A significant increase in the risk for exposure of health information in the United States: result from analysing the US data breach registry

Johan Gustav Bellika
Norwegian Centre for e-health research, University hospital of North Norway, Tromsø, Norway / Department of Clinical Medicine, Faculty of Health Sciences, UiT The Arctic University of Norway

Alexandra Makhlysheva
Norwegian Centre for e-health research, University hospital of North Norway, Tromsø, Norway

Per Atle Bakkevoll
Norwegian Centre for e-health research, University hospital of North Norway, Tromsø, Norway

Ingår i: Proceedings from The 15th Scandinavian Conference on Health Informatics 2017 Kristiansand, Norway, August 29–30, 2017

Linköping Electronic Conference Proceedings 145:9, s. 55-59

Publicerad: 2018-01-04

ISBN: 978-91-7685-364-1

ISSN: 1650-3686 (tryckt), 1650-3740 (online)


The study surveys the probability and consequences of protected health information (PHI) data breaches. We analysed the development of data breaches in the US data breach registry available online in 2010-2016 by focusing on two PHI breach categories: theft and loss, and hacking and unauthorised use. 79% of all analysed PHI breaches was the result of hacking or unauthorised use versus 19% caused by loss or theft. Totally over 171 million persons were affected by PHI breaches during the analysed period, which corresponds to 54% of the US population. On average, 4.6 million persons are annually affected by theft or loss of PHI versus 19.4 million affected by hacking and unauthorised use of PHI. The number of hacking attacks increased by 15 times from 2010 to 2016. The largest single loss of PHI so far is 78.8 million records. The analysis has shown the risk of PHI breaches in the US is high and significantly increasing. In Scandinavian settings, such a risk would imply measures to reduce both probability and consequence of breaches


Computer Security, Cybersecurity, Risk Assessment


