Summary of indicators
| Criteria | Indicator | Indicator description | Other notes |
|---|---|---|---|
| Data breach cause | Hacking/IT Incident | Total number of hacking/IT breaches | – |
| Improper Disposal | Total number of improper disposal breaches | ||
| Loss | Total number of loss breaches | ||
| Theft | Total number of theft breaches | ||
| Unauthorized Access/Disclosure | Total number of unauthorized access/disclosure breaches | ||
| Data breach locus | Locations | Total number of locations affected as a result of breaches | HIPAA classifies locations holding PHI into eight categories: desktop computers, electronic medical records (EMRs), emails, laptops, network servers, paper/films, other portable electronic devices, and others (U.S. Department of Health and Human Services, 2013). These locations represent both physical (e.g. paper records) and online locations (e.g. email, network servers) |
| Data breach impact | PHI Stolen | Number of types of PHI stolen. For example, if the breach led to the loss of medical diagnoses and billing numbers, the cell in data should show the number “2,” indicating that two types of PHI were stolen | HIPAA web description provides the type of PHI stolen. While covered entities can select predefined categories, they can enter additional types of PHI as they find appropriate. Examples included names, social security numbers, diagnoses, medications prescribed, and treatment information |
| Number of Individuals Affected | Number of individuals affected as a result of the data breach | – |
| Criteria | Indicator | Indicator description | Other notes |
|---|---|---|---|
| Data breach cause | Hacking/IT Incident | Total number of hacking/IT breaches | – |
| Improper Disposal | Total number of improper disposal breaches | ||
| Loss | Total number of loss breaches | ||
| Theft | Total number of theft breaches | ||
| Unauthorized Access/Disclosure | Total number of unauthorized access/disclosure breaches | ||
| Data breach locus | Locations | Total number of locations affected as a result of breaches | HIPAA classifies locations holding PHI into eight categories: desktop computers, electronic medical records (EMRs), emails, laptops, network servers, paper/films, other portable electronic devices, and others ( |
| Data breach impact | PHI Stolen | Number of types of PHI stolen. For example, if the breach led to the loss of medical diagnoses and billing numbers, the cell in data should show the number “2,” indicating that two types of PHI were stolen | HIPAA web description provides the type of PHI stolen. While covered entities can select predefined categories, they can enter additional types of PHI as they find appropriate. Examples included names, social security numbers, diagnoses, medications prescribed, and treatment information |
| Number of Individuals Affected | Number of individuals affected as a result of the data breach | – |
Source(s): Table by authors
Sharing content requires targeting cookies to be enabled. Please update your cookie preferences to use this feature.