Showing posts with label Protenus Breach Barometer. Show all posts
Showing posts with label Protenus Breach Barometer. Show all posts

Wednesday, August 2, 2017

Protenus receives $3M in series A funding

Protenus, a company that is established an analytics platform intended to stop data breaches and secure patient information, recently gained $3 million in funding from investors to advance research and product development.

Kaiser Permanente Ventures and F-Prime Capital Partners invested in Protenus in its series A funding.

Protenus collaborates with several healthcare systems and hospitals across the country, and is capable to secure data for more than 44 million patients.

“This extra funding will assist us explore the cost and benefits of different kinds of products built off of our analytics platform to understand what is most needed in healthcare and how we can help best,” claims Nick Culbertson, the company’s CEO.

Protenus utilizes artificial intelligence techniques to better understand workflows in the healthcare industry, and the approach enables it to distinguish unsuitable access to patient information.

“We develop profiles on patients based on what kind of treatment they are getting, and we build profiles based on human resources data to understand what type of employees are accessing patient data,” Culbertson states.

In the year of 2016, over 27 million patient records were breached, as reported by the Protenus Breach Barometer, and so far this year, there has been an average of at least one health data breach a day, with 40% of them a result of insider access.

“We use system access logs to explain how certain kinds of workers are accessing (records of) certain kinds of patients throughout that care workflow process. In other words, we develop the clinical workflow in a virtual environment and understand how employees are virtually passing medical records from one to another,” says Culbertson.

Protenus expects to be able to use its platform to identify other anomalies in those workflows, enabling it to catch problems such as prescription abuse, fraud or other types of medical anomalies.

“We like to consider it [Protenus] as a tool to cause cultural reform, because a lot of individuals are doing things because they do not realize it is illegal, and so when you are able to identify it early, educate them and remind them that they are abusing access to sufferer data, that is a chance to educate and stop that in the future,” says Culbertson.

 

Tuesday, May 23, 2017

Organizations informing data breaches faster to federal agencies

The Department of Health and Human Services’ OCR (Office for Civil Rights) is cracking down on providers that don’t report data breaches of protected health information in a basic timely manner. OCR in the month of March initiated to fine agencies that don’t notify federal agencies of breaches within sixty days as required. The effect has been dramatic—average reporting times for breaches were merely 45 days in the month of March and 59 in the month of April, compared with 478 days in February, in accordance to Protenus, a vendor that offers a cloud platform to monitor and secure the security of hospital electronic health records (EHRs).

“It is complex to know for sure with limited information, but we might recommend 2 reasons for this trend of reduced breach reporting time,” claims Robert Lord, co-founder and CEO at Protenus. “One potential reason is that initiating earlier this year, HHS has arguably stepped up enforcement on healthcare agencies that don’t report breaches within the required 60-day window. Organizations are informing data breaches faster to federal agencies.

“An extra potential reason is that healthcare agencies are becoming more diligent in their analysis and reporting of breaches, as awareness of the significance of reporting grows,” Lord continues. “While these tragedies are unfortunate, they can be utilized as a learning experience to educate other covered entities on best practices.”

The number of days between when a breach occurred and when it was discovered in the month of April ranged from almost instantly to 228 days. Organizations are informing data breaches faster to federal agencies.

In April, 16 hacking tragedies accounted for 47% of all breaches. Additionally, another 29% were caused by insiders; 15% involved lost or stolen information and 9% by unknown means. The total number of records breached in the April attacks for which Protenus has numbers includes 171,268 patients.

The kinds of breaches reported last month involve providers (79% of all incidents), health insurers (5.8%), business associates or vendors (5.8%) and other (8.8%). Data from the monthly Protenus Breach Barometer report comes from DataBreaches.net.