Survey: Orgs. Doing More Health Data Risk Analysis, Still Lack Breach Response Plan

Dec. 13, 2012
According to a new survey from the Healthcare Information and Management Systems Society (HIMSS), even as more healthcare organizations conduct annual security risk analyses to protect patient data, most are still without a data breach response plan. Thanks to incentives provided by the Centers for Medicare & Medicaid Services’ (CMS) meaningful use program, there is increased focus on data protection, say authors of the report, 2012 HIMSS Security Survey.

According to a new survey from the Healthcare Information and Management Systems Society (HIMSS), even as more healthcare organizations conduct annual security risk analyses to protect patient data, most are still without a data breach response plan. Thanks to incentives provided by the Centers for Medicare & Medicaid Services’ (CMS) meaningful use program, there is increased focus on data protection, say authors of the report, 2012 HIMSS Security Survey.

The study, of 303 individuals, included feedback from physician practices, standalone hospitals, healthcare systems, and what HIMSS calls a “variety of healthcare organizations.” Overall, 90 percent of respondents working at hospitals conduct an annual risk analysis. Of those at a physician practice, 65 percent of respondents said they conduct an annual risk analysis.

However, less than half of the organizations surveyed (43 percent) said they had a data breach response plan.  Also the overall IT security budget has remained largely unchanged since last year, the authors of the report found. Fifty-seven percent of the respondents indicated their organization used only a single method for controlling employee access to patient information. 

Of those surveyed, only 22 percent indicated they reported a security breach last year. This sharply contrasts the survey from The Ponemon Institute, which found 94 percent of healthcare organizations had suffered a data breach.  

“As our survey results indicate, more hospitals and physician practices have increased their emphasis on security of patient health data, but have more to accomplish when it comes to ongoing data security,”  Lisa Gallagher, senior director, privacy & security, HIMSS, said in a statement.

Sponsored Recommendations

ASK THE EXPERT: ServiceNow’s Erin Smithouser on what C-suite healthcare executives need to know about artificial intelligence

Generative artificial intelligence, also known as GenAI, learns from vast amounts of existing data and large language models to help healthcare organizations improve hospital ...

TEST: Ask the Expert: Is Your Patients' Understanding Putting You at Risk?

Effective health literacy in healthcare is essential for ensuring informed consent, reducing medical malpractice risks, and enhancing patient-provider communication. Unfortunately...

From Strategy to Action: The Power of Enterprise Value-Based Care

Ever wonder why your meticulously planned value-based care model hasn't moved beyond the concept stage? You're not alone! Transition from theory to practice with enterprise value...

State of the Market: Transforming Healthcare; Strategies for Building a Resilient and Adaptive Workforce

The U.S. healthcare system is facing critical challenges, including workforce shortages, high turnover, and regulatory pressures. This guide highlights the vital role of technology...