Jump to HeaderJump to Main ContentJump to Footer
Michigan State University
  • Browse Stories By

    Topics

    Explore stories by subject area

    • Arts and Culture
    • Business and Economy
    • Climate and Environment
    • Education and Learning
    • Engineering, Science and Technology
    • Government and Society
    • Health and Medicine
    • Media and Communications
    • MSU Leadership and Impact
    • Sports and Recreation
    • Student and Campus Experience
    View All Stories

    Collections

    Curated story series

    • Turfgrass
    • Ask the Expert
    • Big Ideas
    • Climate solutions
    • Water at MSU
    • Mobility
    • Spartan Perspectives
    • Student views
    • Graduate voices
    • Faculty voices
    View All Collections

    Featured

    Editor's picks

    • The Spartans behind your favorite Michigan golf courses

      July 22, 2026

      The Spartans behind your favorite Michigan golf courses

    • MSU in the 1990s: 10 Spartan milestones

      July 14, 2026

      MSU in the 1990s: 10 Spartan milestones

MSUTODAY
  • Browse Stories By

< Browse Stories By

Topics

Explore stories by subject area

  • Arts and Culture
  • Business and Economy
  • Climate and Environment
  • Education and Learning
  • Engineering, Science and Technology
  • Government and Society
  • Health and Medicine
  • Media and Communications
  • MSU Leadership and Impact
  • Sports and Recreation
  • Student and Campus Experience
  • View All Stories

Collections

Curated story series

  • Turfgrass
  • Ask the Expert
  • Big Ideas
  • Climate solutions
  • Water at MSU
  • Mobility
  • Spartan Perspectives
  • Student views
  • Graduate voices
  • Faculty voices
  • View All Collections

Featured

Editor's picks

  • The Spartans behind your favorite Michigan golf courses

    July 22, 2026

    The Spartans behind your favorite Michigan golf courses

  • MSU in the 1990s: 10 Spartan milestones

    July 14, 2026

    MSU in the 1990s: 10 Spartan milestones

  • For Media
  • Experts
  • Releases and Statements
  • Sign Up
  • Update Information

Resources

  • A to Z Index
  • Find People
  • Maps
  • Email
  • Student Information System (SIS)
  • D2L
  • Libraries
  • Tech Support
  • MSU Misconduct Hotline
  • Social Media Directory
  • Events Calendar
  • For Media
Michigan State University
MSUToday
  • For Media
  • Experts
  • Releases and Statements
  • Sign Up
  • Update Information
MSUTODAY
MSU Research

Nov. 16, 2018

Health care providers &ndash; not hackers &ndash; leak more of your data

Your personal identity may fall at the mercy of sophisticated hackers on many websites, but when it comes to health data breaches, hospitals, doctors offices and even insurance companies are oftentimes the culprits.

New research from Michigan State University and Johns Hopkins University found that more than half of the recent personal health information, or PHI, data breaches were because of internal issues with medical providers – not because of hackers or external parties.

“There’s no perfect way to store information, but more than half of the cases we reviewed were not triggered by external factors – but rather by internal negligence,” said John (Xuefeng) Jiang, lead author and associate professor of accounting and information systems at MSU’s Eli Broad College of Business.

The research, published in JAMA Internal Medicine, follows the joint 2017 study that showed the magnitude of hospital data breaches in the United States. The research revealed nearly 1,800 occurrences of large data breaches in patient information over seven years, with 33 hospitals experiencing more than one substantial breach.

For this paper, Jiang and co-author Ge Bai, associate professor at the Johns Hopkins Carey Business School, dove deeper to identify triggers of the PHI data breaches. They reviewed nearly 1,150 cases between October 2009 and December 2017 that affected more than 164 million patients.

“Every time a hospital has some sort of a data breach, they need to report it to the Department of Health and Human Services and classify what they believe is the cause,” Jiang, the Plante Moran Faculty Fellow, said. “These causes fell into six categories: theft, unauthorized access, hacking or an IT incident, loss, improper disposal or ‘other.’”

After reviewing detailed reports, assessing notes and reclassifying cases with specific benchmarks, Jiang and Bai found that 53 percent were the result of internal factors in health care entities.

“One quarter of all the cases were caused by unauthorized access or disclosure – more than twice the amount that were caused by external hackers,” Jiang said. “This could be an employee taking PHI home or forwarding to a personal account or device, accessing data without authorization, or even through email mistakes, like sending to the wrong recipients, copying instead of blind copying or sharing unencrypted content.”

While some of the errors seem to be common sense, Jiang said that the big mistakes can lead to even bigger accidents and that seemingly innocuous errors can compromise patients’ personal data.

“Hospitals, doctors offices, insurance companies, small physician offices and even pharmacies are making these kinds of errors and putting patients at risk,” Jiang said.

Of the external breaches, theft accounted for 33 percent with hacking credited for just 12 percent.

Some data breaches might result in minor consequences, such as obtaining the phone numbers of patients, but others can have much more invasive effects. For example, when Anthem, Inc. suffered a data breach in 2015, 37.5 million records were compromised. Many of the victims were not notified immediately, so weren’t aware of the situation until they went to file their taxes only to discover that a third-party fraudulently filed them with the data they obtained from Anthem.

While tight software and hardware security can protect from theft and hackers, Jiang and Bai suggest health care providers adopt internal policies and procedures that can tighten processes and prevent internal parties from leaking PHI by following a set of simple protocols. The procedures to mitigate PHI breaches related to storage include transitioning from paper to digital medical records, safe storage, moving to non-mobile policies for patient-protected information and implementing encryption. Procedures related to PHI communication include mandatory verification of mailing recipients, following a “copy vs. blind copy” protocol (bcc vs cc) as well as encryption of content.

“Not putting on the whole armor opened health care entities to enemy’s attacks,” Bai said. “The good news is that the armor is not hard to put on if simple protocols are followed.”

Next, Jiang and Bai plan to look even more closely at the kind of data that is hacked from external sources to learn what exactly digital thieves hope to steal from patient data.

MEDIA CONTACTS

Xuefeng Jiang
MSU ResearchMSU Leadership and ImpactEngineeringEngineering, Science and TechnologyFinance and InvestmentsBusiness and Economy

Latest News

MSUToday Weekly Update

The MSUToday Weekly Update email showcases how Spartans are making a difference through academic excellence, research impact and community outreach. Get inspired by these stories of innovation, collaboration and determination. Plus, enjoy photos and videos of campus and more MSU content to help keep you connected to the Spartan community.

Sign UpUpdate My Information

Connect With Us

Visit our Facebook pageVisit our page on XVisit our Instagram pageVisit our LinkedIn pageVisit our YouTube pageVisit our TikTok page

Health and Safety

  • MSU Police and Public Safety
  • Olin Health Center
  • Counseling & Psychiatric Services (CAPS)
  • University Health and Wellbeing
  • MSU Health Care
  • Civil Rights and Title IX
  • Our Commitment
  • Center for Survivors
  • Security & Fire Safety Report
  • University Policy on Relationship Violence and Sexual Misconduct
  • Notice of Non-Discrimination, Anti-Harassment and Non-Retaliation
  • Health Care Non-Discrimination Notice

Support Services

  • Disability Resources
  • Supportive Services
  • Learning Resources

Working at MSU

  • Human Resources
  • EBS Login
  • Job Postings
  • Employee Assistance Program

Reports

  • CARES Act Funding
  • Student Achievement and Outcomes

Contact us

517-355-1855

Address

Michigan State University 426 Auditorium Road East Lansing, MI 48824

Follow Us

  • Visit our Facebook page
  • Visit our page on X
  • Visit our Instagram page
  • Visit our TikTok page
  • Visit our LinkedIn page
  • Visit our YouTube page

If you're having accessibility issues, please let us know.

Know More: Campus Safety Information and ResourcesTransparency Reporting: Budget & Salary/Compensation
  • Contact Information|
  • Site Map|
  • Privacy Statement|
  • Site Accessibility|
  • Call MSU: (517) 355-1855|
  • Visit: msu.edu|
  • Notice of Nondiscrimination|

SPARTANS WILL|© Michigan State University|