The City of Providence wants to investigate consolidating certain data sources across municipal and school district networks when its schools return from state to local control. The district superintendent is concerned about the plan’s finer points when it comes to data sharing. (Photo illustration by Alexander Castro/Rhode Island Current)
Health care providers are becoming more vulnerable to computer hackers.
Photo illustration by Alexander Castro/Rhode Island Current

How Patients Can Protect Themselves in the Wake of Recent Medical Data Breaches in Rhode Island

Tech experts say these incidents are becoming increasingly difficult to prevent, thanks to hackers who use artificial intelligence to their advantage

Tech experts say these incidents are becoming increasingly difficult to prevent, thanks to hackers who use artificial intelligence to their advantage

Share
The City of Providence wants to investigate consolidating certain data sources across municipal and school district networks when its schools return from state to local control. The district superintendent is concerned about the plan’s finer points when it comes to data sharing. (Photo illustration by Alexander Castro/Rhode Island Current)
Health care providers are becoming more vulnerable to computer hackers.
Photo illustration by Alexander Castro/Rhode Island Current
How Patients Can Protect Themselves in the Wake of Recent Medical Data Breaches in Rhode Island
Copy

Last month, Wood River Health announced a data breach that affected nearly 55,000 patients in Rhode Island and Connecticut. It was the latest in a string of instances that have seen hundreds of thousands of Rhode Islanders’ personal health data exposed.

Morning Host Luis Hernandez spoke with Lee Kim, senior principal of cybersecurity and privacy of the Healthcare Information and Management Systems Society, about what Rhode Islanders can do to protect themselves if their personal data is compromised in a data breach.

Interview highlights

What patients can do, generally do to protect their personal information

Lee Kim: Health care is about trust, so there is some degree of responsibility on the provider. But there is so much that we do online to converse with our doctor and to pull our records and reports as well, such as through the patient portal. As a result, we need to ensure that we are using multifactor authentication, where we can, to log into those portals; we are using strong passwords that are not inappropriately shared or reused.

On what patients can do if their personal info is compromised in a data breach

Kim: I would recommend to review, like a hawk, your explanation of benefits that you get from your insurance company to make sure it matches the services that you get. One of the problems is that sometimes there’s medical identity theft where someone can use your insurance information to get medical services, things that you never really signed up for, so to speak.

The other thing that you could do is on the financial side. What is really important is that people go to freecreditreport.com, and with that you can check your credit score and activity vis-a-vis the three major credit bureaus in the United States. That is something that you could pull for free once a year. Each of these three credit bureaus have, for a fee, credit monitoring services, which you can partake of if there is some kind of change.

On what health care providers can to do prevent data breaches

Kim: What providers can do to ensure that this happens less is, first of all, they need to get their security teams in order in terms of governance; make sure that security is a priority across the entire organization; train them on phishing; ensure that they have the best state-of-the-art security tools, and they’re using AI to fight AI, and make sure that vendors and other third parties and contractors are following suit as well.

On whether certain types of medical practices are more vulnerable to data theft

Kim: The answer is yes. Obviously, the weaker your defenses, the less money you have to defend yourself. Let’s say you are an entity that is publicly-funded or you are an entity that is essentially subsidized in part by the government or you’re a rural healthcare provider. That’s a lot more difficult because, unfortunately, many of the security tools that are out there today do require significant investment. So those small entities are much more vulnerable than others. Also, vendors that are smaller or startup companies might be more vulnerable than others that have been around the block, so to speak.

T.F. Green received a score of 84.9 in the annual Travel + Leisure magazine competition based on reader surveys evaluating airport amenities
The hospital allowed an unlicensed medical assistant to do a procedure prohibited under state regulations
Famiglietti, a personal injury lawyer who serves on North Providence’s town council, won more than 70% of the district’s votes in a four-way race
A rare legal clash between the Justice Department and the federal judiciary echoes to Rhode Island, where a 1990s-era lawsuit filed by then–U.S. Attorney Sheldon Whitehouse offers precedent and underscores the escalating tensions between executive power and judicial independence
The new state law also mandates RAs to be trained to administer the life-saving opioid reversal medication
In her latest novel These Summer Storms, Rhode Island author Sarah MacLean trades dukes for tech dynasties, spinning a tale of inheritance games, family dysfunction, and second chances—set against the brooding backdrop of a storm-lashed island estate