Estimating Financial Damage Often Difficult
Dom Nicastro just posted an article on HealthLeaders Media titled “HITRUST: HIPAA Breaches Near $1 Billion.”
http://www.healthleadersmedia.com/content/TEC-255015/HITRUST-HIPAA-Breaches-Near-1-Billion##
“Covered entities and business associates reporting breaches of unsecured personal health information (PHI) affecting 500 or more individuals to the Office for Civil Rights (OCR) together could spend nearly $1 billion because of those breaches.” Nicastro continues:
“HITRUST used the 2009 Ponemon Institute study that found the average cost for a compromised record to be approximately $144 in indirect costs and $60 of direct costs, for a total cost of $204.”
Fort Worth Star-Telegram
Just days ago, Jan Jarvis described a data breach in the Fort Worth Star-Telegram titled “Fort Worth medical clinic spends $15,000 notifying patients of theft.”
http://www.star-telegram.com/2010/08/06/2389717/fort-worth-medical-clinic-spends.html#ixzz0wIaU5AQa
Jarvis writes,
“In June, employees at a Fort Worth allergy clinic discovered that the office door had been kicked in and four computers containing patients’ personal information including Social Security numbers and birth dates had been stolen.”
Jarvis reports that 25,000 records were involved, and it only cost $15,000 to notify them. That’s only 60 cents per record instead of 60 dollars each as estimated by the Ponemon Institute. Instead of it costing the clinic $1.5 million for direct costs, it only cost them $15,000. That’s a savings of 99%.
Assessment
So what’s the deal? Is the Ponemon Institute that far off in their estimates?
Conclusion
Your thoughts and comments on this ME-P are appreciated. Feel free to review our top-left column, and top-right sidebar materials, links, URLs and related websites, too. Then, subscribe to the ME-P. It is fast, free and secure.
Link: http://feeds.feedburner.com/HealthcareFinancialsthePostForcxos
Speaker: If you need a moderator or speaker for an upcoming event, Dr. David E. Marcinko; MBA – Publisher-in-Chief of the Medical Executive-Post – is available for seminar or speaking engagements. Contact: MarcinkoAdvisors@msn.com
OUR OTHER PRINT BOOKS AND RELATED INFORMATION SOURCES:
DICTIONARIES: http://www.springerpub.com/Search/marcinko
PHYSICIANS: www.MedicalBusinessAdvisors.com
PRACTICES: www.BusinessofMedicalPractice.com
HOSPITALS: http://www.crcpress.com/product/isbn/9781466558731
CLINICS: http://www.crcpress.com/product/isbn/9781439879900
BLOG: www.MedicalExecutivePost.com
FINANCE: Financial Planning for Physicians and Advisors
INSURANCE: Risk Management and Insurance Strategies for Physicians and Advisors
Filed under: Information Technology, Practice Management, Pruitt's Platform, Research & Development | Tagged: Dom Nicastro, eDRs, EHRs, EMRs, Healthcare Data Breaches, HealthLeaders Media, HIPAA, Jan Jarvis, OCR, PHI, Ponemon Institute | 11 Comments »














