Channel News and Analysis - Channel Insider
Empowering the next generation Channel
 

Bull’s Eye Awards
Nominations Open for Channel Insider 2009 Bull’s Eye Awards
Nominations are now open for the Channel Insider 2009 Bull’s Eye Awards, which recognize excellence in customer service, technology prowess, business acumen, channel leadership, communications and community building, and innovation among vendors, solution providers, distributors and channel services companies.



Sponsored Links
  • Control VM Sprawl, What You Don’t Know Can Hurt You
  • FREE Sophos Encryption Tool: Encrypt, compress and share files easily
  • LSI 6Gb/s Portfolio Expands to Include SATA+SAS HBAs
  • Reduce the cost of managing your mobile workers.
  • Find out 7 Ways to Drive Data Center Efficiency
  • SonicWALL breaks through network and email gridlock
  • Save up to 40% on calling costs with Avaya Aura™



  •  

    GAO Report: Medicare Patient Data Vulnerable

    in Channel News and Analysis


    Article Rating:starstarstarstarstar / 0
    Article Views: 683

    Rate This Article:
    Add This Article To:
    CMS' current security is insufficient to protect patients' personal information, such as social security numbers and psychiatric treatment history, a government report said.

    The personal data of Medicare patients is at risk because Centers for Medicare and Medicaid Services has not held its network contractor to its own security standards, according to a report issued by the Government Accountability Office.

    The GAO concluded that information on the network could be disclosed without authorization and that vulnerabilities could be used to disrupt CMS services.

    A security breach could allow "unauthorized access to personally identifiable medical data, seriously diminishing the public's trust in CMS' ability to protect the sensitive beneficiary data it is entrusted with." The report comes at a time when worries about medical identity theft are growing.

    Besides personally identifiable information like name, address, and social security number, potentially compromised information could include treatments for psychiatric disorders and substance abuse problems.

    According to the GAO, Medicare helps over 42 million patients obtain health care from over 1 million providers, collecting droves of sensitive data in the process.

    Resource Library:

    To reach its conclusions, GAO researchers visited three network contractor sites that transmit CMS information, examining "routers, network management servers, switches, firewalls and administrator workstations."

    CMS did not always encrypt medical data or other sensitive information traveling over these networks, according to the report. CMS also allowed its contractor to use passwords that were too simple and gave workers more access than they needed to do their jobs. These and other vulnerabilities "provide more opportunities for an attacker to escalate their privileges and make unauthorized changes to files" as well as "to gain unauthorized access to network resources," the report said.

    Click here to read about Centers for Medicare and Medicaid Services' decision to test the use of personal health records.

    The situation did not surprise one manager at a network security firm, who asked not to named. "It's a standard set of problems." The manager had not worked with the CMS network but has worked with other government systems.

    In a statement, CMS Administrator Mark McClellan, in Baltimore, said CMS had been aware of and was addressing many of the problems. He downplayed their significance, saying that about half of the identified problems had already been fixed, and that there are no signs that any of the vulnerabilities had been exploited. Because the network transmits rather than houses information, intercepting the information would be difficult, he said.

    However, the network security manager said, "It's harder to get the data because you have to watch for it, but the data are still vulnerable." In particular, thieves could monitor for authentication codes that they could then use to gain access to particular information they want.

    Sensitive information throughout the network is at risk, the GAO report concluded. Such information is communicated between diverse agencies, said the report, "including the CMS central office and data center, CMS regional offices, financial institutions, Medicare intermediaries and carriers, Medicare data centers, skilled nursing facilities and home health agencies, CMS contractors, state Medicaid offices, other federal agencies, quality information organizations, and CMS disaster recovery services."

    The identified vulnerabilities fell into several categories including user identification, authentication and authorization. Additionally, "security-related events" were not monitored or audited, provisions to make sure network configurations were secure were flawed, and different components of the network were not physically or logistically separated, so that people with legitimate access to one part of the network could have an easier time reaching areas for which they are unauthorized.

    In some cases, said the report, "certain network devices did not have any users defined, allowing for the execution of unauthorized commands without any means of designating individual accountability for the action."

    The study was conducted at the request of the Senate Finance Committee. The full report is available as a pdf.

    Check out eWEEK.com's for the latest news, views and analysis of technology's impact on government and politics.



    Discuss GAO Report: Medicare Patient Data Vulnerable
     
    >>> Be the FIRST to comment on this article!
     

     
     
    >>> More Channel News and Analysis Articles          >>> More By M.L. Baker
     


     


    [ci] feeds
    XML
    Add Channel News, Product Reviews, Trends and Analysis to your RSS newsreader or My Yahoo!


    HTML PLAIN TEXT

    Keep on top of news for VARs and Resellers with CI's Weekly Newsletter and Alerts.

     


    CHANNEL RESOURCE CENTER
     
     
    Enterprise Mobility Zone
    The Enterprise Mobility Zone (EMZ) blog is a tool designed to help senior IT executives discuss, create and deploy next-generation mobile strategies in their organizations.
    Go beyond yesterday's tactical approach to mobility!
     
    Build A More Efficient Data Center
    Demands are growing but budgets are not. Solve your pressing IT issues using the resources you already have. Determine which technologies can help you drive efficiencies and how they are applied. Gain a quick ROI on new initiatives
    Find out how
    Let Enterprise TechBrief do the work for you. Aggregated content, tech news, product reviews, vendor updates, how-to’s—all you need to boost your efficiencies and cut costs, all from one place.
    enterprisetechbrief.com