Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
Medical Identity Theft Costs Victims $13,450 Apiece
Newest First  |  Oldest First  |  Threaded View
Joe Stanganelli
50%
50%
Joe Stanganelli,
User Rank: Ninja
3/1/2015 | 3:00:38 AM
Re: An example > borrow insurance?
That's funny, Marilyn; it seems I *always* have to present my medical ID whenever I go in for a doctor's appointment.  I guess it depends where you go.
Sara Peters
50%
50%
Sara Peters,
User Rank: Author
2/27/2015 | 11:51:36 AM
Re: An example > borrow insurance?
@Marilyn  Wow! What did you do about it? And what sort of creature was Bridget?
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
2/26/2015 | 2:19:11 PM
Re: An example > borrow insurance?
Now that you mention it, @sarapeters, i've never had to present my ID for a medical appointment. And speaking of health records, i got an email from a Veterinarian's office in Seattle recently about an outpatient discharge report for a "Bridget" Cohodas (no relation-- as far as  I know). So much for confidentiality of PII . But then, maybe pets aren't covered by HIPAA. :-)
Sara Peters
50%
50%
Sara Peters,
User Rank: Author
2/26/2015 | 12:49:10 PM
Re: An example > borrow insurance?
@Marilyn  Not really, Marilyn. Generally, they'll ask for your insurance card, but not your ID. And most of the time you're getting billed, not paying up front (except maybe a co-pay that you can pay in cash), so they won't even see a credit card or a checkbook with the wrong person's name on it.

They'll ask for all kinds of medical history on your first appointment. But since most healthcare centers don't share that information, they won't necessarily know that the 37-year-old Sara Peters with epilepsy at hospital A is one person and the 22-year-old 'Sara Peters' with diabetes is a different person, much less a fraud. This is one of those reasons that health information exchange technology could be useful.
JPtaylorL
50%
50%
JPtaylorL,
User Rank: Apprentice
2/26/2015 | 12:48:07 PM
huh?
So if anyone went out at looked at the HHS Wall of Shame (which is where public breaches of PHI are disclosed), you'll see that there are 278 breaches in 2014.   31 were actually as a result (self reported) of hacking.  The vast majority of other issues tagged - were mistakes or problems resulting from poor execution of policies and procedures.  Hacking is a problem.  Advanced malware is a problem.  However, GETTING GOOD AT RISK ASSESSMENTS, RESPONDING TO RISK, and EXECUTING POLICIES AND PROCEDURES is STILL the most reliable method for avoiding getting owned. The spin is spin.
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
2/26/2015 | 11:09:50 AM
Re: An example > borrow insurance?
@Sara, Call me naive but how is it possible to borrow insurance? Don't you need to provide information about your identity, beyond simply the insurance card/number? 
Sara Peters
50%
50%
Sara Peters,
User Rank: Author
2/25/2015 | 10:52:21 AM
Re: An example
@Nemos   Yes, you've got it. Health insurance in the US is very expensive, but the costs of medical appointments and procedures is INCREDIBLY expensive.

(For example, when I was admitted to the hospital a few years ago, the hospital room cost $800 per night. That's not including the doctors, the medication, the tests, the procedures, etc. The MRI I had was about $13,000 insurance, if I remember correctly. Even with insurance, the trip cost me a couple thousand dollars. Even with insurance, an ambulance trip cost me $600.)

And that's why people often ALLOW their friends/family to borrow their insurance. And why it costs so much to remediate the damage.

 
Nemos
50%
50%
Nemos,
User Rank: Apprentice
2/24/2015 | 5:50:29 PM
An example
Could you please give an example as here in Europe we have a bit different health system and I dont understand why one should cheat about his/her identity ? Is this action has to do that there is not a public insurance therefore you have to pay for your medical expenses ?


COVID-19: Latest Security News & Commentary
Dark Reading Staff 7/2/2020
Ripple20 Threatens Increasingly Connected Medical Devices
Kelly Sheridan, Staff Editor, Dark Reading,  6/30/2020
DDoS Attacks Jump 542% from Q4 2019 to Q1 2020
Dark Reading Staff 6/30/2020
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
How Cybersecurity Incident Response Programs Work (and Why Some Don't)
This Tech Digest takes a look at the vital role cybersecurity incident response (IR) plays in managing cyber-risk within organizations. Download the Tech Digest today to find out how well-planned IR programs can detect intrusions, contain breaches, and help an organization restore normal operations.
Flash Poll
The Threat from the Internetand What Your Organization Can Do About It
The Threat from the Internetand What Your Organization Can Do About It
This report describes some of the latest attacks and threats emanating from the Internet, as well as advice and tips on how your organization can mitigate those threats before they affect your business. Download it today!
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2020-9498
PUBLISHED: 2020-07-02
Apache Guacamole 1.1.0 and older may mishandle pointers involved inprocessing data received via RDP static virtual channels. If a userconnects to a malicious or compromised RDP server, a series ofspecially-crafted PDUs could result in memory corruption, possiblyallowing arbitrary code to be executed...
CVE-2020-3282
PUBLISHED: 2020-07-02
A vulnerability in the web-based management interface of Cisco Unified Communications Manager, Cisco Unified Communications Manager Session Management Edition, Cisco Unified Communications Manager IM & Presence Service, and Cisco Unity Connection could allow an unauthenticated, remote attack...
CVE-2020-5909
PUBLISHED: 2020-07-02
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, when users run the command displayed in NGINX Controller user interface (UI) to fetch the agent installer, the server TLS certificate is not verified.
CVE-2020-5910
PUBLISHED: 2020-07-02
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the Neural Autonomic Transport System (NATS) messaging services in use by the NGINX Controller do not require any form of authentication, so any successful connection would be authorized.
CVE-2020-5911
PUBLISHED: 2020-07-02
In versions 3.0.0-3.5.0, 2.0.0-2.9.0, and 1.0.1, the NGINX Controller installer starts the download of Kubernetes packages from an HTTP URL On Debian/Ubuntu system.