RightPatient-can-prevent-medical-identity-theft

Hospital data breach results in an expensive lawsuit – Is yours next?

RightPatient-can-prevent-medical-identity-theft

Hospital data breaches have been rampant for quite some years now. Last year’s figures alone are quite frightening – one states that 41 million patient records were exposed, essentially making the patients potential victims of medical identity theft. Thus, both data breaches and medical identity theft has been in the limelight. These unwanted nuisances have turned the attention towards healthcare providers who are suffering from these events. One such provider is the University of Missouri Health Care (MU Health), who suffered a data breach of 14 thousand records and also were hit by a lawsuit by the impacted patients.

This happened back in 2019. The provider was sued by patients who were affected by the breach in question. The patients reasoned that the breach had made their sensitive records prone to medical identity theft – their fear was not irrational.

RightPatient-can-prevent-medical-identity-theft

The actual story

On the first day of May 2019, the healthcare provider found out that an outsider somehow accessed email accounts of two employees for more than a week. Following the incident, the concerned officials said that they took the necessary steps to secure both accounts. 

It was not disclosed how the hacker got access and whether it was a phishing incident or not. However, the healthcare provider revealed that the affected account had sensitive patient data stored, such as names, DOB, medical record numbers, insurance details, as well as treatment details. The hospital data breach even consisted of the Social Security Numbers of some unlucky patients.

The data breach, fortunately, did not affect all the patients of MU Health. However, it did affect around 14,400 patients, which is no small number. As soon as the provider’s inquiry ended regarding the breach on the twenty-seventh day of July, it started to inform the patients regarding the breach. Oddly, the organization notified the patients after the required timeframe of 60 days as per HIPAA regulations.

The aftermath

Within the same week of notifying the patients, one of them filed a lawsuit, followed by 19 others. Their reason was very simple – the data breach would likely result in medical identity theft and lead to lower-quality care. The patients also believed that they were paying quite an amount of money, and thus, MU Health should add stringent security with their services.

Hospital data breaches can arm hackers with enough information to obtain medical services assigned to the patients. The hackers could either expose the data, sell it, or use it for themselves. These could lead to the patients paying for healthcare services they did not avail. These could also become denied claims for healthcare providers. Whichever way one looks at it, data breaches and medical identity theft is extremely undesirable. 

How do hospitals prevent medical identity theft?

Although it is quite prevalent nowadays, medical identity theft can actually be prevented. One way to make sure that the medical records are safe is by locking them with a key that hackers cannot forge. That is exactly what RightPatient does. It is a biometric patient identification platform that locks the patient records with their biometric data. Once the platform attaches the medical record with the data during enrollment, a third party cannot come and claim that record, preventing medical identity theft and ensuring accurate patient identification. RightPatient has been preventing medical identity theft for leading hospitals such as University Health Care System and Grady Health System.

RightPatient-ensures-accurate-patient-identification

How RightPatient Benefits Medical Identity Theft and the Healthcare Red Flags Rule

RightPatient-ensures-accurate-patient-identification

It’s no secret that medical identity theft is on the rise. Over 2 million Americans each year become victims of medical identity theft, and, unfortunately, that number only continues to grow.

It’s growing for a number of reasons. First of all, there were more healthcare data breaches in 2019 than the previous three years combined. These breaches compromised the medical records of over 40 million Americans

Let’s consider this in light of rising healthcare costs and a worsening opioid epidemic. These facts create a ripe market for medical identity theft. Patient identity data is readily available on the black market and there is a ton of demand for it.

rightpatient-prevents-medical-identity-theft

When medical identity theft is perpetrated, patients and healthcare providers suffer. Victims can face bills for services they never received, incorrect treatment data mixed into their medical record can affect future outcomes and quality of care, and the costs to restore their identity can be prohibitive. 

Healthcare providers lose millions of dollars for services that will never be paid for. Increasingly, they also face litigation costs from patient lawsuits for failing to protect their information. 

Providers also face another burden. In 2009, the FTC started to enforce the Red Flags Rule, which requires healthcare providers to develop programs that can help to detect and address situations that are “red flag” indicators of medical identity theft. The goal is to ensure vigilance and reduce the potential costs associated with medical identity theft.

However, implementing red flag processes, keeping them current, and ensuring compliance can be expensive and time consuming for healthcare providers. These processes must also be administered by front-line staff members, typically patient access employees that handle registration. 

This is an enormous responsibility for these employees when considering the potential consequences of medical identity theft. Compliance with red flag rules also places a substantial burden on registrars who are already buried with additional duties such as verifying insurance, collecting payment, and processing patients as efficiently as possible to reduce wait times and improve margins. 

RightPatient-ensures-accurate-patient-identification

Now, against the backdrop of these market realities, imagine if the risk of medical identity theft could be substantially mitigated, if not eliminated altogether. This is where RightPatient comes into play. 

RightPatient validates that patients are who they claim to be when scheduling appointments by comparing a patient’s selfie photo to the photo on her driver’s license or other ID cards. When patients show up for visits, RightPatient accurately identifies them during registration and other points along the care continuum. 

RightPatient creates a closed-loop platform to prevent medical identity theft and other errors that can impact patient safety, revenue cycle, and data quality. This saves a lot of time, money, and hassle for patients and healthcare providers.

Why The Coronavirus Makes Patient Identification More Critical Than Ever

In case you’ve been sleeping under a rock somewhere, the COVID-19 coronavirus is causing global concern, with some health professionals and media outlets already referring to the outbreak as a pandemic. 

The lack of available testing kits in the U.S. has hindered our ability to accurately determine the actual scale of the problem here. However, as of this writing, we do know that coronavirus has infected more than 108,000 people globally, with nearly 600 cases in the U.S. and 22 deaths. 

why-coronavirus-makes-patient-identification-more-critical-than-ever-rightpatient

With the virus continuing to spread in the U.S., those experiencing symptoms are being advised to call their healthcare provider. While many healthcare providers and states are preparing to handle the growing outbreak, many patients are seeking treatment at emergency rooms where the risk of spreading the virus to other patients and health workers can increase dramatically.

In addition, some patients that do not meet certain testing criteria may not be immediately diagnosed as having coronavirus. Accurate patient identification is absolutely critical in these circumstances to help contain the growth of coronavirus infections. 

Imagine a patient who arrives at the ER with respiratory symptoms but does not meet the testing criteria. The patient could be treated without needed precautions and released. If the patient returned later with worsening or other symptoms and was misidentified, the clinical team would not have access to critical information that could immediately trigger the prerequisites of a coronavirus infection, putting every person in that facility at even greater risk. 

COVID-19-requires-a-touchless-patient-identifier-like-RightPatient

Biometric patient identification can certainly help to prevent these mistakes. However, the type of biometric technology being utilized can have significant consequences. For example, healthcare providers using contact-dependent devices such as palm vein biometrics may risk exacerbating the spread of the coronavirus. That particular modality requires patients to place their entire hand on a plastic mold to read their vein pattern. 

Under the current market conditions, would you want to touch that device, especially knowing that every other patient was being instructed to do the same? 

At a minimum, healthcare workers would need to disinfect the device after every patient encounter. This is not a practical or safe approach. 

IT companies in Hyderabad India have actually been instructed to suspend use of fingerprint biometric systems for employees as standard operating procedure if the coronavirus is detected on their premises. If this is being advised for employee time and attendance in an IT company, will healthcare providers continue to ask each and every patient to touch a biometric device across their locations? If not, how will the risk of patient misidentification contribute to the spread of coronavirus?

Since our inception, we have advocated for using the RightPatient platform with our photo-based engine. This was based on 18 years of experience in biometric software and our vision for the company. We are now the leader in this space with many providers using our platform. 

One factor involved in our decision-making process was hygiene and infection control. Our photo-based biometric patient authentication platform does not require patients to touch anything, which is ideal in a healthcare environment even under normal market conditions, but particularly now in light of the COVID-19 coronavirus. 

Our mission is to prevent medical identity theft and duplicate medical records to mitigate risk for healthcare providers while improving patient safety, data quality, and revenue cycle. Especially now, accurate patient identification is critically important but providers should think about the risks of a contact-dependent solution. They should also consider the experience, vision, and track record of their vendor to select a trusted partner that will always keep them ahead of the curve.