Healthcare breaches have dominated the second half of the year. Consider these lessons learned.
Though the second half of the year has been comparably calmer than the first half's database breaches at RSA, Sony, and Epsilon, the breach numbers continued to roll in--especially at healthcare organizations, which made up a disproportionate number of exposed records. Here are some of the biggest breaches that went down in the second half of the year, along with a few database security lessons learned.
1. The Breach Victim: Nemours Assets Stolen/Affected: Names, addresses, dates of birth, Social Security numbers, insurance data, medical treatment data, and bank account information for 1.6 million patients, vendors, and employees.
Three unencrypted tapes containing a mother lode of personal information on patients, vendors, and employees were lost amid the dust of a facility remodel project when a cabinet that held them since 2004 went missing.
Lessons Learned: Database backups are often the Achilles' heel in enterprise database security. Because of their portability and longevity, database backup tapes are frequently lost in transit or in these types of relocation scenarios. Encryption of data is key to ensuring security even when tapes can't be physically secured.
[ From healthcare to game companies to trusted third-party security companies, a number of significant breaches were reported in 2011. See Slide Show: The Year In Data Theft. ]
2. The Breach Victim: Tricare/SAIC Assets Stolen/Affected: Protected health information from 5.1 million patients of U.S. military hospitals and clinics.
Another day, another backup tape gone missing. In September, Tricare announced that an employee for one of its contractors, Science Applications International Corp. (SAIC), was driving around with a backup tape containing patient data from 1992 all the way through 2011 for San Antonio-area military treatment facilities. The tapes were stolen from the car, exposing Social Security numbers, addresses, phone numbers, clinical notes, lab test results, prescriptions, and other medical information.
Lessons Learned: In addition to the lessons about backup tape protection, this case shows how important third-party contractor security procedures are to an organization. Enterprises and government agencies alike must be aware of how contractors are touching database information and whether they're employing best practices with regard to how that data is handled.
IT's spending as much as ever on disaster recovery, despite advances in virtualization and cloud techniques. It's time to break free. Download our Disaster Recovery Disaster supplement now. (Free registration required.)
Dark Reading Tech Digest, Dec. 19, 2014Software-defined networking can be a net plus for security. The key: Work with the network team to implement gradually, test as you go, and take the opportunity to overhaul your security strategy.
Published: 2015-01-28 Multiple cross-site scripting (XSS) vulnerabilities in (1) mainpage.jsp and (2) GetImageServlet.img in IBM TRIRIGA Application Platform 3.2.1.x, 3.3.2 before 188.8.131.52, and 3.4.1 before 184.108.40.206 allow remote authenticated users to inject arbitrary web script or HTML via a crafted URL.
Published: 2015-01-28 Open redirect vulnerability in IBM TRIRIGA Application Platform 3.2.1.x, 3.3.2 before 220.127.116.11, and 3.4.1 before 18.104.22.168 allows remote authenticated users to redirect users to arbitrary web sites and conduct phishing attacks via the out parameter.
Published: 2015-01-28 IBM TRIRIGA Application Platform 3.2.1.x, 3.3.2 before 22.214.171.124, and 3.4.1 before 126.96.36.199 allows remote attackers to bypass intended access restrictions and read the image files of arbitrary users via a crafted URL.
Published: 2015-01-28 Multiple cross-site scripting (XSS) vulnerabilities in (1) dojox/form/resources/uploader.swf (aka upload.swf), (2) dojox/form/resources/fileuploader.swf (aka fileupload.swf), (3) dojox/av/resources/audio.swf, and (4) dojox/av/resources/video.swf in the IBM Dojo Toolkit, as used in IBM Social Media A...
If youíre a security professional, youíve probably been asked many questions about the December attack on Sony. On Jan. 21 at 1pm eastern, you can join a special, one-hour Dark Reading Radio discussion devoted to the Sony hack and the issues that may arise from it.