at Michigan State University.

ad goes here:advert-2
ADVERTISEMENT
SCROLL TO CONTINUE

“But Social Security numbers, credit card numbers and demographic data—such as names, birth dates and other personal identifiers—can be sold on the dark web,” Prof. Jiang said. “The main message for hospitals and health care providers is, if you have limited resources to safeguard information, you should put more emphasis on the sensitive kinds of information that can be sold on the dark web.”

For patients, the advice is to look past the numbers in media reports and focus on what types of information have been compromised, Prof. Jiang said.

To take a closer look at the kinds of data that get stolen in healthcare data hacks, Prof. Jiang and his coauthor pored over U.S. Department of Health and Human Services records on breaches that occurred between 2009 and 2019.

The HHS requires all health plans, healthcare clearinghouses and healthcare providers to notify the agency after a hack and it publishes information online whenever a breach affects 500 or more people.

After examining the hacks of 1,461 healthcare organizations, the researchers found that all involved at least one piece of demographic data. In 964 breaches, which affected 150 million patients, sensitive information, including Social Security numbers, drivers’ license numbers, and dates of birth, was compromised. Those breaches accounted for 66% of the hacks examined by the researchers.

A total of 513 breaches, or 35%, left service or financial information vulnerable. In 186 of the 513, which affected 49 million patients, compromised sensitive financial information, including credit card and bank account numbers.

Overall, 71% of the hacks that occurred over the 10-year study period, affecting 159 million patients, compromised sensitive demographic or financial information that could be used in identity theft and financial fraud, the researchers concluded.

Page: 1 2 | Single Page
Share: 

Filed under:Technology Tagged with:hackinghealth informationHealth Information Technologypatient dataTechnology

Related Articles

    Health Data Breaches on the Rise

    April 15, 2015

    Large-scale health data breaches reported by doctors and health plans have been rising steadily, a new report shows. From 2010 to 2013, nearly 1000 large breaches affected more than 29 million individual health records, and more than half ad goes here:advert-1ADVERTISEMENTSCROLL TO CONTINUEresulted from theft or loss of laptops, thumb drives and paper records, according…

    Legal Updates: Healthcare Data Privacy and Security under HIPAA

    May 1, 2014

    Maintaining the privacy of healthcare data Is paramount, and a breach can cost you hundreds of thousands of dollars

    Rheumatoid Arthritis Research Provides New Insights on Risk Factors, Identification Tools, Intervention

    Rheumatoid Arthritis Research Provides New Insights on Risk Factors, Identification Tools, Intervention

    October 11, 2016

    Established wisdom holds that patients with rheumatoid arthritis (RA) will fare better if their disease is diagnosed as early as possible, and treatments with disease-modifying drugs are started before inflammation can do more damage to joints and tissue. Usually, early diagnosis means spotting the clinical signs of disease, but new research tells us more about…

    Implications of Florida’s Electronic Health Records Data Storage Law

    August 7, 2023

    Healthcare is a high-priority target for cyber criminals. State-level measures, such as a new Florida law, fail to address the root problems of data security but may affect how providers manage patient data.

  • About Us
  • Meet the Editors
  • Issue Archives
  • Contribute
  • Advertise
  • Contact Us
  • Copyright © 2025 by John Wiley & Sons, Inc. All rights reserved, including rights for text and data mining and training of artificial technologies or similar technologies. ISSN 1931-3268 (print). ISSN 1931-3209 (online).
  • DEI Statement
  • Privacy Policy
  • Terms of Use
  • Cookie Preferences