Blog, Privacy, Reflectiz Blog, Security Compliance
5 Best Practices for Healthcare CISOs to Secure PHI | Reflectiz
5 Best Practices for Healthcare CISOs to Secure PHI
**This article is originally published by our partner, Reflectiz. Click here to view the original article.

These days, a patient’s medical records can change hands for between $250 and $1000 on the black market. In contrast, Social Security numbers sell for around a dollar each, and credit card numbers for around five dollars on the dark web. So it isn’t hard to see why the healthcare industry has increasingly come under attack by cybercriminals in recent years.
Unfortunately, this has been happening at a time when hospitals have shifted more of their operations to the cloud, including electronic health records. Still, as IBM security consultant Limor Kessem has noted, they haven’t invested enough in cloud security. While the financial sector has 30 years of experience deterring cyberattacks, it seems likely the healthcare industry is only waking up to the need to maintain secure PHI as it moves away from paper records.
What is PHI?
HIPAA, the Health Insurance Portability and Accountability Act, defined PHI as Protected Health Information. It means any stored information that can uniquely identify a patient, and the act places various responsibilities on healthcare providers and related industries (like insurance) for maintaining it safely.
When providers fail to secure PHI, the costs can be enormous. Aside from causing widespread distress and the potential for blackmail and fraud too so many patients, the reputational loss for healthcare companies, as well as the cost of restoring damaged systems, fighting lawsuits, paying damages, and paying fines (to the U.S. Department of Health and Human Services Office of Civil Rights) for non-compliance, can be crippling.
The Cost of a PHI Data Breach
Fines can range from $100-$50,000 for each violation. An IBM security analysis revealed that the average overall cost of each healthcare breach now exceeds $10 million, considerably more than the $4.35 million average across all industries.
In the U.S. in 2022, the 11 most significant data breaches exposed the private health information of more than 21.5 million people. Attackers harvested various information such as social security numbers, details of health conditions, names, and addresses, which criminals can now potentially use to defraud them.
Maintaining Secure PHI
As custodians of so much valuable data, maintaining secure PHI has to be at the top of every healthcare CISO’s to-do list. But this is becoming more of a challenge in a world where competing providers want and need to offer seamless services to patients. Organizations are leaning toward computerized systems for paying claims, answering eligibility questions, offering health information, and streamlining various other clinical and administrative tasks, including electronic health records, automated physician order entry systems, radiology, pharmacy, and laboratory systems. Health plans offer access to claims and care management, and members can use self-service apps.
While these innovations make healthcare management easier for all, they also create multiple potential weak points for cybercriminals to exploit. Some of these are not even directly related to healthcare.
For instance, the software that providers rely on to perform tasks such as measuring the effectiveness of their advertising has created new potential vulnerabilities that need to be monitored carefully. In 2022, a tracking pixel from Meta, the owner of Facebook, was found to send a data packet to Facebook every time someone scheduled a doctor’s appointment online; this brings us to the first of our suggested best practices.
Securing Your Online Presence
Keep your online businesses safe by mitigating security and privacy risks resulting from next generation third-party threats on your website, without adding a single line of code.
Free Reflectiz Information Kit
Get first-hand information and use cases to discover how Reflectiz can protect your website from advanced third party based attacks
Get Web Asset Free Assessment
Request a free non-intrusive security assessment of your website, and get a report with an overview of client-side security risks.






