With all the commotion surrounding health reform, its easy for senior leaders at group health plans to lose focus on data security. They may get lulled into complacency by two fallacies about data breaches: that only big retailers are experiencing costly security breaches and teenage hackers or international cyber-teams are always to blame.
The Department of Health and Human Services has a web page dubbed the Wall of Shame that includes the names of hundreds of large and small healthcare organizations including group health plans that have been victimized by data breaches affecting millions of Americans. Only about 6% of those breaches are due to hacking or IT incidents; the other 94% are the result of dumb mistakes and mischief by employees, yours and your many business associates. As a covered entity under the HIPAA rules, a group plan is responsible for any data breaches caused by BAs, like those who handle eligibility, enrollment, claims management and IT services for the plan.