Skip to main content
Subscribe
  • Login
  • My Account
  • Logout
  • Register For Free
  • Subscribe
  • News
    • Current News
    • Providers
    • Insurance
    • Government
    • Finance
    • Technology
    • Safety & Quality
    • Digital Health
    • Transformation
    • ESG
    • People
    • Regional News
    • Digital Edition (Web Version)
    • Patients
    • Operations
    • Care Delivery
    • Payment
    • Midwest
    • Northeast
    • South
    • West
  • Blogs
    • AI
    • Deals
    • Layoff Tracker
    • HLTH 2024
    • Sponsored Content: Vital Signs Blog
  • Opinion
    • Letters
    • From the Editor
  • Events & Awards
    • Awards
    • Conferences
    • Galas
    • Virtual Briefings
    • Webinars
    • Nominate/Eligibility
    • 100 Most Influential People
    • 50 Most Influential Clinical Executives
    • 40 Under 40
    • Best Places to Work in Healthcare
    • Healthcare Marketing Impact Awards
    • Innovators Awards
    • Diversity Leaders
    • Leading Women
    • Best in Business Awards
    • The 2030 Playbook Conference
    • Innovations in Patient Experience
    • Leading Women Conference & Awards Luncheon
    • Leadership Summit
    • Workforce Summit
    • Best Places to Work Awards Gala
    • - Looking Ahead to 2025
    • - Financial Growth
    • - Hospital of the Future
    • - Value Based Care
    • - Looking Ahead to 2026
  • Multimedia
    • Podcast - Beyond the Byline
    • Sponsored Podcast - Healthcare Insider
    • Sponsored Video Series - One on One
    • Sponsored Video Series - Checking In with Dan Peres
  • Data & Insights
    • Data & Insights Home
    • Hospital Financials
    • Staffing & Compensation
    • Quality & Safety
    • Mergers & Acquisitions
    • Skilled Nursing Facilities
    • Data Archive
    • Resource Guide: By the Numbers
    • Surveys
    • Data Points
  • Newsletters
  • MORE+
    • Contact Us
    • Advertise
    • Media Kit
    • Jobs
    • People on the Move
    • Reprints & Licensing
    • Sponsored Content
MENU
Breadcrumb
  1. Home
  2. Providers
August 30, 2013 12:00 AM

Advocate data breach highlights lack of encryption, a widespread issue

Joseph Conn
  • Tweet
  • Share
  • Share
  • Email
  • More
    Reprints Print

    (Article updated at 7:45 p.m. ET.)

    One warm night in mid-July, more than 4 million patient records breezed out the door of the Advocate Medical Group administrative office in Park Ridge, Ill., in the arms of an unidentified thief who stole four computers from the largest medical group in Illinois. The 1,100-physician medical group is part of the 11-hospital Advocate Health Care system.

    Because those records were kept on four stolen computers that were not protected by encryption, if a summary of that event gets posted to the “wall of shame” website kept by the Office for Civil Rights at HHS, which most likely it will, it will rank as the largest breach of federally protected records by a healthcare provider in U.S. history—at least in the history of the Office for Civil Rights' breach list, which the HHS agency has been required to publicly post since September 2009 under the American Recovery and Reinvestment Act.

    Penalties in the form of settlement agreements for breaches of this magnitude in recent years have run to $1 million or more.

    “It's a huge breach,” said Tom Walsh, principal of Tom Walsh Consulting, Overland Park, Kan. This is likely to be the second trip to the OCR wall for Advocate. The theft of a laptop back in November 2009 also made the list because it, too, was unencrypted. The stolen laptop had the medical records of 812 individuals on board.

    In an Aug. 23 statement, Advocate announced the breach, adding that it had sent letters to the affected patients and had offered them one year of credit monitoring. Advocate also said it had “reinforced our security protocols and encryption program with associates.” An Advocate spokeswoman said an encryption program launched by the organization in 2009 had not reached the four computers in the Park Ridge office.

    Susan McAndrew, deputy director for health information privacy at the Office for Civil Rights, confirmed the agency, which has privacy and security rule enforcement authority under the Health Insurance Portability and Accountability Act, had received a breach report from Advocate and has referred it to its regional office in Chicago for investigation.

    Maura Possley, spokeswoman for Illinois Attorney General Lisa Madigan, said the attorney general's office is also investigating the Advocate breach incident for potential violations under HIPAA and the Illinois Consumer Fraud and Deceptive Business Practices Act.

    The costs to Advocate of this latest breach are likely to be substantial.

    “You can imagine the extent of the forensic analysis to uncover what was on those hard drives,” said Kelly Jo Golson, senior vice president and chief marketing officer for Advocate Health Care, based in Downers Grove, Ill. “To the best of our knowledge, this data goes back to the early 1990s.”

    “We established the call center, we set up the website,” Golson said. Advocate also sent out more than 4 million letters to affected patients and even hired 24/7 security guard coverage at its Park Ridge administrative office and is reviewing the need for physical security throughout the organization.

    Golson said Advocate hasn't tallied up the costs of the breach. “At some point, we'll look at the financial implications, but we're not there yet.”

    So far, there has been no recovery of the computers or an arrest.

    Golson said Advocate embarked on a program of encrypting its computers in 2009, the year the laptop went missing. The initial target was to encrypt “all new laptops and all old ones that were able to be encrypted.” Next, the hospital started on desktop computers, again, ensuring all new ones were encrypted and “we began a process to encrypt old ones.”

    Golson said she didn't know the number of computers Advocate uses at its more than 250 care sites. “We do have 35,000 associates across the Advocate enterprise, so it's a large number.”

    Golson said the data types in the stolen records varied. Some included Social Security numbers or medical record numbers, for example, while others did not. The data was used for primarily operational and administrative purposes” such as appointments scheduling, benefits verification, coordination of care and patient registration.

    Those data elements, while limited, still would be sufficient for medical identity theft, said Pam Dixon, founder and executive director of the World Privacy Forum.

    In two online public statements, Advocate said the breach involved “no patient medical records” and it “has no impact on patient care.”

    “We are certainly not trying to state that this information couldn't be used inappropriately,” Golson said. “We just wanted to assure folks it wasn't the level of information that's include in a full medical record. We understand why our patients are concerned. We deeply regret this.”

    According to Walsh, given the risk of storing data without encryption and the relatively low cost to encrypt—about $55 per computer—it's hard to accept the lack of encryption on purely the cost of installing encryption software. Data handlers are supposed to be in compliance with HIPAA's security standards.

    Only 64% of healthcare organizations—both hospitals and office based physician practices—use encryption when they transmit healthcare information, according to a survey conducted in 2012 by the Healthcare Information and Management Systems Society, said Lisa Gallagher, vice president, technology solutions for HIMSS

    Advocates of encryption say there is a people problem in convincing physician groups to use encryption. “Their eyes kinda of glaze over,” he said. “They don't have anybody that's technically qualified. It's generally going to fall to the practice manager who's going to be the compliance officer, the privacy officer, the security officer and every other thing they have to do, including running a practice.”

    Walsh said he's also heard grumbling, “If you put full-disk encryption on, and you boot up, it slows the boot up the process.” Walsh said it might require two passwords, one for encryption and one for the operating system. “A lot of times people think that's inconvenient.” But with the latest Windows operating system, disk encryption is available as an option. All that needs be done is to turn it on, he said.

    For a big group like Advocate, not addressing encryption is another story. “I just can't understand how an organization could have allowed that to occur,” Walsh said. “They should have identified this through their risk analysis years ago, and it should have been remediated.”

    The record for the all-time largest HIPAA breach for any entity thus far goes to Science Applications International Corp., the business associate of a HIPAA-covered entity, Tricare Management Activity, the Defense Department's health insurer. In 2011, an SAIC employee reportedly had backup tapes stolen from his parked car in San Antonio. Those unencrypted tapes bore the records of 4.9 million active duty and retired military personnel covered by Tricare.

    If lack of encryption seems to be a common theme running through these three breach incidents, there's good reason.

    There are currently 659 breaches on the OCR list. In each, the records of 500 or more individuals have been exposed. Combined, they account for more than 22.8 million records breached. Of the listed breaches involving unencrypted computers or other electronic devices, 48% of the incident reports mention theft, 11% loss; and 8% hacking, all events that encryption might have mitigated.

    Encryption won't by itself solve all of the healthcare industry's medical records security problems—nearly 1 in 4 reported breaches (24%) on the Office for Civil Rights list involved paper records. But encrypting electronic records would go a long way toward keeping a healthcare organization out of hot water with the feds. Under HIPAA, data that are sufficiently encrypted to be rendered “unusable, unreadable or indecipherable” make it unnecessary to file a breach notification, for example.

    Gallagher said her organization is about to begin this year's survey and should have results by December. With more rigorous enforcement of the HIPAA security rule in recent years, Gallagher said she hopes to see a rise in encryption usage.

    Follow Joseph Conn on Twitter: @MHJConn

    Letter
    to the
    Editor

    Send us a letter

    Have an opinion about this story? Click here to submit a Letter to the Editor, and we may publish it in print.

    Recommended for You
    mh-20250516-patient-experience2
    How providers are tying patient experience to the bottom line
    mh-20250512-David-Dill-Lifepoint
    Lifepoint Health eyes expansion despite uncertain environment
    Most Popular
    1
    Here are new state healthcare laws taking effect in 2025
    2
    Best Places to Work in Healthcare - 2025 (alphabetical list)
    3
    Downside risk, upside payment highlight new CMS innovation agenda
    4
    UnitedHealth Group to cut Medicare drug plan commissions
    5
    GE HealthCare debuts new MRI for cardiac and oncology imaging
    Sponsored Content
    Modern Healthcare A.M. Newsletter: Sign up to receive a comprehensive weekday morning newsletter designed for busy healthcare executives who need the latest and most important healthcare news and analysis.
    Get Newsletters

    Sign up for enewsletters and alerts to receive breaking news and in-depth coverage of healthcare events and trends, as they happen, right to your inbox.

    Subscribe Today
    MH Magazine Cover

    MH magazine offers content that sheds light on healthcare leaders’ complex choices and touch points—from strategy, governance, leadership development and finance to operations, clinical care, and marketing.

    Subscribe
    Connect with Us
    • LinkedIn
    • Twitter
    • Facebook
    • RSS

    Our Mission

    Modern Healthcare empowers industry leaders to succeed by providing unbiased reporting of the news, insights, analysis and data.

    Contact Us

    (877) 812-1581

    Email us

     

    Resources
    • Contact Us
    • Help Center
    • Advertise with Us
    • Ad Choices
    • Sitemap
    Editorial Dept
    • Submission Guidelines
    • Code of Ethics
    • Awards
    • About Us
    Legal
    • Terms and Conditions
    • Privacy Policy
    • Privacy Request
    Modern Healthcare
    Copyright © 1996-2025. Crain Communications, Inc. All Rights Reserved.
    • News
      • Current News
      • Providers
      • Insurance
      • Government
      • Finance
      • Technology
      • Safety & Quality
      • Digital Health
      • Transformation
        • Patients
        • Operations
        • Care Delivery
        • Payment
      • ESG
      • People
      • Regional News
        • Midwest
        • Northeast
        • South
        • West
      • Digital Edition (Web Version)
    • Blogs
      • AI
      • Deals
      • Layoff Tracker
      • HLTH 2024
      • Sponsored Content: Vital Signs Blog
    • Opinion
      • Letters
      • From the Editor
    • Events & Awards
      • Awards
        • Nominate/Eligibility
        • 100 Most Influential People
        • 50 Most Influential Clinical Executives
        • 40 Under 40
        • Best Places to Work in Healthcare
        • Healthcare Marketing Impact Awards
        • Innovators Awards
        • Diversity Leaders
        • Leading Women
        • Best in Business Awards
      • Conferences
        • The 2030 Playbook Conference
        • Innovations in Patient Experience
        • Leading Women Conference & Awards Luncheon
        • Leadership Summit
        • Workforce Summit
      • Galas
        • Best Places to Work Awards Gala
      • Virtual Briefings
        • - Looking Ahead to 2025
        • - Financial Growth
        • - Hospital of the Future
        • - Value Based Care
        • - Looking Ahead to 2026
      • Webinars
    • Multimedia
      • Podcast - Beyond the Byline
      • Sponsored Podcast - Healthcare Insider
      • Sponsored Video Series - One on One
      • Sponsored Video Series - Checking In with Dan Peres
    • Data & Insights
      • Data & Insights Home
      • Hospital Financials
      • Staffing & Compensation
      • Quality & Safety
      • Mergers & Acquisitions
      • Skilled Nursing Facilities
      • Data Archive
      • Resource Guide: By the Numbers
      • Surveys
      • Data Points
    • Newsletters
    • MORE+
      • Contact Us
      • Advertise
      • Media Kit
      • Jobs
      • People on the Move
      • Reprints & Licensing
      • Sponsored Content