Dark Reading is part of the Informa Tech Division of Informa PLC

This site is operated by a business or businesses owned by Informa PLC and all copyright resides with them.Informa PLC's registered office is 5 Howick Place, London SW1P 1WG. Registered in England and Wales. Number 8860726.

Risk

7/13/2011
11:28 AM
50%
50%

P2P Networks Expose Healthcare Data To Identity Theft

File-sharing software can open healthcare organization networks to criminal activity.

Healthcare IT Vendor Directory
Slideshow: Healthcare IT Vendor Directory
(click image for larger view and for slideshow)
Even as healthcare organizations spend lots of money and time to protect their data from hackers, viruses, and malware, they may be overlooking a non-malicious vulnerability: employees using peer-to-peer (P2P) file-sharing networks on their work computers.

The challenge with peer-to-peer sharing is that it is not malware, according to Todd Davis, CEO of LifeLock, a consumer-facing identity theft protection company. "It's legal to download peer-to-peer software," Davis said in an interview. Illegal behavior usually is related to downloading copyrighted materials with the software, but the software itself is legal.

But the act of installing such software could open up networks to data theft. "They accepted the terms and conditions," Davis said. Those terms could include things such as providing access to a protected database, but few people take the time to read the fine print. "Now my entire network has potentially been compromised," Davis explained.

Antivirus software won't prevent an employee inadvertently granting access to the network. "It doesn't matter what firewall you have," Davis said.

Davis said healthcare enterprises are particularly good targets of identity thieves because of the amount of information collected from patients, including social security numbers, financial records, and health insurance IDs. "Criminals know," Davis said. "They attack healthcare providers," he added.

"The other valuable piece is diagnosis codes." Someone being treated for pain or certain mental health conditions might be on a controlled substance. A criminal who can obtain a diagnosis and a valid insurance number could easily order a 90-day supply of a painkiller or a "lifestyle" drug such as Viagra through a mail-order pharmacy before the victim places an order, Davis said. "Anything that has street value" is what they target, he said.

Other than educating staff about the risks of peer-to-peer networks and spending a lot of money to encrypt data, there is not a whole lot healthcare organizations can do to prevent such attacks, Davis said. He noted that the typical response is to offer credit monitoring services to individuals whose information may have been exposed, but that is not a preventive step.

"Credit monitoring just notifies you after the fact, after there is a change in your credit status," Davis said. "What companies are realizing is, they need to be more proactive." Their credibility is on the line.

Hospitals and large organizations can struggle to meet this threat, and it's even more difficult for small providers. "The dentist's office doesn't have a privacy officer or an encryption specialist," Davis noted.

Davis reports seeing some healthcare organizations buying LifeLock services for employees, which is more proactive than the standard credit monitoring. This does not, however, address theft of nonemployee patient records.

According to Davis, companies have been cognizant of having to protect data, but don't always understand exactly what they have to do. He recommends setting up "in case of emergency, break glass" plans, including the names of whom to contact to mitigate damage should a breach occur, but that, too, is a reactive response.

Providers do not always know what data elements they need to protect, Davis said. A particular point of confusion is the so-called Red Flags rule, a Federal Trade Commission regulation that requires certain companies and organizations to develop written plans to prevent and detect identity theft.

The FTC has suspended enforcement of the rule multiple times after doctor and hospital groups complained, but a law enacted in December 2010 specifically exempts healthcare providers when they accept insurance. Several physician organizations have sued the FTC to prevent them being considered "creditors" in other cases, so uncertainly lingers. "They aren't really sure of what their responsibilities are or what steps they have to take," Davis said.

"Nobody's really cracked the code" on how to protect small and midsized businesses, Davis said, but he expects innovation to catch up with this threat soon. "I think you're going to see a progression of technologies around the Red Flags rule," he predicted.

In the new, all-digital InformationWeek Healthcare: iPads are leading a new wave of devices into the exam room. Are security, tech support, and infection control up to the task? Download it now. (Free registration required.)

Comment  | 
Print  | 
More Insights
Comments
Newest First  |  Oldest First  |  Threaded View
Data Leak Week: Billions of Sensitive Files Exposed Online
Kelly Jackson Higgins, Executive Editor at Dark Reading,  12/10/2019
Intel Issues Fix for 'Plundervolt' SGX Flaw
Kelly Jackson Higgins, Executive Editor at Dark Reading,  12/11/2019
Register for Dark Reading Newsletters
White Papers
Video
Cartoon
Current Issue
The Year in Security: 2019
This Tech Digest provides a wrap up and overview of the year's top cybersecurity news stories. It was a year of new twists on old threats, with fears of another WannaCry-type worm and of a possible botnet army of Wi-Fi routers. But 2019 also underscored the risk of firmware and trusted security tools harboring dangerous holes that cybercriminals and nation-state hackers could readily abuse. Read more.
Flash Poll
Rethinking Enterprise Data Defense
Rethinking Enterprise Data Defense
Frustrated with recurring intrusions and breaches, cybersecurity professionals are questioning some of the industrys conventional wisdom. Heres a look at what theyre thinking about.
Twitter Feed
Dark Reading - Bug Report
Bug Report
Enterprise Vulnerabilities
From DHS/US-CERT's National Vulnerability Database
CVE-2019-5252
PUBLISHED: 2019-12-14
There is an improper authentication vulnerability in Huawei smartphones (Y9, Honor 8X, Honor 9 Lite, Honor 9i, Y6 Pro). The applock does not perform a sufficient authentication in a rare condition. Successful exploit could allow the attacker to use the application locked by applock in an instant.
CVE-2019-5235
PUBLISHED: 2019-12-14
Some Huawei smart phones have a null pointer dereference vulnerability. An attacker crafts specific packets and sends to the affected product to exploit this vulnerability. Successful exploitation may cause the affected phone to be abnormal.
CVE-2019-5264
PUBLISHED: 2019-12-13
There is an information disclosure vulnerability in certain Huawei smartphones (Mate 10;Mate 10 Pro;Honor V10;Changxiang 7S;P-smart;Changxiang 8 Plus;Y9 2018;Honor 9 Lite;Honor 9i;Mate 9). The software does not properly handle certain information of applications locked by applock in a rare condition...
CVE-2019-5277
PUBLISHED: 2019-12-13
Huawei CloudUSM-EUA V600R006C10;V600R019C00 have an information leak vulnerability. Due to improper configuration, the attacker may cause information leak by successful exploitation.
CVE-2019-5254
PUBLISHED: 2019-12-13
Certain Huawei products (AP2000;IPS Module;NGFW Module;NIP6300;NIP6600;NIP6800;S5700;SVN5600;SVN5800;SVN5800-C;SeMG9811;Secospace AntiDDoS8000;Secospace USG6300;Secospace USG6500;Secospace USG6600;USG6000V;eSpace U1981) have an out-of-bounds read vulnerability. An attacker who logs in to the board m...