(opens in new tab)Skip to main content

How to protect your health data: what patients should know

Learn where your health information lives, why it’s at risk, and tips to protect you from cyber threats and scams

Protecting Your Personal Health Data

Your health data is more valuable than you might think – and not just to your care team. As more of our health information moves online, into apps, and through connected devices, it's worth understanding where that data lives, who might want it, and what you can actually do to protect it.

Where your health data lives

It's not just in your doctor's chart anymore. Nathan Moon, Senior Director of the Cybersecurity Fusion Center at Intermountain Health, explains: "Our health data resides in many different places."

Think about everything connected to your health on any given day. There's your patient portal (e.g. MyChart), your smartwatch tracking your heart rate and sleep, any fitness or wellness apps on your phone, and increasingly, social media posts with friends and family. Add in smart home devices, connected mattresses, and even your home Wi-Fi network – and you start to get a picture of just how distributed your personal information really is.

And then there's the question of how you're accessing all of it. "Are you at home? How secure is your home network? Are you traveling and you want access to it, and you're pulling over into a Starbucks?" Moon says. Where you connect matters just as much as where the data lives.

Why health data is a target

Here's something that surprises a lot of people: your health records are actually more valuable to bad actors than your credit card number. Why? Because you can cancel a credit card. You can't change your health data.

"If I have your health data, I can then use the information to create fake identities to apply for credit cards, prescribe medication or bill insurance companies for services rendered," Moon explains. An old X-ray might seem harmless, but if it contains your Social Security number or home address, that information can be used to submitted false claims, to open credit accounts, apply for loans, or sign up for rewards programs, all in your name, without your knowledge."

It's less about someone wanting to know your diagnosis and more about the personal identifying information attached to your health record. That's what has value on the dark web.

The biggest risk is closer than you think

The most sophisticated cybersecurity system in the world still has one vulnerability: people. "The weakest link is always the person," Moon says, "and bad actors know the easiest way to get in is through the individual."

This is called social engineering. And it usually shows up in your inbox or as a phone call. Someone reaches out with limited information about you, gets you talking, and uses what you share to piece together more. It can look like:

  • A survey offering a gift card for completing a few quick questions 
  • An email asking you to verify account information
  • A phone call from someone claiming to be from your healthcare provider
  • A text that looks like a routine billing or appointment notice

Moon's advice on unsolicited calls is simple and practical: "I think it's fine to ask: which company are you calling from? and let me call you back before I start answering those questions."

If someone you weren't expecting asks for your date of birth or account information right out of the gate, that's your cue to pause.

Three things you can do right now

  1. Never share personal information with someone who contacts you out of the blue. “Intermountain Health will not contact customers by phone to demand emergency payment of an insurance premium for a policy that is about to lapse or to pay a bill.  Our customers might occasionally receive a call for pre-registration or customer surveys.  If you're suspicious, gather any information noted above if possible, hang up, and call the Intermountain hospital or clinic you visited or plan to visit.  If the Intermountain or SelectHealth name or logos are used in a communication and you are suspicious, call the Intermountain facility you visit or SelectHealth representative you work with to help you determine what you received is authentic.
  2. Protect your usernames and passwords. Use strong, unique passwords for health-related accounts and consider a password manager or a secure method for keeping track of them. Reusing the same password across accounts is one of the most common ways people get compromised.
  3. When in doubt, trust your gut. If it sounds really good, it's probably too good to be true.

One more step worth adding: set up multi-factor authentication (MFA) on any account that offers it. It's an extra layer that makes it significantly harder for someone to access your information even if they have your password.

A note on AI and health apps

As AI tools become more common in healthcare settings and as patients get more comfortable using tools like ChatGPT to ask health questions, it's worth being thoughtful about what you share.

Before uploading a lab result or describing symptoms in detail to a public AI tool, consider whether you're comfortable with that information potentially being stored or used to train a model.

The same applies to health apps and wearables. Before you tap "accept" on a permissions screen, take a moment to understand what you're agreeing to. 

What Intermountain Health does to protect your patient data

If you're a patient at a large health system like Intermountain Health, there's a significant amount of protection already working in the background. Moon oversees a team that monitors around the clock, watching for unusual activity, investigating potential threats, and scanning for patient data that may have surfaced on public networks and the dark web.

"We have a dedicated cyber team monitoring 24/7, and our systems are looking for anomalous behavior," he says. The team also works within Epic's recommended security framework to make sure guardrails are in place for patient access. 

Good habits make a secure system even stronger

Protecting your health data doesn't require a cybersecurity degree. It requires a little awareness and a few consistent habits. At Intermountain Health, the work to protect patient information is ongoing. Moon says the goal is tied directly to the organization's mission: "To help people live the healthiest life possible. We take that with the data that we receive from our patients."

Your part is smaller, but it matters. Stay skeptical of unsolicited contact, manage your credentials carefully, and when something doesn't feel right, trust that instinct.