VA Information Security Weaknesses Will Take Further 22 Months To Remediate
Last week, the VA Office of Inspector General issued a report of a 2015 Department of Veteran Affairs (VA) audit conducted to determine whether the VA’s Security Program complied with Federal Information Security Modernization Act (FISMA) requirements and NIST guidelines. The audit report indicates progress has been made to improve cybersecurity protections at the VA, but there is still a long way to go before the VA’s InfoSec program raises standards to the level required by FISMA. Auditors discovered a number of significant security deficiencies in the VA’s identity management and access controls, configuration management controls, contingency planning processes, incident response and monitoring procedures, contractor systems oversight, continuous monitoring, system development/change management controls, and its agency-wide security management program. While some efforts have been made to improve access and configuration management controls, security control standards had not yet been applied to all servers, databases, and network devices and a number of system security...
Phase 2 HIPAA Compliance Audits Commence
The Department of Health and Human Services’ Office for Civil Rights has announced that the phase 2 HIPAA compliance audits have officially started. According to the recent OCR announcement, “Audits are an important compliance tool for OCR that supplements OCR’s other enforcement tools, such as complaint investigations and compliance reviews.” The announcement goes on to explain that the process of auditing covered entities allows OCR to “proactively uncover and address risks and vulnerabilities to protected health information.” Start Date for the Second Phase of HIPAA Compliance Audits While the audit process has now officially started, covered entities still have some time to get their policies and procedures in order. It will still be some time before the document checks for the 2016 compliance audits actually begin. The OCR announcement does not give a start date for the 2016 HIPAA compliance audits, but indicates that the first stage of desk audits will be completed by December 2016. The date when the first desk audits will actually be conducted was not detailed in the...
Virtua Medical Group Vendor Error Puts Patient Data in Search Engines
Virtua Medical Group has notified 1,654 patients that some of their protected health information had been accidentally indexed by search engines and was accessible over the Internet. An error was made by a transcription vendor during a server upgrade that resulted in patients’ names, birthdates, physicians’ names, and treatment information being indexed by search engines for up to three weeks. The server error occurred in early January and the error was identified on January 21, 2016. No financial data, insurance information, or Social Security numbers were exposed. Upon discovery of the error, Virtua Medical Group contacted its vendor to secure the data and efforts were made to remove the records from the search engines. The information is no longer accessible. It is unclear whether data were accessed by unauthorized individuals during the period they were accessible, although no reports of inappropriate data use have been reported. As a result of the breach of patient data, Virtua Medical Group has terminated its relationship with the transcription vendor. According to a...
Methodist Hospital in Lockdown After Ransomware Attack
Methodist Hospital in Henderson, KY., is currently in lockdown after a ransomware attack. The hospital has declared an “internal state of emergency,” after critical files were copied and locked. The hospital responded to the cyberattack quickly and was able to contain the malware, although as a result of the lockdown access to electronic communications and web-based systems remains limited. The malicious software was inadvertently installed on the network resulting in files containing patient data being copied and encrypted. According to a statement issued by Methodist COO David Park, “the hackers have copied patients records and locked those copies. They’ve deleted the originals.” Methodist Hospital was able to activate a backup system. Normal operations are continuing at the hospital without any interruption to patient services, but the issue has yet to be resolved and the main network remains locked. The FBI has been notified and an investigation into the cyberattack has commenced. Methodist Hospital is working with the FBI to determine the best way to resolve the issue. A...
Non-Compliant Hospital Pager Use Persists
Communicating protected health information (PHI) over unsecured networks is not permitted under the Health Insurance Portability and Accountability Act (HIPAA), which means pagers cannot be used to send PHI unless messages are encrypted. Encryption alone is not sufficient to ensure compliance with HIPAA. Not only must messages be encrypted to prevent interception, there must be a means of verifying the identity of the user. User authentication is essential, as there is no guarantee that a message containing PHI will be received by the intended recipient. If a pager is lost, stolen, or is left unattended, PHI could potentially be accessed by an unauthorized individual. It is also necessary to implement controls to automatically log off users and allow messages to be remotely erased in the event that a pager is lost or stolen. Due to the cost implications of applying these safeguards, and the difficult in doing so, many hospitals implement policies that prohibit the transmission of PHI over the pager network. If PHI needs to be communicated, a pager message is sent and the recipient...



