Electronic medical record breaches continue, yet the public pays little attention to healthcare provider security and privacy policies. While the healthcare industry moves to invest billions into electronic health records, a steady trail of breaches and broken promises of security is starting to take its toll on patient trust.Just last week Virginia Commonwealth University made public a breach involving the compromise of two servers that left personal information on former and current VCU and VCU Health System faculty, staff, students and affiliates exposed. The VCU reported that the records of 176,567 people were exposed in this incident notification.Also see For me, healthcare security is personalAccording to the University, two servers had been compromised, with one server having data that included Social Security numbers, names, or electronic IDs, and a subset of files contained date of birth, contact information among other information. VCU is no unusual incident. Earlier this month the St. Joseph Medical Center reported that 5,000 x-rays with patients’ name, date of birth, medical record number, date of service, referring physician, the type of study and the radiologist’s medical interpretation of the film were stolen. At University of California Los Angeles Health System, 16,288 patients’ names, medical and other demographic information was stolen from a hard drive during a home burglary.And in yet another recent incident, at Premier Imaging LLC, an employee was fired after bringing files on 47 patients home for reasons that still remain unclear. According to the Privacy Rights Clearinghouse, a watchdog group that tracks data breaches, there have been 355 medical data related breaches, involving 10,120,287 records, that have been made public since 2010.Despite all this bad news, a recent survey found that such occurrences probably won’t temper the trust consumers have in data sharing or using electronic health records. According to a survey of 1,000 consumers conducted by the PwC Health Research Institute, 60 percent of respondents would be comfortable having their health data shared for improving overall care, 54 percent for improving decision-making in their care, and 36 percent to provide data for better analysis of doctor’s performance.However, only 30 percent of respondents said, if factors such as cost, quality, and access were even among competing providers, clear security and privacy policies would impact their healthcare decisions. “It’s easy for respondents to say this, but the reality is that consumers will not likely have any level of confidence on their ability to judge one provider’s security and privacy policies over another,” says Pete Lindstrom, research director at Spire Security.George V. Hulme writes about security and technology from his home in Minneapolis. You can also find him tweeting about those topics on Twitter @georgevhulme. Related content news analysis DHS unveils one common platform for reporting cyber incidents Ahead of CISA cyber incident reporting regulations, DHS issued a report on harmonizing 52 cyber incident reporting requirements, presenting a model common reporting platform that could encompass them all. By Cynthia Brumfield Sep 25, 2023 10 mins Regulation Regulation Regulation news Chinese state actors behind espionage attacks on Southeast Asian government The distinct groups of activities formed three different clusters, each attributed to a specific APT group. By Shweta Sharma Sep 25, 2023 4 mins Advanced Persistent Threats Cyberattacks feature How to pick the best endpoint detection and response solution EDR software has emerged as one of the preeminent tools in the CISO’s arsenal. Here’s what to look for and what to avoid when choosing EDR software. By Linda Rosencrance Sep 25, 2023 10 mins Intrusion Detection Software Security Monitoring Software Data and Information Security feature Top cybersecurity M&A deals for 2023 Fears of recession, rising interest rates, mass tech layoffs, and conservative spending trends are likely to make dealmakers cautious, but an ever-increasing need to defend against bigger and faster attacks will likely keep M&A activity steady in By CSO Staff Sep 22, 2023 24 mins Mergers and Acquisitions Data and Information Security IT Leadership Podcasts Videos Resources Events SUBSCRIBE TO OUR NEWSLETTER From our editors straight to your inbox Get started by entering your email address below. Please enter a valid email address Subscribe