Protenus, a company that is established an analytics platform intended to stop data breaches and secure patient information, recently gained $3 million in funding from investors to advance research and product development.
Kaiser Permanente Ventures and F-Prime Capital Partners invested in Protenus in its series A funding.
Protenus collaborates with several healthcare systems and hospitals across the country, and is capable to secure data for more than 44 million patients.
“This extra funding will assist us explore the cost and benefits of different kinds of products built off of our analytics platform to understand what is most needed in healthcare and how we can help best,” claims Nick Culbertson, the company’s CEO.
Protenus utilizes artificial intelligence techniques to better understand workflows in the healthcare industry, and the approach enables it to distinguish unsuitable access to patient information.
“We develop profiles on patients based on what kind of treatment they are getting, and we build profiles based on human resources data to understand what type of employees are accessing patient data,” Culbertson states.
In the year of 2016, over 27 million patient records were breached, as reported by the Protenus Breach Barometer, and so far this year, there has been an average of at least one health data breach a day, with 40% of them a result of insider access.
“We use system access logs to explain how certain kinds of workers are accessing (records of) certain kinds of patients throughout that care workflow process. In other words, we develop the clinical workflow in a virtual environment and understand how employees are virtually passing medical records from one to another,” says Culbertson.
Protenus expects to be able to use its platform to identify other anomalies in those workflows, enabling it to catch problems such as prescription abuse, fraud or other types of medical anomalies.
“We like to consider it [Protenus] as a tool to cause cultural reform, because a lot of individuals are doing things because they do not realize it is illegal, and so when you are able to identify it early, educate them and remind them that they are abusing access to sufferer data, that is a chance to educate and stop that in the future,” says Culbertson.
Showing posts with label Data Security. Show all posts
Showing posts with label Data Security. Show all posts
Wednesday, August 2, 2017
Tuesday, August 1, 2017
Contractor breach impacts data of 18,500 Anthem Medicare members
Only one week after Anthem accepted to pay $115 million to victims of its massive February 2015 data breach that impacted the 78.8 million people, the company confronts another data breach discovered by a contractor, this time affecting over 18,500 of Anthem Medicare members.
LaunchPoint Ventures, which gives insurance coordination services to Anthem, learned in the month of April that a worker likely was engaged in identity theft activities. The contractor then employed a forensic firm to assess suspicious incidents.
In the month of late May, LaunchPoint learned that the employee might have accessed data of other LaunchPoint customers, in addition to that of Anthem. The inquiry further determined that the worker emailed a file with information on Anthem members to his personal address in the month of July 2016; the inquiry couldn’t determine if the employee had a legitimate work-related reason for doing so.
LaunchPoint says the worker has since been terminated and is now being held by law enforcement on charges that are unrelated to the Anthem breach.
In June, LaunchPoint was capable to confirm that the Anthem data emailed by the worker contained protected health information of Anthem Medicare members. There is not yet evidence the data was misused. Compromised member information includes Medicare ID numbers including Social Security numbers, health plan ID numbers, Medicare contract numbers, dates of enrollment, and a restricted number of last names and dates of birth.
LaunchPoint is now reinforcing policies and protocols, and evaluating additional safeguards. The company is providing affected individuals 2 years of free credit monitoring and identity theft services with AllClear ID.
Anthem refused to comment on the incident, and executives didn’t say whether it will continue to use LaunchPoint’s services.
LaunchPoint Ventures, which gives insurance coordination services to Anthem, learned in the month of April that a worker likely was engaged in identity theft activities. The contractor then employed a forensic firm to assess suspicious incidents.
In the month of late May, LaunchPoint learned that the employee might have accessed data of other LaunchPoint customers, in addition to that of Anthem. The inquiry further determined that the worker emailed a file with information on Anthem members to his personal address in the month of July 2016; the inquiry couldn’t determine if the employee had a legitimate work-related reason for doing so.
LaunchPoint says the worker has since been terminated and is now being held by law enforcement on charges that are unrelated to the Anthem breach.
In June, LaunchPoint was capable to confirm that the Anthem data emailed by the worker contained protected health information of Anthem Medicare members. There is not yet evidence the data was misused. Compromised member information includes Medicare ID numbers including Social Security numbers, health plan ID numbers, Medicare contract numbers, dates of enrollment, and a restricted number of last names and dates of birth.
LaunchPoint is now reinforcing policies and protocols, and evaluating additional safeguards. The company is providing affected individuals 2 years of free credit monitoring and identity theft services with AllClear ID.
Anthem refused to comment on the incident, and executives didn’t say whether it will continue to use LaunchPoint’s services.
Labels:
Anthem Medicare,
Data Security,
Healthcare Scams,
ID,
Social Security
Monday, July 31, 2017
Attacks of Ransomware strucks South Dakota plastic surgery practice
Plastic Surgery of South Dakota is providing about 10,200 current and former patients a year of credit and identity protection services amid concerns that their information was accessed during a mid-February ransomware attack.
The agency removed the ransomware from its information systems and decrypted data, then brought in security experts to determine if any data was accessed by unauthorized users. While the majority of records were not accessed, the practice was unable to rule out whether a smaller subset of sufferer records had been breached.
To date, although, there is no proof of any actual or attempted misuse of data, the practice noted in a patient notification letter. Information that could have been compromised includes patients’ names, driver’s license numbers, Social Security numbers, state identification numbers, credit and debit card information, medical conditions and diagnosis information, lab results, addresses, dates of birth and health insurance data.
Plastic Surgery of South Dakota is further recommending a range of steps for affected individuals to take to protect themselves, including monitoring credit reports and explanations of benefits; getting free credit reports from the three major credit bureaus; placing fraud alerts on credit files and placing a security freeze on credit reports, which prohibits release of information from the reports absent consumer authorization.
The practice refused to give further details about the incident beyond a patient notification letter.
The agency removed the ransomware from its information systems and decrypted data, then brought in security experts to determine if any data was accessed by unauthorized users. While the majority of records were not accessed, the practice was unable to rule out whether a smaller subset of sufferer records had been breached.
To date, although, there is no proof of any actual or attempted misuse of data, the practice noted in a patient notification letter. Information that could have been compromised includes patients’ names, driver’s license numbers, Social Security numbers, state identification numbers, credit and debit card information, medical conditions and diagnosis information, lab results, addresses, dates of birth and health insurance data.
Plastic Surgery of South Dakota is further recommending a range of steps for affected individuals to take to protect themselves, including monitoring credit reports and explanations of benefits; getting free credit reports from the three major credit bureaus; placing fraud alerts on credit files and placing a security freeze on credit reports, which prohibits release of information from the reports absent consumer authorization.
The practice refused to give further details about the incident beyond a patient notification letter.
Labels:
Data Security,
Social Security,
South Dakota
Tuesday, July 25, 2017
Tewksbury Hospital in Massachusetts terminates worker after long-term snooping
A worker at Tewksbury Hospital in Massachusetts was discovered to be occasionally snooping in sufferers’ electronic medical records without clinical justification.
The inappropriate access of medical records occurred from the year of 2003 until it was discovered this past spring. Now, the facility—one of four hospitals in the Massachusetts Department of Public Health serving complex chronically ill adult sufferers and psychiatric patients—has notified more than 1,100 affected people.
Tewksbury Hospital officials say they learned of the breach in April, when a former patient expressed concern that their medical record might have been inappropriately accessed. Compromised data involved names, addresses, and dates of birth, gender, diagnoses and medical treatments. Less than half of the records involved viewing of Social Security numbers, according to the hospital.
The state’s department of health has terminated the worker.
“To decrease the chance of future tragedies like this occurring, we are reviewing our policies regarding access to the electronic medical records system,” Tewksbury executives noted in a statement. “We’re also reassessing how we review our workforce members’ use of the electronic medical records system and will be reviewing the training we provide to all workforce members regarding the privacy and security of confidential information.”
Tewksbury Hospital is advising affected people to notify credit reporting agencies, order a credit report and review it for signs of fraud, and request a security freeze to prevent the opening of new accounts using the compromised information.
In its notification to sufferers, Tewksbury Hospital is not offering credit monitoring or identity theft protection services. Currently, there is no indication that information has been accessed or misused, in accordance with a spokesperson for the hospital.
The hospital refused to give additional details about the incident, and did not comment on why the inappropriate access had gone undetected for fourteen years.
The inappropriate access of medical records occurred from the year of 2003 until it was discovered this past spring. Now, the facility—one of four hospitals in the Massachusetts Department of Public Health serving complex chronically ill adult sufferers and psychiatric patients—has notified more than 1,100 affected people.
Tewksbury Hospital officials say they learned of the breach in April, when a former patient expressed concern that their medical record might have been inappropriately accessed. Compromised data involved names, addresses, and dates of birth, gender, diagnoses and medical treatments. Less than half of the records involved viewing of Social Security numbers, according to the hospital.
The state’s department of health has terminated the worker.
“To decrease the chance of future tragedies like this occurring, we are reviewing our policies regarding access to the electronic medical records system,” Tewksbury executives noted in a statement. “We’re also reassessing how we review our workforce members’ use of the electronic medical records system and will be reviewing the training we provide to all workforce members regarding the privacy and security of confidential information.”
Tewksbury Hospital is advising affected people to notify credit reporting agencies, order a credit report and review it for signs of fraud, and request a security freeze to prevent the opening of new accounts using the compromised information.
In its notification to sufferers, Tewksbury Hospital is not offering credit monitoring or identity theft protection services. Currently, there is no indication that information has been accessed or misused, in accordance with a spokesperson for the hospital.
The hospital refused to give additional details about the incident, and did not comment on why the inappropriate access had gone undetected for fourteen years.
Sunday, July 9, 2017
Hacking of Medical devices increasing as a next huge threat
Medical devices, involving those that are implanted within patients, are increasingly likely to be targeted by hackers and could pose a nightmare scenario if providers do not take measures to improve their defenses.
“The issue with security is that hackers always follow the path of least resistance,” claims Sam Rehman, the chief technology officer at security vendor Arxan, which serves multiple industries and has a large footprint in healthcare.
Like several other security vendors, Rehman says providers require conducting a comprehensive risk assessment and fixing vulnerabilities. In healthcare, medical devices security is a hot topic and for great reason, because providers mostly have hundreds if not thousands of devices in their facilities.
But providers also require increasing security levels for devices that are implanted in patients, and that is because several of those devices have wireless capabilities that enable hackers to interfere with them, Rehman says.
For instance, physicians can utilize hand-held medical devices to wirelessly collect data and even update an implant, for example to change device settings on insulin pumps, pacemakers and other devices. Although, a hacker in a hospital can do the same thing, which represents a potential risk to patient safety, Rehman cautions.
Many hackers might not need to intentionally cause harm, but others will do what someone pays them to do, which could involve causing injury to patients. Rehman says monetary motivation, particularly through blackmail, could rise as a potential risk.
Such hacking could involve efforts to affect the share price of a device manufacturer. Rehman says stock price manipulation could provide another financial motive for hacking. For imstance, if one person can make money by paying another person to cause harm, the instigator can make money when a company’s stock price falls.
A scenario similar to this has already occurred. Previously this year, the Food and Drug Administration confirmed cybersecurity vulnerabilities in St. Jude Medical’s implantable cardiac devices and its Merlin@home transmitter. The vulnerabilities were originally declared by an investment group that threatened to make money by selling its stock short.
St. Jude Medical devices, the FDA stated, could be hacked by outsiders, leading to injury or death, and St. Jude’s share price quickly dropped by 10% as the company scrambled to make fixes. “If someone can make money, this absolutely will happen,” Rehman assumes.
“The issue with security is that hackers always follow the path of least resistance,” claims Sam Rehman, the chief technology officer at security vendor Arxan, which serves multiple industries and has a large footprint in healthcare.
Like several other security vendors, Rehman says providers require conducting a comprehensive risk assessment and fixing vulnerabilities. In healthcare, medical devices security is a hot topic and for great reason, because providers mostly have hundreds if not thousands of devices in their facilities.
But providers also require increasing security levels for devices that are implanted in patients, and that is because several of those devices have wireless capabilities that enable hackers to interfere with them, Rehman says.
For instance, physicians can utilize hand-held medical devices to wirelessly collect data and even update an implant, for example to change device settings on insulin pumps, pacemakers and other devices. Although, a hacker in a hospital can do the same thing, which represents a potential risk to patient safety, Rehman cautions.
Many hackers might not need to intentionally cause harm, but others will do what someone pays them to do, which could involve causing injury to patients. Rehman says monetary motivation, particularly through blackmail, could rise as a potential risk.
Such hacking could involve efforts to affect the share price of a device manufacturer. Rehman says stock price manipulation could provide another financial motive for hacking. For imstance, if one person can make money by paying another person to cause harm, the instigator can make money when a company’s stock price falls.
A scenario similar to this has already occurred. Previously this year, the Food and Drug Administration confirmed cybersecurity vulnerabilities in St. Jude Medical’s implantable cardiac devices and its Merlin@home transmitter. The vulnerabilities were originally declared by an investment group that threatened to make money by selling its stock short.
St. Jude Medical devices, the FDA stated, could be hacked by outsiders, leading to injury or death, and St. Jude’s share price quickly dropped by 10% as the company scrambled to make fixes. “If someone can make money, this absolutely will happen,” Rehman assumes.
Labels:
Data Security,
Drug Administration,
FDA,
Jude Medical,
Sam Rehman
Tuesday, July 4, 2017
CHIME provides new certification program for industry executives
The College of Healthcare Information Management Executives (CHIME) is launching a new certification program that seeks to appreciate the expertise of executives who work for companies that give products or services to the healthcare industry.
The Ann Arbor, Mich.-based professional organization has initiated the CHIME Foundation Certified Healthcare Executive program (CFCHE) for information technology experts who are not CIOs, but are at a senior level and have other achievements in the HIT industry.
Experts who may seek the new designation may be consultants, implementers, sales representatives or in other roles, claims Keith Fraidenburg, executive vice president and COO at CHIME.
CHIME considers the new designation will facilitate interactions within the healthcare IT industry, he states. For instance, when a CIO or other technology professional discusses technology with a person with a CFCHE designation, the CIO will know the other person has passed a tough exam and has studied the challenges confronting CIOs, other healthcare leaders and payers, along with other IT experts outside a healthcare organization, Fraidenburg says.
CHIME has experience developing professional designations for the healthcare IT industry. In the year of 2009 it started a new certification program for IT executives called the Certified Healthcare CIO (CHCIO) program. Currently, more than 350 CHIME members have studied for and acquired the CHCIO title. Becoming a CHCIO is a demonstration of knowledge, skill and competency earned over various years and is the CIO equivalent of being a “black belt,” Fraidenburg asserts.
For CHIME’s newest program, after an individual has registered to participate in the CFCHE certification program, a candidate will get an extensive list of reading materials, and will take a sample exam that is not like the real exam but written in the similar way as the CIO exam to ascertain where the candidate did well and where he or she requires improving.
The Ann Arbor, Mich.-based professional organization has initiated the CHIME Foundation Certified Healthcare Executive program (CFCHE) for information technology experts who are not CIOs, but are at a senior level and have other achievements in the HIT industry.
Experts who may seek the new designation may be consultants, implementers, sales representatives or in other roles, claims Keith Fraidenburg, executive vice president and COO at CHIME.
CHIME considers the new designation will facilitate interactions within the healthcare IT industry, he states. For instance, when a CIO or other technology professional discusses technology with a person with a CFCHE designation, the CIO will know the other person has passed a tough exam and has studied the challenges confronting CIOs, other healthcare leaders and payers, along with other IT experts outside a healthcare organization, Fraidenburg says.
CHIME has experience developing professional designations for the healthcare IT industry. In the year of 2009 it started a new certification program for IT executives called the Certified Healthcare CIO (CHCIO) program. Currently, more than 350 CHIME members have studied for and acquired the CHCIO title. Becoming a CHCIO is a demonstration of knowledge, skill and competency earned over various years and is the CIO equivalent of being a “black belt,” Fraidenburg asserts.
For CHIME’s newest program, after an individual has registered to participate in the CFCHE certification program, a candidate will get an extensive list of reading materials, and will take a sample exam that is not like the real exam but written in the similar way as the CIO exam to ascertain where the candidate did well and where he or she requires improving.
Labels:
CFCHE,
CHCIO,
CHIME,
COO,
Data Security,
EHR Privacy,
Health Info Exchange
Sunday, July 2, 2017
Ransomware attacks Cleveland Medical, affects info of 22,000 sufferers
Cleveland Medical Associates is providing about 22,000 sufferers identity protection services after a ransomware attack against the practice.
The five-clinician practice is giving a year of protective services through Equifax to both current and former sufferers whose information may have been affected.
Cleveland Medical Associates refused to give more details about the tragedy and also did not provide any extra statements about the attack.
The breach was discovered the morning of April 17. In response, the practice executed a new medical records system and engaged forensic specialists to verify the extent to which information was affected. The practice believes the motive for the attack was extortion and that access to patient health information wasn’t an end result of the attack.
“Based upon our inquiry, there is no evidence that your protected health information was taken from our system or misused as result of the incident,” the practice told patients in a notification letter. “Because we were not able to determine with reasonable certainty whether or not there was an unauthorized access of your information, however, we’re offering you with notification of this incident.”
Protected health information that could have been compromised involves patient names, addresses, demographics, telephone numbers, email addresses, clinical information, insurance billings and Social Security numbers.
The Equifax protection package offers credit monitoring, as much as $25,000 in identity theft insurance and automatic fraud alerts of changes to a credit report.
The five-clinician practice is giving a year of protective services through Equifax to both current and former sufferers whose information may have been affected.
Cleveland Medical Associates refused to give more details about the tragedy and also did not provide any extra statements about the attack.
The breach was discovered the morning of April 17. In response, the practice executed a new medical records system and engaged forensic specialists to verify the extent to which information was affected. The practice believes the motive for the attack was extortion and that access to patient health information wasn’t an end result of the attack.
“Based upon our inquiry, there is no evidence that your protected health information was taken from our system or misused as result of the incident,” the practice told patients in a notification letter. “Because we were not able to determine with reasonable certainty whether or not there was an unauthorized access of your information, however, we’re offering you with notification of this incident.”
Protected health information that could have been compromised involves patient names, addresses, demographics, telephone numbers, email addresses, clinical information, insurance billings and Social Security numbers.
The Equifax protection package offers credit monitoring, as much as $25,000 in identity theft insurance and automatic fraud alerts of changes to a credit report.
Tuesday, June 20, 2017
Washington State University experiences a major breach of PHI
The health and wellness services division of Washington State University in Seattle has faced a huge breach of protected health information, but the extent of the tragedy isn’t yet clear.
Local media, involving KUOW a National Public Radio station, have reported the breach affects 1 million people, but the HHS Office for Civil Rights, which enforces the HIPAA privacy and security rules, hasn’t publicly confirmed that number.
On the day of April 21, the Washington State University discovered that a hard drive was stolen from a locked safe. The hard drive held back-up files from a server utilized by the Social and Economic Sciences Research Center, which involved a health survey that collected PHI.
Breached data from the health and wellness services division covered data of sufferers of medical and dental clinics, vision clinics, behavioral health organizations and local pharmacies.
Compromised data included Social Security numbers, names and undisclosed personal health information. Entities giving the information included school districts and community colleges, along with other undisclosed customers.
Washington State University is providing affected individuals one year of credit monitoring and identity theft protection services. Notification letters were mailed on the day of June 9, and the university is inquiring individuals who believe they may have been affected and have not got a letter by June 30 to call a dedicated hot line.
“As president of Washington State University, I deeply regret that this tragedy occurred and am truly sorry for any concern it might cause our community,” Kirk H. Schulz claimed in the notification letters. He pledged to strengthen IT operations through a comprehensive assessment of IT practices and policies, as well as improving security awareness training of employees.
The university refused to give additional information on the incident.
Local media, involving KUOW a National Public Radio station, have reported the breach affects 1 million people, but the HHS Office for Civil Rights, which enforces the HIPAA privacy and security rules, hasn’t publicly confirmed that number.
On the day of April 21, the Washington State University discovered that a hard drive was stolen from a locked safe. The hard drive held back-up files from a server utilized by the Social and Economic Sciences Research Center, which involved a health survey that collected PHI.
Breached data from the health and wellness services division covered data of sufferers of medical and dental clinics, vision clinics, behavioral health organizations and local pharmacies.
Compromised data included Social Security numbers, names and undisclosed personal health information. Entities giving the information included school districts and community colleges, along with other undisclosed customers.
Washington State University is providing affected individuals one year of credit monitoring and identity theft protection services. Notification letters were mailed on the day of June 9, and the university is inquiring individuals who believe they may have been affected and have not got a letter by June 30 to call a dedicated hot line.
“As president of Washington State University, I deeply regret that this tragedy occurred and am truly sorry for any concern it might cause our community,” Kirk H. Schulz claimed in the notification letters. He pledged to strengthen IT operations through a comprehensive assessment of IT practices and policies, as well as improving security awareness training of employees.
The university refused to give additional information on the incident.
Thursday, June 15, 2017
Approximately half of agencies using Internet of Things struck by breaches
Almost half of U.S.-based companies using an Internet of Things (IoT) network have been struck by a recent security breach, in accordance with a new survey data released by strategy consulting firm Altman Vilandrie & Company.
The April survey of 397 IT executives across nineteen industries showed that 48% of agencies have experienced at least one IoT security breach. It disclosed the significant financial exposure of weak IoT security for companies of all sizes, with almost half of the businesses with yearly revenues above $2 billion assumed the potential cost of one Internet of Things breach at more than $20 million.
“While traditional cyber security has grabbed the nation’s attention, Internet of Things (IoT) security has been somewhat under the radar, even for few companies that have a lot to lose through a breach,” claimed Stefan Bewley, director of Altman Vilandrie and author of the study.
“IoT attacks reveal companies to the loss of information and services and can render connected devices dangerous to customers, workers and the public at large,” Bewley said. “The potential vulnerabilities for firms of all sizes will sustain to grow as more devices become Internet dependent.”
The study demonstrated that preparedness helps. Companies that haven’t experienced a security incursion have invested 65% more on IoT security than those who have been breached. Other key findings: 68% of respondents think about IoT security as a distinct category, yet only 43% have a standalone budget.
The April survey of 397 IT executives across nineteen industries showed that 48% of agencies have experienced at least one IoT security breach. It disclosed the significant financial exposure of weak IoT security for companies of all sizes, with almost half of the businesses with yearly revenues above $2 billion assumed the potential cost of one Internet of Things breach at more than $20 million.
“While traditional cyber security has grabbed the nation’s attention, Internet of Things (IoT) security has been somewhat under the radar, even for few companies that have a lot to lose through a breach,” claimed Stefan Bewley, director of Altman Vilandrie and author of the study.
“IoT attacks reveal companies to the loss of information and services and can render connected devices dangerous to customers, workers and the public at large,” Bewley said. “The potential vulnerabilities for firms of all sizes will sustain to grow as more devices become Internet dependent.”
The study demonstrated that preparedness helps. Companies that haven’t experienced a security incursion have invested 65% more on IoT security than those who have been breached. Other key findings: 68% of respondents think about IoT security as a distinct category, yet only 43% have a standalone budget.
Labels:
Altman Vilandrie Company,
Data Security,
EHR Privacy,
IT,
Stefan Bewley
Tuesday, June 13, 2017
Two breaches Incidents Smash Beverly Hills physician practice
Two breach tragedies have compromised records at Advanced ENT Head and Neck Surgery, a Beverly Hills physician practice, Calif.-based practice with sufferers in 16 states and 4 countries.
The provider assumes that the incidents have potentially exposed the healthcare information of about 15,000 sufferers.
In one of the breaches reported to federal agencies in the month of late May, a contracted employee is considered to have taken photos of patients before and during surgeries, and copied and stolen patient records, claims Zain Kadri, MD, who leads the practice.
Data taken by the contract worker is said to involve credit and debit card information, identification documents, copies of checks, user names, passwords and recorded conversations, as well as data on the company.
Earlier in May, the practice was struck by a break-in at its facility in which paper records and data devices were taken. The loss of data and information from that first tragedy has complicated the practice’s response because it lost contact information for many of its patients, Kadri claims.
The practice is working with regional pharmacies and other companies in the medical community to locate contact information for its sufferers.
In the latest breach tragedy, the contract worker was using a corporate smartphone to acquire data; examination of the phone assisted in the discovery of the breach, law enforcement officials said.
The practice released the following information to sufferers to head off potential incidents in which callers might recognize themselves as working for the Beverly Hills physician practice provider. “If anyone contacts you, claiming to be from Advanced ENT Head & Neck Surgery, please get their name and call our main number; then, ask to speak to (that person) directly before continuing the conversation.”
The Beverly Hills physician practice also emphasized sufferers to change their credit and debit card numbers, review accounts for unauthorized transactions, notify banks if unauthorized purchases, withdrawals or cash advances are discovered, monitor credit reports and notify local law enforcement if they become a victim of fraud. The declaration of the breaches didn’t mention the offering of protective services to affected patients, and the agency didn’t respond to a request for extra information.
The provider assumes that the incidents have potentially exposed the healthcare information of about 15,000 sufferers.
In one of the breaches reported to federal agencies in the month of late May, a contracted employee is considered to have taken photos of patients before and during surgeries, and copied and stolen patient records, claims Zain Kadri, MD, who leads the practice.
Data taken by the contract worker is said to involve credit and debit card information, identification documents, copies of checks, user names, passwords and recorded conversations, as well as data on the company.
Earlier in May, the practice was struck by a break-in at its facility in which paper records and data devices were taken. The loss of data and information from that first tragedy has complicated the practice’s response because it lost contact information for many of its patients, Kadri claims.
The practice is working with regional pharmacies and other companies in the medical community to locate contact information for its sufferers.
In the latest breach tragedy, the contract worker was using a corporate smartphone to acquire data; examination of the phone assisted in the discovery of the breach, law enforcement officials said.
The practice released the following information to sufferers to head off potential incidents in which callers might recognize themselves as working for the Beverly Hills physician practice provider. “If anyone contacts you, claiming to be from Advanced ENT Head & Neck Surgery, please get their name and call our main number; then, ask to speak to (that person) directly before continuing the conversation.”
The Beverly Hills physician practice also emphasized sufferers to change their credit and debit card numbers, review accounts for unauthorized transactions, notify banks if unauthorized purchases, withdrawals or cash advances are discovered, monitor credit reports and notify local law enforcement if they become a victim of fraud. The declaration of the breaches didn’t mention the offering of protective services to affected patients, and the agency didn’t respond to a request for extra information.
Labels:
Beverly Hills,
Data Security,
Zain Kadri
Saturday, June 3, 2017
Agencies more vulnerable than ever to cyber security attack
Cyber security attack vulnerability is at all-time high, and just one in five agencies can manage an attack “very well,” in accordance with new research from audit and advisory firm KPMG LLP and recruitment firm and IT outsourcing provider Harvey Nash.
Almost two-thirds (64 percent) of the 4,498 global CIOs and technology leaders that the firms surveyed between the time period of December 2016 and April 2017 are adapting their technology strategies in the midst of unprecedented global political and economic uncertainty. The proportion of agencies surveyed that now have enterprise-wide digital strategies increased 52% in just 2 years, and those agencies with a chief digital officer have increased 39% over last year, in accordance to the study. Organizations are more vulnerable than ever to cyber security attack.
To assist deliver these complex digital strategies, organizations also report a huge demand for enterprise architects—the fastest increasing technology skill this year, up 26% compared with the year of 2016.
Nearly, one third of the IT leaders (32%) reported that their agencies had been the target of a major cyber security attack in the last 24 months, a 45% increase from 2013. Just one in five (21 percent) said they are “very well” prepared to respond to these attacks, down from 29% in the year of 2014.
The biggest rise in threats comes from insider attacks, increasing from 40% to 47% over last year.
“From an organizational and cultural perspective, the CIO is now confronted with a full transformation to digital, enterprise-wide,” said Bob Miano, president and CEO at Harvey Nash. This full-scale move to a digital atmosphere is increasing data vulnerability.
“Digital is without question the CIO’s priority. But specifically for legacy organizations, leading this change to a complete, unified digital strategy is top of mind,” Miano stated.
While the fastest-growing demand for a technology skill this year was enterprise architecture, big data and analytics sustained to be the most in-demand skill, at 42%, up 8% over last year.
Almost two-thirds (64 percent) of the 4,498 global CIOs and technology leaders that the firms surveyed between the time period of December 2016 and April 2017 are adapting their technology strategies in the midst of unprecedented global political and economic uncertainty. The proportion of agencies surveyed that now have enterprise-wide digital strategies increased 52% in just 2 years, and those agencies with a chief digital officer have increased 39% over last year, in accordance to the study. Organizations are more vulnerable than ever to cyber security attack.
To assist deliver these complex digital strategies, organizations also report a huge demand for enterprise architects—the fastest increasing technology skill this year, up 26% compared with the year of 2016.
Nearly, one third of the IT leaders (32%) reported that their agencies had been the target of a major cyber security attack in the last 24 months, a 45% increase from 2013. Just one in five (21 percent) said they are “very well” prepared to respond to these attacks, down from 29% in the year of 2014.
The biggest rise in threats comes from insider attacks, increasing from 40% to 47% over last year.
“From an organizational and cultural perspective, the CIO is now confronted with a full transformation to digital, enterprise-wide,” said Bob Miano, president and CEO at Harvey Nash. This full-scale move to a digital atmosphere is increasing data vulnerability.
“Digital is without question the CIO’s priority. But specifically for legacy organizations, leading this change to a complete, unified digital strategy is top of mind,” Miano stated.
While the fastest-growing demand for a technology skill this year was enterprise architecture, big data and analytics sustained to be the most in-demand skill, at 42%, up 8% over last year.
Labels:
Bob Miano,
CIO,
Data Security,
Harvey Nash,
Healthcare Scams,
IT
Thursday, June 1, 2017
Worker at Trios Health snoops on information of 600 sufferers
A worker at Trios Health, which is anchored by Trios Southridge Hospital in Washington State, was utilizing its electronic health record (EHR) system not just to perform job duties but to also look up data on sufferers outside of the employee's job function.
The tragedy is the latest in a spate of breaches at healthcare agencies by insiders.
The Trios Health breach was discovered by its health information management department on the day of March 14. Compromised data involved dates of service, diagnoses, demographic information, Social Security numbers, driver’s license numbers, phone numbers and email addresses.
After an inquiry, the agency put in new EHR use restrictions to staff within the worker’s department and terminated the employee. The inquiry continues and as does extra privacy training and new standard auditing procedures to secure PHI. Notification letters to about 600 affected patients started being mailed on the day of May 29.
Trios Health is providing a year of identity theft, credit and fraud monitoring protection services for affected sufferers through Identity Force. Spokespersons for the agency didn’t respond to a request for extra information.
Other breaches at healthcare agencies of protected health information caused by insiders involve the following:
* At Med Center Health in Kentucky, a worker took data on 2 occasions to develop an outside business.
* Beacon Health System in Indiana discovered a worker had been accessing patient emergency department records for 3 years without permission or a reason to view them.
* A volunteer at NYC Health + Hospitals inadvertently caused a breach because she managed protected health information before being completely vetted and trained by the human resources department.
* 2 employees in the patient transport department at the institute of Vanderbilt University Medical Center were inappropriately accessing patient records by gaining more information than required to do their jobs.
The tragedy is the latest in a spate of breaches at healthcare agencies by insiders.
The Trios Health breach was discovered by its health information management department on the day of March 14. Compromised data involved dates of service, diagnoses, demographic information, Social Security numbers, driver’s license numbers, phone numbers and email addresses.
After an inquiry, the agency put in new EHR use restrictions to staff within the worker’s department and terminated the employee. The inquiry continues and as does extra privacy training and new standard auditing procedures to secure PHI. Notification letters to about 600 affected patients started being mailed on the day of May 29.
Trios Health is providing a year of identity theft, credit and fraud monitoring protection services for affected sufferers through Identity Force. Spokespersons for the agency didn’t respond to a request for extra information.
Other breaches at healthcare agencies of protected health information caused by insiders involve the following:
* At Med Center Health in Kentucky, a worker took data on 2 occasions to develop an outside business.
* Beacon Health System in Indiana discovered a worker had been accessing patient emergency department records for 3 years without permission or a reason to view them.
* A volunteer at NYC Health + Hospitals inadvertently caused a breach because she managed protected health information before being completely vetted and trained by the human resources department.
* 2 employees in the patient transport department at the institute of Vanderbilt University Medical Center were inappropriately accessing patient records by gaining more information than required to do their jobs.
Labels:
Beacon Health System,
Data Security,
EHR,
Identity Force,
Trios Health
Tuesday, May 30, 2017
Manufacturers, Healthcare providers fear attack likely on medical devices
Manufacturers, Healthcare providers fear attack likely on medical devices
The healthcare providers and the medical devices manufacturers that use these devices are primarily unprepared to defend against cyber attacks on their devices, in accordance to the outcomes of a recent survey on security preparedness.
The research by the Ponemon Institute indicates that both makers and users of medical devices are concerned about the likelihood that key medical equipment could be hacked. Two-thirds of device makers and 56% of healthcare providers say an attack on devices is likely during the next year, in accordance to the Ponemon survey.
The Ponemon Institute conducted the research for Synopsys, which sells a platform to handle security and quality problems in software development. The survey covered 242 device makers and 262 healthcare delivery organizations in the North America market.
Some 80% of device firms and healthcare respondents recognized the development of secure devices as a key challenge, asserting that devices remain vulnerable due to coding errors, lack of expertise on secure coding practices and pressure to meet product deadlines.
Despite those complications, fewer than 10% of respondents test devices at least yearly, with 53% of healthcare agencies and 43% of manufacturers report that they do no testing on devices, a finding that surprises Larry Ponemon, chair and founder of Ponemon Institute.
“I was blinded when we discovered that,” he contends. “I would have assumed (providers and manufacturers would have) testing; you would think there would be more due to the cyber threat, but that does not seem to be a driver for change.”
Ponemon puts the onus for change on healthcare organization management, not essentially on chief information officers and chief information security officers, who are attempting to do the right things but do not have the resources or backing of senior leaders.
He claims that, when an attack happens, the CISO often is the fall guy and is fired, even though he or she may have been forcing for higher security. But the main mission for device makers and healthcare agency is to produce and distribute the product.
The survey discovered that one-third of all respondents reported that no person or function in their agency is primarily responsible for medical device security. Only half of device makers and 44% of healthcare organizations follow Food and Drug Administration guidance on mitigating device security risks.
The challenges that providers face with medical devices, which involve clinician mobile devices like smartphones, are overwhelming. Clinicians, Ponemon says, rely on their devices to efficiently serve sufferers, yet security protocols or architecture built in devices rarely adequately protects data. Security funding increases often occur merely after a serious attack, and encryption is not widely used with Internet of Thing devices.
Too often, Ponemon asserts, providers assume that security of pacemakers, insulin pumps and other devices brought into the hospital is the responsibility of the vendor.
“Healthcare doesn’t prioritize security as much as other industries,” he says. “Healthcare providers are thinking of patient safety, not security risks. We see pressures on healthcare providers to have products available to meet the needs of patients. Are we even capable of knowing if we have been hacked?”
Ponemon was glad to see the Food and Drug Administration recently issue guidance on cybersecurity, which he calls “pretty decent but not prescriptive—it does not tell you step-by-step what to do.” But he fears that following the guidance could be seen by device manufacturers and providers as just adding to existing costs.
“We’re living in a world where everything is a connected device. As we have more connected Internet of Things devices, risks increase. IOT devices are convenient to hack. In healthcare, this could kill people,” he claims.
The full report is available here.
The healthcare providers and the medical devices manufacturers that use these devices are primarily unprepared to defend against cyber attacks on their devices, in accordance to the outcomes of a recent survey on security preparedness.
The research by the Ponemon Institute indicates that both makers and users of medical devices are concerned about the likelihood that key medical equipment could be hacked. Two-thirds of device makers and 56% of healthcare providers say an attack on devices is likely during the next year, in accordance to the Ponemon survey.
The Ponemon Institute conducted the research for Synopsys, which sells a platform to handle security and quality problems in software development. The survey covered 242 device makers and 262 healthcare delivery organizations in the North America market.
Some 80% of device firms and healthcare respondents recognized the development of secure devices as a key challenge, asserting that devices remain vulnerable due to coding errors, lack of expertise on secure coding practices and pressure to meet product deadlines.
Despite those complications, fewer than 10% of respondents test devices at least yearly, with 53% of healthcare agencies and 43% of manufacturers report that they do no testing on devices, a finding that surprises Larry Ponemon, chair and founder of Ponemon Institute.
“I was blinded when we discovered that,” he contends. “I would have assumed (providers and manufacturers would have) testing; you would think there would be more due to the cyber threat, but that does not seem to be a driver for change.”
Ponemon puts the onus for change on healthcare organization management, not essentially on chief information officers and chief information security officers, who are attempting to do the right things but do not have the resources or backing of senior leaders.
He claims that, when an attack happens, the CISO often is the fall guy and is fired, even though he or she may have been forcing for higher security. But the main mission for device makers and healthcare agency is to produce and distribute the product.
The survey discovered that one-third of all respondents reported that no person or function in their agency is primarily responsible for medical device security. Only half of device makers and 44% of healthcare organizations follow Food and Drug Administration guidance on mitigating device security risks.
The challenges that providers face with medical devices, which involve clinician mobile devices like smartphones, are overwhelming. Clinicians, Ponemon says, rely on their devices to efficiently serve sufferers, yet security protocols or architecture built in devices rarely adequately protects data. Security funding increases often occur merely after a serious attack, and encryption is not widely used with Internet of Thing devices.
Too often, Ponemon asserts, providers assume that security of pacemakers, insulin pumps and other devices brought into the hospital is the responsibility of the vendor.
“Healthcare doesn’t prioritize security as much as other industries,” he says. “Healthcare providers are thinking of patient safety, not security risks. We see pressures on healthcare providers to have products available to meet the needs of patients. Are we even capable of knowing if we have been hacked?”
Ponemon was glad to see the Food and Drug Administration recently issue guidance on cybersecurity, which he calls “pretty decent but not prescriptive—it does not tell you step-by-step what to do.” But he fears that following the guidance could be seen by device manufacturers and providers as just adding to existing costs.
“We’re living in a world where everything is a connected device. As we have more connected Internet of Things devices, risks increase. IOT devices are convenient to hack. In healthcare, this could kill people,” he claims.
The full report is available here.
Tuesday, May 23, 2017
Organizations informing data breaches faster to federal agencies
The Department of Health and Human Services’ OCR (Office for Civil Rights) is cracking down on providers that don’t report data breaches of protected health information in a basic timely manner. OCR in the month of March initiated to fine agencies that don’t notify federal agencies of breaches within sixty days as required. The effect has been dramatic—average reporting times for breaches were merely 45 days in the month of March and 59 in the month of April, compared with 478 days in February, in accordance to Protenus, a vendor that offers a cloud platform to monitor and secure the security of hospital electronic health records (EHRs).
“It is complex to know for sure with limited information, but we might recommend 2 reasons for this trend of reduced breach reporting time,” claims Robert Lord, co-founder and CEO at Protenus. “One potential reason is that initiating earlier this year, HHS has arguably stepped up enforcement on healthcare agencies that don’t report breaches within the required 60-day window. Organizations are informing data breaches faster to federal agencies.
“An extra potential reason is that healthcare agencies are becoming more diligent in their analysis and reporting of breaches, as awareness of the significance of reporting grows,” Lord continues. “While these tragedies are unfortunate, they can be utilized as a learning experience to educate other covered entities on best practices.”
The number of days between when a breach occurred and when it was discovered in the month of April ranged from almost instantly to 228 days. Organizations are informing data breaches faster to federal agencies.
In April, 16 hacking tragedies accounted for 47% of all breaches. Additionally, another 29% were caused by insiders; 15% involved lost or stolen information and 9% by unknown means. The total number of records breached in the April attacks for which Protenus has numbers includes 171,268 patients.
The kinds of breaches reported last month involve providers (79% of all incidents), health insurers (5.8%), business associates or vendors (5.8%) and other (8.8%). Data from the monthly Protenus Breach Barometer report comes from DataBreaches.net.
“It is complex to know for sure with limited information, but we might recommend 2 reasons for this trend of reduced breach reporting time,” claims Robert Lord, co-founder and CEO at Protenus. “One potential reason is that initiating earlier this year, HHS has arguably stepped up enforcement on healthcare agencies that don’t report breaches within the required 60-day window. Organizations are informing data breaches faster to federal agencies.
“An extra potential reason is that healthcare agencies are becoming more diligent in their analysis and reporting of breaches, as awareness of the significance of reporting grows,” Lord continues. “While these tragedies are unfortunate, they can be utilized as a learning experience to educate other covered entities on best practices.”
The number of days between when a breach occurred and when it was discovered in the month of April ranged from almost instantly to 228 days. Organizations are informing data breaches faster to federal agencies.
In April, 16 hacking tragedies accounted for 47% of all breaches. Additionally, another 29% were caused by insiders; 15% involved lost or stolen information and 9% by unknown means. The total number of records breached in the April attacks for which Protenus has numbers includes 171,268 patients.
The kinds of breaches reported last month involve providers (79% of all incidents), health insurers (5.8%), business associates or vendors (5.8%) and other (8.8%). Data from the monthly Protenus Breach Barometer report comes from DataBreaches.net.
Labels:
Civil Rights,
Data Security,
HIPAA,
OCR,
Protenus Breach Barometer,
Robert Lord
Wednesday, May 10, 2017
NIST issues new guidance for protecting wireless infusion pumps
The NIST (National Institute of Standards and Technology) has released latest guidance on protecting wireless infusion pumps in hopes of hardening the devices against the cyber attacks.
The federal agency released the directions in collaboration with the National Cybersecurity Center of Excellence (NCCoE), which is a unit within NIST. The NCCoE has developed a plan indicating providers how to use standards-based commercially available technology to secure wireless infusion pumps, patient data and drug library dosing limits.
Various significant vendors collaborated with NIST on the report. They involve B.Braun, Baxter, BD, Cisco, Clearwater Compliance, DigiCert, Hospira, Intercede, MDISS, PFP, RAMPARTS, Smiths Medical, Symantec and TD Medical.
The plan involves a questionnaire-based risk assessment mapping security characteristics to available cyber security standards as well as to the requirements of HIPAA security rule to apply security controls for pumps and other data systems or networks to which they might connect.
“Finally, we demonstrate how biomedical, networking and cybersecurity engineers and IT experts can securely configure and deploy wireless infusion pumps to decrease cybersecurity risk,” NIST’s report asserts.
The new report depicts more than a year of work on infusion pump security by NIST, which called on technology companies in the year of January 2016 to mount a collaborative effort to make better the security of wireless pumps.
Federal organizations and watchdog groups raised awareness of the fact that wireless infusion pumps could be compromised by hackers, increasing risks for sufferers and also prompting uncertainties that the networks to which they are connected could be accessed through cyber attacks. Security on the devices generally is weak and can be conveniently manipulated by external agents.
“In specific, the wireless infusion pumps ecosystem (the pump, the network and the data stored in or on a pump) confront a range of threats involving unauthorized access to protected health information, changes to prescribed drug doses and interference with the function of pump,” the guidance states, referring a report of the Association for the Advancement of Medical Instrumentation.
However connecting infusion pumps to point-of-care medication systems and electronic health records (EHRs) can improve the healthcare delivery procedures, utilizing a medical device’s connectivity capabilities can pose increased threat, which could lead to operational or safety problems, NIST points out.
In general, wireless infusion pumps don’t interface with a lot of other information systems; they take data and push it to the pharmacy using an HL7 central server, and the data may also go into the electronic health record, says Tom Walsh, president of the Tom Walsh Consulting security practice. But because there are so many different vendors and varieties of pumps, it’s been difficult to devise one approach to protect them.
Part of the vulnerability stems from the fact that vendors often remotely access their devices in hospitals to troubleshoot them. “How do you know it’s the vendor in the device or someone hacking in?” Walsh asks. “The vendor may or may not collaborate with IT or biomedical.”
The full NIST guidance is available here. A model of a network infrastructure is here.
The federal agency released the directions in collaboration with the National Cybersecurity Center of Excellence (NCCoE), which is a unit within NIST. The NCCoE has developed a plan indicating providers how to use standards-based commercially available technology to secure wireless infusion pumps, patient data and drug library dosing limits.
Various significant vendors collaborated with NIST on the report. They involve B.Braun, Baxter, BD, Cisco, Clearwater Compliance, DigiCert, Hospira, Intercede, MDISS, PFP, RAMPARTS, Smiths Medical, Symantec and TD Medical.
The plan involves a questionnaire-based risk assessment mapping security characteristics to available cyber security standards as well as to the requirements of HIPAA security rule to apply security controls for pumps and other data systems or networks to which they might connect.
“Finally, we demonstrate how biomedical, networking and cybersecurity engineers and IT experts can securely configure and deploy wireless infusion pumps to decrease cybersecurity risk,” NIST’s report asserts.
The new report depicts more than a year of work on infusion pump security by NIST, which called on technology companies in the year of January 2016 to mount a collaborative effort to make better the security of wireless pumps.
Federal organizations and watchdog groups raised awareness of the fact that wireless infusion pumps could be compromised by hackers, increasing risks for sufferers and also prompting uncertainties that the networks to which they are connected could be accessed through cyber attacks. Security on the devices generally is weak and can be conveniently manipulated by external agents.
“In specific, the wireless infusion pumps ecosystem (the pump, the network and the data stored in or on a pump) confront a range of threats involving unauthorized access to protected health information, changes to prescribed drug doses and interference with the function of pump,” the guidance states, referring a report of the Association for the Advancement of Medical Instrumentation.
However connecting infusion pumps to point-of-care medication systems and electronic health records (EHRs) can improve the healthcare delivery procedures, utilizing a medical device’s connectivity capabilities can pose increased threat, which could lead to operational or safety problems, NIST points out.
In general, wireless infusion pumps don’t interface with a lot of other information systems; they take data and push it to the pharmacy using an HL7 central server, and the data may also go into the electronic health record, says Tom Walsh, president of the Tom Walsh Consulting security practice. But because there are so many different vendors and varieties of pumps, it’s been difficult to devise one approach to protect them.
Part of the vulnerability stems from the fact that vendors often remotely access their devices in hospitals to troubleshoot them. “How do you know it’s the vendor in the device or someone hacking in?” Walsh asks. “The vendor may or may not collaborate with IT or biomedical.”
The full NIST guidance is available here. A model of a network infrastructure is here.
Labels:
Data Security,
MDISS,
NIST,
Smiths Medical,
Tom Walsh Consulting
Friday, April 28, 2017
Approximately 90% of agencies struck by a data breach
Hackers sustain to gain the upper hand in the war for data breach, with an astounding 87% of agencies saying they were the victims of cyberattacks in the past twelve months.
That is one of the findings in the new research “Threats Below the Surface Report,” which surveyed more than 3,000 Information Technology (IT) experts on the security risks, priorities and capabilities that are top-of-mind. The research also discovered that one in three agencies reported that they had been hacked more than 5 times in the last 12 months, double the rate of 2014.
One of the leading causes of the rise in data breach risks is the rapid adoption of cloud computing, the study demonstrates.
“Enterprise cloud apps lack critical controls for data security that could primarily decrease the threat of a breach,” stated Nat Kausik, chief executive officer at Bitglass, which co-produced the study along with the CyberEdge Group and Information Security Community. “While few agencies can recognize potential leaks after the fact, some organizations can remediate threats in real time.”
Kausik shared several dramatic statistics regarding data breaches and cyber preparedness:
The research also discovered that 62% of organizations that have adopted the cloud say improved threat detection is the most critical threat management capability. Other capabilities most in demand involve data encryption (cited by 72%), traffic encryption (cited by 60%) and access controls (cited by 56%).
As for cloud-specific concerns, the problems that organizations are struggling with the most include data leakage (cited by 57%), data privacy (cited by 49%), confidentiality (cited by 47%) and compliance (cited by 36%).
That is one of the findings in the new research “Threats Below the Surface Report,” which surveyed more than 3,000 Information Technology (IT) experts on the security risks, priorities and capabilities that are top-of-mind. The research also discovered that one in three agencies reported that they had been hacked more than 5 times in the last 12 months, double the rate of 2014.
One of the leading causes of the rise in data breach risks is the rapid adoption of cloud computing, the study demonstrates.
“Enterprise cloud apps lack critical controls for data security that could primarily decrease the threat of a breach,” stated Nat Kausik, chief executive officer at Bitglass, which co-produced the study along with the CyberEdge Group and Information Security Community. “While few agencies can recognize potential leaks after the fact, some organizations can remediate threats in real time.”
Kausik shared several dramatic statistics regarding data breaches and cyber preparedness:
- 54% of organizations hit with a ransonware attack were capable to recover without paying up.
- 52% of organizations hope to increase their overall information security budgets.
- 39% of agencies in retail and 36% in technology are spending a larger portion of their budgets on information security than in other vertical markets.
- 37% said phishing is a top security concern, followed by insider threats (cited by 33%) and malware (32%)
- 36% of agencies monitor mobile devices
- 24% of organizations monitor SaaS and IaaS apps for security risks
The research also discovered that 62% of organizations that have adopted the cloud say improved threat detection is the most critical threat management capability. Other capabilities most in demand involve data encryption (cited by 72%), traffic encryption (cited by 60%) and access controls (cited by 56%).
As for cloud-specific concerns, the problems that organizations are struggling with the most include data leakage (cited by 57%), data privacy (cited by 49%), confidentiality (cited by 47%) and compliance (cited by 36%).
Labels:
Data Security,
Nat Kausik
Wednesday, April 26, 2017
Ransomware epidemic will sustain to devastate healthcare industry
There is a ransomware epidemic prevailing across the industry of healthcare that indicates no signs of slowing down, in accordance to GreyCastle Security CEO Reg Harnish.
He asserts that healthcare is not any more susceptible to ransomware epidemic than other industries. But Harnish analyzes that—given the value of patient data and medical records—providers are the focus of cyber criminals who are aiming them with file-encrypting malware.
“You take their information away, and it usually threatens lives, patient safety and patient care, so they are much more likely to pay a ransom,” he adds.
Business is booming at GreyCastle, which is faing triple-digit growth year over year. The Troy, N.Y.-based consultancy has merely been in operation for 6 years, but Harnish asserts that his company is considered to be one of the largest cybersecurity risk assessment, advisory, and mitigation firms in the country.
“We’ve a very deep practice in healthcare, involving incident response where we have been addressing ransomware,” claims Harnish. “It is everywhere. This issue is not going away.”
When it comes to prevention, Harnish considers that healthcare agencies must conduct regular and systematic assessments to recognize, prioritize and measure cybersecurity risk. He points out that most ransomware epidemic cases appear “because an end user on the clinical staff or administration falls victim to a social engineering attack.”
To stop these kinds of breaches, Harnish suggests healthcare agencies adopt a heightened sense of awareness that comes from training end users on emerging cyber threats and what to do about them. “An effective awareness program that assists their employees and contractors to be capable to identify a social engineering attack and then report it is job No. 1,” he contends.
He says that Locky and Sage ransomware epidemic sustain to appear on the phishing threat landscape in the year of 2017. “The reality is that our adversaries are getting better faster,” in accordance to Harnish, who says ransomware is evolving in terms of ease-of-use, features, and functionality.
“They are selling this stuff merely like Microsoft,” he adds. “They are in business to sell software or, in their case, malware. All of them today are undergoing a similar ype of evolution to (what we saw with) Microsoft Office. Cyber criminals aren’t a bunch of teenagers wearing hoodies. It is very organized and sophisticated.”
Harnish recommends that agencies have a response capability, which he analyzes as being critical for handling, coordinating and monitoring a cybersecurity tragedy from initial discovery through resolution. “They require having a response plan so if and when it happens, they can respond very rapidly,” he summarizes.
On the query of whether or not agencies should give in to the demands of cyber criminals using ransomware, Harnish claims that GreyCastle never suggests paying a ransom. “There is no guarantee that the ransom will work,” he cautions. “If you pay the ransom, you might not get decryption keys. And even if you do get decryption keys, they may not be the right ones.”
Moreover, Harnish warns that those agencies that pay a ransom then get put on a list of victims who’ve complied with ransomware demands. As an outcome, he says they are much more likely to be targeted again as a “paying” customer. “None of our customers have ever paid a ransom,” he adds.
He asserts that healthcare is not any more susceptible to ransomware epidemic than other industries. But Harnish analyzes that—given the value of patient data and medical records—providers are the focus of cyber criminals who are aiming them with file-encrypting malware.
“You take their information away, and it usually threatens lives, patient safety and patient care, so they are much more likely to pay a ransom,” he adds.
Business is booming at GreyCastle, which is faing triple-digit growth year over year. The Troy, N.Y.-based consultancy has merely been in operation for 6 years, but Harnish asserts that his company is considered to be one of the largest cybersecurity risk assessment, advisory, and mitigation firms in the country.
“We’ve a very deep practice in healthcare, involving incident response where we have been addressing ransomware,” claims Harnish. “It is everywhere. This issue is not going away.”
When it comes to prevention, Harnish considers that healthcare agencies must conduct regular and systematic assessments to recognize, prioritize and measure cybersecurity risk. He points out that most ransomware epidemic cases appear “because an end user on the clinical staff or administration falls victim to a social engineering attack.”
To stop these kinds of breaches, Harnish suggests healthcare agencies adopt a heightened sense of awareness that comes from training end users on emerging cyber threats and what to do about them. “An effective awareness program that assists their employees and contractors to be capable to identify a social engineering attack and then report it is job No. 1,” he contends.
He says that Locky and Sage ransomware epidemic sustain to appear on the phishing threat landscape in the year of 2017. “The reality is that our adversaries are getting better faster,” in accordance to Harnish, who says ransomware is evolving in terms of ease-of-use, features, and functionality.
“They are selling this stuff merely like Microsoft,” he adds. “They are in business to sell software or, in their case, malware. All of them today are undergoing a similar ype of evolution to (what we saw with) Microsoft Office. Cyber criminals aren’t a bunch of teenagers wearing hoodies. It is very organized and sophisticated.”
Harnish recommends that agencies have a response capability, which he analyzes as being critical for handling, coordinating and monitoring a cybersecurity tragedy from initial discovery through resolution. “They require having a response plan so if and when it happens, they can respond very rapidly,” he summarizes.
On the query of whether or not agencies should give in to the demands of cyber criminals using ransomware, Harnish claims that GreyCastle never suggests paying a ransom. “There is no guarantee that the ransom will work,” he cautions. “If you pay the ransom, you might not get decryption keys. And even if you do get decryption keys, they may not be the right ones.”
Moreover, Harnish warns that those agencies that pay a ransom then get put on a list of victims who’ve complied with ransomware demands. As an outcome, he says they are much more likely to be targeted again as a “paying” customer. “None of our customers have ever paid a ransom,” he adds.
Labels:
Data Security,
Healthcare Scams,
Microsoft Office
Tuesday, April 18, 2017
Medical devices security sustains to be critical question in buying decision
Healthcare agencies searching to purchase medical devices are doing their homework and initiating to inquire manufacturers more queries about security than in the past, claims George Gray, chief technology officer and vice president of software and information systems at Ivenix, a manufacturer of infusion pumps. Medical devices security sustains to be critical question in buying decision.
That is a good start, in accordance to Gray. But, several potential buyers are not aware that pumps are small computers and prospective customers should be asking the similar questions they would inquire when assessing any other kind of information system.
They requirement to challenge vendor assertions that their pumps and other devices are secure by inquiring what kinds of vulnerabilities the devices have as well as the plan and schedule for decreasing the vulnerabilities. Because pumps are small computers confronting all the threats that other computers face, providers must not tolerate hedging by vendors on security answers, Gray suggests. Medical devices security sustains to be critical question in buying decision.
Prospective customers should hope vendors to come clean on any current susceptibilities and resolution plans. In specific, buyers should inquire if they can handle user access, roles, credential and permissions on a device, which offers the user more control over security. Also, they should ask if the vendor contracts with ethical hackers to assess vulnerabilities as its products are being built; the hired help will find vulnerabilities the vendor never knew, Gray contends.
Vendors might say their pumps cannot be hacked because they are running on a proprietary operating system and not Linux or Windows. Although, Gray claims the pumps remain vulnerable because whatever operating system is being used still can be struck by a denial of service attack where a ping, or message, is sent to a device or web site inquiring permission to enter and the pings just keep coming until the device is overwhelmed. “A proprietary operating system can be hacked as conveniently as any other operating systems,” he further adds.
Additionally, vendors should be asked if they can make sure that patient data is locked down and encrypted when being sent as a message or being stored. Gray suggests asking what the vendor will do the day it is hacked and to elaborate the resources it has to identify and fix issues, and processes to rapidly get the fix out to customers. Moreover, he advises asking if a vendor can download software to the customer on a daily basis merely as Microsoft can. Medical devices security sustains to be critical question in buying decision.
“At this stage of the game it is significant to have a straight talk and lay cards on the table,” Gray recommends.
He analyzes that customers often are coming in with a series of questions ready and vendors might be more focused on answering the queries in a way to secure the sales position with the customer, which can turn into a heated discussion with the customer initiating to distrust the vendor.
If a vendor’s present product is not as up to speed on security as it should be, the vendor should be candid with the customer and also giving few options, like falling back on use of a private network until the new product comes out, Gray adds.
That is a good start, in accordance to Gray. But, several potential buyers are not aware that pumps are small computers and prospective customers should be asking the similar questions they would inquire when assessing any other kind of information system.
They requirement to challenge vendor assertions that their pumps and other devices are secure by inquiring what kinds of vulnerabilities the devices have as well as the plan and schedule for decreasing the vulnerabilities. Because pumps are small computers confronting all the threats that other computers face, providers must not tolerate hedging by vendors on security answers, Gray suggests. Medical devices security sustains to be critical question in buying decision.
Prospective customers should hope vendors to come clean on any current susceptibilities and resolution plans. In specific, buyers should inquire if they can handle user access, roles, credential and permissions on a device, which offers the user more control over security. Also, they should ask if the vendor contracts with ethical hackers to assess vulnerabilities as its products are being built; the hired help will find vulnerabilities the vendor never knew, Gray contends.
Vendors might say their pumps cannot be hacked because they are running on a proprietary operating system and not Linux or Windows. Although, Gray claims the pumps remain vulnerable because whatever operating system is being used still can be struck by a denial of service attack where a ping, or message, is sent to a device or web site inquiring permission to enter and the pings just keep coming until the device is overwhelmed. “A proprietary operating system can be hacked as conveniently as any other operating systems,” he further adds.
Additionally, vendors should be asked if they can make sure that patient data is locked down and encrypted when being sent as a message or being stored. Gray suggests asking what the vendor will do the day it is hacked and to elaborate the resources it has to identify and fix issues, and processes to rapidly get the fix out to customers. Moreover, he advises asking if a vendor can download software to the customer on a daily basis merely as Microsoft can. Medical devices security sustains to be critical question in buying decision.
“At this stage of the game it is significant to have a straight talk and lay cards on the table,” Gray recommends.
He analyzes that customers often are coming in with a series of questions ready and vendors might be more focused on answering the queries in a way to secure the sales position with the customer, which can turn into a heated discussion with the customer initiating to distrust the vendor.
If a vendor’s present product is not as up to speed on security as it should be, the vendor should be candid with the customer and also giving few options, like falling back on use of a private network until the new product comes out, Gray adds.
Labels:
Data Security,
George Gray
Sunday, April 16, 2017
How hospital database controls can decrease the susceptibility to hacking?
As hackers increasingly target healthcare industry to gain access to information, hospitals require improving efforts to secure patient information, mostly stored in several places throughout their systems. Hospitals have hundreds if not thousands of hospital database controls and most of them can serve as a launch pad for hackers, asserts Bill Fox, vice president of healthcare and life sciences at MarkLogic, a vendor that gives enterprise database technology.
Too often, workers and clinicians have unlimited access to data, he claims, and that access should be limited on a need-to-know basis; and after a task is done, that access should be eradicated to decrease the chance for accidental exposure.
“Hackers can do many things at even the lowest hospital database controls level,” Fox emphasizes. “They can go in the database and use it to get to another database, not merely using that second database as a hijacking device, but using it to get to the motherlode.”
Fox was an ex-deputy chief of economic and cyber crime at the Philadelphia District Attorney’s Office, where he inquired and prosecuted hackers targeting healthcare agencies and other industries. In one case, hackers sat in a car in the parking lot of a large retail chain and used the inventory mainframe to access other information systems, eventually stealing information on 5,000 people.
Hackers do not just come from the outside; in several cases, they work inside an agency and, as several providers have learned over the years, they are just as dangerous, Fox says. Too many providers aren’t monitoring worker activity when simple analytics could rapidly spot an offender. Using business intelligence tools to observe an organization’s network activity might identify workers accessing parts of hospital database controls that they have never used before.
Developing formal separation of duties among worker will lessen accessibility to information that they do not need, so healthcare agencies should give pieces of documentation and limit authorized information systems access, with everyone merely having the information they require, he counsels.
“You actually need to make sure that the capability to roam all over the network is immensely limited. Teach and enforce rules, involving rules on clinicians who did not go to school to become security experts but to be doctors and nurses, and only now are catching up to the requirement for security to become a priority. Some 73% of healthcare users are security novices—there is your attack surface for a hacker.”
Too often, workers and clinicians have unlimited access to data, he claims, and that access should be limited on a need-to-know basis; and after a task is done, that access should be eradicated to decrease the chance for accidental exposure.
“Hackers can do many things at even the lowest hospital database controls level,” Fox emphasizes. “They can go in the database and use it to get to another database, not merely using that second database as a hijacking device, but using it to get to the motherlode.”
Fox was an ex-deputy chief of economic and cyber crime at the Philadelphia District Attorney’s Office, where he inquired and prosecuted hackers targeting healthcare agencies and other industries. In one case, hackers sat in a car in the parking lot of a large retail chain and used the inventory mainframe to access other information systems, eventually stealing information on 5,000 people.
Hackers do not just come from the outside; in several cases, they work inside an agency and, as several providers have learned over the years, they are just as dangerous, Fox says. Too many providers aren’t monitoring worker activity when simple analytics could rapidly spot an offender. Using business intelligence tools to observe an organization’s network activity might identify workers accessing parts of hospital database controls that they have never used before.
Developing formal separation of duties among worker will lessen accessibility to information that they do not need, so healthcare agencies should give pieces of documentation and limit authorized information systems access, with everyone merely having the information they require, he counsels.
“You actually need to make sure that the capability to roam all over the network is immensely limited. Teach and enforce rules, involving rules on clinicians who did not go to school to become security experts but to be doctors and nurses, and only now are catching up to the requirement for security to become a priority. Some 73% of healthcare users are security novices—there is your attack surface for a hacker.”
Friday, April 14, 2017
Feds punishes Metro community provider network with $400,000 Fine for HIPAA violations
Unsuccessful to undertook a risk analysis and establish a risk management plan as required under the HIPAA privacy and security rules has landed a provider agency in trouble with the HHS Office for Civil Rights, leading to a $400,000 fine and imposition of a 3-year corrective action plan. Metro Community Provider Network is a huge federally qualified health center with 21 clinics serving 43,000 primarily poor sufferers in 5 counties throughout the Denver region. Its services involve primary care, pharmacy, dental, social work and behavioral health.
In the month of January 2012, Metro Community Provider Network informed OCR that a hacker accessed workers’ email accounts through a phishing attack and gained electronic protected health information on 3,200 people. “OCR’s investigation disclosed that MCPN took important corrective action related to the phishing tragedy; although, the investigation also unveiled that MCPN failed to conduct a risk analysis until the year of mid-February 2012,” the agency asserts in a statement.
When MCPN ultimately conducted a risk analysis, it and subsequent risk analyses weren’t enough to meet HIPAA security rule requirements, in accordance to OCR.
OCR has now levied huge sanctions against almost 50 HIPAA covered entities. Although, starting in the year of 2016, OCR has ramped up HIPAA enforcement actions and is levying considerably higher fines, concentrating on covered entities’ requirement to have viable risk assessment programs in place. Fines levied against providers in the year of 2016 and 2017 have ranged from $2.14 million to $5.55 million.
However, in the declaration of sanctions against Metro Community Provider Network, OCR appeared to provide the organization a financial break due to the nature of the work it does. “With this settlement amount, OCR considered MCPN’s status as a federally qualified health center when balancing the importance of the violation with MCPN’s capability to maintain sufficient financial standing to make sure the provision of ongoing care.”
In response to an appeal for comment, Metro Community Provider Network released the following statement:
“In the year of 2011, Metro Community Provider Network (MCPN) had a phishing tragedy which was reported to Health and Human Services and the Office for Civil Rights. Since that time, the agency has worked with these entities to assure HIPAA compliance, involving reaching an agreed upon settlement of $400,000. MCPN is happy with the work that has been done and continues to assure that sufferer privacy is protected.”
The resolution agreement and corrective action plan are available here.
In the month of January 2012, Metro Community Provider Network informed OCR that a hacker accessed workers’ email accounts through a phishing attack and gained electronic protected health information on 3,200 people. “OCR’s investigation disclosed that MCPN took important corrective action related to the phishing tragedy; although, the investigation also unveiled that MCPN failed to conduct a risk analysis until the year of mid-February 2012,” the agency asserts in a statement.
When MCPN ultimately conducted a risk analysis, it and subsequent risk analyses weren’t enough to meet HIPAA security rule requirements, in accordance to OCR.
OCR has now levied huge sanctions against almost 50 HIPAA covered entities. Although, starting in the year of 2016, OCR has ramped up HIPAA enforcement actions and is levying considerably higher fines, concentrating on covered entities’ requirement to have viable risk assessment programs in place. Fines levied against providers in the year of 2016 and 2017 have ranged from $2.14 million to $5.55 million.
However, in the declaration of sanctions against Metro Community Provider Network, OCR appeared to provide the organization a financial break due to the nature of the work it does. “With this settlement amount, OCR considered MCPN’s status as a federally qualified health center when balancing the importance of the violation with MCPN’s capability to maintain sufficient financial standing to make sure the provision of ongoing care.”
In response to an appeal for comment, Metro Community Provider Network released the following statement:
“In the year of 2011, Metro Community Provider Network (MCPN) had a phishing tragedy which was reported to Health and Human Services and the Office for Civil Rights. Since that time, the agency has worked with these entities to assure HIPAA compliance, involving reaching an agreed upon settlement of $400,000. MCPN is happy with the work that has been done and continues to assure that sufferer privacy is protected.”
The resolution agreement and corrective action plan are available here.
Labels:
Civil Rights,
Data Security,
HIPAA,
MCPN,
OCR
Subscribe to:
Posts (Atom)





