Risk
9/19/2010
02:52 PM
George V. Hulme
George V. Hulme
Commentary
50%
50%

Steady Bleed: State of HealthCare Data Breaches

Study reveals that, for many healthcare providers, patient data breaches continue - month after month - at an alarming rate.

Study reveals that, for many healthcare providers, patient data breaches continue - month after month - at an alarming rate.Readers of this blog know that I like to hammer the message about how poorly health care providers, broadly, have approached how they secure patient information. To date, according to a quick search of the open Security Foundation's DatalossDB, millions of medical records have already been compromised.

Frankly, it wasn't too difficult to see the current sorry state of patient data security coming. In the late 1990s, we saw applications that were running on local area networks that were rushed to the Web. To this day, web application security is a big problem with no easy solution. Consider how many web sites today are serving malware - more than one million -- according to the latest report from Dasient.

A few years later we saw a mad rush into eCommerce and online payments, and once again we saw a tremendous amount of credit card breaches soon follow.

Consider these stats from the U.S. Department of Health & Human Services, which shows that 153 health care organizations have reported data breaches involving 500 or more patients since that organization started tracking data last year.

Why we collectively surge forward with new technological initiatives - without first considering whether or not we have the proper security and privacy safeguards in place - I'm not sure. Especially now, following so many security failures during the past 11 years.

Now, if the data that has come to light from HHS isn't enough to convince you that health care companies aren't doing what they need to do to protect patient data, consider some of the numbers from a new study by the privacy breach detection firm FairWarning.

The company claims that the four clients below are typical of the other 300 clients the company says it currently services:

• 200-bed hospital with a few small clinics, Rurally based: 24 confirmed incidents per month.

• U.S. based physician practice with 20 clinics metro and rurally dispersed: 29 confirmed incidents per month.

• UK based teaching hospital in major metropolitan area as well as rurally based facilities: 130 confirmed incidents per month

• Top 50 U.S. Health System with multiple affiliated hospitals and clinics - Based in a major metropolitan area: 125 confirmed incidents per month.

Particularly concerning is that the report noted multiple reports of staff from rural and metropolitan providers using the EHR system to regularly steal the identities of dead people to conduct identity theft. Seems to me if they're willing to steal the credentials and identity of dead people, it's not too far a leap to think they'd steal the identities and medical information of other patients if they could sell or otherwise profit from that information.

The report also lists a number of privacy breach anecdotes the company says it has culled from the companies it monitors:

• Employee of a premier specialty hospital owned an assisted living facility as a side business and was mining patients from their EHR account to feed his own business

• Major physician practice in which a valued senior physician hired several low-paid junior physicians to enter notes in the senior physician‟s name resulting in billing fraud

• Many locations and incidents involving sports star snooping (football, baseball, soccer, basketball) particularly during media coverage immediately before or after major games, most common in the metropolitan area where the sports team is based

• Major teaching hospital involved in a homicide investigation in which law enforcement requested audit trail of suspected co-conspirators who were employees of health system and examining soon to be deceased victim through electronic health record system

• Multiple reports from metropolitan and rural based care providers detecting staff using EHR access to systematically steal the identities of deceased patients to commit financial identity theft

• Staff members of metropolitan health system using pharmacy dispensing system to self-prescribe oxycodone

• Thousands of occurrences of family member snooping, self examination, employee as patient, and general VIP snooping. Career gain, child custody, blackmail, lawsuits as well as general curiosity are reported as motivations during the remediation process

It's clear hospitals and others and others in the health industry that handle electronic patient records need to do more - much more - to protect the data they're being entrusted to collect and manage.

For my security and technology observations throughout the day, consider following me on Twitter.

Comment  | 
Print  | 
More Insights
Comments
Threaded  |  Newest First  |  Oldest First
Register for Dark Reading Newsletters
White Papers
Video
Cartoon Contest
Write a Caption, Win a Starbucks Card! Click Here
Latest Comment: just wondering...Thanx
Current Issue
Security Operations and IT Operations: Finding the Path to Collaboration
A wide gulf has emerged between SOC and NOC teams that's keeping both of them from assuring the confidentiality, integrity, and availability of IT systems. Here's how experts think it should be bridged.
Flash Poll
New Best Practices for Secure App Development
New Best Practices for Secure App Development
The transition from DevOps to SecDevOps is combining with the move toward cloud computing to create new challenges - and new opportunities - for the information security team. Download this report, to learn about the new best practices for secure application development.
Slideshows
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2017-0290
Published: 2017-05-09
NScript in mpengine in Microsoft Malware Protection Engine with Engine Version before 1.1.13704.0, as used in Windows Defender and other products, allows remote attackers to execute arbitrary code or cause a denial of service (type confusion and application crash) via crafted JavaScript code within ...

CVE-2016-10369
Published: 2017-05-08
unixsocket.c in lxterminal through 0.3.0 insecurely uses /tmp for a socket file, allowing a local user to cause a denial of service (preventing terminal launch), or possibly have other impact (bypassing terminal access control).

CVE-2016-8202
Published: 2017-05-08
A privilege escalation vulnerability in Brocade Fibre Channel SAN products running Brocade Fabric OS (FOS) releases earlier than v7.4.1d and v8.0.1b could allow an authenticated attacker to elevate the privileges of user accounts accessing the system via command line interface. With affected version...

CVE-2016-8209
Published: 2017-05-08
Improper checks for unusual or exceptional conditions in Brocade NetIron 05.8.00 and later releases up to and including 06.1.00, when the Management Module is continuously scanned on port 22, may allow attackers to cause a denial of service (crash and reload) of the management module.

CVE-2017-0890
Published: 2017-05-08
Nextcloud Server before 11.0.3 is vulnerable to an inadequate escaping leading to a XSS vulnerability in the search module. To be exploitable a user has to write or paste malicious content into the search dialogue.

Dark Reading Radio
Archived Dark Reading Radio
In past years, security researchers have discovered ways to hack cars, medical devices, automated teller machines, and many other targets. Dark Reading Executive Editor Kelly Jackson Higgins hosts researcher Samy Kamkar and Levi Gundert, vice president of threat intelligence at Recorded Future, to discuss some of 2016's most unusual and creative hacks by white hats, and what these new vulnerabilities might mean for the coming year.