More organizations that collect protected health information are facing cyber-extortion plots, the U.S. Department of Health and Human Services (HHS) warns.
About 3.6 million records were involved in 146 hack-type breaches of medical organizations made public in 2017 alone, according to the Privacy Rights Clearinghouse, a nonprofit group based in San Diego.
Health care organizations store tens of millions of patients’ personal health information, which is highly regulated by the federal Health Insurance Portability and Accountability Act of 1996 (HIPAA). In spite of HIPAA safeguards, cyber-extortion attempts are not uncommon, according to HHS’s Office for Civil Rights, which is responsible for enforcing HIPAA.
(Related: Maybe HIPAA Protected You From WannaCry)
Breaches involving protected health information must be reported to HHS.
“Incidents of cyber extortion have risen steadily over the past couple of years and, by many estimates, will continue to be a major source of disruption for many organizations,” according to the Office for Civil Rights’ January newsletter. “Organizations that provide necessary services or maintain sensitive data, such as Healthcare and Public Health … sector organizations are often the targets of cyber-extortion attacks.”