Perimeter
Guest Blog // Selected Security Content Provided By Sophos
What's This?
9/22/2011
08:58 AM
Dark Reading
Dark Reading
Security Insights
50%
50%

20K Stanford Hospital Emergency Room Patients Have Health Records Posted Online

'An ounce of prevention is better than a pound of cure' adage rings true

20,000 people have joined the ranks of the 11 million+ victims whose personal medical data has been improperly exposed in the past two years. Last week, The New York Times reported that 20,000 records of patients who visited the emergency room at Stanford Hospital in 2009 were posted on the Internet for over a year.

The leaked information included names, diagnosis codes, account numbers, admission and discharge dates, and billing charges. The source of the leak is likely Multi-Specialty Collection Services, a billing contractor for the hospital.

But remember: the “how” of this breach should not be the focal point in this situation. The more important question is, why was the data not protected (encrypted) in the first place?

I see several problems at work in these types of incidents...

First, medical organizations that are required to protect confidential patient data in the United States under the HIPAA and HITECH acts often outsource work to third parties.

Simply inserting some clauses in their contracts to require these third parties to meet these regulations does not ensure the data will be protected.

Secondly, our attitudes—and the laws—around data protection are outdated. If you think you should treat data differently when it is inside than when it is outside, you are setting the stage for a data breach. Think of the many groups of people touch personal health information “internally”—doctors, nurses, billing departments, etc. Each time the data is accessed or changes hands is another opportunity for that data to be compromised.

Confidential information, whether it is sensitive health records or source code to your secret Jesus phone to be released next month cannot be "inside" or "outside." There is no inside.

And thirdly, organizations that cite cost as a reason to not protect their data are setting themselves up for a bigger financial burden in the long run. The average cost of a data breach is $7.3 million. This number includes federal and state fines for noncompliance with HIPAA/HITECH laws, as well as other incidentals like the cost of notifying victims of the data breach and providing them with identity protection services. And don’t forget the non-monetary repercussions like lost customer confidence and bad publicity.

So instead of cleaning up after a data breach, prevent one from happening. Classify your data based upon its importance. Now, based on that classification, take the appropriate actions to control and protect that data. Please?

Chester Wisniewski is a senior security adviser at Sophos Canada

Need help? Check out Sophos’s free Data Security Report to understand what puts data at risk and how to defend against data loss and prevent future breaches.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Flash Poll
Title Partner’s Role in Perimeter Security
Title Partner’s Role in Perimeter Security
Considering how prevalent third-party attacks are, we need to ask hard questions about how partners and suppliers are safeguarding systems and data.
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2015-0121
Published: 2015-05-30
IBM Rational Requirements Composer 3.0 through 3.0.1.6 and 4.0 through 4.0.7 and Rational DOORS Next Generation (RDNG) 4.0 through 4.0.7 and 5.0 through 5.0.2, when LTPA single sign on is used with WebSphere Application Server, do not terminate a Requirements Management (RM) session upon LTPA token ...

CVE-2015-0191
Published: 2015-05-30
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-0191. Reason: This candidate is a duplicate of CVE-2014-0191. A typo caused the wrong ID to be used. Notes: All CVE users should reference CVE-2014-0191 instead of this candidate. All references and descriptions in this candid...

CVE-2015-0193
Published: 2015-05-30
Cross-site scripting (XSS) vulnerability in IBM Business Process Manager (BPM) 7.5.x through 7.5.1.2, 8.0.x through 8.0.1.3, and 8.5.x through 8.5.5.0 and WebSphere Lombardi Edition (WLE) 7.2.x through 7.2.0.5 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL...

CVE-2015-0733
Published: 2015-05-30
CRLF injection vulnerability in the HTTP Header Handler in Digital Broadband Delivery System in Cisco Headend System Release allows remote attackers to inject arbitrary HTTP headers, and conduct HTTP response splitting attacks or cross-site scripting (XSS) attacks, via a crafted request, aka Bug ID ...

CVE-2015-0743
Published: 2015-05-30
Cisco Headend System Release allows remote attackers to cause a denial of service (DHCP and TFTP outage) via a flood of crafted UDP traffic, aka Bug ID CSCus04097.

Dark Reading Radio
Archived Dark Reading Radio
After a serious cybersecurity incident, everyone will be looking to you for answers -- but you’ll never have complete information and you’ll never have enough time. So in those heated moments, when a business is on the brink of collapse, how will you and the rest of the board room executives respond?