Serious Adobe Flash Security Vulnerability Discovered
In addition to dealing with the increased threat of Cryptowall ransomware and Stegoloader malware attacks, healthcare IT professionals must be aware of the latest software security vulnerabilities as they can all too easily cause a data breach. Adobe Flash in particular is a major security risk, with yet another serious security vulnerability discovered in the past few days. The latest Adobe Flash security flaw has an easy fix; the company issued a patch last week to tackle the vulnerability; however any computer that does not have the latest version of the software installed is a potential attack point for hackers. This could pose a problem for multiple hospital systems with thousands of networked computers to update. Another Adobe Flash Hacking Risk Discovered The security vulnerability was discovered not by Adobe, but FireEye Intelligence, a cyber-security company specializing in zero-day malware and advanced security threats. The company identified a security flaw that can be exploited by criminals to gain access to computers running Adobe Flash software. Hackers use a...
Healthcare Data under Threat from Stegoloader Malware
Back in 2013, a new form of malware was discovered that was capable of stealing information from the system on which it was installed – as with other malware – however, this variant differs in that it hides in PNG image files, making it look innocuous. The malware has recently been discovered to be having something of a resurgence, and healthcare providers are being targeted. Risk of Malware Transmission via PNG Images The Trojan works using a process called digital steganography. Steganography has Greek origins, and roughly translates as “covered writing”. The technique allows hackers to hide bits of code within the image pixels or other parts of the image such as the header section. The Danger of the Stegoloader Trojan The Stegoloader Trojan family is otherwise known as Win32/Gatak.DR and TSPY_GATAK.GTK according to Dell SecureWorks. The latest variants of the malicious software identified by Trend Micro are TROJ_GATAK.SMJV, TROJ_GATAK.SMN, and TROJ_GATAK.SMP. The latest three variants are most commonly acquired from file-sharing websites; in particular illegal software and games...
Healthcare Providers Seek Protection from HIPAA Breaches
Phishing, malware & direct attacks by hackers are on the increase and employees are abusing data access rights: Any organization required to collect, store or use Protected Health Information (PHI) is likely to suffer a data breach. It is just a matter of when that breach will occur. Even when healthcare providers abide by HIPAA Rules – and avoid OCR financial penalties – the cost of a healthcare data breach can be considerable. Patients must be notified, credit protection services provided and identity theft insurance offered. The cost of printing and posting breach notification letters represents a sizable cost. Mid-sized healthcare providers that hold millions of patient health records and Social Security numbers could well find a large-scale data breach to be ruinous. Inevitable Data Breaches Mean Insurance Policies are Required Even the best security systems can be undone by a single worker. The data breach at Medical Management LLC occurred when an employee took data from the company and disclosed it to a third party. A recent data breach at Penn State University...
Extent of Unauthorized Cloud Service Usage by Employees Uncovered
How many cloud services is your organization using? According to a new report, if the figure is under 928 – the average number of cloud services used by healthcare providers – you may be underestimating the extent to which employees are using the cloud. The data suggest employees are breaching security policies by using cloud services that lack the necessary security controls. If the data collected is representative of the healthcare industry as a whole, HIPAA violations are being committed on a daily, if not hourly basis by healthcare professionals. Benefits of HIPAA-Compliant Cloud Services There are a number of advantages to be gained from using cloud services. Healthcare providers and other HIPAA-covered entities can cut IT equipment and maintenance costs by hosting data in the cloud. Leveraging cloud services can also improve productivity, and speed up accessing and logging of patient data. A number of healthcare providers have been able to improve patient health outcomes by making use of cloud services. Security Risks Being Taken by Employees Skyhigh Networks...
Privacy Incident Reported by Meritus Medical Center
The Meritus Medical Center (MMC) in Hagerstown, Maryland has started issuing breach notification letters to 1, 029 patients after a “privacy incident” was discovered in which patient names and other Personally Identifiable Information (PII) were exposed along with healthcare information and Social Security numbers, according to a report in the Herald Mail. Dates of birth, patient gender and medical record numbers were potentially viewed along with healthcare data such as medical test results. Not all individuals had their Social Security numbers compromised, as this data was only stored on a limited number of individuals. MMC has confirmed that no financial information was exposed in the data breach. Breach Notification Letters Sent HIPAA-Covered Entities often delay the issuing of breach notices to patients to enable a full breach investigation to be conducted, which can take some time to complete. This proved to be the case with Meritus Medical Center; although according to a statement released by a MMC spokesperson, Mary Rizk, the breach notice letters were sent “as soon as...



