Healthcare Organizations Need to Be Proactive and Hunt for Security Threats
Many organizations are now opting to outsource cybersecurity to managed security services providers (MSSPs) due to a lack of internal resources and expertise. However, many MSSPs are unable to offer the advanced threat detection services necessary to significantly improve cybersecurity posture. Raytheon Foreground Security recently commissioned a Ponemon Institute study to investigate how MSSPs were being used by organizations. Raytheon surveyed 1,784 information security leaders from a range of organizations – including healthcare providers – in North America, the Middle East, Europe, and the Asia-Pacific region. Respondents were asked about the role of MSSPs, how important their services are, and how MSSPs fit in to business strategies. 80% of organizations that have enlisted the services of MSSPs say that they are an important element of their IT overall security strategy and provide a range of services that cannot be managed in house. Many organizations do not have sufficient IT personnel to make their cybersecurity strategies more effective, and when staff are available they...
ONC Reminds App Developers to Check Regulatory Requirements
The Office of the National Coordinator for Health Information Technology (ONC) has reminded developers of health apps not only to put more thought into data security, but also to build security controls into the core of their apps. Data security features should not simply be bolted as an afterthought. They are an essential part of the design of the apps and therefore must be incorporated during the initial design process. The ONC points out that health apps are no longer just being developed by computer science graduates. Health apps have been developed by clinicians who have identified a need for an app and a gap in the market. Even patients have been working on health apps to log and record a wide variety of health data or to issue appointment and medication reminders. No matter who conceives and develops a new health app, it is essential that the legal implications are considered and incorporated into the design. App developers must become familiar with the legislation covering health apps and the data they record. The Health Insurance Portability and Accountability Act (HIPAA)...
VA Implements New Measures to Improve Medical Device Cybersecurity
In May, a top official at the Veteran’s administration said that the risk of medical devices being hacked to give patients’ overdoses or otherwise cause them to come to harm is relatively unlikely; however, VA deputy director of health information security Lynette Sherrill did point out that medical devices could be a weak link that cyberattackers attempt to exploit. One of the problems is medical devices are not always patched promptly. The devices connect to networks via traditional operating systems such as Windows. When patches are released by Microsoft, medical devices are often the last devices to have the updates applied. The Information Security Monthly Activity Report sent by the VA to congress often shows that medical devices have been infected with malware. In January, the VA discovered three medical devices had been infected, with a further case in February and two more in April. Since malware infections started to be tracked by the VA in 2009, 181 medical device infections have been discovered. These infections have all been contained and are not believed to have...
Indiana Attorney General’s Office Investigates Dumping of Medical Records
Earlier this week, an officer from the Indianapolis Metropolitan Police Department (IMPD) discovered a number of medical records in a public recycling dumpster in Broad Ripple Park, Indianapolis. A number of confidential documents were found in file folders in the dumpster which had been mixed up with newspapers and other paper and cardboard. IMPD recovered the files and folders from the recycling dumpster, although there is no way of telling whether any documents had been removed by members of the public. It is also unclear whether files had been dumped on a single occasion, or whether material had been disposed of over an extended period of time. The Indiana Attorney General’s Office is now involved and efforts have been made to contact recycling and waste disposal companies who potentially may have come into contact with dumped medical records. If any further files and folders are recovered the attorney general’s office will arrange for the files to be collected and secured. According to the police report, the files contain highly sensitive data including patient names,...
16K ENT and Allergy Center Patients Affected by Bizmatics Breach
ENT and Allergy Care, P.A. has announced that its patients have been affected by the data breach at Bizmatics. In early 2015, the server used to host the Bizmatics PrognoCIS tool was hacked. Access to the server was gained and data stored on the server were potentially accessed. In December, 2015., the intrusion was detected and access to the server was rapidly shut down. Bizmatics started investigating the cyberattack and enlisted the services of an external computer forensics company. Law enforcement was also notified on the security breach. Bizmatics notified ENT and Allergy Care of the security breach by mail in January 2016; however, at the time it was not possible to tell whether ENT and Allergy Care patients had been affected. The Bizmatics investigation continued, and in April 2016 ENT and Allergy Care was notified that “at least some” data stored in the PrognoCIS tool had been accessed and possibly copied. Bizmatics was unable to determine exactly which patients’ data were accessed. The data stored in the PrognoCIS tool included patients’ names, addresses, and information...



