Risk

10/23/2008
12:27 AM
George V. Hulme
George V. Hulme
Commentary
50%
50%

New FTC Rules Governing Health Providers Go Into Effect Nov. 1

Are you ready? In about a week, new so-called "Red Flag Rules" from the FTC go into effect, aimed at curbing medical identity theft.

Are you ready? In about a week, new so-called "Red Flag Rules" from the FTC go into effect, aimed at curbing medical identity theft.It's a good thing, too. It seems new headlines surrounding medical identity theft surface all of the time. Just last week, a Californian pleaded guilty to federal charges for defrauding Medicare. The man allegedly used patients' Medicare identification numbers without their knowledge. His sentencing is scheduled for sometime this January, and he faces 12 years for billing the Medicare system for about $1,640,000.

Sometimes it's not outright fraud, sometimes it's just negligence on the part of hospitals themselves for failing to properly protect patient data. Consider this recent story about patients at Mary Washington Hospital, who learned it was possible for anyone to look at the private medical information of about 803 maternity patients on the hospital's online registration system. A hospital spokesperson called the incident an "anomaly." Ten years of reporting on these types of breaches tells me its a high probability of neglecting to properly secure or patch the system. While there was no medical identity theft in this specific case (that we know of), such carelessness can and will certainly lead to more incidents.

Now, the U.S. Department of Health & Human Services (HHS) is showing more interest the role health care providers can play in combating medical identity theft in the face of new Federal Trade Commission rules that go into place Nov. 1.

According to this press release, many hospitals aren't even aware of the rules:

In October, both the HHS Office for Civil Rights (OCR) and the Office of the National Coordination for Health Information Technology (ONC) signaled that stronger actions to address the issues of identity theft and particularly medical identity theft are coming.

On Oct. 10, OCR said it was examining the FTC's identity theft regulations, as questions have been raised over whether violations of the so-called "Red Flag" rules could also constitute violations of the HIPAA privacy or security rules. There also have been no decisions on whether OCR or CMS would refer cases to the FTC when they receive complaints in their HIPAA enforcement systems.

Many health care organizations are not aware that they will come under FTC authority as a result of identity theft rules that were once thought to only apply to financial institutions and other lenders.

The Red Flag rules require any organization -- including nonprofits and government agencies not traditionally subject to FTC jurisdiction -- that does not require payment at the time it provides service to establish and maintain a program to spot and address possible ID theft.

In recent weeks, the FTC said the rules also applied to health care entities.

This is good news, even if these red flag rules from the FTC do overlap with HIPAA. Why? Because too few hospitals have been fined or sanctioned for failing to properly safeguard patient data -- like Mary Washington Hospital -- by adequately putting into place the precautions necessary to make sure someone's health privacy isn't violated by an avoidable "anomaly."

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
'Hidden Tunnels' Help Hackers Launch Financial Services Attacks
Kelly Sheridan, Staff Editor, Dark Reading,  6/20/2018
Inside a SamSam Ransomware Attack
Ajit Sancheti, CEO and Co-Founder, Preempt,  6/20/2018
Tesla Employee Steals, Sabotages Company Data
Jai Vijayan, Freelance writer,  6/19/2018
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2018-12697
PUBLISHED: 2018-06-23
A NULL pointer dereference (aka SEGV on unknown address 0x000000000000) was discovered in work_stuff_copy_to_from in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30. This can occur during execution of objdump.
CVE-2018-12698
PUBLISHED: 2018-06-23
demangle_template in cplus-dem.c in GNU libiberty, as distributed in GNU Binutils 2.30, allows attackers to trigger excessive memory consumption (aka OOM) during the "Create an array for saving the template argument values" XNEWVEC call. This can occur during execution of objdump.
CVE-2018-12699
PUBLISHED: 2018-06-23
finish_stab in stabs.c in GNU Binutils 2.30 allows attackers to cause a denial of service (heap-based buffer overflow) or possibly have unspecified other impact, as demonstrated by an out-of-bounds write of 8 bytes. This can occur during execution of objdump.
CVE-2018-12700
PUBLISHED: 2018-06-23
A Stack Exhaustion issue was discovered in debug_write_type in debug.c in GNU Binutils 2.30 because of DEBUG_KIND_INDIRECT infinite recursion.
CVE-2018-11560
PUBLISHED: 2018-06-23
The webService binary on Insteon HD IP Camera White 2864-222 devices has a stack-based Buffer Overflow leading to Control-Flow Hijacking via a crafted usr key, as demonstrated by a long remoteIp parameter to cgi-bin/CGIProxy.fcgi on port 34100.