• Skip to primary navigation
  • Skip to main content
  • Skip to primary sidebar
  • Skip to footer
TechEngage

TechEngage®

Hands-on reviews, research-backed buying guides and technology news.

  • News
    • Internet & Social
    • Gadgets
    • Car Tech
    • Business
    • Science & Health
  • Reviews
  • Buying Guides
  • How-to
  • AI
  • Computing
    • Apps
    • Security
    • Gaming
  • More
    • Tools
    • Puzzles
    • Mobile
  • Launchpad
  • Sign in
TechEngage » Security & Privacy

Is your medical data safe from the data breach epidemic?

Explainer

Avatar for Dr. Hafsa Akbar Ali Dr. Hafsa Akbar Ali Follow Dr. Hafsa Akbar Ali on X Published: Jul 27, 2020 · 9:23 AM ET Updated: Feb 2, 2021 · 7:00 AM ET

A person typing on a laptop while a stethoscope is placed on the table
FacebookTweetPinLinkedInPrint

We know that data breaches occur regularly. Haven’t we all scrambled to secure an account after news of a breach at one of our online haunts appeared in news headlines?

Unfortunately, massive data breaches at well-known companies represent just a tiny portion of the problem. We never hear about the vast majority of smaller data breaches that occur daily at businesses with lower profiles.

It’s not always a hacker!

Privacy breaches occur in different ways for various reasons and sometimes happen due to a chain of unforeseen events that ultimately causes a disaster. While cybercriminals use targeted attacks to hack into information systems, the accidental loss or exposure of sensitive information via non-criminal means is also regarded as a data breach. Such incidents may, in fact, cause more harm than big, well-publicized hacks. A few pre-2009 examples of (possibly) accidental breaches:

  • Employee lost a laptop on public transportation: AvMed Health Plans, 1.22 million patient records.
  • Loss of unencrypted thumb drive: Blue Cross Blue Shield, 1.02 million records.
  • Loss of data backup tapes: Nemours Foundation that runs children’s hospitals, 1.05 million records.
  • Lost hard drives: Health Net, 1.9 million records.
  • Lost backup tapes: the DOD health care program Tricare, 4.9 million records of military personnel, retirees, and their dependents.

A long, extremely messy history of major medical care data breaches

And then 2019 became the worst data security ever for health care providers:

  • LifeLab 2019: 15 million
  • Inmediata Health Group: 1.5 million
  • UW Medicine: Around 1 million
  • LabCorp: 7.7 million records, linked to the Quest Diagnostics: 11.9 million records and AMCA: full extent unknown, but at least 11.9 million, as well as Clinical Pathology Laboratories (CPL) incident: 2.2 million
  • LabCorp again: at least 10,000 documents including lab test results and diagnostic data of oncology patients.

An eye-popping non-exhaustive list of smaller 2019 healthcare data breaches:

The 2019 HIPAA Healthcare data breach report makes for alarming reading. To mention just a few that may be close to home:

Rutland Regional Medical Center: 72,000, Zoll Medical: 277,319, Milestone Family Medicine:

32,178, Verity Health Systems: 14,894, Baystate Health: 12,000, Prisma Health: 23,811, Steps to Recovery: 145,000, EmCare: 60,000, Opko Health: 422,600, Dominion National: 95,000, Los Angeles County Department of Health Services: 14,600, Presbyterian Healthcare Services: 183,000, Providence Health Plan: 122,000, Methodist Hospitals of Indiana: 68,000, Kalispell Regional Healthcare: 130,000, Critical Care, Pulmonary & Sleep Associates (CCPSA): 23,000, Alaska Department of Health & Social Services (DHSS): 100 000, Catawba Valley Medical Center: 20,000, Advent Health: 42 000, UConn Health: 326,000, EyeSouth Partners: 24,000, Rush University Medical Center: 45,000, Health Alliance Plan: 120,000, Pasquotank-Camden Emergency Medical Services: 20,420, Spectrum Health Lakeland: 60,000.

Why are there such astonishing numbers of data breaches in the health sector?

Medical records are not all that valuable per se. The reason why bad actors focus on health and medical records is that the medical sector has an awful track record of poor security.

Of course, patient names, credit card numbers, Social Security numbers, and information about patients’ financial standing provide an immediate payday for the perpetrator. Around 30% of data breach victims have reported that scammers were able to obtain new credit card accounts and even valid driver’s licenses using explicit, stolen information.

Other benefits to be had from stealing medical information

  • Information on medical conditions enable scammers to impersonate representatives from medical insurance companies
  • Scammers can use your private health information (PHI) to shape phishing and social engineering campaigns.The current COVID-19 crisis offers new opportunities for phishing attacks and scams.
  • Scammers can obtain prescription drugs.
  • Scammers can file fraudulent insurance claims.
  • There has also been an increase in patient impersonation scams, where uninsured patients obtain medical care using fraudulent medical insurance particulars.
  • Health Savings Accounts (HSAs) that are linked to specialized debit cards can be used for regular purchases.

We should be worried about an epidemic of small, non-publicized data breaches

The massive numbers of smaller data breaches in the health sector point to a much greater problem across all businesses and all sectors of the economy. We’ll never know how many other companies suffer data losses from accidents or unintentional theft.

Thieves don’t usually cruise the streets looking for data to steal. They just want to nab the computer. Crime figures show that thieves get away with hard drives, tablets, mobile phones, and laptops, and will automatically snatch electronic equipment first.

Data theft, albeit on such a small scale and accidental to boot, can still lead to compromised credit card details, scams, and identity theft.

Do we have any defense?

Despite data breaches becoming regular occurrences, many businesses still fail to understand that their organizations might be a target for hacking or data theft. Management is often ignorant of the need for security technology, or have simply never had to deal with accountability issues about their clients’ right to privacy. Business owners and management should take note of these threats before an incident hits them where it hurts.

Ask your health care provider about their privacy and data security policies, and find out more about their general security practices. They have a solemn duty to protect your privacy and should be willing and able to address your concerns. Thanks to increased penalties for violations of the Health Insurance Portability and Accountability Act (HIPAA), larger medical concerns have started paying attention.

Regularly conduct a full Nuwber social and public profile audit to establish your general risk level, and to spot inconsistencies that may indicate activities by bad actors using your personal information. Nuwber’s complete personal profiles are based on information from all over the internet, and could potentially pick up unusual activities that you would not consider looking for. Hackers usually sell stolen credit card details and Social Security numbers fast, but other data may take years to make its way to market.

Above all, we should understand that information has become an immensely valuable commodity, and that we should fight for our right to own it.


Related reading

  • Google pulls down several apps from Play Store for stealing Facebook data
  • Popular apps caught sharing user's location data with US military
  • 3 ways to test if you are vulnerable to hackers
  • Effortless ways to protect your smartphones from hacks
Something incorrect? Report an error in this article. Include a source if you have one; your name and email are optional.

Filed Under: Security & Privacy Tagged With: Data breach, Hackers

Related Stories

  • Openai Pauses Advanced-Model Research After Agent Bypasses Network Restrictions

    OpenAI pauses advanced-model research after agent bypasses network restrictions

    Tech News & AnalysisSep 27, 2026

  • 5 Internet Security Suites To Get For Fortifying Your Internet Security

    5 Internet Security Suites to Get For Fortifying Your Internet Security

    Security & PrivacyMay 24, 2023

  • Google Authenticator Finally Gets Most Awaited Cloud Sync Feature

    Google Authenticator finally gets most awaited cloud sync feature

    Security & PrivacyApr 26, 2023

Stay on top of technology

Get TechEngage reviews, buying guides and news in your feed.

Follow on Google News
FacebookTweetPinLinkedInPrint
Avatar for Dr. Hafsa Akbar Ali

Dr. Hafsa Akbar Ali

Medical Writer & Health Professional

Dr. Hafsa Akbar Ali is a medical writer at TechEngage who covers health and medical technology. She holds an MBBS from King Edward Medical University with clinical training at Mayo Hospital in Lahore, and later earned an MD in the United States. She brings a clinical perspective to coverage of healthcare breakthroughs and medical devices.

Joined TechEngage September 2018First article on TechEngage September 2018

Reader Interactions

Share Your Thoughts Cancel reply

Please read our comment policy before submitting your comment. Your email address will not be used or published anywhere. You will only receive comment notifications if you opt to subscribe below.

Primary Sidebar

Google News

Get TechEngage in your feed

Reviews, news, and buying guides as they publish.

Follow on Google News

Recent Stories

  • Usb C Power Meters Techengage |
    Computing & HardwareBest USB-C Power Meters for Chargers and CablesSep 28, 2026
  • Akamai Anthropic Cloud Techengage |
    Tech News & AnalysisAkamai’s $11.6 billion Anthropic cloud deal: costs, timeline and CPU strategySep 27, 2026
  • Openai Agent Dns Incident Techengage |
    Tech News & AnalysisOpenAI pauses advanced-model research after agent bypasses network restrictionsSep 27, 2026
  • Ai Markets Feat |
    AIThree CEOs Asked to Slow Down. The President Said No and the Market Fell 3 Percent. Hassan Taher on What Actually Happened.Sep 21, 2026
  • Iphone 18 Pro Availability Sept 18 |
    Tech News & AnalysisiPhone 18 Pro and Pro Max Available Today in 65+ CountriesSep 18, 2026

More in Security & Privacy

  • Openai Agent Dns Incident Techengage |
    OpenAI pauses advanced-model research after agent bypasses network restrictionsSep 27, 2026
  • Photo 2023 05 23 19 03 36 Jpg |
    5 Internet Security Suites to Get For Fortifying Your Internet SecurityMay 24, 2023
  • Google Authenticator Gets Cloud Backup Support Jpg |
    Google Authenticator finally gets most awaited cloud sync featureApr 26, 2023
  • Uk Twitter Accounts Hacked Abdugeek Jpg |
    Twitter’s SMS 2FA is going away today, switch before it’s too lateMar 20, 2023
More Security & Privacy stories →

Footer

Discover

  • About TechEngage
  • Company News & Updates
  • Our Team
  • Advertise
  • Send us a tip
  • Submit your company to TechEngage Launchpad Hot
  • TechEngage Brand Kit
  • Contact us
  • Tools & Calculators

Legal pages

  • Editorial Standards
  • Reviews Policy
  • Our Ethics
  • Corrections Policy
  • Affiliate Disclosure
  • Privacy Policy
  • Cookies Policy
  • Terms & Conditions
  • GDPR Compliance
  • Copyright & DMCA

Must reads

  • Best Mechanical Keyboards Under $100
  • Best USB-C Hubs
  • Best Portable SSDs
  • Best Gaming Graphics Cards (GPUs)
  • Best Long-Range Outdoor WiFi Extenders
  • Best Wireless CarPlay Adapters
  • Best Slack Alternatives
  • Best Long-Range Walkie-Talkies

About TechEngage

TechEngage® is an independent technology publication covering tech news, reviews and buying guides.

Founded
2003
Publisher
TechAbout LLC
ISSN
2690-3776
Google NewsRSS feed

© 2026 TechEngage®. All Rights Reserved. TechEngage® is a project of TechAbout LLC.

TechEngage® is a registered trademark in the United States under Trademark Number 6823709 and in the United Kingdom under Trademark Number UK00003417167. It is also ISSN protected under ISSN 2690-3776 and has OCLC Number 1139335774.

Contact team@techengage.com · WhatsApp +1-307-381-8801

Your analytics choice
Allow Google Analytics to help us understand readership? You can use the site without it and change this choice anytime.

Privacy details