Maintenance Notice

Due to necessary scheduled maintenance, the JMIR Publications website will be unavailable from Wednesday, July 01, 2020 at 8:00 PM to 10:00 PM EST. We apologize in advance for any inconvenience this may cause you.

Who will be affected?

Accepted for/Published in: Journal of Medical Internet Research

Date Submitted: Apr 18, 2024
Date Accepted: Sep 15, 2024

The final, peer-reviewed published version of this preprint can be found here:

Patient Health Record Protection Beyond the Health Insurance Portability and Accountability Act: Mixed Methods Study

Subramanian H, Sengupta A, Xu Y

Patient Health Record Protection Beyond the Health Insurance Portability and Accountability Act: Mixed Methods Study

J Med Internet Res 2024;26:e59674

DOI: 10.2196/59674

PMID: 39504550

PMCID: 11579621

Patient Health Record Protection beyond HIPAA: A Multi-Method Analysis

  • Hemang Subramanian; 
  • Arijit Sengupta; 
  • Yilin Xu

ABSTRACT

Background:

Despite strict HIPAA enforcement, healthcare systems in the USA continue to face frequent and impactful data breaches. This paper examines the effectiveness of HIPAA regulations and the necessity for robust best practices in healthcare security through extensive data analysis.

Objective:

The study aims to assess the effectiveness of HIPAA regulations in preventing data breaches and to identify and recommend best practices based on major types of breaches observed in the healthcare system.

Methods:

This study utilized a mixed-method approach, including both qualitative and quantitative analyses. Data from over 15 years of publicly available breach reports by the US Department of Health and Human Services was analyzed. The study also included econometric models with state-wise fixed effects to evaluate the impact of HIPAA regulations and various breach types on the number of affected individuals.

Results:

Our findings indicate that certain breach types such as hacking and IT incidents have a more significant impact on the number of individuals affected compared to others like improper disposal or unauthorized access. States with laws more stringent than HIPAA also showed a variation in breach impacts. The econometric analysis underscores that despite stringent regulations, breaches remain frequent and their impacts significant.

Conclusions:

The study concludes that while HIPAA has increased the privacy and security of patient information, its effectiveness in preventing breaches is limited. It suggests that a multi-layered regulatory approach and the adoption of industry best practices might enhance the resilience of healthcare data systems. The study advocates for continuous reassessment of security protocols and dynamic updating of regulations to address evolving cyber threats and technological advances.


 Citation

Please cite as:

Subramanian H, Sengupta A, Xu Y

Patient Health Record Protection Beyond the Health Insurance Portability and Accountability Act: Mixed Methods Study

J Med Internet Res 2024;26:e59674

DOI: 10.2196/59674

PMID: 39504550

PMCID: 11579621

Download PDF


Request queued. Please wait while the file is being generated. It may take some time.

© The authors. All rights reserved. This is a privileged document currently under peer-review/community review (or an accepted/rejected manuscript). Authors have provided JMIR Publications with an exclusive license to publish this preprint on it's website for review and ahead-of-print citation purposes only. While the final peer-reviewed paper may be licensed under a cc-by license on publication, at this stage authors and publisher expressively prohibit redistribution of this draft paper other than for review purposes.