Encryption and the Loss of Patient Data
Name
Tucker_Encryption and the loss.pdf
Size
339.94 KB
Format
Adobe PDF
Checksum (MD5)
b3f4409e20da56016640d0941ecb3ab9
Author(s) •
Tucker, Catherine Elizabeth
Miller, Amalia R.
Date Issued
May 2011
Journal
Journal of Policy Analysis and Management
Publisher
Wiley Blackwell
Citation
Miller, Amalia R., and Catherine E. Tucker. “Encryption and the Loss of Patient Data.” Journal of Policy Analysis and Management 30.3 (2011): 534–556.
Version
Author's final manuscript
Abstract
Fast-paced IT advances have made it increasingly possible and useful for firms to collect data on their customers on an unprecedented scale. One downside of this is that firms can experience negative publicity and financial damage if their data are breached. This is particularly the case in the medical sector, where we find empirical evidence that increased digitization of patient data is associated with more data breaches. The encryption of customer data is often presented as a potential solution, because encryption acts as a disincentive for potential malicious hackers, and can minimize the risk of breached data being put to malicious use. However, encryption both requires careful data management policies to be successful and does not ward off the insider threat. Indeed, we find no empirical evidence of a decrease in publicized instances of data loss associated with the use of encryption. Instead, there are actually increases in the cases of publicized data loss due to internal fraud or loss of computer equipment.
MIT Department
Sloan School of Management
Terms of Use
Creative Commons Attribution-Noncommercial-Share Alike 3.0
Persistent DSpace Link
DOI of Published Version
https://doi.org/10.1002/pam.20590