X
Edition:
United States

  • Business
    • Business Home
    • Legal
    • Deals
    • Aerospace & Defense
    • Finance
    • Autos
    • Reuters Summits
    • ADventures
    • Data Dive
  • Markets
    • Markets Home
    • U.S. Markets
    • European Markets
    • Asian Markets
    • Global Market Data
    • Indices
    • Stocks
    • Bonds
    • Currencies
    • Comm & Energy
    • Futures
    • Funds
    • Earnings
    • Dividends
  • World
    • World Home
    • U.S.
    • Special Reports
    • Reuters Investigates
    • Euro Zone
    • Middle East
    • China
    • Japan
    • Mexico
    • Brazil
    • Africa
    • Russia
    • India
  • Politics
    • Politics Home
    • Election 2016
    • Polling Explorer
    • Just In: Election 2016
    • What Voters Want
    • Supreme Court
  • Tech
    • Technology Home
    • Science
    • Top 100 Global Innovators
    • Environment
    • Innovation
  • Commentary
    • Commentary Home
    • Podcasts
  • Breakingviews
    • Breakingviews Home
    • Breakingviews Video
  • Money
    • Money Home
    • Retirement
    • Lipper Awards
    • Analyst Research
    • Stock Screener
    • Fund Screener
  • Life
    • Health
    • Sports
    • Arts
    • Entertainment
    • Oddly Enough
  • Pictures
    • Pictures Home
    • The Wider Image
    • Photographers
    • Focus 360
  • Video
Your medical record is worth more to hackers than your credit card
  • Africa
    América Latina
  • عربي
    Argentina
  • Brasil
    Canada
  • 中国
    Deutschland
  • España
    France
  • India
    Italia
  • 日本
    México
  • РОССИЯ
    United Kingdom
  • United States
Technology News | Wed Sep 24, 2014 | 2:24pm EDT

Your medical record is worth more to hackers than your credit card

A man types on a computer keyboard in this illustration picture taken in Warsaw February 28, 2013.   REUTERS/Kacper Pempel
A man types on a computer keyboard in this illustration picture taken in Warsaw February 28, 2013. REUTERS/Kacper Pempel
By Caroline Humer and Jim Finkle | NEW YORK/BOSTON

NEW YORK/BOSTON Your medical information is worth 10 times more than your credit card number on the black market.

Last month, the FBI warned healthcare providers to guard against cyber attacks after one of the largest U.S. hospital operators, Community Health Systems Inc, said Chinese hackers had broken into its computer network and stolen the personal information of 4.5 million patients.

Security experts say cyber criminals are increasingly targeting the $3 trillion U.S. healthcare industry, which has many companies still reliant on aging computer systems that do not use the latest security features.

"As attackers discover new methods to make money, the healthcare industry is becoming a much riper target because of the ability to sell large batches of personal data for profit," said Dave Kennedy, an expert on healthcare security and CEO of TrustedSEC LLC. "Hospitals have low security, so it's relatively easy for these hackers to get a large amount of personal data for medical fraud."

Interviews with nearly a dozen healthcare executives, cybersecurity investigators and fraud experts provide a detailed account of the underground market for stolen patient data.

The data for sale includes names, birth dates, policy numbers, diagnosis codes and billing information. Fraudsters use this data to create fake IDs to buy medical equipment or drugs that can be resold, or they combine a patient number with a false provider number and file made-up claims with insurers, according to experts who have investigated cyber attacks on healthcare organizations.

Medical identity theft is often not immediately identified by a patient or their provider, giving criminals years to milk such credentials. That makes medical data more valuable than credit cards, which tend to be quickly canceled by banks once fraud is detected.

Stolen health credentials can go for $10 each, about 10 or 20 times the value of a U.S. credit card number, according to Don Jackson, director of threat intelligence at PhishLabs, a cyber crime protection company. He obtained the data by monitoring underground exchanges where hackers sell the information.

   

ATTACKS ON THE RISE

The percentage of healthcare organizations that have reported a criminal cyber attack has risen to 40 percent in 2013 from 20 percent in 2009, according to an annual survey by the Ponemon Institute think tank on data protection policy.

Founder Larry Ponemon, who is privy to details of attacks on healthcare firms that have not been made public, said he has seen an increase this year in both the number of cyber attacks and number of records stolen in those breaches.     

Fueling that increase is a shift to electronic medical records by a majority of U.S. healthcare providers.

Marc Probst, chief information officer of Intermountain Healthcare in Salt Lake City, said his hospital system fends off thousands of attempts to penetrate its network each week. So far it is not aware of a successful attack.

"The only reason to buy that data is so they can fraudulently bill," Probst said.

Healthcare providers and insurers must publicly disclose data breaches affecting more than 500 people, but there are no laws requiring criminal prosecution. As a result, the total cost of cyber attacks on the healthcare system is difficult to pin down. Insurance industry experts say they are one of many expenses ultimately passed onto Americans as part of rising health insurance premiums.

Consumers sometimes discover their credentials have been stolen only after fraudsters use their personal medical ID to impersonate them and obtain health services. When the unpaid bills are sent on to debt collectors, they track down the fraud victims and seek payment.     

Ponemon cited a case last year in which one patient learned that his records at a major hospital chain were compromised after he started receiving bills related to a heart procedure he had not undergone. The man's credentials were also used to buy a mobility scooter and several pieces of medical equipment, racking up tens of thousands of dollars in total fraud.

MEDICARE FRAUD

The government's efforts to combat Medicare fraud have focused on traditional types of scams that involve provider billing and over billing. Fraud involving the Medicare program for seniors and the disabled totaled more than $6 billion in the last two years, according to a database maintained by Medical Identity Fraud Alliance.

"Healthcare providers and hospitals are just some of the easiest networks to break into," said Jeff Horne, vice president at cybersecurity firm Accuvant, which is majority-owned by private equity firm Blackstone Group.

"When I've looked at hospitals, and when I've talked to other people inside of a breach, they are using very old legacy systems - Windows systems that are 10 plus years old that have not seen a patch."

KPMG partner Michael Ebert said security has been an afterthought for many medical providers - whether it is building encryption into software used to create electronic patient records or in setting budgets.

"Are you going to put money into a brand new MRI machine or laser surgery or are you going to put money into a new firewall?" he said.

(Additional reporting by Susan Kelly in Chicago; Editing by Michele Gershberg and Tiffany Wu)

Next In Technology News

Toyota to pilot Smart Key Box technology with ride-hailing start-up

TOKYO Toyota Motor Corp will pilot its new Smart Key Box technology in fleets used by U.S. car-sharing service Getaround next year, stepping up its push to benefit from new mobility services seen by some as a threat to traditional car ownership.

Hedge fund raided by the FBI? There's an app for that

NEW YORK An agent from the Federal Bureau of Investigation approaches a hedge fund trader as he leaves the office, wanting to ask a few questions. Nervous about saying no to an official, the trader dishes, and information he provides is later used against him.

Sony bullish on sensors after quake causes quarterly profit to halve

TOKYO Japan's Sony Corp on Tuesday said it remained bullish about the long-term prospects of its cash-cow imaging sensor business after earthquake damage to a major factory contributed to a 48 percent drop in quarterly profit.

MORE FROM REUTERS

Sponsored Content

From Around the Web Promoted by Taboola

Trending Stories

    Editor's Pick

    LIVE: Election 2016

    Pictures

    Photos of the day

    Sponsored Topics

    X
    Follow Reuters:
    • Follow Us On Twitter
    • Follow Us On Facebook
    • Follow Us On RSS
    • Follow Us On Instagram
    • Follow Us On YouTube
    • Follow Us On LinkedIn
    Subscribe: Feeds | Newsletters | Podcasts | Apps
    Reuters News Agency | Brand Attribution Guidelines

    Reuters is the news and media division of Thomson Reuters. Thomson Reuters is the world's largest international multimedia news agency, providing investing news, world news, business news, technology news, headline news, small business news, news alerts, personal finance, stock market, and mutual funds information available on Reuters.com, video, mobile, and interactive television platforms. Learn more about Thomson Reuters products:

    Eikon
    Information, analytics and exclusive news on financial markets - delivered in an intuitive desktop and mobile interface
    Elektron
    Everything you need to empower your workflow and enhance your enterprise data management
    World-Check
    Screen for heightened risk individual and entities globally to help uncover hidden risks in business relationships and human networks
    Westlaw
    Build the strongest argument relying on authoritative content, attorney-editor expertise, and industry defining technology
    ONESOURCE
    The most comprehensive solution to manage all your complex and ever-expanding tax and compliance needs
    CHECKPOINT
    The industry leader for online information for tax, accounting and finance professionals

    All quotes delayed a minimum of 15 minutes. See here for a complete list of exchanges and delays.

    • Site Feedback
    • Corrections
    • Advertise With Us
    • Advertising Guidelines
    • AdChoices
    • Terms of Use
    • Privacy Policy