9 years ago
1
Patients' medical records under threat from data breaches
Your private medical information is under threat. That's according to a study that found almost 30 million health records nationwide were involved in criminal theft, malicious hacking or other data breaches over four years. The incidents seem to be increasing.
Continue Reading http://bigstory.ap.org
Additional Contributions:
Join the Discussion
Might be a good time to mention that the Verizon DBIR was recently released. I'll add that to the related links.
Sadly, all the interaction that I have had with healthcare companies leaves a lot to be desired. None of their environments were setup for security in mind. Shared accounts, VPN's unmonitored, zero auditing or evidence of ongoing review.
A lot of the blame goes to the HIPAA. If you hold up the HIPAA technical requirements and the PCI requirements you immediately see the difference. The HIPAA is labyrinthine, confusing, and hard to read for mortals. The PCI is straightforward bullet points "you will have a firewall. the firewall will be configured like so. you will review on a quarterly basis. you will document the review... etc, etc". Very straightforward to handle.
I fear it will get worse before it gets better.