





















Dr. Mark Boxer is Board Chair of P-n-T Data Corp and is an internationally recognized healthcare technology executive.

getty
Data breaches have become disturbingly routine—both in scale and in cost. In 2024 alone, Americans received more than 1.35 billion breach notifications.
These numbers are troubling on their own, but the stakes are even higher in healthcare, where the exposure of medical data carries deeper privacy implications and far greater financial value. Hackers and other bad actors target healthcare for three reasons: the vast number of entry points, the high connectivity among electronic systems where data resides and the depth of information held in such systems.
While healthcare providers and facilities need to retain patient data for a specified period, many other players in the healthcare ecosystem either retain data longer than necessary or compile data to sell to other entities.
Patients don’t know where their healthcare data is, and they don’t understand how it’s protected or not protected. Instead, they leave it to the industry, and it’s the Wild West out there. To truly protect patients, companies must retain the minimum amount of data in the least number of places possible.
Healthcare leaders should think about data retention as a risk-sharing problem, not just a compliance one. Each stakeholder stores data differently because each sits at a different point in the workflow, and each has different obligations for operations, reimbursement and recordkeeping.
Providers, for example, keep data to support care continuity, billing, audits and legal defense. Clearinghouses need it to route claims and standardize transactions. Insurers hold data to adjudicate coverage, detect fraud and manage utilization. And business associates often retain data to deliver analytics and services related to population health, revenue cycle or business processes.
Fragmentation in how data is used, along with the push for interoperability, creates a major security challenge: The same patient record can be copied across systems, vendors and archives, expanding the number of places attackers can target. As more companies store the data, the harder it becomes to know what's still needed, where it lives, who can access it and whether old copies have been properly deleted.
For healthcare leaders, protecting data isn't just about stronger encryption and access controls. It also means minimizing duplication, tightening retention schedules, segmenting sensitive datasets and scrutinizing downstream vendors that may keep data far longer than the original business purpose requires.
The safest data is data that was never broadly copied in the first place.
That brings me to a very large clearinghouse, where a February 2024 breach exposed more than 192 million medical records. Clearinghouses don’t have to hold the data they have access to in their role as intermediary between providers and payers, but most of them do. Until the healthcare industry shifts fundamentally away from holding data, I fear the incidence of hacking and data breaches will continue.
New and better data models are emerging, such as what we call a “no-residency” transport model that reduces breach risk by ensuring data moves directly to its approved destination or is processed without being stored in extra places. The value of such an approach is high, not only because healthcare organizations handle sensitive data but also because that data is widely shared among providers, payers, labs and vendors. By limiting where data exists, organizations can shrink the attack surface, reduce the fallout of an incident and make compliance easier to demonstrate.
This approach works best when paired with encryption, strict access controls, audit trails and zero-trust security. This model not only allows data to move faster but also minimizes unnecessary storage and exposure. For breach-conscious healthcare companies, that makes it a practical security and governance strategy.
While that breach was eye-popping in terms of the number of records accessed by bad actors, another 738 breaches of more than 500 records were reported in 2024 to the Office of Civil Rights of the U.S. Department of Health and Human Services, keepers of the so-called “Wall of Shame.”
The IBM "Cost of a Data Breach Report 2025" shows that the cost to detect and remediate a healthcare breach fell 24% in 2025 to $7.42 million, while the "mean time organizations took to identify and contain a breach fell to 241 days," down 16% from its 2021 peak.
Think about that last figure for a moment. The industry is doing a better job at finding and containing breaches, but companies still need more than eight months to find and contain them. That figure alone shows that fundamental changes are needed to protect patient data.
Preventing breaches starts with better data management and control. But that can’t happen without understanding all the places where data resides and making sure that data is retained in as few places as possible.
For healthcare leaders, the point isn't simply to improve technical controls. It's to understand exactly where patient data lives, who controls each copy, why it's retained and whether every stored version is truly necessary. The goal is to reduce exposure, limit the impact of a breach and demonstrate disciplined stewardship to regulators, partners and patients.
Available data protection options exist on a spectrum. At one end are stronger retention policies, deletion discipline, encryption, segmentation and tighter vendor oversight. At the other are newer transport approaches, including “no-residency” models, that move data directly to approved destinations or process it without creating extra stored copies outside compliant environments.
The trade-offs are real. Legacy systems may not support cleaner data flows, interoperability can still require duplication and analytics teams may depend on broad access. Vendors also often retain data longer than the original business purpose requires. For healthcare executives, the core challenge is treating data residency as a governance issue, not just an IT issue.
Every unnecessary copy of data is another liability.
Forbes Technology Council is an invitation-only community for world-class CIOs, CTOs and technology executives. Do I qualify?
此内容由惯性聚合(RSS阅读器)自动聚合整理,仅供阅读参考。 原文来自 — 版权归原作者所有。