← Back to list

Why Securing Patient Data Under HIPAA is Important

In an interview with CNBC, cybersecurity researcher Jeremiah Fowler said that

Annaloisugbaka · 2025-02-08 01:58 · 0 claps · 2.8 min read
#hipaa-compliance #data-breach-protection #hipaa-violation #patient-data-security #data-breach-response-plan
Open on Medium ↗
Wiki topics: 🔒 · Cybersecurity

Why Securing Patient Data Under HIPAA is Important

Google Image

Google Image

In an interview with CNBC, cybersecurity researcher Jeremiah Fowler said that

“on the dark web, medical records sell for $60 compared to $15 for a Social Security number and $3 for a credit card”.

This statistic is very concerning. Now more than ever, securing patients’ data cannot be overemphasized. According to the Health Insurance Portability and Accountability Act of 1996 (HIPAA), healthcare providers and covered entities should proactively secure patients’ data.

Security breaches involving patient data can have many negative consequences for the victims. Years after the breach, many patients are still grappling with its effects. That’s why any organization handling patients’ data in any capacity, no matter how minor, should ALWAYS ensure that adequate steps are taken to protect patients’ data.

Steps to Safeguard Patients Data

A. Risk assessments to identify risks and vulnerabilities: Conduct a risk assessment to identify vulnerabilities in your process that could make patients’ data vulnerable to a breach. Physical methods of storing patients’ data, such as in a physical file, while tedious to manage and not readily available, are also not secure. It is also difficult to limit access to a physical file. If your patient’s data is stored in a database, you can conduct vulnerability testing to test how secure your patient’s data is using SAST (Software Application Testing Tools).

B. Migrate your data to a secure storage medium. In addition to speed, availability, and security, cloud storage enables organizations to store, access, and maintain data without the added hassles of building, securing, and maintaining their data centers.

C. Create a Risk Management Plan. A risk management plan can help your organization identify potential security risks and create a strategy to eliminate or reduce their impact. I outlined below the steps organizations covered under the HIPAA Act may take to minimize or eliminate risk.

  • One security risk you may face as a healthcare provider or covered entity under the HIPAA Act is hackers gaining entry into your patients’ database through an employee’s carelessness or ignorance. You can mitigate this risk by migrating your patients’ data to cloud storage, using advanced email protection, setting password authentication, logging users out of the cloud workspace after a period of inactivity, granting only necessary access to cloud users, and educating your employees on best security practices.
  • Another security risk is undetected database vulnerability: You can mitigate this risk by deleting all default settings in your server, detecting traffic anomalies early by monitoring and analyzing cloud log data, adding multiple layers of security to your network, implementing advanced encryption algorithm (AES), and appointing a dedicated security engineer to monitor your database.
  • Patient data must be readily available when needed in compliance with the HIPAA Act. Hackers can deploy a Distributed Denial of Service (DDOS) attack to make your data unavailable to authorized users. To eliminate this risk, set up DDOS protection, deploy your servers in separate networks, and back up your data in multiple locations or with multiple cloud providers.
  • Sometimes, a data breach can happen due to the fault of a third-party provider. In this case, you had no power to prevent the breach. You can protect your organization by signing a Business Associate Agreement (BAA) with the third-party provider at the start of your contract, absolving your organization from all responsibility and assigning the blame and cost to the third party where the breach is from their end.
  • Finally, get insured. Sometimes, even the best-laid plans may go awry. Get insured for the times when your best effort to prevent security breaches is not enough.

Where Data Has Been Breached

Where your patient’s data has already been breached:

  • Investigate the breach. You may even need to call forensic experts to investigate. Follow the HIPAA compliance rules (where applicable) regarding methods of investigation.
  • Report the breach to victims promptly and provide details. Follow the HIPAA compliance rules (where applicable) regarding methods of investigation.
  • Implement security measures in your organization to ensure that such breaches do not reoccur.

Reflection

Does your organization have a risk mitigation management plan that identifies potential security risks?

How important is securing patient data to your organization?


메타데이터
post_id
d18ec783ef8e
slug
why-securing-patient-data-under-hipaa-is-important-d18ec783ef8e
url
https://medium.com/@annaloisugbaka/why-securing-patient-data-under-hipaa-is-important-d18ec783ef8e
canonical_url
https://medium.com/@annaloisugbaka/why-securing-patient-data-under-hipaa-is-important-d18ec783ef8e
author_url
https://medium.com/@annaloisugbaka
status
ok
fetched_at
2026-06-22 12:55:45