Most Popular Stories
Featured Jobs
-
Electronic Health Records Application Support Manager RN-New Year New Career
Avanti on behalf of Respected Health System - San Francisco, CA -
ICD-10 Revenue Cycle, Manager
Meditology Services - Atlanta, GA
Events
- 3rd Healthcare IT Innovation Asia
Mar 14-15 2012 — Singapore - Medical Devices Summit 2012
March 6-7 2012 — The Boston Park Plaza Hotel & Towers, Boston, MA - IHI's Transforming the Primary Care Practice
May 1-3, 2012 — San Diego, CA - Complimentary Webinar: Making Public Data Work for You
March 1, 2012 11am
Paid Research Reports
- Electronic health records: getting it right first time
- Cloud Computing Adoption In The APAC Life Sciences Industry
- Stakeholder Opinions: Ophthalmology - Leading brands under threat
- Genomics, Proteomics and Metabolomics in Diagnostics: Market landscape, innovative technologies and future outlook
- Healthcare Regulatory Update: The United Arab Emirates
- Point of Care Testing: Evaluating the return to evidence based medicine, novel technologies and the competitive landscape
Free Newsletter
Latest News
Free Newsletter
FierceHealthIT is the leading source of Healthcare IT news with a special focus on CPOE, EMR adoption, HIPAA compliance and other critical areas. Join 44,00 healthcare industry insiders who get FierceHealthIT via daily email for their must know IT news. Sign up today!
About | View Sample | Privacy
Top Tags
Whitepapers
- On Your Side: How Outsourced Billing can Strengthen Your Practice
- Meaningful Use Requirements for Patient Education
- Reducing Contralateral Breast Dose using TomoDirectâ„¢ and Daily MVCT Imaging
- Improving Heart Failure Outcomes through Interactive Patient Care: The Sentara Virginia Beach General Hospital Experience
- Invaluable insight led us to $2.5 million in savings in less than one-year
- Leveraging Uptime and Availability to Improve Productivity with EMR/EHR
Hospital use of data breach insurance increases as incidents multiply
With all of the health data breaches reported recently, it's not surprising that more and healthcare providers have been purchasing data breach insurance, aka cyber insurance or network security insurance. While this kind of coverage won't stop anybody from stealing or losing personal health information, it could help hospital executives sleep a whole lot better.
Larry Harb, president and CEO of Okemos, Mich.-based IT Risk Managers, told FierceHealthIT that his company's revenue from data breach insurance has increased in double-digits for 10 of the 12 years the firm has been in business. Lately, with the rapid growth in digitized clinical data, sales have accelerated even more, he said.
Cyber insurance actually dates back to the late 1990s, when companies began to realize that traditional property insurance didn't cover data loss or theft. Up to that point, Harb said, insurance claims could be triggered only when there was physical damage, such as that caused by a fire or an auto accident. So insurers began writing new policies that specifically covered data and the harm caused by losing control over it.
The kind of information covered by data breach insurance does not necessarily have to be online or on electronic media. For example, Harb noted, Massachusetts General Hospital was sued in 2009 after an employee left a printout containing names of HIV-positive patients on a train. In addition, MGH had to pay a fine for a HIPAA violation.
Data breach policies cover HIPAA fines and penalties, according to Harb. They also pay defense costs if somebody sues a healthcare provider, and they may cover judgments, as well. These kinds of suits, he added, usually are class actions, which require a minimum of 20 plaintiffs. Most cyber insurance covers class action suits.
However, he pointed out, "there are no standardized data breach policies. Every policy is different. When we write a policy for a hospital, we're going to customize that policy to meet the needs of the client."
Big property and casualty insurers underwrite most of these policies, noted Harb. Among them are Lloyds of London, Chartis (formerly AIG), Hitchcock and Beazley.
Cyber insurance usually covers "third party liability" for damages to parties other than the insured. But some policies also cover the hospital itself for the costs involved in patient notification, reimbursement of victims and so forth, Harb said.
Business associates of providers cause many data breaches. Last September, for instance, Stanford University Hospital discovered that a billing contractor had inadvertently posted a spreadsheet containing information on 20,000 of its ED patients on a public website. In that case, the billing service accepted responsibility for the data breach.
Harb observed that many contracts between hospitals and third parties now contain clauses that hold hospitals harmless for data breaches by those third parties. Whether or not a hospital is able to include such a clause depends on its negotiating power, he added. Without the indemnification clause, the liability for data loss belongs to the hospital.
Healthcare providers are becoming increasingly aware of their vulnerability to data breaches. Last year, according to the Ponemon Institute, reported incidents of data loss and theft increased by 32 percent.
"Every time there's a breach, more and more people jump onboard cyber insurance, because they say, 'This stuff can happen to me,'" Harb said.
To learn more:|
- read InformationWeek Healthcare piece on the need for cyber insurance
- check out the Privacy Rights Clearinghouse website
Related Articles:
Health data breaches cost $6.5 billion annually
Breach of info for 20K patients at Stanford underscores gaps in business associate security
Related Stories
- AHIMA to providers: Don't put brakes on ICD-10
- Speech recognition still a work in progress for radiologists
- CPOE, trend spotting integral to managing radiation
- Breach of info for 20K patients at Stanford underscores gaps in business associate security
- Civil Rights data access proposal unrealistic, expensive, CHIME says
- Data-mining tool helps to justify costly imaging tests
- SPOTLIGHT: How Partners HealthCare boosts med reconciliation
- Surescripts' reaction to e-prescribing study doesn't erase the need for improvement
- Digital certificates would give federal access to private providers
- OCR invites state AGs to gear up for HIPAA security crackdown
Home
| Subscribe | Advertise | Mobile Edition | RSS |
Privacy
| Site Map
| Editors | List in Marketplace | Supplier in MarketplaceTHE FIERCEMARKETS NETWORKFierceEnergy | FierceSmartGrid | FierceFinance | FierceFinanceIT | FierceComplianceIT | FierceHealthcare | FierceHealthFinance | FierceHealthIT | Hospital Impact | FierceMobileHealthcare | FierceHealthPayer | FiercePracticeManagement | FierceEMR | FierceCIO | FierceCIO:TechWatch | FierceContentManagement | FierceMobileIT | FierceGovernmentIT | FierceGovernment | FierceHomelandSecurity | FierceBiotech | FierceBiotech Research | FiercePharma | FierceVaccines | FierceBiotechIT | FiercePharma Manufacturing | FierceMedicalDevices | FierceDrugDelivery | FierceCRO | FierceIPTV | FierceOnlineVideo | FierceTelecom | FierceEnterpriseCommunications | FierceBroadbandWireless | FierceDeveloper | FierceMobileContent | FierceWireless | FierceWireless:Europe | FierceCable© 2012 FierceMarkets. All rights reserved. |
![]() |
