Call us 01603 513 271
Search

Can’t find what you’re looking for? Get in touch today.

Top results for ''

View all ()

No results for ''

Please try searching again with a different term, visit our FAQs page or get in touch.

Product has been added to your cart

View Cart
4.9/5

Why are medical records so valuable to data thieves?

When you think of a data breach, what’s the first thing that springs to mind? The theft of credit card information? Other financial data falling into the wrong hands? While protecting confidential financial data is very important, it’s actually health data and medical records at the highest risk of a breach.

Between 2019 and 2025, there were 206,140 data breaches noted in the ICO's Data Security Incident Trends report. Of these, the health sector experienced 32,127 breaches - around 15.59% of the total. The causes of these breaches are noted in the table below.

Incident type

Number of incidents

Alteration of personal data

82

Brute Force

82

Data emailed to incorrect recipient

3,924

Data of wrong data subject shown in client portal

679

Data posted or faxed to incorrect recipient

3,134

Denial of service

22

Failure to redact

925

Failure to use bcc

429

Hardware/software misconfiguration

1,019

Incorrect disposal of hardware

21

Incorrect disposal of paperwork

227

Loss/theft of device containing personal data

612

Loss/theft of paperwork or data left in insecure location

3,083

Malware

136

Not Provided

1,146

Other cyber incident

573

Other non-cyber incident

6,762

Phishing

1,445

Ransomware

1,560

Unauthorised access

5,216

Verbal disclosure of personal data

1,050

Breach levels have been increasing with growing severity in the last couple of years. This trend goes beyond the UK, too. In 2015, a US-based health insurance company had the personal information of 78.8 million current and former customers stolen. Information stolen included names, addresses, Social Security numbers, employment histories, and dates of birth. In other words, everything a hacker needs to commit identity fraud. This was one of the largest medical data breaches in healthcare history.

Why are health sector data breaches so high?

To understand why health data and medical records are so valuable to hackers, we must get into the thieves’ minds.

Firstly, medical records provide an opportunity for crimes with more longevity than, for example, credit card information. Acts of fraud using stolen bank cards are likely to be detected very quickly. This is due to intricate artificial intelligence within fraud detection systems. In most attempts, card fraud is unsuccessful. If they are successful, banks almost always refund any money taken unlawfully. With few fraud detection systems in place in the medical sector, it is often a laborious investigative process to detect any breaches. As a result, leaks and misuse of healthcare data can often take months or even years to detect.

Secondly, there is a lot a thief can do with a full medical record. Medical records typically include a patient’s name, date of birth, address, preferred GP, medical history, employment history, and prescription information. Thieves can use this data to create false identities, commit health insurance fraud and illegally obtain prescription drugs or medical equipment.

Thieves also don’t even need to process this information themselves. They can sell stolen patient information to other criminals for vast sums of money. A single, full medical record can sell for around £15.21 ($20) on the Dark Web. Additionally, if thieves use the data to create fake passports, prescriptions and other documents, they can sell for up to £1520 ($2000) each.

In the mind of the hacker, it’s more economical to attempt the theft of high quantities of healthcare data than it is to scam individuals out of their bank details, for instance.

The importance of protecting health information

It is absolutely imperative to take measures to prevent breaches of healthcare information. First and foremost, this data is extremely personal to the victims. Imagine if your own medical history were on display for the world to see and misuse. While this may seem unlikely, in January 2019, it became known that the HIV-positive status of 14,200 people who either lived in or visited Singapore had been leaked online. Such information becoming public could be life-changing.

So, what can we all do to avoid these breaches?

Luckily, there are many preventative methods that can be taken to avoid a data breach in the workplace.

A large part of compliance and data breach prevention is knowing when to destroy data. Here at Shred Station, we can help with this. We work with all types of health and social care organisations and medical bodies. This includes hospitals, hospices, local health trusts, doctors' and GPs’ surgeries, private clinics, dental practices, pharmacies, care home providers and care organisations. Not only do we shred paper documents, but we can also destroy everything from clothing and uniforms to ID cards, X-rays, photographic prints, CCTV tapes, digital media, electronic equipment, hard drives, and data storage devices.

If you want to know more about how we can assist you, get in touch with one of our data destruction experts today.