DataBreaches.Net

Menu
  • About
  • Breach Notification Laws
  • Privacy Policy
  • Transparency Report
Menu

The State Of Health Data For Vulnerable Populations, Why Cybercriminals Target Children, The Elderly, and the Dead

Posted on April 14, 2021 by Dissent

Jessica Sganga  and Kenneth Wang of Knobbe Marten write:

As of 2021, more than twice the number of data breaches are now being reported than 6 years ago and three times the number of data breaches that occurred in 2010.[1] While credit cards and social security numbers are perennial favorites, cybercrime has begun to favor the theft of electronic medical records (EMR) as sources of revenue. With banks and major financial institutions starting to wise up and tighten their electronic security, cybercriminals have begun to target vulnerable healthcare institutions with a particular focus on the records of children, elderly people, and the deceased.

Compared to credit cards and social security numbers, health records are often more lucrative for cyber criminals. Most credit card and social security numbers sell for about $5, while medical records fetch an average of $250, with the most complete records reportedly going for $1,000.[2].

I’m going to stop this right there, as they are just repeating inaccurate information that has been previously called out as inaccurate. Experian corrected their error years ago after I pointed it out to them and yet many people still link to and repeat the old incorrect information.  Similarly, a study done years ago that found a medical record could have a selling/asking price of $250 has no real predictive value in today’s market, where the market has been flooded, and a medical record might sell for a few dollars unless it belongs to some celebrity or person of great public interest.

There are good reasons to consider youth and the elderly vulnerable populations, but let’s not exaggerate the commercial value of records or data. DataBreaches.net sees patient information records on a daily basis from hacks, dumps, and misconfigured storage servers. When you see a 10-page scanned file on a patient that has PII and PHI, you might think “Great!”  Then again, you may realize how time-consuming it would be to extract information from scanned pdfs in bulk.  If someone needs just one record, ok, but many criminals would not invest their time in data unless it is in readily usable format.

Category: Commentaries and AnalysesHealth Data

Post navigation

← Court Dismisses Data Privacy Litigation Alleging Defendant Failed to Maintain Reasonable Security Procedures in Wake of Data Breach
Swedish prosecutor says Russia’s GRU hacked Sweden’s sports body, WADA →

2 thoughts on “The State Of Health Data For Vulnerable Populations, Why Cybercriminals Target Children, The Elderly, and the Dead”

  1. Axel Wirth says:
    April 14, 2021 at 9:24 am

    The problem with these snapshot statistics, although well intended, is that they are being kept alive through continual re-citation. A few years ago I was getting skeptical about the often quoted statistics that “according tho the FBI, on the Black Market, your Health Records is worth $50, compared to $1 for a Credit Card Number”, then typically citing an article from a year or so ago that was also dubiously also referencing this mystical FBI report.
    Turns out, if you follow the chain, it leads to a FBI Private Industry Notification (PIN) from April 2014, which in turn references an RSA whitepaper from July 2013, which refers back to an article in the Electronic Health Reporter from Jan. 2013 that seems to rely on something IDExperts published in Feb. 2012. And, curiously, both (Electronic Health Reporter and IDExperts) reference research by the World Privacy Forum that was presented at a workshop in 2006.
    To your point – today’s reality is far more complex and can not (nor should it) be reduced to a simple number.

    1. Dissent says:
      April 14, 2021 at 9:56 am

      Absolutely. I went down the same chain/rabbit hole trying to track down the source of the $50, and when I got to Pam Dixon of the World Privacy Forum, she could not give me an actual research-based sourcing. But because WPF’s report on medical identity theft was the seminal paper on the topic, that number has been reported by numerous other papers and presenters.

      Whether it had any validity at the time unknown to me. It certainly does not appear valid now, and I wonder about all the people who repeat it without ever going to look on dark web markets or forums to see what things really sell for/list at.

Comments are closed.

Now more than ever

"Stand with Ukraine:" above raised hands. The illustration is in blue and yellow, the colors of Ukraine's flag.

Search

Browse by Categories

Recent Posts

  • Ransomware Attack on ADP Partner Exposes Broadcom Employee Data
  • Anne Arundel ransomware attack compromised confidential health data, county says
  • Australian national known as “DR32” sentenced in U.S. federal court
  • Alabama Man Sentenced to 14 Months in Connection with Securities and Exchange Commission X Hack that Spiked Bitcoin Prices
  • Japan enacts new Active Cyberdefense Law allowing for offensive cyber operations
  • Breachforums Boss “Pompompurin” to Pay $700k in Healthcare Breach
  • HHS Office for Civil Rights Settles HIPAA Cybersecurity Investigation with Vision Upright MRI
  • Additional 12 Defendants Charged in RICO Conspiracy for over $263 Million Cryptocurrency Thefts, Money Laundering, Home Break-Ins
  • RIBridges firewall worked. But forensic report says hundreds of alarms went unnoticed by Deloitte.
  • Chinese Hackers Hit Drone Sector in Supply Chain Attacks

No, You Can’t Buy a Post or an Interview

This site does not accept sponsored posts or link-back arrangements. Inquiries about either are ignored.

And despite what some trolls may try to claim: DataBreaches has never accepted even one dime to interview or report on anyone. Nor will DataBreaches ever pay anyone for data or to interview them.

Want to Get Our RSS Feed?

Grab it here:

https://databreaches.net/feed/

RSS Recent Posts on PogoWasRight.org

  • Massachusetts Senate Committee Approves Robust Comprehensive Privacy Law
  • Montana Becomes First State to Close the Law Enforcement Data Broker Loophole
  • Privacy enforcement under Andrew Ferguson’s FTC
  • “We would be less confidential than Google” – Proton threatens to quit Switzerland over new surveillance law
  • CFPB Quietly Kills Rule to Shield Americans From Data Brokers
  • South Korea fines Temu for data protection violations
  • The BR Privacy & Security Download: May 2025

Have a News Tip?

Email: Tips[at]DataBreaches.net

Signal: +1 516-776-7756

Contact Me

Email: info[at]databreaches.net

Mastodon: Infosec.Exchange/@PogoWasRight

Signal: +1 516-776-7756

DMCA Concern: dmca[at]databreaches.net
© 2009 – 2025 DataBreaches.net and DataBreaches LLC. All rights reserved.