Connect with us

Forgotten Dairies

American Healthcare Is Hoarding Data It Cannot Defend -By Fransiscus Nanga Roka

Treating patients is one thing, but hoarding life-long biological secrets without the lifelong security of healthcare institutions. They are manufacturing hostages.

Published

on

Two Health Care Breaches, More Than 6.9 Million Victims And One Ultimate Finding: America’s Medical-Data Economy Gathers Each Piece Of Data With Clinical Precision But Secures It With Institutional Negligence

AdaptHealth and Baylor Genetics announced separate June hacks targeting 4,115,802 and 2,810,878 people on August 14. Both were reported to the US2 Department of Health and Human Services putting them on the 2026 largest healthcare breaches list. Under HIPAA, significant violations are investigated by HHS’s Office for Civil Rights.

The why, who, what and when are all crystal clear. The how unveils two very different types of security failure.

In the case of AdaptHealth, a home medical equipment and related services company an attacker was reportedly able to take over an active session from a third-party contractor via social engineering. Unauthorized use started on approximately June 5. The firm was issued an extortion note by the perpetrator on June 15th which claimed that it stole files from its systems. AdaptHealth went on to confirm that information could have retrieved behind the attack may also include names, contact and demographic details, health information and insurance data. A disclosure with the SEC confirms the breach claimed by actor on June 15.

AdaptHealth said Social Security numbers and financial information were not included. That is comforting only by the appropriately low bar for American breach response. Data can include diagnoses, treatment information, insurance records and contact details — any of which could be used to commit medical-identity theft, fraudulent billing, blackmail or even tailored phishing. This is even truer if you think about how health data can expose weaknesses that no amount of password resetting will ever cover up.

Advertisement

The more immediate danger comes from Baylor Genetics. The cybercriminal had access to portions of its network between June 11 and June 17. The compromised data may have contained names, birth dates, medical-testing information, laboratory results and insurance details as well as Social Security numbers for a small number of patients. Some present and past employees were also exposed to government identifiers and financial-account data. (globenewswire. com)

The genetic and lab data are not ordinary assets of a corporation. They could reveal risks of inherited diseases, biological relationships and private medical information—not just about patients but perhaps also about their relatives. It is too late to put the genie back in the bottle: credit monitoring cannot restore genetic privacy. You cannot delete a genome and issue a different one.

The why is structural. Healthcare organizations have created huge ecosystems incorporating cloud platforms, laboratories, insurers, contractor sand billing intermediaries. Each additional integration increases the potential area for attack, but blame is diffused between contracts. Describing the AdaptHealth hack as social engineering is on the verge of obfuscating an architectural failure: a single compromised contractor session should not get access to millions of PII records.

Both companies report that the systems were secured, monitoring and access controls enhanced, forensic experts engaged and protective services offered. These steps are required but post-breach remediation is as poor proof of pre-breach diligence.

HHS should perform its own HIPAA Security Rule investigations, and publicly state whether access controls, audit logs, risk analyses and vendor oversight were sufficient; if not, fines should be calibrated based on the number and sensitivity of exposed records. Every contractor accessing protected health information should use phishing-resistant authentication, sessions bound to devices, continuous behavioral analysis, least-privilege access and near-instantaneous revocation of compromised credentials.

Advertisement

There is no doubt Congress needs to do the same for genetic data: strict limits on retention, prohibitions on secondary commercialization, encryption with segregated keys plus a private right of action without proof of completed identity theft.

Lastly, healthcare boards should personally certify the effectiveness of cyber-risk controls, similar to how executives certify financial reporting. Accountability has to climb the chain of command—for those who approved insecure systems—not just end with a duped employee or contractor.

Treating patients is one thing, but hoarding life-long biological secrets without the lifelong security of healthcare institutions. They are manufacturing hostages.

Fransiscus Nanga Roka

Faculty of Law University 17 August 1945 Surabaya and managing Partner Law Firm Victorious Indonesia

Advertisement
Continue Reading
Advertisement
Click to comment

Leave a Reply

Your email address will not be published. Required fields are marked *

Trending Contents

Topical Issues

Job Joseph Job Joseph
Forgotten Dairies2 hours ago

Analysing The Legal Frameworks And Strategies Employed By Financial Institutions In Restructuring Debt Portfolios -By Job Joseph

In Nigeria, the legal framework for debt restructuring is not contained in a single statute. Rather, it is distributed among...

BOLA AHMED TINUBU BOLA AHMED TINUBU
Forgotten Dairies6 hours ago

Sell Akara, Not Babies and Human Parts -By Abdulkadir Salaudeen

Since the Tinubu government, through the First Lady, Iya Alakara, has promised jobless Nigerians grants to start selling akara, let...

Flag,Of,Japan,Waving,In,The,Wind Flag,Of,Japan,Waving,In,The,Wind
Global Issues6 hours ago

Japan’s Zero Trust Government Trusted a Vulnerable VPN -By Fransiscus Nanga Roka

Lastly, the government should make breach simulations mandatory for all ministries. Zero trust is slain not by documentation claiming a...

cybersecurity-cybercrime cybersecurity-cybercrime
Forgotten Dairies6 hours ago

Europe Just Criminalized Corporate Silence on Cybersecurity -By Fransiscus Nanga Roka

Preventing wealthy corporations from looking at fines the same way as operating expenses. Enforcement should focus on whether someone concealed...

PETER OBI BLOCKADE PETER OBI BLOCKADE
Forgotten Dairies12 hours ago

Benue Blocked Peter Obi’s Humanitarian Convoy: Is Enugu Trying to Block His Political Messages? -By Vitus Ozoke, PhD

If a citizen owns a property and voluntarily wishes to display a lawful political message there, the burden should be...

Hajia-Hadiza-Mohammed Hajia-Hadiza-Mohammed
Forgotten Dairies14 hours ago

The Need For The Opposition To Come Together For A Purposeful Democratic Coalition To Rescue Nigeria And Save Our Democracy -By Hajia Hadiza Mohammed

I expect them to also pull their resources together, mobilize and sensitize the masses, invest in the technology and other...

Peter Obi and Tinubu Peter Obi and Tinubu
Breaking News16 hours ago

APC, Presidency dismiss Obi’s 2023 victory claim, predict Tinubu win in 2027

Peter Obi insists he won the 2023 presidential election, while the APC and Presidency reject his claim and predict another...

Osun State Osun State
Forgotten Dairies17 hours ago

Akindele And The Turnaround Of Osun Public Healthcare Deliveries -By Olajide Adeniyi

As he marks a new age, I am very sure that Osun people will be grateful for the impressive impacts...

Peter Obi and Hyacinth Alia Peter Obi and Hyacinth Alia
Forgotten Dairies18 hours ago

An Open Letter to His Excellency, Hyacinth Iormem Alia, The Executive Governor of Benue State -By Dokpesi Timothy Adidi, Ph.D

This threatens the very theological maxim that says “the water of baptism is thicker than blood”—a truth used across Christian...

Peter Obi Peter Obi
Breaking News1 day ago

Peter Obi: ‘We believed INEC’ but chairman worked for opposition in 2023

Peter Obi says Nigerians took the 2023 election for granted by trusting INEC, alleging that its chairman worked for the...