Risk
10/25/2010
02:54 PM
George V. Hulme
George V. Hulme
Commentary
50%
50%

More Patient Data Dumps

Yet another case where patient medical records are left in a dumpster and out in plain sight.

Yet another case where patient medical records are left in a dumpster and out in plain sight.What is it going to take to ensure hospitals and medical facilities properly dispose of patient records? NewsChannel4, KFOR.com in Oklahoma City reports that a resident found dumped patient records from at least two different offices.

Within each folder they found oncology patient record details on children and their parents. The news station says it retrieved all of the medical files and then contacted both medical offices.

It's quite possible that the firm the offices use to dispose of their records failed to properly shred them. The video of the news report is below:

 

Unfortunately, these types of incidents are not uncommon. We recently covered an Urgent Care that was fined $50,000 for a similar dump. And we've noted others occurring in Monicello, NY, Chattanooga, TN, and Port Lucie, FL.

Security firm McAfee recently had breaches that involved Social Security numbers between January 2009 and this October analyzed to rank the most dangerous locations for one to leave their Social Security number. The breach data was sourced from the Identity Theft Resource Center, Privacy Rights Clearinghouse and the Open Security Foundation that involved Social Security number breaches from January 2009 - October 2010.

Turned out health care related offices took 3 of the top 10 slots. Third place was hospitals, seventh was medical related businesses (distributors, billing services, etc.), and tenth place tied with medical insurance firms and medical offices and clinics.

So hospitals and medical offices may not only be ideal places to pick up a new disease, they're also ideal for having your identity information stolen.

For my security and technology observations throughout the day, find me on Twitter.

Comment  | 
Print  | 
More Insights
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Flash Poll
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2014-9651
Published: 2015-08-28
Buffer overflow in CHICKEN 4.9.0.x before 4.9.0.2, 4.9.x before 4.9.1, and before 5.0 allows attackers to have unspecified impact via a positive START argument to the "substring-index[-ci] procedures."

CVE-2015-1171
Published: 2015-08-28
Stack-based buffer overflow in GSM SIM Utility (aka SIM Card Editor) 6.6 allows remote attackers to execute arbitrary code via a long entry in a .sms file.

CVE-2015-2987
Published: 2015-08-28
Type74 ED before 4.0 misuses 128-bit ECB encryption for small files, which makes it easier for attackers to obtain plaintext data via differential cryptanalysis of a file with an original length smaller than 128 bits.

CVE-2015-6266
Published: 2015-08-28
The guest portal in Cisco Identity Services Engine (ISE) 3300 1.2(0.899) does not restrict access to uploaded HTML documents, which allows remote attackers to obtain sensitive information from customized documents via a direct request, aka Bug ID CSCuo78045.

CVE-2015-6267
Published: 2015-08-28
Cisco IOS XE before 2.2.3 on ASR 1000 devices allows remote attackers to cause a denial of service (Embedded Services Processor crash) via a crafted L2TP packet, aka Bug IDs CSCsw95722 and CSCsw95496.

Dark Reading Radio
Archived Dark Reading Radio
Another Black Hat is in the books and Dark Reading was there. Join the editors as they share their top stories, biggest lessons, and best conversations from the premier security conference.