May 2023 Healthcare Breach Report

Each month, we review healthcare breaches posted on the Office for Civil Rights (OCR) online breach portal to determine the leading causes and how the incidents could have been prevented. The OCR publicly posts healthcare breaches that affected 500 or more individuals to ensure that all affected patients know their information could have been potentially compromised.

In May 2023, there were 75 breaches reported affecting 19,044,544 patients.

  • 36 healthcare providers reported breaches, affecting 6,512,403 which was 34.20% of records breached in May
  • 25 business associates reported breaches, affecting 9,648,884 which was 50.66% of records breached in May
  • 15 health plans reported breaches, affecting 2,883,257 which was 15.14% of records breached in May

May 2023 Healthcare Breaches and Hacking

There were 61 hacking incidents reported in May that affected the PHI of 18,956,101 patients. These 61 incidents represented 99.54% of all documented records breached during the month.

How to Prevent Hacking Incidents

As hacking incidents have become the leading cause behind healthcare breaches for several years, minimizing your risk of being targeted is crucial.

Security Risk Assessments and Remediation

Security risk assessments (SRAs) are vital for security and compliance. An SRA aims to identify weaknesses and vulnerabilities in your security practices to prepare yourself against potential threats. Once SRAs have been conducted, it is essential to create remediation plans to address any identified deficiencies.

Employee Cybersecurity Training

A significant portion of hacking incidents results from phishing emails. Employee cybersecurity training is essential to your organization’s overall security posture. Employees should be trained on recognizing phishing attempts and what to do if they suspect an incident has occurred.

Rated #1 on G2

“Compliancy Group makes a highly complex process easy to understand.”

G2 Easiest to Do Business With

May 2023 Healthcare Breaches and Unauthorized Access or Disclosure

Incidents of unauthorized access or disclosures of PHI can occur in two ways – an authorized employee accesses PHI inappropriately, or an unauthorized party gains access to PHI. May 2023 recorded 11 incidents of unauthorized access or disclosure of PHI. These incidents affected 82,236 patients, representing 0.43% of the breached records reported in May.

How to Prevent Unauthorized Access or Disclosure

As we mentioned, there are two ways in which unauthorized access or disclosures occur – inappropriate employee access or unauthorized access by another entity.

Policies and Procedures and Employee Training

HIPAA policies and procedures are essential to HIPAA compliance as they guide employees on what is appropriate. HIPAA requires employee use and disclosure of PHI to be limited to the minimum necessary to perform their job functions. Your policies and procedures should dictate this, and employees should be trained on the policies and procedures to be aware of their obligations. 

User Authentication, Access Controls, and Audit Controls

To ensure adherence to the minimum necessary standard, you must implement user authentication, access controls, and audit controls. User authentication provides unique login credentials for each employee, while access controls enable administrators to designate different PHI access levels using those unique login credentials. Also, based on the implementation of unique login credentials, audit controls track access to data to ensure that PHI is accessed appropriately by each employee.

May 2023 Healthcare Breaches and Other Causes

In May 2023, there were two incidents of PHI theft reported, affecting 5,632 patients, representing 0.03% of records breached that month. The best way to prevent PHI theft is through access controls, audit controls, security measures that limit PHI access, and employee training.

Are you using HIPAA compliant tools?

Make sure you’re following all of the HIPAA rules.