A | B | C | D | E | F | G | H | I | J | K | L | M | N | O | P | Q | R | S | T | U | V | W | X | Y | Z | |
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1 | Calculating the average cost per individual affected by a hacking-related healthcare data breach | |||||||||||||||||||||||||
2 | ||||||||||||||||||||||||||
3 | According to IBM's 2022 "Cost of a Data Breach Report" the average healthcare data breach is $10.1 million. | |||||||||||||||||||||||||
4 | Analysis period for this report is set for March 2021 to March 2022 | |||||||||||||||||||||||||
5 | ||||||||||||||||||||||||||
6 | In order to understand how many individuals may have been affected and the estimated costs, we collected breach data from the U.S. Department of Health and Human Services Office for Civil Rights (HHS-OCR) reflecting the analysis period from the IBM report (March 2021 to March 2022, collected below). | |||||||||||||||||||||||||
7 | Average number of individuals affected: | 67,639 | ||||||||||||||||||||||||
8 | ||||||||||||||||||||||||||
9 | We then divided the estimated cost per data breach from IBM's analysis by the average number of individuals affected within the same analysis period. | |||||||||||||||||||||||||
10 | This provides us with an "estimated average cost per individual affected" which we can use to analze the estimated costs of breaches. | |||||||||||||||||||||||||
11 | ||||||||||||||||||||||||||
12 | IBM average cost of a healthcare data breach (March 2021 to March 2022) | HHS-OCR reported average number of individuals affected per breach from March 2021-2022 | Estimated average cost per individual affected = (IBM average cost of a healthcare breach) / (HHS-OCR reported average number of individuals affected per breach during IBM analysis period) | |||||||||||||||||||||||
13 | $10,100,000 | 67639 | $149 | |||||||||||||||||||||||
14 | ||||||||||||||||||||||||||
15 | ||||||||||||||||||||||||||
16 | ||||||||||||||||||||||||||
17 | ||||||||||||||||||||||||||
18 | HHS-OCR Breaches from March 2021 to March 2022 | |||||||||||||||||||||||||
19 | U.S. Department of Health and Human Services Office for Civil Rights - Total healthcare/hacking breaches collected from March 2021 to March 2022 | |||||||||||||||||||||||||
20 | ||||||||||||||||||||||||||
21 | Type | Name of Covered Entity | State | Covered Entity Type | Individuals Affected | Breach Submission Date | Type of Breach | Location of Breached Information | Business Associate Present | Cost of Breach | ||||||||||||||||
22 | UI | Urgent Team Holdings | TN | Healthcare Provider | 166601 | 3/31/2022 | Hacking/IT Incident | Network Server | No | $24,823,549 | ||||||||||||||||
23 | UI | Englewood Health | NJ | Healthcare Provider | 3901 | 3/30/2022 | Hacking/IT Incident | Network Server | No | $581,249 | ||||||||||||||||
24 | UI | Resources for Human Development | PA | Healthcare Provider | 46673 | 3/29/2022 | Theft | Other Portable Electronic Device | No | $6,954,277 | ||||||||||||||||
25 | UI | Super Care, Inc. dba SuperCare Health | CA | Healthcare Provider | 318379 | 3/28/2022 | Hacking/IT Incident | Network Server | No | $47,438,471 | ||||||||||||||||
26 | UI | Medical Surgical Eye Care | KS | Healthcare Provider | 2000 | 3/28/2022 | Hacking/IT Incident | Network Server | No | $298,000 | ||||||||||||||||
27 | UI | Law Enforcement Health Benefits, Inc. | PA | Health Plan | 85282 | 3/28/2022 | Hacking/IT Incident | Network Server | No | $12,707,018 | ||||||||||||||||
28 | UI | Charleston Area Medical Center, Inc. | WV | Healthcare Provider | 54000 | 3/28/2022 | Hacking/IT Incident | No | $8,046,000 | |||||||||||||||||
29 | UI | Colorado Physician Partners, PLLC | CO | Healthcare Provider | 12877 | 3/25/2022 | Hacking/IT Incident | No | $1,918,673 | |||||||||||||||||
30 | UI | Cytometry Specialists, Inc., d/b/a CSI Laboratories | GA | Healthcare Provider | 312000 | 3/25/2022 | Hacking/IT Incident | Network Server | No | $46,488,000 | ||||||||||||||||
31 | UI | Lutheran Social Services of Illinois | IL | Healthcare Provider | 1000 | 3/25/2022 | Hacking/IT Incident | Network Server | No | $149,000 | ||||||||||||||||
32 | UI | Christie Business Holdings Company, P.C. | IL | Healthcare Provider | 502869 | 3/25/2022 | Hacking/IT Incident | No | $74,927,481 | |||||||||||||||||
33 | UI | Thomas Allen, Inc. | MN | Healthcare Provider | 2803 | 3/23/2022 | Hacking/IT Incident | No | $417,647 | |||||||||||||||||
34 | UI | Advanced Medical Practice Management | NJ | Business Associate | 56427 | 3/23/2022 | Hacking/IT Incident | Network Server | Yes | $8,407,623 | ||||||||||||||||
35 | UI | Taylor Regional Hospital | KY | Healthcare Provider | 190209 | 3/21/2022 | Hacking/IT Incident | Network Server | No | $28,341,141 | ||||||||||||||||
36 | UI | Valley View Hospital Association | CO | Healthcare Provider | 501 | 3/19/2022 | Hacking/IT Incident | No | $74,649 | |||||||||||||||||
37 | UI | Cancer and Hematology Centers of Western Michigan | MI | Healthcare Provider | 43071 | 3/18/2022 | Hacking/IT Incident | Network Server | No | $6,417,579 | ||||||||||||||||
38 | UI | Clinic of North Texas, LLP | TX | Healthcare Provider | 244174 | 3/18/2022 | Hacking/IT Incident | Network Server | No | $36,381,926 | ||||||||||||||||
39 | UI | Wheeling Health Right Inc | WV | Healthcare Provider | 3912 | 3/18/2022 | Hacking/IT Incident | Network Server | No | $582,888 | ||||||||||||||||
40 | UI | Central Minnesota Mental Health Center | MN | Healthcare Provider | 28725 | 3/17/2022 | Hacking/IT Incident | No | $4,280,025 | |||||||||||||||||
41 | UI | Chelan Douglas Health District | WA | Healthcare Provider | 188236 | 3/15/2022 | Hacking/IT Incident | Network Server | No | $28,047,164 | ||||||||||||||||
42 | UI | Trinity Home Care, Inc. | MA | Healthcare Provider | 1541 | 3/14/2022 | Hacking/IT Incident | Network Server | No | $229,609 | ||||||||||||||||
43 | UI | Virginia Mason Medical Center | WA | Healthcare Provider | 2733 | 3/14/2022 | Hacking/IT Incident | No | $407,217 | |||||||||||||||||
44 | UI | Laboratorio Clinico Toledo | Healthcare Provider | 500 | 3/14/2022 | Hacking/IT Incident | Network Server | No | $74,500 | |||||||||||||||||
45 | UI | Labette Health | KS | Healthcare Provider | 85635 | 3/11/2022 | Hacking/IT Incident | Network Server | No | $12,759,615 | ||||||||||||||||
46 | UI | Major League Baseball Players Benefit Plan | MD | Health Plan | 13156 | 3/11/2022 | Hacking/IT Incident | Network Server | Yes | $1,960,244 | ||||||||||||||||
47 | UI | Capital Region Medical Center | MO | Healthcare Provider | 17578 | 3/11/2022 | Hacking/IT Incident | Network Server | No | $2,619,122 | ||||||||||||||||
48 | Archive | Local 295 IBT Employer Group Welfare Fund | NY | Health Plan | 6123 | 3/11/2022 | Hacking/IT Incident | Network Server | Yes | $912,327 | ||||||||||||||||
49 | UI | Highmark Inc | PA | Health Plan | 67147 | 3/11/2022 | Hacking/IT Incident | Network Server | Yes | $10,004,903 | ||||||||||||||||
50 | UI | Dialyze Direct, LLC | NJ | Healthcare Provider | 14203 | 3/10/2022 | Hacking/IT Incident | No | $2,116,247 | |||||||||||||||||
51 | UI | New Jersey Brain and Spine | NJ | Healthcare Provider | 92453 | 3/10/2022 | Hacking/IT Incident | Network Server | No | $13,775,497 | ||||||||||||||||
52 | UI | Gainwell Technologies, LLC | TX | Business Associate | 810 | 3/10/2022 | Unauthorized Access/Disclosure | Network Server | Yes | $120,690 | ||||||||||||||||
53 | UI | Gainwell Technologies, LLC | TX | Business Associate | 1955 | 3/10/2022 | Unauthorized Access/Disclosure | Network Server | Yes | $291,295 | ||||||||||||||||
54 | UI | Horizon Actuarial Services, LLC (“Horizon Actuarial”) | GA | Business Associate | 38418 | 3/9/2022 | Hacking/IT Incident | Network Server | Yes | $5,724,282 | ||||||||||||||||
55 | UI | Parkland Community Health Plan, Inc. | TX | Health Plan | 1682 | 3/8/2022 | Unauthorized Access/Disclosure | Paper/Films | Yes | $250,618 | ||||||||||||||||
56 | UI | Central Indiana Orthopedics | IN | Healthcare Provider | 83705 | 3/7/2022 | Hacking/IT Incident | Network Server | No | $12,472,045 | ||||||||||||||||
57 | UI | Laboratorio Clínico Caparros | Healthcare Provider | 500 | 3/6/2022 | Hacking/IT Incident | Network Server | No | $74,500 | |||||||||||||||||
58 | UI | South Denver Cardiology Associates, PC | CO | Healthcare Provider | 287652 | 3/4/2022 | Hacking/IT Incident | Network Server | No | $42,860,148 | ||||||||||||||||
59 | UI | Indiana Hemophilia and Thrombosis Center, Inc. | IN | Healthcare Provider | 2575 | 3/4/2022 | Hacking/IT Incident | No | $383,675 | |||||||||||||||||
60 | UI | Duncan Regional Hospital, Incorporated | OK | Healthcare Provider | 86379 | 3/4/2022 | Hacking/IT Incident | Network Server | No | $12,870,471 | ||||||||||||||||
61 | UI | Familylinks | PA | Healthcare Provider | 1494 | 3/4/2022 | Hacking/IT Incident | Electronic Medical Record, Network Server | Yes | $222,606 | ||||||||||||||||
62 | UI | University of Michigan/Michigan Medicine | MI | Healthcare Provider | 2921 | 3/3/2022 | Hacking/IT Incident | No | $435,229 | |||||||||||||||||
63 | UI | Molecular Pathology Laboratory Network, Inc. | TN | Healthcare Provider | 339471 | 3/3/2022 | Hacking/IT Incident | Network Server | No | $50,581,179 | ||||||||||||||||
64 | UI | Crossroads Health | OH | Healthcare Provider | 10324 | 3/2/2022 | Hacking/IT Incident | Network Server | No | $1,538,276 | ||||||||||||||||
65 | UI | LGAA, LLC | UT | Health Plan | 864 | 3/1/2022 | Hacking/IT Incident | Network Server | No | $128,736 | ||||||||||||||||
66 | UI | UMass Memorial Health, Inc. | MA | Business Associate | 4270 | 2/28/2022 | Hacking/IT Incident | Yes | $636,230 | |||||||||||||||||
67 | UI | Monongalia Health System, Inc. | WV | Healthcare Provider | 492861 | 2/28/2022 | Hacking/IT Incident | Network Server | No | $73,436,289 | ||||||||||||||||
68 | UI | Norwood Clinic | AL | Healthcare Provider | 228000 | 2/25/2022 | Hacking/IT Incident | Electronic Medical Record, Network Server | No | $33,972,000 | ||||||||||||||||
69 | UI | Montrose Regional Health | CO | Healthcare Provider | 52632 | 2/25/2022 | Hacking/IT Incident | No | $7,842,168 | |||||||||||||||||
70 | UI | First Step of Sarasota, Inc. | FL | Healthcare Provider | 1858 | 2/25/2022 | Hacking/IT Incident | Network Server | No | $276,842 | ||||||||||||||||
71 | UI | Bako Diagnostics | GA | Healthcare Provider | 25745 | 2/25/2022 | Hacking/IT Incident | Network Server | No | $3,836,005 | ||||||||||||||||
72 | Archive | The Art & Science of Dermatology, P.C. | VA | Healthcare Provider | 4500 | 2/25/2022 | Loss | Network Server | No | $670,500 | ||||||||||||||||
73 | UI | Kittitas Valley Healthcare | WA | Healthcare Provider | 3987 | 2/25/2022 | Hacking/IT Incident | Network Server | Yes | $594,063 | ||||||||||||||||
74 | UI | University Medical Center Southern Nevada | NV | Healthcare Provider | 12230 | 2/24/2022 | Hacking/IT Incident | Yes | $1,822,270 | |||||||||||||||||
75 | UI | Houston Health Department | TX | Healthcare Provider | 10291 | 2/24/2022 | Unauthorized Access/Disclosure | Electronic Medical Record | No | $1,533,359 | ||||||||||||||||
76 | UI | Alliance Physical Therapy Group, LLC | MI | Business Associate | 14970 | 2/23/2022 | Hacking/IT Incident | Network Server | Yes | $2,230,530 | ||||||||||||||||
77 | UI | Cooperman Barnabas Medical Center | NJ | Healthcare Provider | 538 | 2/23/2022 | Hacking/IT Incident | Yes | $80,162 | |||||||||||||||||
78 | UI | Ultimate Care, Inc. | NY | Healthcare Provider | 15788 | 2/23/2022 | Hacking/IT Incident | No | $2,352,412 | |||||||||||||||||
79 | UI | Community Association of Progressive Dominicans, Inc. | NY | Healthcare Provider | 656 | 2/23/2022 | Hacking/IT Incident | No | $97,744 | |||||||||||||||||
80 | Archive | The Puerto Rican Organization to Motivate, Enltighten, and Serve Addicts, Inc. | NY | Healthcare Provider | 33933 | 2/23/2022 | Hacking/IT Incident | No | $5,056,017 | |||||||||||||||||
81 | Archive | Bronx Addiction Services Integrated Concepts Systems, Inc. | NY | Healthcare Provider | 823 | 2/23/2022 | Hacking/IT Incident | No | $122,627 | |||||||||||||||||
82 | UI | CareOregon Advantage | OR | Health Plan | 10467 | 2/23/2022 | Unauthorized Access/Disclosure | No | $1,559,583 | |||||||||||||||||
83 | UI | Zoe Therapy Services | VA | Healthcare Provider | 1100 | 2/23/2022 | Hacking/IT Incident | No | $163,900 | |||||||||||||||||
84 | UI | Ascension Michigan (single affiliated covered entity) ACE | MI | Healthcare Provider | 27177 | 2/22/2022 | Unauthorized Access/Disclosure | Electronic Medical Record | No | $4,049,373 | ||||||||||||||||
85 | UI | Logan Health Medical Center | MT | Healthcare Provider | 213543 | 2/22/2022 | Hacking/IT Incident | Network Server | No | $31,817,907 | ||||||||||||||||
86 | UI | Memorial village er | TX | Healthcare Provider | 80000 | 2/19/2022 | Hacking/IT Incident | Network Server | No | $11,920,000 | ||||||||||||||||
87 | UI | US Radiology Specialists, Inc. | NC | Business Associate | 87552 | 2/18/2022 | Hacking/IT Incident | Network Server | Yes | $13,045,248 | ||||||||||||||||
88 | UI | Bible Fellowship Church Homes, Inc. dba Fellowship Community | PA | Healthcare Provider | 3500 | 2/18/2022 | Hacking/IT Incident | Network Server | No | $521,500 | ||||||||||||||||
89 | UI | Town Home Care, LLC | NJ | Healthcare Provider | 5591 | 2/17/2022 | Hacking/IT Incident | Network Server | No | $833,059 | ||||||||||||||||
90 | UI | Liberty of Oklahoma Corporation | PA | Business Associate | 5746 | 2/17/2022 | Hacking/IT Incident | Network Server | Yes | $856,154 | ||||||||||||||||
91 | UI | Extend Fertility | NY | Healthcare Provider | 10373 | 2/16/2022 | Hacking/IT Incident | Network Server | No | $1,545,577 | ||||||||||||||||
92 | UI | Aetna ACE | CT | Health Plan | 893 | 2/15/2022 | Hacking/IT Incident | Network Server | Yes | $133,057 | ||||||||||||||||
93 | UI | Comprehensive Health Services | FL | Healthcare Provider | 106752 | 2/15/2022 | Hacking/IT Incident | No | $15,906,048 | |||||||||||||||||
94 | UI | Jersey City Medical Center | NJ | Healthcare Provider | 1130 | 2/15/2022 | Hacking/IT Incident | Yes | $168,370 | |||||||||||||||||
95 | Archive | Priority Health | MI | Health Plan | 2112 | 2/14/2022 | Hacking/IT Incident | Network Server | No | $314,688 | ||||||||||||||||
96 | UI | Cooper University Health Care | NJ | Healthcare Provider | 1039 | 2/14/2022 | Hacking/IT Incident | No | $154,811 | |||||||||||||||||
97 | Archive | Community Medical Center | NJ | Healthcare Provider | 630 | 2/14/2022 | Hacking/IT Incident | Yes | $93,870 | |||||||||||||||||
98 | UI | Jackson County Hospital District | FL | Healthcare Provider | 501 | 2/11/2022 | Hacking/IT Incident | Network Server | No | $74,649 | ||||||||||||||||
99 | UI | Family Fare LLC | MI | Healthcare Provider | 3892 | 2/11/2022 | Hacking/IT Incident | Network Server | Yes | $579,908 | ||||||||||||||||
100 | UI | Englewood Health | NJ | Healthcare Provider | 582 | 2/11/2022 | Hacking/IT Incident | Yes | $86,718 |