Risk
11/14/2011
11:22 AM
Connect Directly
RSS
E-Mail
50%
50%

Encryption Security Lags In Healthcare?

Tech leaders warn policymakers that even as more electronic health records flood health IT systems, more encryption is needed.

Healthcare and IT experts convened on Capitol Hill last week to warn Congress that as healthcare organizations are increasing the use of electronic health records in light of federal mandates, they are not protecting these records within the database and elsewhere. Security professionals agree that in order for the public to trust these records, healthcare organizations need to start working on database security best practices--the same first-order practices that any organization with minimal security should start with to shore up sensitive data stores.

"Simply stated, the effort to promote widespread adoption and use of health IT to improve individual and population health will fail if the public does not trust it," said Deven McGraw, director of the Health Privacy Project for the Center for Democracy, in testimony to the Senate Committee on the Judiciary Subcommittee on Privacy, Technology, and the Law (PDF), Nov. 9.

According to McGraw, even with certain safe harbor incentives in place for organizations to be exempt from costly breach notifications if exposed data is encrypted, statistics show that healthcare organizations are still not encrypting their data.

"The new breach notification provisions of HITECH provide an incentive for healthcare providers to encrypt health information using standards approved by the National Institute of Standards and Technology (NIST)," he said. "But we know from the statistics on breaches that have occurred since the notification provisions went into effect in 2009 that the healthcare industry appears to be rarely encrypting data."

Todd Thiemann, senior director of product marketing at encryption vendor Vormetric, said his experiences corroborate what McGraw's seen.

"From what we've seen, you have a lot of data out there that government programs are tempting healthcare organizations to turn into electronic records from paper records, and a lot of institutions are still grappling with how to secure that stuff," he says. "The push for electronic medical records is this new wave crashing on the shore that they're dealing with."

As McGraw explained in his testimony, there has been no comprehensive study of why healthcare hasn't embraced encryption, but Thiemann has his hunches.

Read the rest of this article on Dark Reading.

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Lisa Henderson
50%
50%
Lisa Henderson,
User Rank: Apprentice
11/15/2011 | 12:00:43 AM
re: Encryption Security Lags In Healthcare?
So the perception that most consumers have about not trusting health records that are stored electroncially is actually a truism? That healthcare organizations lag other industries in regard to security issues.

I agree with McGraw. Widespread adoption of healthcare IT to improve public health won't happen if people don't trust it and therefore don't use it. It doesn't matter how much money the government throws at it.

Lisa Henderson, InformationWeek Healthcare, contributing editor
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading, September 16, 2014
Malicious software is morphing to be more targeted, stealthy, and destructive. Are you prepared to stop it?
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2006-1318
Published: 2014-09-19
Microsoft Office 2003 SP1 and SP2, Office XP SP3, Office 2000 SP3, Office 2004 for Mac, and Office X for Mac do not properly parse record lengths, which allows remote attackers to execute arbitrary code via a malformed control in an Office document, aka "Microsoft Office Control Vulnerability."

CVE-2012-2588
Published: 2014-09-19
Multiple cross-site scripting (XSS) vulnerabilities in MailEnable Enterprise 6.5 allow remote attackers to inject arbitrary web script or HTML via the (1) From, (2) To, or (3) Subject header or (4) body in an SMTP e-mail message.

CVE-2012-6659
Published: 2014-09-19
Cross-site scripting (XSS) vulnerability in the admin interface in Phorum before 5.2.19 allows remote attackers to inject arbitrary web script or HTML via a crafted URL.

CVE-2014-1391
Published: 2014-09-19
QT Media Foundation in Apple OS X before 10.9.5 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption and application crash) via a crafted movie file with RLE encoding.

CVE-2014-3614
Published: 2014-09-19
Unspecified vulnerability in PowerDNS Recursor (aka pdns_recursor) 3.6.x before 3.6.1 allows remote attackers to cause a denial of service (crash) via an unknown sequence of malformed packets.

Best of the Web
Dark Reading Radio