Review of Medicare Administrative Contractors Shows 8pc Annual Rise in Data Security Gaps
An annual review of Medicare administrative contractors (MAC) conducted by Pricewaterhouse Coopers (PwC) on behalf of the Office of Inspector General revealed 129 data security gaps existed in 2014, representing an increase of 8% from the previous year. The Social Security Act requires the information security programs of all MACs to be assessed by an independent entity on an annual basis. This year PwC was contracted to assess all nine MACs on the eight major requirements of the Federal Information Security Management Act of 2002 (FISMA) in addition to the Centers for Medicare and Medicaid Services (CMS) core security requirements. Data security gaps are defined as the incomplete implementation of FISMA or CMS core security requirements. Each data security gap is rated as high risk, medium risk, or low risk. For high and medium risk data security gaps, each MAC must develop an action plan to address the issues and the CMS is required to follow up and ensure that those data security gaps have been addressed. PwC discovered 18 high risk, 45 medium risk, and 66 low risk gaps. The...
Verizon: Human Error the Main Cause of Security Incidents
The Verizon 2016 Data Breach Investigations Report was released this week. The biggest cause of security incidents over the past 12 months has been what Verizon calls “miscellaneous errors,” a category which includes misconfigured IT systems, improper disposal of company data, lost and stolen devices and email errors. In the case of the latter, 26% of breaches were caused by individuals emailing data to incorrect individuals. Weak passwords continue to cause organizations problems. 63% of confirmed data breaches were attributed to either poor passwords, default login credentials that had not been changed, or the use of stolen login credentials. Cyberattacks are often made possible due to the failure to install patches promptly. In the majority of cases, hackers exploit vulnerabilities that have existed for months, even though patches have been made available. Verizon reports that 85% of successful exploits of took advantage of the top 10 known vulnerabilities. The biggest cause of data breaches this year is web application attacks, which have increased by 33% since the 2015 report....
American Dental Association Mails Malware-Infected USB Drives to Members
A recent mailing sent to American Dental Association (ADA) members included a USB stick containing malware. The USB drive contained a file with code that directed users to a domain which could enable cybercriminals to install malware, potentially allowing them to gain control of computers. The USB stick sent by the ADA was a credit card-sized drive that can be plugged into a laptop computer or a desktop. The device was used to send an electronic copy of the 2016 CDT manual containing dental procedure codes. One recipient of the device decided to check the contents of the USB stick on a spare machine as he was wary of using the device on a machine that contained sensitive data. He discovered the drive contained an HTML launcher in a hidden iframe that contained a potentially malicious URL with a Chinese ccTLD. An autorun file was also included on the device according to his DLS Reports post. ADA was informed about the malware infection and an investigation was launched. ADA informed Krebs on Security that the infection was introduced on certain devices during production in China....
Mailing Error Exposes PHI of American Fidelity Customers
Oklahoma City-based American Fidelity Assurance Company has notified 2,664 customers that some of their data have been disclosed to other customers as a result of a mailing error. The mailing error, which has been attributed to human error, occurred on February 15, 2015. American Fidelity mailed debit card substantiation letters to some of its customers which contained a section of information intended for other customers. The information printed on the letters included names and addresses, employer names and ID numbers, dates of service, provider names, payment amounts, and the last four digits of another customer’s debit card number. The letters also included details of customers’ recent flexible spending account debit card usage. No Social Security numbers or dates of birth were included in the mailings. Affected customers had their data exposed to another individual, although due to the nature of the incident and limited amount of data exposed, American Fidelity does not believe customers are at risk of data being used inappropriately. Customers have been notified of the...
Edwin Shaw Rehabilitation Hospital Patients’ PHI Exposed
Akron General Health System is notifying 975 patients of the Akron General Edwin Shaw Rehabilitation hospital that some of their protected health information has been exposed after an employee lost an unencrypted flash drive. The flash drive contained “generic” data on patients that had visited the hospital for treatment between 2010 and 2011. No Social Security numbers, financial information, dates of birth, addresses, or phone numbers were exposed. Patients therefore face a low risk of the information being used inappropriately, should the device have been recovered by a third party. Data stored on the device include patient names, medical record numbers, treatment provided, name of the insurance carrier, and referring provider. The flash drive was believed to have been lost on February 19, 2015. An Edwin Shaw employee who worked at the Cuyahoga Falls rehab center had taken the portable storage device off-site while attending a business meeting. The employee discovered the drive to be missing five days later. The loss was reported to the hospital and an investigation was...



