Skip to main content
Best Practices

The True Cost of a HIPAA Data Breach

Another week, another HIPAA data breach. On September 10th, healthcare behemoth Kaiser Permanente sent out a letter to 670 patients, notifying them that their PHI had been impermissibly emailed out of network. But in light of all these recent data breaches and security failures, one might ask, “who cares?” If fixing the issue is as simple as writing an apology letter like Kaiser did, why go through all the hoops of encryption and access control and HIPAA compliance? After all, HHS still has the ultimate discretion of whether to assess penalties, right?

3 min read
true cost of hipaa data breach|cost of a hipaa data breach

Another week, another HIPAA data breach. On September 10th, healthcare behemoth Kaiser Permanente sent out a letter to 670 patients, notifying them that their PHI had been impermissibly emailed out of network. But in light of all these recent data breaches and security failures, one might ask, “who cares?” If fixing the issue is as simple as writing an apology letter like Kaiser did, why go through all the hoops of encryption and access control and HIPAA compliance? After all, HHS still has the ultimate discretion of whether to assess penalties, right?

Well, if the only cost was paying a fee to HHS, this analysis would be correct. Unfortunately for providers, the true cost of a HIPAA data breach typically dwarfs any sort of HIPAA or regulatory fine.

The True Cost of a Data Breach per Patient Record

cost of a hipaa data breach

In a white paper put out earlier this year by tech company Symantec, a global analysis yielded that the average cost of a US data breach fell just a shade under $200 per record compromised, which aligns with other studies done on the subject. If this number seems high, it’s because it is. The $200/record figure takes into account the cost of notifying individuals, providing credit monitoring services to them for the next decade or two, and various other costs associated with remedying the event.

Think about that number again. $200 per person! That means that for each of the four laptops that were stolen from Advocate earlier this summer – with their one million of patient records stored on each – each mobile device represented, on average, about $200 million in potential liability to the health system. This number is truly astounding. Put another way, the liability risk for each laptop more or less equated to the asset price of the hospital building they walked out of.

HIPAA Data Breaches are Expensive

To make matters worse, some could argue that $200/person mark represents a low estimate of the true total cost of a data breach. If an entity was particularly negligent, it could invite a class action lawsuit where the plaintiffs can and have asked for upwards of $1,000/record. Moreover, the $200/record figure doesn’t take into account the negative publicity and the effect that this could have on a publically traded healthcare company. Just ask CVS.

The Magnitude of Risk for a HIPAA Breach

The scariest part of all of this is that many providers don’t understand the magnitude of the risks they are taking by skipping some of the HIPAA regulations. Sure, you could get caught by HHS under HIPAA and get penalized for not using secured email or secure text messaging, and you might have to pay a hefty fine as a result. However, the much bigger risk is having an IT failure and letting thousands of records walk out of your facility in a heartbeat. The real cost of that sort of an event will blow the regulatory fine away.

Frequently Asked Questions

Find answers to common questions about this topic.

According to Symantec's analysis, the average cost of a US data breach is just under $200 per compromised patient record. This cost includes patient notification, credit monitoring services, and various remediation expenses that can span decades.

A laptop containing one million patient records represents approximately $200 million in potential liability based on the average cost per record. This liability risk can equal the asset value of an entire hospital building.

Yes, particularly negligent entities may face class action lawsuits seeking upwards of $1,000 per record. The $200 figure also doesn't account for negative publicity costs or stock price impacts on publicly traded healthcare companies.

While HHS regulatory fines are significant, the true financial risk comes from breach remediation costs, patient notification expenses, and potential class action lawsuits. These costs typically far exceed any regulatory penalties imposed by HHS.

The $200 per record cost includes patient breach notification expenses, credit monitoring services for affected individuals, and various other remediation costs. These services may need to be provided for up to two decades following the breach incident.

Krishna Kurapati

Written by

Krishna Kurapati

Founder & CEO

Founder & CEO of QliqSOFT with 20+ years of healthcare technology experience.

View all posts

Related Articles

wellpoint hipaa breach alert|wellpoint hipaa breach settlement
Best Practices

HIPAA Breach Alert: WellPoint fined $1.7M

In what is believed to be one of the larger HIPAA breach settlements in recent memory, health insurer WellPoint has agreed to settle with HHS for $1.7M stemming from a 2009 and 2010 incident where WellPoint impermissibly disclosed the ePHI of over 600,000 individuals through an unsecured online application. During its investigation, OCR found that WellPoint had not enacted the appropriate administrative, technical, and physical safeguards mandated under HIPAA.

Krishna KurapatiKrishna Kurapati
1 min read
hipaa data breaches|securing your healthcare organization from HIPAA data breaches
Best Practices

HIPAA Data Breaches: Bad Technology or Bad Training?

As regular readers of the qliqSOFT blog are now aware, the HIPAA Omnibus changes have been in effect for just over two weeks. In the wake of the September 23 compliance deadline, HIPAA compliance should be on the minds of most covered entities even more than usual, and rightfully so – HIPAA data breaches not only sacrifice the trust you’ve established with your patients, but also they’re extraordinarily expensive.

Krishna KurapatiKrishna Kurapati
3 min read
3m left