Skip to main content

Privacy & Security

By Jessica Davis | 03:23 pm | October 19, 2018
The issues shared during an Oct. 18 state senate meeting mirror those the healthcare sector faces: a lack of resources and an onslaught of attacks make it nearly impossible to keep up.
By Tom Sullivan | 12:31 pm | October 19, 2018
It starts with hiring "hardcore cloud animals," to change the culture and rethink infosec’s role in patient experience.
By Dean Koh | 03:38 am | October 18, 2018
HealthHub, a one-stop portal and mobile application for Singaporeans to access a wide range of health content, rewards and e-services, which was launched in 2015, had experienced a series of unauthorised log-ins, according to the Health Promotion Board’s (HPB) recent statement. The portal is an initiative by the Ministry of Health, and Health Promotion Board, supported by Integrated Health Information Systems (IHiS), the national technology agency for healthcare in Singapore. HPB and IHiS had detected the unauthorised log-ins during investigations into unusual activities on the portal. The agencies had found “higher than usual attempted log-ins” to the HealthHub portal on four days – Sept 28, Oct 3, Oct 8 and Oct 9 – using more than 27,000 unique IDs or email addresses. Although 98 per cent of the email addresses used were not related to existing HealthHub accounts and the log-in attempts were unsuccessful, 72 accounts were successfully logged in during those time periods. These accounts were subsequently locked and HPB had contacted the account holders to inform them of the suspicious activity, and to check if they had made the attempts themselves. HPB was first alerted when a user suspected her email account had been used without her permission to log in to the portal, and informed HPB. The agency also added that no evidence of a breach in the HealthHub system has been found. Healthcare cybersecurity in Singapore has been in the limelight since the SingHealth cyberattack, which occurred in June 2018. Described as one of the worst cyberattacks in the country, the incident saw the personal information of 1.5 million SingHealth patients being stolen by sophisticated hackers over the period between June 27 and July 4. Singapore Health Services or SingHealth is Singapore’s largest group of healthcare institutions, which consists of 4 public hospitals island wide, 5 national specialty centres and a network of 9 polyclinics. An ongoing Committee of Inquiry (COI) for the SingHealth cyberattack which was convened on July 24, held a series of public and private court hearings since last month and is expected to submit a report of its findings by the end of 2018.  
By Jessica Davis | 12:19 pm | October 16, 2018
While healthcare organizations are better understanding and investing in cybersecurity needs, hackers are keeping pace -- and then some, according to a panel of CISOs at the HIMSS Security Forum in Boston.
By Jessica Davis | 05:56 pm | October 12, 2018
The Food and Drug Administration issued a cybersecurity alert on two Medtronic devices that could allow a hacker to hijack the software update process to change the device’s function. Medtronic disabled the online software update to eliminate the flaw. IMPACT Following a review of potential security vulnerabilities around the internet connection, the FDA found 34,000 CareLink cardiac implantable electronic devices are at risk. If exploited, a hacker could change the programmer’s functionality or the device itself during the implantation or follow-up visits. The flaw is found in the internet connection between the CareLink 2090 and Encore 29901 Programmers, used for downloading software from Medtronic’s Software Distribution Network. The programmers are used by providers to adjust the cardiac device settings and collect locally stored data. While software updates typically include new software for the programmer functionality and updates to the implanted device firmware through a virtual private network, the programmers don’t verify they’re still connect to the VPN before downloading the updates. As a result, attempting to update the program through the internet connection will result in an error message. Medtronic updated its network, which was approved by the FDA on Oct. 5. The fix will intentionally block the currently existing programmer from accessing the Medtronic SDN. The vendor is continuing to implement security updates to further address the flaw. The FDA recommends providers continue to use the programmers, as network connectivity isn’t required for normal CIEF programming. Further, providers should not attempt to update the programmer through the SDN, which is no longer available. Future updates are currently only available through Medtronic with a USB update. THE TREND Medical device vulnerabilities are well-known, and vulnerability reporting by vendors have increased 400 percent per quarter since the FDA released its cybersecurity guidance in 2016. However, the increase in FDA alerts is meant to further improve cybersecurity, rather than to shame the vendor. Medtronic has reported several vulnerabilities in recent years, as has Philips, Abbott and a host of others. .jumbotron{ background-image: url("http://www.healthcareitnews.com/sites/default/files/u2231/cybersecurity-jumbotron-712.jpg"); background-size: cover; color: white; } .jumbotron h2{ color: white; } Focus on Cybersecurity In October, we take a deep dive into security strategy and pressing threats. Twitter: @JF_Davis_ Email the writer: jessica.davis@himssmedia.com
By Jessica Davis | 03:14 pm | October 12, 2018
For more than a month, two separate employee accounts were compromised by the cyberattacks before the IT department discovered the hack.
By Mike Miliard | 03:35 pm | October 11, 2018
Keeping software up to date without disrupting care delivery requires a plan for regular patching – and responding to emergency alerts when necessary.
By Jessica Davis | 03:08 pm | October 10, 2018
HITRUST launched a security program to help start-up companies bolster their privacy and security foundations, including the adoption of the most comprehensive risk management, compliance and security services. WHY IT MATTERS The goal is to support startups in adopting best practices as they grow. HITRUST is working closely with those small businesses to ensure these security features are baked into their products from the beginning. To accomplish this, HITRUST is bundling and pricing its programs to align with small businesses that have been in business for less than three years, have fewer than 50 employees and less than $10 million in annual revenue. The program will streamline HITRUST adoption. ON THE RECORD “Navigating risk management and compliance requirements can be costly and a strain on internal resources and can be daunting for any company, but it can be compounded in start-ups that are focusing on bringing their vision to market,” Mike Parisi, HITRUST’s vice president of assurance strategy and community development, said in a statement. THE TREND HITRUST was formed in 2007 and is seen as one of the industry’s gold standards for security. In May, it launched a certification program for the NIST Cybersecurity Framework for hospitals and health systems to ensure security compliance. The RightStart Program will ensure these startups embed these security standards into “their evolving business models,” Parisi added. HITRUST officials stressed that often these types of security measures are seen as a barrier to adoption. And as a result, companies will add programs in an ad hoc way, which leads to a loss of time and money, without a guaranteed improved risk posture. To Hoala Greevy, Paubox CEO, the hope is that the program will give the company the ability to adopt a security framework that will scale with the organization. “HITRUST provides us with the tools for secure, compliant growth needed to increase our bottom line,” Greevy said in a statement. “Our customer focus demands we have security, compliance, and risk management in place by design and not as an afterthought.” .jumbotron{ background-image: url("http://www.healthcareitnews.com/sites/default/files/u2231/cybersecurity-jumbotron-712.jpg"); background-size: cover; color: white; } .jumbotron h2{ color: white; } Focus on Cybersecurity In October, we take a deep dive into security strategy and pressing threats. Twitter: @JF_Davis_ Email the writer: jessica.davis@himssmedia.com
By Jessica Davis | 01:17 pm | October 10, 2018
A researcher discovered the North Carolina-based tech vendor is leaking protected patient data through its Amazon S3 bucket twice in a month.
By Jessica Davis | 10:38 pm | October 09, 2018
A hacker obtained access to an employee email account of California-based Gold Coast Health Plan, attempting to fraudulently move funds to their account.