By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Health Works CollectiveHealth Works CollectiveHealth Works Collective
  • Health
    • Mental Health
  • Policy and Law
    • Global Healthcare
    • Medical Ethics
  • Medical Innovations
  • News
  • Wellness
  • Tech
Search
© 2023 HealthWorks Collective. All Rights Reserved.
Reading: PCI & HIPAA Data Breaches of 2012: Lessons Learned
Share
Notification Show More
Font ResizerAa
Health Works CollectiveHealth Works Collective
Font ResizerAa
Search
Follow US
  • About
  • Contact
  • Privacy
© 2023 HealthWorks Collective. All Rights Reserved.
Health Works Collective > eHealth > PCI & HIPAA Data Breaches of 2012: Lessons Learned
eHealth

PCI & HIPAA Data Breaches of 2012: Lessons Learned

onlinetech
onlinetech
Share
4 Min Read
SHARE

Here’s a review of the top 2012 data breaches within both the PCI and HIPAA compliant industries, and a quick analysis of what went wrong so you can easily learn from their lessons without accruing the associated costs and legalities.

Here’s a review of the top 2012 data breaches within both the PCI and HIPAA compliant industries, and a quick analysis of what went wrong so you can easily learn from their lessons without accruing the associated costs and legalities.

3.8 Million Tax Records Stolen in Largest State Agency Attack
Both Social Security and credit card numbers were stolen from the South Carolina Department of Revenue by hackers in August. A phishing email enabled hackers to steal credentials from users and eventually steal 74 GB of encrypted and unencrypted data.

Lessons learned: Encryption is a requirement for all organizations (including federal) that store credit card data and therefore need to meet PCI DSS compliance standards. One step ahead of encryption is administrative security, including training staff on security issues, which can prevent users from clicking on phishing emails and allowing the initial breach to occur. Check with any third-parties to ensure their staff is also properly trained.

More Read

Top 10 Healthcare Influencers to Follow on Twitter
FDA Issues Final Guidance on Wireless Medical Devices
Beyond the Buzz: What the New Twitter Profile Means for Healthcare Marketing
Does FTC Social Media Guidance Provide Clues for Pharma?
Veterans and mHealth: A Sensible Patient Engagement Strategy

Server Hack Leads to HIPAA Violation by Utah Department of Health
In April, 780,000 individuals were affected in a server hack at the authentication level that allowed hackers to access and steal SSNs and personal health records from the Utah Department of Health. One server was not configured according to normal procedure, and this allowed hackers to access the system.

Lessons learned: Technical staff in particular need proper HIPAA compliance training to ensure servers are configured correctly, especially servers that may contain ePHI (electronic protected health information) at rest. The state of Utah remediated by hiring an auditing firm to conduct independent security/HIPAA audits across all of their state agencies, suggesting they had not undergone one prior to the event. They also assigned a privacy and security officer to the department of health and improved security controls by adding network monitoring and intrusion detection.

Global Payments Inc. PCI Data Breach Affects 1.5 Million
Nearly 1.5 million consumers were affected by hackers accessing Global Payments Inc.’s payment processing system in January and February.

Lessons Learned: While the details of the system breach have been kept under wraps, the lesson to be learned here is to do your due diligence in confirming all third-party vendors are, in fact, PCI compliant. Global Payments is a widely used electronic transaction processing company that had been listed on Visa’s Global Registry of service Providers. They were removed after the attack. Even if your providers claim to be PCI compliant, it’s your job to check the requirements against their actual documented policies and technical services, if applicable, to keep credit card data secure.


 


 


 

TAGGED:data breach
Share This Article
Facebook Copy Link Print
Share

Stay Connected

1.5KFollowersLike
4.5KFollowersFollow
2.8KFollowersPin
136KSubscribersSubscribe

Latest News

public health housing
Structural Integrity in Homes and Its Impact on Public Health
Public Health
March 5, 2026
health and wellness
Redefining Self-Care: Health and Wellness Beyond the Trends 
Health Uncategorized
February 28, 2026
Understanding Leaky Gut Syndrome
Understanding Leaky Gut Syndrome
Health
February 25, 2026
Invisalign for Adults: Is It Too Late to Straighten Your Teeth?
Dental health Specialties
February 24, 2026

You Might also Like

Pew Social Media
BusinesseHealthSocial Media

Engagement: Making Your Social Media Matrix Sticky

January 19, 2014

Cervical Cancer? Yup, an App For That, Too–But Is It Any Good?

August 2, 2012

Commodization of EMR

October 30, 2011
Image
BusinessSocial Media

Beyond the Buzz: A Guide to Social Media Monitoring for Healthcare

August 16, 2014
Subscribe
Subscribe to our newsletter to get our newest articles instantly!
Follow US
© 2008-2025 HealthWorks Collective. All Rights Reserved.
  • About
  • Contact
  • Privacy
Welcome Back!

Sign in to your account

Username or Email Address
Password

Lost your password?