Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Comments
Healthcare Information Security: Still No Respect
Oldest First  |  Newest First  |  Threaded View
Page 1 / 2   >   >>
RobPreston
50%
50%
RobPreston,
User Rank: Apprentice
2/10/2014 | 9:16:39 AM
R-E-S-P-E-C-T
I'm sure there's new found respect for information security in the retail industry -- at least I hope there is -- following the recent high-profile breaches at Target and other outlets. Will it take a major breach at a major private sector healthcare provider to wake up that indusry?
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
2/10/2014 | 9:42:39 AM
Re: R-E-S-P-E-C-T
I'm taking a wait-and-see position on whether the recent data breaches at Target etc will trigger an ephiphany in the retail industry. My guess is that security officers in that industry don't get any respect either. And that's with PCI-DSS regs to contend with.

In terms of healthcare, it's a sad commentary that 10 years after HIPAA, hospitals and other organizations talk the talk, but still don't walk the walk. What will it take for business leaders to empower security officers in the post ACA-era? I wish I knew. It certainly seems like it should be an urgent prioritiy to me. 
Drew Conry-Murray
50%
50%
Drew Conry-Murray,
User Rank: Ninja
2/10/2014 | 9:44:50 AM
Re: R-E-S-P-E-C-T
If healthcare is anything like retail, it's going to take a dozen high-profile breaches and significant financial losses for security to be taken seriously.
David F. Carr
50%
50%
David F. Carr,
User Rank: Strategist
2/10/2014 | 11:13:44 AM
Exceptions to the rule?
Kate,

Frightening that you see this as such a strong pattern, despite all we hear about HIPAA.

You must have seen some exceptions, right? What organization would you hold up as the positive example to follow?

 

 
Laurianne
50%
50%
Laurianne,
User Rank: Apprentice
2/10/2014 | 2:37:52 PM
Funding or structure?
This paints quite a different picture than what I have heard from top hospital CIOs, who say things like "It is part of my job to keep us out of the newspaper." Those CIOs speak of a crushing regulatory burden right now. How are the smaller healthcare organizations keeping up with it, if the lack of expertise is this extreme?
zcobb
50%
50%
zcobb,
User Rank: Apprentice
2/10/2014 | 3:25:56 PM
Breaching misperceptions
Thank you so much for this article. Sheds light on a serious problem. Not enough organizations realize any PII is fair game for cyber crooks, the fact that it might be PHI doesn't enter the equation for many of them. And this is so true: "But too many breaches today -- not only in healthcare but in other sectors -- arent due to zero-day attacks exploiting previously undiscovered vulnerabilities. They are avoidable events that are frequently tied to lack of security expertise and resources to implement security controls." Agreed! Stephen Cobb, CISSP
WKash
50%
50%
WKash,
User Rank: Apprentice
2/10/2014 | 6:07:22 PM
50 Reasons Why We Need Better EHR Security
Depending on what report you read, a stolen medical ID number and record currently sells on the black market for $50 (and as much as $100), whereas a stolen credit card number is only worth $1.  The reason: In gaining access to a person's health records, a hacker has – in one fell swoop – acquired almost full reign of a person's identity, and the opportunity for prolonged fraud against the medical establishment. Yet it's clear the medical community is no where close to having the security controls of say, the banking industry, or the federal government.
Kate Borten
50%
50%
Kate Borten,
User Rank: Apprentice
2/11/2014 | 3:17:48 PM
Re: Funding or structure?
It's not inconsistent for CIOs to say their job is to keep the organization out of the papers (and really mean it), and yet not have good infosec programs in place.  They often don't know what a strong program looks like.  This is a big problem since, in my experience, many organizations of all sizes - but especially small - are not compliant.  They don't know what they don't know.  I'm sympathetic to the regulatory burden in healthcare, but good security is good business.  I think the real issue comes down to money.
Marilyn Cohodas
50%
50%
Marilyn Cohodas,
User Rank: Strategist
2/13/2014 | 3:00:23 PM
Re: Funding or structure?
"People don't know what they don't know." 

Kate, I really think that is true on so many levels. On the medical side, I think doctors' training is to diagnose a condition through medical tests. In many cases, rule out things to discover what a patient doesn't have. Figuring out what you don't know is much much harder... That's true in medicine, InfoSec and most everything we do in life!
Gary Scott
50%
50%
Gary Scott,
User Rank: Strategist
2/13/2014 | 6:01:55 PM
EPHI Data Breach - One lost laptop or 10,000 recycled computers?
The biggest source of data breaches is not the one or two stolen laptops we hear about in the news but, the 100,000's of PCs and loose hard drives that organizations donate or send out for recycling. 

Small healthcare organizations continue to rely on electronic recycling companies to destroy hard drives and other digital media which may contain 1 million EPHI records each.  These unvetted recycling companies are allowed full access to EPHI - computer hard drives - from the time they leave the healthcare organization until the drives are finally destroyed.  

Organizations should insist that electronic recyclers physically shred hard drives (EPHI) prior to leaving the organizations custody.
Page 1 / 2   >   >>


Edge-DRsplash-10-edge-articles
I Smell a RAT! New Cybersecurity Threats for the Crypto Industry
David Trepp, Partner, IT Assurance with accounting and advisory firm BPM LLP,  7/9/2021
News
Attacks on Kaseya Servers Led to Ransomware in Less Than 2 Hours
Robert Lemos, Contributing Writer,  7/7/2021
Commentary
It's in the Game (but It Shouldn't Be)
Tal Memran, Cybersecurity Expert, CYE,  7/9/2021
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
How Data Breaches Affect the Enterprise
Data breaches continue to cause negative outcomes for companies worldwide. However, many organizations report that major impacts have declined significantly compared with a year ago, suggesting that many have gotten better at containing breach fallout. Download Dark Reading's Report "How Data Breaches Affect the Enterprise" to delve more into this timely topic.
Flash Poll
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2021-4020
PUBLISHED: 2021-11-27
janus-gateway is vulnerable to Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
CVE-2021-23654
PUBLISHED: 2021-11-26
This affects all versions of package html-to-csv. When there is a formula embedded in a HTML page, it gets accepted without any validation and the same would be pushed while converting it into a CSV file. Through this a malicious actor can embed or generate a malicious link or execute commands via C...
CVE-2021-43785
PUBLISHED: 2021-11-26
@joeattardi/emoji-button is a Vanilla JavaScript emoji picker component. In affected versions there are two vectors for XSS attacks: a URL for a custom emoji, and an i18n string. In both of these cases, a value can be crafted such that it can insert a `script` tag into the page and execute malicious...
CVE-2021-43776
PUBLISHED: 2021-11-26
Backstage is an open platform for building developer portals. In affected versions the auth-backend plugin allows a malicious actor to trick another user into visiting a vulnerable URL that executes an XSS attack. This attack can potentially allow the attacker to exfiltrate access tokens or other se...
CVE-2021-41243
PUBLISHED: 2021-11-26
There is a Potential Zip Slip Vulnerability and OS Command Injection Vulnerability on the management system of baserCMS. Users with permissions to upload files may upload crafted zip files which may execute arbitrary commands on the host operating system. This is a vulnerability that needs to be add...