Where is the Risk? Analysis of Government Reported Patient Medical Data Breaches
Suzanna Schmeelk · 2019
Managing healthcare organizational cybersecurity risk is complex. This work examines government reported patient health data breaches to learn more about trends in reported breaches to inform organizational risk budgeting, trends and focus areas. In many cases, organizations only have enough time to survive daily risk management activities. They all too often have little, if any, time for actual risk management research beyond third-party vendor threat intelligence. Our research fills this gap by analyzing the breach data reported to the United States (US) Health and Human Services (HHS) Office of Civil Rights (OCR) from May 1, 2018 until May 1, 2019. The analysis reports on trends from breach factors reported to the government to further inform cybersecurity patient health data risk management.