Risk
7/22/2010
09:56 PM
George V. Hulme
George V. Hulme
Commentary
50%
50%

Healthcare Breaches Spin Out Of Control

If the past week is any indication (and I'm afraid it is), health care companies are doing an abysmal job at protecting personal health care data.

If the past week is any indication (and I'm afraid it is), health care companies are doing an abysmal job at protecting personal health care data.This evening the Colorado Department of Health Care Policy and Financing announced that state officials discovered an unauthorized removal of a computer hard drive from the state's Office of Information Technology Department:

The information did NOT include addresses, dates of birth, social security numbers or any other financial information that could be used for identity theft. It included name, state ID number and the name of the client's program.

Approximately 111,000 clients, or one-fifth of those receiving public health insurance, will receive notification by first-class mail, as required by HIPAA.

So there it is, roughly 20 percent of the state's clients' data is at risk. Thankfully Social Security numbers were not exposed. Still: why is stored sensitive data not encrypted?

Perhaps because it's easier not to encrypt the data and then have to deal with all of the extra hassle. Just as it's easier to dump medical records than it is to have them properly destroyed.

Consider the shock when a Florida couple went to their local recycling center to discover "thousands" of medical records just tossed in the trash.

From Tampa Bay Online:

When they looked at the paper bin it was not only full to the point of pushing up the lid, it was practically bursting at its seams. Inside were what looked to be thousands of pastel and manila file folders, all with neat tabs attached.

Curious, they pulled out a couple and were stunned to see that they appeared to be medical records, Karen Keith said.

The information inside the files included some that couldn't be more personal - or dangerous: Social Security numbers, copies of drivers' license numbers and even credit cards numbers, she said.

Nice. Fortunately the couple called authorities, and the paperwork wasn't found by a crook, or someone willing to sell the data to a bunch of crooks. Unfortunately, we probably don't hear about it when that actually happens, we just witness the resulting spike in identity and medical identity theft.

Also last week, a professional data management firm lost data on 800,000 patients. From South Shore Hospital's notice:

Based upon South Shore Hospital's investigation so far, the back-up computer files could contain personally identifiable information for approximately 800,000 individuals. Included among those individuals are patients who received medical services at South Shore Hospital - as well as employees, physicians, volunteers, donors, vendors and other business partners associated with South Shore Hospital - between January 1, 1996 and January 6, 2010. The information on the back-up computer files may include individuals' full names, addresses, phone numbers, dates of birth, Social Security numbers, driver's license numbers, medical record numbers, patient numbers, health plan information, dates of service, protected health information including diagnoses and treatments relating to certain hospital and home health care visits, and other personal information. Bank account information and credit card numbers for a very small subset of individuals also may have been on the back-up computer files.

South Shore Hospital's back-up computer files were shipped for offsite destruction on February 26, 2010. When certificates of destruction were not provided to the hospital in a timely manner, the hospital pressed the data management company for an explanation. South Shore Hospital was finally informed on June 17, 2010 that only a portion of the shipped back-up computer files had been received and destroyed.

Unfortunately, this past week isn't much unlike any other week. Patient records are lost and stolen constantly.

So how does the health care industry bring some level of control over these breaches? Personally, I think they're adopting electronic medical records way too quickly: so slowing that down a bit would be a start. At least slowing down the implementation enough to conduct a security assessment of the health care provider, and make sure such records are adequately protected.

Another would be more aggressive enforcement. A recent example of a successful action would be the successful action of the Connecticut Attorney General's Office against the regional health plan, Health Net, for a lost portable drive that included health information, Social Security and bank account numbers on about 446,000 patients. In that incident, Health Net agreed to pay a $250,000 fine and implement a Corrective Action Plan to improve their security program. For a good overview, read Richard Santalesa's analysis of the settlement here, published yesterday.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Cartoon
Current Issue
Dark Reading December Tech Digest
Experts weigh in on the pros and cons of end-user security training.
Flash Poll
Video
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-1421
Published: 2014-11-25
mountall 1.54, as used in Ubuntu 14.10, does not properly handle the umask when using the mount utility, which allows local users to bypass intended access restrictions via unspecified vectors.

CVE-2014-3605
Published: 2014-11-25
** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: CVE-2014-6407. Reason: This candidate is a reservation duplicate of CVE-2014-6407. Notes: All CVE users should reference CVE-2014-6407 instead of this candidate. All references and descriptions in this candidate have been removed to pre...

CVE-2014-6093
Published: 2014-11-25
Cross-site scripting (XSS) vulnerability in IBM WebSphere Portal 7.0.x before 7.0.0.2 CF29, 8.0.x through 8.0.0.1 CF14, and 8.5.x before 8.5.0 CF02 allows remote authenticated users to inject arbitrary web script or HTML via a crafted URL.

CVE-2014-6196
Published: 2014-11-25
Cross-site scripting (XSS) vulnerability in IBM Web Experience Factory (WEF) 6.1.5 through 8.5.0.1, as used in WebSphere Dashboard Framework (WDF) and Lotus Widget Factory (LWF), allows remote attackers to inject arbitrary web script or HTML by leveraging a Dojo builder error in an unspecified WebSp...

CVE-2014-7247
Published: 2014-11-25
Unspecified vulnerability in JustSystems Ichitaro 2008 through 2011; Ichitaro Government 6, 7, 2008, 2009, and 2010; Ichitaro Pro; Ichitaro Pro 2; Ichitaro 2011 Sou; Ichitaro 2012 Shou; Ichitaro 2013 Gen; and Ichitaro 2014 Tetsu allows remote attackers to execute arbitrary code via a crafted file.

Best of the Web
Dark Reading Radio
Archived Dark Reading Radio
Now that the holiday season is about to begin both online and in stores, will this be yet another season of nonstop gifting to cybercriminals?