Showing posts with label Johns Hopkins University. Show all posts
Showing posts with label Johns Hopkins University. Show all posts

Friday, October 28, 2016

Ransomware and malware: The top cyber criminals exploits

When it comes to the cybersecurity, healthcare agencies are most concerned over the social engineering, information theft and internal threats. And they perceive ransomware and malware as the top ways that cyber criminals are exploiting their weaknesses. Ransomware and malware are believed to be the top cyber criminals exploits.


Those are among the findings of a new survey of almost 200 members of the Association for Executives in Healthcare Information Security (AEHIS) and College of Healthcare Information Management Executives (CHIME).


The top-ranked potential security susceptibilities in the survey that worry AEHIS and CHIME members are data exposure, security misconfiguration and worst authentication/session management. Although, they showed that the most usual security risks to their agencies are social engineering, insider threats and the IoT (internet of things). Ransomware and malware are believed to be the top cyber criminals exploits.


Asked how their agencies would perform if systems or information were compromised by a targeted attack compared with a year ago, survey respondents claimed that they are now better ready for a security tragedy by having systems in place. Furthermore, they assert that their capabilities for discovering a security tragedy and recovering from it are presently better in contrast with a year ago.


Avi Rubin, director of the Health and Medical Security Lab at Johns Hopkins University, claims that there were no surprises in the outcomes of the survey and that they were exactly what he would have hoped.


CHIME Vice President for Federal Affairs Mari Savickis presented the findings of the survey this week to the Department of Health and Human Services’ Cybersecurity Task Force, mandated by Congress to establish suggestions to counter the healthcare industry’s growing cyber threats putting patient data at risk.


While healthcare agencies stated that they require greater assistance from federal agencies to make better information sharing and threat assessments, almost 65% of survey respondents showed that they were somewhat confident or not confident at all that federal legislators understand the significance of cybersecurity enough to support primary information security initiatives.


Nevertheless, they need lawmakers to adopt incentives that will motivate greater information sharing, involving shielding agencies that voluntarily work to make better security across the delivery system from government audits and reduce the top cyber criminals exploits i.e. Ransomware and Malware.

Thursday, May 5, 2016

Study finds medical mistakes are the 3rd leading cause of death

Medical mistakes are the 3rd leading cause of death for Americans, claiming a quarter of a million lives a year, in accordance to study results released by researchers at Johns Hopkins University.


If fatalities resulting from errors and safety lapses in medical care were counted as deaths, as are deaths from disease and injury, they would account for more fatalities than respiratory disease, and trail only heart disease and cancer as a cause of death, argues researchers in the report, published in the British Medical Journal.


To better track, research and neglect medical mistakes in the future, the authors of the BMJ study call for a space on death certificates where doctors can indicate that a medical error contributed to the death.

Monday, January 25, 2016

Contributors add latest layers to cyber defense measures

Brigham and Women’s, St. Luke’s Cornwall, Allina Health, Middesex Hospital. Entire these agencies in the last sixty days joined the government’s list of health contributors impacted by security violations. And the year 2015 looks to be the worst year ever for healthcare security challenges. While certain incidents are a result of lost or stolen data, smart hackers looking to lift the treasure trove of data discovered in health records are now the leading reason of information loss.


The risk is not likely to ease. Cybercrime is an “increasing $6 billion epidemic that puts millions of sufferers and their data at risk,” in accordance to a report on healthcare data security issued previous year by the Ponemon Institute.


To counter the increasing danger, contributors require rethinking their security measures.


No longer are virus scanning and intrusion detection software enough.


“Protection technologies have an intention; the issue is there are actually amazing ways to evade these things,” states Ronald Mehring, chief information security officer (CISO) for Texas Health Resources. “We have seen that with a multitude of violations across agencies that have powerful programs.”


The key, claim experts, is a complicated solution of various defense layers embedded with latest data analysis techniques that can track hackers before they can break into health information stores.


CIOs and their security staffs have to think about a class of more sophisticated devices that can sense when a violation is being implemented or already underway. For instance, advanced classes of firewalls are aware of the applications running behind them and can take into consideration what is and is not normal traffic trying to approach those applications.


Many agencies are turning to these kinds of layered protection, healthcare security experts say.


“You need to have advanced application-level firewalls at the edge,” states David Reis, vice president of IT governance and security at Lahey Health, Burlington, Mass. “You need to have intrusion detection and prevention at the network layer inside the firewall to capture those things that get through the firewall. And then for the Internet-facing networks that you are really upset and worried about, you can put host-based intrusion detection on those very particular servers.”


But layered accesses alone may be incomplete because of risks burrowing in from the Internet, states Mehring. “Before, we analyzed at it like this iterative access. Somebody comes in from the Internet; they beat an external firewall--some kind of defense network that keeps them out, at the outer shell. Then if they make it past there, there is some other control, then some other control, and some other control. It does not quite work that way anymore, because of the way users communicate with technology, the Internet.”


Detection is significant, but we are putting a lot more of our concentration on preventive steps rather than detection measures. 


Network protections can be thwarted when a worker unwisely falls prey to a phishing gambit, by either clicking on a hacker’s URL link or attachment. “Professionally and personally, that is my huge worry,” states Reis. Phishing attacks “can be astonishingly effective, especially in the healthcare market where we are all trained to be patient-centric, trained to be helpful.”


HIPAA has prompted health networks to elevate their attempts, adding encryption of information at rest, media protections, and backup and security protocols, claims Russell Branzell, president and CEO of the College of Healthcare Information Management Executives. “It was the nudge we required to get started, and most agencies generally have those in area today,” he claims. Now they have to weigh technology “that steps and reacts to human nature and attitude.”


Barrier technologies are programmed to look for distinctive measures of a finite number of viruses and other malware. “You require so many hits of persons, machines, users getting infected in case for a rule, a pattern, a signature to be generated,” states Lee Kim, director of privacy and security for the Healthcare Information and Management Systems Society. In comparison to rules-based responses to attackers, the newer behavior-deployed methods look for departures from general activity.


It is all about trying to stay even with hackers who are continuously altering their attack modes. “Prevention now is far more significant than it is ever been,” Reis emphasizes. “Detection is primary, but we are putting a lot more of our concentration on preventive steps rather than detection steps, because things happen so much more rapidly now than they did even 5 years ago. If you wait until you have detected, you have had a very big event. The key now is to make certain that event does not happen.”



Increasingly, security technology is performing analyses on information coming from breach prevention and detection networks, sifting for suspicious activity, states Darren Lacey, CISO and director of IT compliance at Johns Hopkins University and its medical school. “Detection controls, what they do is they claim, ‘Well, this thing is happening, and it looks sort of funny--what do you want me to do about it?’ ”


Answering those queries are a set of investigative controls, sometimes automated in their reactions, but usually operated by a staff pro responding to alerts, claims Lacey, adding, “Detection controls are most profitable when they are integrated well with investigating.” Data aggregated from the multiple detection points--firewalls, host-based protection networks, audited activity logs and so on--aid in “creating recent prevention signatures and latest prevention rules.” And if a detection network sees something get through, “that will shape what prevention controls you run in the coming days.”


Prevention controls at the outer rim of the IT network involve lists of IP addresses known to be both destinations for stolen information and sources of command-and-control centers for a network of malware called bots, directing them through a breached network looking for lucre. “But sometimes these botnets alters the IP addresses, so your preventive rule sets do not tell you a lot,” states Lacey.



A detection network might recognize a new IP address to which various devices inside an IT network are interacting back and forth, for unknown reasons. Possibilities are that something suspicious is in play, Lacey elaborates, and an alert is triggered for investigation. The 1st response likely is to set up a latest preventive control, adding the address to the block list. If it stops a compromised computer from interacting back to an outlaw site, “that greatly lessens the rate of damage that bots can do.”


Texas Health Resources takes the analytical route even further, devising threat profiles of users in its 25-hospital networks deployed on their access to places of the network, especially greatly sensitive lodes of data, and how much of a target they would be for, claim, phishing efforts, says Mehring. He calls it a zonal approach within the network as compared with a layered approach, intended to shut down violations before they can flourish.


“Quickness is key,” Mehring announces. “What we have discovered is that when that phishing email comes in, those first 2 hours that it is in your atmosphere is the most critical.” THR uses a cloud-based product that does a better job than in the past at tracking an attack and purging the invading agent, he states.


Vast modifications in the speed, computing capability and connectedness of healthcare data technology highly complicate the business of keeping IT networks safe from intrusion. “Not merely do hackers’ methods change, but the systems that we are trying to protect evolve as well,” states Reis. “The systems get more complex, and the hackers get more sophisticated, and to be effective we have to be capable to keep up with both at the similar rate.”


The fast movement of great amounts of information makes near-real-time intrusion detection critically significant, claims Kim of HIMSS, because attackers that get in can move rapidly and access quantities of information in no time. A reactive measure of spotting known malware in action will miss the mark, she asserts, because reaction hours or days later is often too late.


Monday, January 17, 2011

Watermelon lowers blood pressure

Amino acids found in watermelon have been shown to lower blood pressure. In addition to healthy vitamins and minerals, watermelon contains two amino acids, L-arginine and L-citrulline, that reduce hypertension.Other Natural Blood Pressure Lowering Foods
Other foods have also been shown to lower blood pressure. Bananas can lower hypertension, as can raisins, beets and even chocolate.

Watermelon Research
Researchers at Florida State University used a concentrated extract of watermelon for the research on nine subjects. The dosage used in the study was six grams of the combined watermelon amino acids. After six weeks, all of the participants, 100 percent, showed reduced blood pressure. The study concluded that watermelon could be used by people who have pre-hypertension to keep the condition from progressing to high blood pressure. This means that eating watermelon may allow those at risk for heart disease to avoid taking preventative blood pressure lowering medications that are usually prescribed.

Blood Pressure Prevention Medication Side EffectsPharmaceutical drugs are frequently prescribed for those with a tendency towards high blood pressure, a condition called pre-hypertension. These medications have been shown to have numerous side effects, including potassium loss that leads to an increased risk of diabetes. Other side effects, reported by Johns Hopkins University, include constipation, frequent urination, headaches, digestive upset, dizziness, and a tendency to dehydration, which causes a number of health issues in itself.

Watermelon, on the other hand, has no known side effects. Watermelon Contains Vitamins and Lycopene Watermelon also contains healthy nutrients, such as vitamins A, vitamin C and vitamin B6, along with potassium and fiber. Watermelon also contains lycopene, the nutrient plentiful in tomatoes that has been show to have numerous health benefits. Lycopene is an antioxidant. Eating foods high in lycopene has been shown to reduce the incidence of many types of cancer, including breast cancer and prostate cancer. Lycopene has been shown to prevent heart attacks both in studies at John HopkinsJohn Hopkins University and in international studies.

Though tomatoes were used in the studies, other foods known to be rich in lycopene are watermelons, grapefruits, apricots and guavas. Watermelon Mechanism of Action Watermelon lowers blood pressure because of its action in production of nitric oxide, researchers surmise. This is because L-citrulline in the watermelon is converted into L-arginine, which is then used to make nitric oxide. Nitric oxide, in turn, helps control blood pressure. L-Arginine Alone is Not Enough Taking the amino acids L-arginine by itself is not an effective treatment for high blood pressure, nor is it recommended because the amino acid is not easy to digest and can cause digestive problems, including diarrhea. Watermelon Dosage to Prevent High Blood Pressure The dosage used in the watermelon study was four to six grams of watermelon extract, but a healthier alternative is to add raw watermelon to the diet.