Mitigating the consequences of electronic health record data breaches for patients and healthcare workers
Jeffrey C. L. Looi A B * , Stephen Allison B C , Tarun Bastiampillai B C D , Paul A. Maguire A B , Steve Kisely B E F and Richard C. H. Looi GA
B
C
D
E
F
G Independent Scholar,
Abstract
Electronic health records (EHRs) have been widely adopted in Australian public sector healthcare and will remain an ongoing, essential data system. However, recent substantial data breaches from hacked business data systems in Australian enterprises, as well as international healthcare providers, mean that EHR data breaches are increasingly likely in Australia. Risks include medical identity theft and extortion attempts based on threats to release sensitive patient information. Hacking is now a foreseeable additional risk of medical treatment. Risk mitigation for the consequences of data breaches needs to be considered, as well as support for patients (and families) and healthcare workers. This includes identity theft protection services, cybersecurity insurance, and psychological support.
Keywords: consumers, cyber security, data breach, e-health, electronic health record, health services management, healthcare workers, information management.
References
1 OIAC. AIC v Australian Clinical Labs Limited Concise Statement. 2023. Available at https://www.oaic.gov.au/__data/assets/pdf_file/0017/112526/AIC-v-Australian-Clinical-Labs-Limited-concise-statement.pdf [accessed 1 December 2023].
2 OIAC. Notifiable Data Breaches Report: January to June 2023. 2023. Available at https://www.oaic.gov.au/privacy/notifiable-data-breaches/notifiable-data-breaches-publications/notifiable-data-breaches-report-january-to-june-2023 [accessed 25 September 2023].
3 Terzon E, Yang S. Medibank says all customers’ personal data compromised by cyber attack. 2022. Available at https://www.abc.net.au/news/2022-10-26/medibank-hack-criminals-access-hack-data/101578438 [accessed 25 September 2023].
4 Terzon E. Pathology company Australian Clinical Labs reveals it was hit by cyber attack in February. 2022. Available at https://www.abc.net.au/news/2022-10-27/acl-cyber-attack-pathology-lab-health-data/101584072 [accessed 25 September 2023].
5 OIAC. OAIC commences Federal Court proceedings against Australian Clinical Labs Limited. 2023. Available at https://www.oaic.gov.au/newsroom/oaic-commences-federal-court-proceedings-against-australian-clinical-labs-limited [accessed 1 December 2023].
6 IBM Security. Cost of Data Breach Report. 2023. Available at https://mysecuritymarketplace.com/reports/cost-of-data-breach-report-2023 [accessed 25 September 2023].
7 VAGO. Security of Patients’ Hospital Data. 2019. Available at https://www.audit.vic.gov.au/report/security-patients-hospital-data?section=33170--3-effectiveness-of-data-security-in-health-services&show-sections=1#33170--3-effectiveness-of-data-security-in-health-services [accessed 29 September 2023].
8 Offner KL, Sitnikova E, Joiner K, et al. Towards understanding cybersecurity capability in Australian healthcare organisations: a systematic review of recent trends, threats and mitigation. Intellig Nat Secur 2020; 35: 556-585.
| Crossref | Google Scholar |
9 Papoutsi C, Reed JE, Marston C, et al. Patient and public views about the security and privacy of Electronic Health Records (EHRs) in the UK: results from a mixed methods study. BMC Med Inform Decis Mak 2015; 15: 86.
| Crossref | Google Scholar |
10 Entzeridou E, Markopoulou E, Mollaki V. Public and physician’s expectations and ethical concerns about electronic health record: Benefits outweigh risks except for information security. Int J Med Inform 2018; 110: 98-107.
| Crossref | Google Scholar |
11 ABC. Hackers claim they demanded $15 million ransom as more Medibank customer data posted to dark web. 2022. Available at https://www.abc.net.au/news/2022-11-10/medibank-data-breach-latest/101637160 [accessed 25 September 2023].
12 Chen M, Cheung ASY, Chan KL. Doxing: What Adolescents Look for and Their Intentions. Int J Environ Res Public Health 2019; 16: 218.
| Crossref | Google Scholar |
13 Clifford T. Provider liability and medical identity theft: can I get your (insurance) number? Northwestern J Law Policy 2016; 12: 45-68.
| Google Scholar |
14 Medibank Private Limited. Cyber Response Support Program. 2023. Available at https://www.medibank.com.au/health-insurance/info/cyber-security/cyber-support/ [accessed 1 December 2023].
15 US Department of Health and Human Services. Health information privacy. 2023. Available at https://www.hhs.gov/hipaa/for-professionals/index.html [accessed 11 October 2023].