Skip to content
Literature · Aesthetic Surgery Journal EN LLM context A cited markdown file you can paste into your AI assistant (ChatGPT, Claude, a RAG or project knowledge base) to ground it in this document. Contains: this document’s text, its sections with their topics, and the full text of every law provision it applies. Everything links back to its source on overview.legal — legal information, not advice.

General Data Protection Regulation (GDPR) and Data Breaches: What You Should Know

Foad Nahai — Aesthetic Surgery Journal

Foad Nahai — Aesthetic Surgery Journal

Aesthetic Surgery Journal
DOI

How it connects

Full text

On May 25, 2018, the new General Data Protection Regulation (GDPR) enforced by the European Union and the United Kingdom Information Commissioner’s Office went into effect. Data protected by GDPR ranges from the relatively simple, such as email and IP addresses, to the highly sensitive, such as patient electronic health records. This recent regulation has resulted in a storm of activity by businesses and other data-collecting entities to comply with the requirements by updating privacy policies, opt-in notices, and email lists.1 How, if at all, does GDPR affect you? Generally speaking, the rules of GDPR differ somewhat from similar regulations in the United States, many of which are mandated on a state-by-state basis and involve varying definitions and remedies for a data breach.2 GDPR also differs in some respects from the Health Insurance Portability and Accountability (HIPAA) Breach Notification Rule issued by the US Department of Health and Human Services3 that details procedures by which covered entities and their business associates must provide notification following a breach of unsecured protected health information. Consider, however, that GDPR may have a broader definition of data breach than these other rules and that it protects the personal data rights of European Union citizens no matter where they live or where the breach occurs.1 Further, the widespread adoption of GDPR privacy standards by international companies may be a case of the “Brussels effect,” in which European laws and regulations are used as a global baseline.4 Therefore, wherever you conduct business, engage in research, or practice medicine, it is prudent to be aware of GDPR standards and their potential impact. The implications of GDPR for research and scholarly publishing entities are difficult and complex. Our subscribers, authors, and reviewers are located around the world, which means that this journal is clearly subject to GDPR rules. Our data security systems and procedures have always been robust, but we have taken all necessary steps to ensure that our data protection policies are completely GDPR-compliant. One of the greatest challenges for journals such as ours is to combine required diligence in data protection with the aim of increased transparency and accessibility in scientific research. Open science practices include sharing data sets as part of the publication process; this, of course, requires that such data be collected, stored, and shared in accordance with appropriate consent procedures and with ample regard for data sensitivity.1 Certainly, such concepts are not new. ASJ has always had a deep respect for data privacy and has, since its inception, implemented strict procedures to ensure confidentiality of sensitive data. In our case, GDPR simply serves to reinforce that obligation. Journal marketing practices must also be GDPR-compliant. This means that journals must obtain proper consent to store customer contact information and take measures to ensure that customers’ communication preferences are noted, kept current, and scrupulously adhered to. Although some may find a barrage of opt-in requests or opt-out offers somewhat annoying, such notifications allow consumers to specify their preferences for type and frequency of telemarketing, emails, e-alerts, and other communications.1 You undoubtedly will receive many such notices as businesses of all varieties struggle to meet GDPR requirements. Because violations of privacy standards—whether those established by GDPR, HIPAA, or the various states—can carry stiff financial penalties as well as result in loss of brand integrity, adherence to these standards is essential. In no instance is it more critical than in the case of healthcare providers. Clearly, although everyone in a position of responsibility with regard to patient data should be well familiar with applicable regulations for customer communications and data breach notification, even more important is preventing the compromise of data to begin with. Generally, any entity handling personal and sensitive data should ensure that the proper technical and organizational controls, meeting industry best practices, are in place to protect against a security breach.5 It has been reported that 95% of all breaches of enterprise networks enter through a spear phishing attack, that is, an email that is designed to appear legitimate but has a malicious attachment or link which, when selected, installs malware and attempts to access the user’s system. These spear phishing expeditions may often succeed in bypassing spam filters and antivirus engines. Experts recommend equipping your system with multiple antivirus engines, which should significantly increase malware detection rates. Other technologies, such as data sanitization and file type verification, may also be useful.6 Employee education, including training to identify vulnerabilities and risks, is vital. Most spear phishing emails will be sent to specific individuals within your organization, which enables the emails to avoid traditional spam filters. And if you think that healthcare entities are not among the preferred targets of malicious outsiders, think again! According to the 2014 Breach Level Index,7 the majority of data breaches by malicious outsiders were not for the purpose of stealing credit card information but, rather, for purposes of identity theft. Physicians and healthcare facilities should be aware that healthcare records are more valuable than credit card data; credit cards can easily be cancelled, but fraud using medical records is more difficult to identify and halt. Further, healthcare entities face the highest cost per stolen record—as high as $363, according to the Ponemon Institute.6 Healthcare facility data is often used to purchase drugs and even medical equipment, all of which can be sold on the black market for tremendous profit.8 Finally, in addition to preventive technology, organizational controls, and employee education, every responsible entity that manages personal and sensitive data should have in place a clear and comprehensive Incident Response Plan. This plan ought to specify all the members of the response team and each person’s exact responsibilities. It should include indicators for response escalation (notifying authorities, customers, media, etc. according to applicable regulations) and be tested for completeness and efficiency.5 Considering the increase in data breaches targeting healthcare entities, no plastic surgeon can afford to stick his or her head in the sand and simply hope for the best. You and virtually every member of your staff, as well as your software consultants, need to be actively engaged in the war against data breaches. Familiarize yourself with all applicable regulations (GDPR, HIPAA, and your individual state rules) that either already affect your practice or may do so. Differences in the various regulations may include: what the rule considers “covered information” (eg, what constitutes “personal information”); the definition of when a breach has occurred; the test for “harm threshold,” which may determine what subsequent actions are necessary; what constitutes a “safe harbor” (eg, the implementation of encryption); and specific notification requirements that must be adhered to with respect to timing, content, and methods.2 With regard to many issues of patient privacy, when there is a conflict between HIPAA and state law, whichever regulation provides the most protection for the patient typically is the one that takes precedence.9 As a footnote, I hasten to remind you that I am neither an IT expert nor a lawyer. The information included in this editorial should not be taken as specific legal or technical advice but, rather, as a general call to action. Each and every one of us should undertake a systematic review of data security. Employees who interface in any way with private data or the software managing that data must be properly trained to recognize and avoid possible breach attempts. Although not all such attacks are preventable, many are. The time and effort spent to fortify your defenses and mobilize your resources for remediation in the event of an attack is not only a wise initiative but, in today’s world, an absolutely necessary one. The author declared no potential conflicts of interest with respect to the research, authorship, and publication of this article. The author received no financial support for the research, authorship, and publication of this article.