In 2020, Babylon Health, a telehealth app based in the United Kingdom, had a breach. Patients
using their general practitioner platform had access to videos of other patients' appointments.
A patient that used the app announced on Twitter that he could view the videos of
approximately 50 patients. The company reported that they found out about the issue shortly
before the patient made his announcement on Twitter. The company reported that they found
the issue and fixed it within 2 hours. They stated it was a software error but did not provide the
specific error. Babylon Health reached out to the affected patients to inform them.
Cybercriminals could have easily accessed these videos and used the patients’ information.
With an increase in the use of telehealth apps since COVID began, this raises security
concerns. Companies must ensure that all aspects of their software and platforms are secure
(Davis, 2020). Appointments completed through a telehealth platform are bound by HIPAA
regulations. This situation violated HIPAA regulations due to unauthorized individuals
accessing patient information.
The healthcare industry collects and stores valuable information, such as birthdates, social
security numbers, financial and health information, making it vulnerable to cyber-attacks.
Several technological tools assist healthcare organizations in preventing breaches. One of the
most critical steps is regularly scheduled risk analyses of the current systems to check for
vulnerabilities. It is vital to implement access controls. Access to information should be based
on an employee’s role and functions. The employee must be identified so the organization can
track their activities. Audit trails can be completed to check the information an employee has
accessed, and any changes made. There should be policies regarding logging on and off the
system. Networks can be segmented for specific users, like a sub-network that patients and
visitors would use separate from the healthcare personnel. Encrypting data will ensure the
integrity of the data and keep the information secure. The Breach Notification Rule states that
it is not considered a breach if encrypted data is lost because it is secure (Sahoo, 2021).
Mobile health has expanded in the last few years. Specialty offices are even using video
conference and health apps to monitor patients. A study was done in Amsterdam to view
cardiac patient experiences with mobile health. The patients would be able to monitor their
vital signs and the provider would get the data sent to them, by the application. As explained
by Kauw et al. (2020), a patient that is having heart palpitations can do an EKG on their watch
and send the information to their cardiologist to review. Each participant of the study was
signed up through mHealth and the provider received the information from the site. There
were some barriers with mHealth, not all mHealth applications integrated in the electronic
medical record. Making this difficult for the provider to review the data.
Healthcare data breaches can happen at any time and in many ways. There are cyber-attacks,
phishing, ransomware, malware, and medical identity theft. As described by Drury, T (2019),
a survey of 322 cybersecurity professionals in healthcare showed at least one breach at their
place of work in the last two years. With cloud technology, third party vendors are used, and
healthcare organizations are making sure their standards meet their needs. Being able to use
audit trails can help a healthcare organization better prepare for breaches. Being able to track
that a staff member who works as a scheduler is looking at patient discharge summaries, can
help the practice. If there is a policy in place stating that job roles have access to different parts
of the electronic health record (EHR), this scheduler will need to be spoke to and possibly
retrained. Audits can also help define which employees should get access to which parts of the
EHR. This can help IT put permissions on an employee’s access within the EHR.
Healthcare data is valuable on the black market because it often contains all of an individual’s
personally identifiable information, as opposed to a single piece of information that may be
found in a financial breach. Often these attacks see hundreds of thousands of patient’s data and
privacy compromised or stolen by those with malicious intent.
Mobile health apps leak sensitive data through APIs
30 mobile health apps to highlight the threats they face through application program interfaces
(APIs). ll of the apps were found to be vulnerable to API attacks, and some allowed access to
electronic health records (EHRs). The 30 apps collectively expose 23 million mobile health
users to attacks, Knight reported. Of the 30 apps tests, 77% contained hardcoded API keys, of
which some do not expire, according to the report, and 7% had hardcoded usernames and
passwords. APIs allow mobile phones to access X-rays, pathology reports and allergy data.
The COVID-19 pandemic has accelerated the use of mobile health apps and virtual care, and
this push motivated.
An API is an Application Programming Interface. API’s transmit data between software
products. The researcher’s findings showed that 100 percent of API endpoints were
susceptible to Broken Object Level Authorization (BOLA) attacks. She was able to see
personally identifying information and personal health information that was not authorized in
the clinician account the researcher used. It is imperative to secure apps before they are
produced and launched for public testing and use.
“With APIs providing access to the most coveted health data, it is urgent that we secure these
APIs,” said Ben Denkers, senior vice president, security and privacy services at cybersecurity
consulting firm CynergisTek.
946 UNC patients' billing info is potentially exposed by unauthorized account access
Chapel Hill, N.C.-based UNC Health is notifying 946 patients that billing information linked
to their accounts might have been accessed by another person who was incorrectly given
access.
UNC Health discovered their billing system contained incorrect authorization information in
the billing portion of their patient’s EHR account. This breach affected the billing
authorization field that normally contains a patient’s relative name or someone they trust.
Furthermore, when a name is present in this field, it gives the individual the ability to access
the patient’s billing information. After the investigation, UNC stated credit card information,
Social Security numbers, and payer identification numbers were not compromised. The
patients were comprised because the unauthorized user gained access to UNC EHR. A billing
data field was altered which granted access to an unauthorized person that the patient did not
know. When billing data is breached, there is always a possibility of financial loss to the
patient. However, UNC states there is no reason to believe any affected patients are or will be
at financial risk because of the breach. UNC has since implemented changes to its EHR system
to prevent future breaches. They immediately reset the billing field that contained the
inaccurate information. They also, upgraded their EHR administration to limit the number of
people that will be authorized to access and or update this field. Assigning risk management
tasks throughout your organization makes it less likely that threats will slip through the cracks.
Mobile health apps (MHAs) and medical apps (MAs) are becoming increasingly popular as
digital interventions in a wide range of health-related applications in almost all sectors of
healthcare. The surge in demand for digital medical solutions has been accelerated by the need
for new diagnostic and therapeutic methods in the current coronavirus disease 2019 pandemic.
This also applies to clinical practice in Gastroenterology, which has, in many respects,
undergone a recent digital transformation with numerous consequences that will impact
patients and health care professionals soon. MHAs and MAs are considered to have great
potential, especially for chronic diseases, as they can support the self-management of patients
in many ways. Despite the great potential associated with the application of MHAs and MAs
in Gastroenterology and health care in general, there are numerous challenges to be met in the
future, including both the ethical and legal aspects of applying this technology. The aim of this
article is to provide an overview of the status of MHA and MA use in the field of
Gastroenterology, describe the future perspectives in this field and point out some of the
challenges that need to be addressed.
Anthem, the second largest health insurance company in the U.S., announced a massive data
breach on Feb. 5. An estimated 80 million customers and employees of multiple health plans
were affected, the Wall Street Journal reported.
In addition to big name breaches over the past year including Target,Home Depot, and JP
Morgan, almost half of U.S. companies have experienced a security breach of some sort in the
past year, according to a report published by the Ponemon Institute in September 2014. What’s
more, a report from the Identity Theft Resource Center found a record number of security
attacks in the U.S. in 2014.
The report also found that health and medical companies are becoming bigger targets,
accounting for 42.5 percent of reported breaches last year. And in healthcare attacks, the
stakes are higher.
Mobile health information technology is something that is continuously growing and changing
the way we care for patients. The idea of mobile health information technology was somewhat
jumpstarted when the pandemic was in full force. We had made progress with technologies
like mobile charts for patients inside of apps and wearable devices to help monitor health
status and conditions. Many of the apps and wearables have many lines of fine print which in
some cases results in your information being given to third-parties to use. e This poses a serious
ethical problem when it comes to the privacy and security of patient health information. The
designers/creators of these apps and wearables to need to consider that even though new
technology is our way forward, the risks of data compromise rise as much as the technology
advances.
To prevent security breaches such as cyber-attacks, phishing, ransomware, malware, medical
identity theft, and data breaches through the use of technological tools such as audit trails and
data quality monitoring programs organizations need to be aware of the constant threats that
are posed daily. A fully-functional IS/IT department with collaboration with the HIM
department can be your best defense against these types of attacks. e My organization sends out
random emails from outside the organization to test employees to see if they can spot phishing
emails. They also offer training opportunities in-person/virtually or on-demand learning in
which an employee can learn at their own pace. Since the beginning of the pandemic there
have also been a sharp rise in cybersecurity attacks on hospitals and organizations need to be
aware that there are targets on their backs. "However, when a patient’s PHI is stolen, the
patient cannot change, for example, their birthdate, blood type, and health and genetic
information. Once stolen, health information is widely applicable and valuable for a range of
crimes, from identity theft to medical fraud. An individual’s health information is valued
significantly more on the dark web than their social security number or credit card number; it
can sell for 10 to 20 times more than this type of data [7, 8]." (Argaw et al., 2020).
Argaw, S. T., Troncoso-Pastoriza, J. R., Lacey, D., Florin, M.-V., Calcavecchia, F., Anderson,
D., Burleson, W., Vogel, J.-M., O’Leary, C., Eshaya-Chauvin, B., & Flahault, A. (2020, July
3). Cybersecurity of hospitals: Discussing the challenges and working towards mitigating the
risks - BMC Medical Informatics and Decision making. BioMed Central. Retrieved May 31,
2022, from https://bmcmedinformdecismak.biomedcentral.com/articles/10.1186/s12911-020-
01161-7
Code of medical ethics - American medical association. (n.d.). Retrieved May 31, 2022, from
https://www.ama-assn.org/sites/ama-assn.org/files/corp/media-browser/code-of-medical-
ethics-chapter-10.pdf
WIRED. (2022). The Root of the Problem: How to Prevent Security Breaches.
https://www.wired.com/insights/2015/02/the-root-of-the-security-problem/
Kernebeck, S., Busse, T. S., Böttcher, M. D., Weitz, J., Ehlers, J., & Bork, U. (2020). Impact
of mobile health and medical applications on clinical practice in gastroenterology. World
journal of gastroenterology, 26(29), 4182–4197. https://doi.org/10.3748/wjg.v26.i29.4182
Fierce Healthcare. (2021, February 24). Mobile health apps leak sensitive data through APIs.
Retrieved June 2, 2022, from https://www.fiercehealthcare.com/tech/mobile-health-apps-leak-
sensitive-data-through-apis-report-finds
Mitchell, H. (2021, November 5). 946 UNC patients’ billing info potentially exposed by
unauthorized account access. Hannah Mitchell. Retrieved June 2, 2022, from
https://www.beckershospitalreview.com/cybersecurity/946-unc-patients-billing-info-
potentially-exposed-by-unauthorized-account-access.html
Secure Link, Inc. (2022, May 6). The Value of Healthcare Data. Secure Link. Retrieved June
2, 2022, from https://www.securelink.com/blog/healthcare-data-new-prize-
hackers/#:%7E:text=Healthcare%20data%20is%20valuable%20on%20the%20black%20mar
ket,compromised%20or%20stolen%20by%20those%20with%20malicious%20intent.
Drury, T. (2019, July 15). Preventing health care breaches, lawsuits. Buffalo Law Journal,
91(28), 13–22.
Kauw, D., Huisma, P. R., Medlock, S. K., Koole, M. A., Wierda, E., Abu-Hanna, A., Schijven,
M. P., Mulder, B. J., Bouma, B. J., Winter, M. M., & Schuuring, M. J. (2020). Mobile Health
in Cardiac Patients: An overview on experiences and challenges of stakeholders involved in
daily use and development. BMJ Innovations, 6(4), 184–191.
https://doi.org/10.1136/bmjinnov-2019-000418
Davis, J. (2020, June 11). Breach of telehealth app Babylon health raises privacy concerns.
Health IT Security. https://healthitsecurity.com/news/breach-of-telehealth-app-babylon-
health-raises-privacy-concerns
Sahoo, N. (2021, June 30). How to prevent healthcare data breaches. Cyber Security
Intelligence. https://www.cybersecurityintelligence.com/blog/how-to-prevent-healthcare-
data-breaches--5723.html