Channel News and Analysis - Channel Insider
Empowering the next generation Channel
 

Sponsored Links
  • Get up and running in as quickly as 30 days with BI. Learn how today.
  • FREE Securing Smartphones & Tablets for Dummies Book from Sophos
  • 5 New Technologies That Will Change Enterprise ITAdvertisement
  • Build an IT Infrastructure That Delivers the Future

  •  

    GAO Report: Medicare Patient Data Vulnerable

    in Channel News and Analysis



    Article Rating:starstarstarstarstar / 0
    Article Views: 1472

    CMS' current security is insufficient to protect patients' personal information, such as social security numbers and psychiatric treatment history, a government report said.

    Rate This Article:
    Add This Article To:
    The personal data of Medicare patients is at risk because Centers for Medicare and Medicaid Services has not held its network contractor to its own security standards, according to a report issued by the Government Accountability Office.

    The GAO concluded that information on the network could be disclosed without authorization and that vulnerabilities could be used to disrupt CMS services.

    A security breach could allow "unauthorized access to personally identifiable medical data, seriously diminishing the public's trust in CMS' ability to protect the sensitive beneficiary data it is entrusted with." The report comes at a time when worries about medical identity theft are growing.

    Besides personally identifiable information like name, address, and social security number, potentially compromised information could include treatments for psychiatric disorders and substance abuse problems.

    According to the GAO, Medicare helps over 42 million patients obtain health care from over 1 million providers, collecting droves of sensitive data in the process.

    To reach its conclusions, GAO researchers visited three network contractor sites that transmit CMS information, examining "routers, network management servers, switches, firewalls and administrator workstations."

    CMS did not always encrypt medical data or other sensitive information traveling over these networks, according to the report. CMS also allowed its contractor to use passwords that were too simple and gave workers more access than they needed to do their jobs. These and other vulnerabilities "provide more opportunities for an attacker to escalate their privileges and make unauthorized changes to files" as well as "to gain unauthorized access to network resources," the report said.

    Click here to read about Centers for Medicare and Medicaid Services' decision to test the use of personal health records.

    The situation did not surprise one manager at a network security firm, who asked not to named. "It's a standard set of problems." The manager had not worked with the CMS network but has worked with other government systems.

    In a statement, CMS Administrator Mark McClellan, in Baltimore, said CMS had been aware of and was addressing many of the problems. He downplayed their significance, saying that about half of the identified problems had already been fixed, and that there are no signs that any of the vulnerabilities had been exploited. Because the network transmits rather than houses information, intercepting the information would be difficult, he said.

    However, the network security manager said, "It's harder to get the data because you have to watch for it, but the data are still vulnerable." In particular, thieves could monitor for authentication codes that they could then use to gain access to particular information they want.

    Sensitive information throughout the network is at risk, the GAO report concluded. Such information is communicated between diverse agencies, said the report, "including the CMS central office and data center, CMS regional offices, financial institutions, Medicare intermediaries and carriers, Medicare data centers, skilled nursing facilities and home health agencies, CMS contractors, state Medicaid offices, other federal agencies, quality information organizations, and CMS disaster recovery services."

    The identified vulnerabilities fell into several categories including user identification, authentication and authorization. Additionally, "security-related events" were not monitored or audited, provisions to make sure network configurations were secure were flawed, and different components of the network were not physically or logistically separated, so that people with legitimate access to one part of the network could have an easier time reaching areas for which they are unauthorized.

    In some cases, said the report, "certain network devices did not have any users defined, allowing for the execution of unauthorized commands without any means of designating individual accountability for the action."

    The study was conducted at the request of the Senate Finance Committee. The full report is available as a pdf.

    Check out eWEEK.com's for the latest news, views and analysis of technology's impact on government and politics.




    comments dic


     
     
    >>> More Channel News and Analysis Articles          >>> More By M.L. Baker
     


     



    channel chatter


    HTML PLAIN TEXT

    Keep on top of news for VARs and Resellers with CI's Weekly Newsletter and Alerts.


    [ci] feeds
    XML
    Add Channel News, Product Reviews, Trends and Analysis to your RSS newsreader or My Yahoo!


     


    CHANNEL SPONSORED RESOURCE CENTER
     
     
     
    Start the New Year with business intelligence—it’s a smart move
    Join us on February 1 for an encore rebroadcast at either 5 am or 12 noon EST and discover how business intelligence (BI) supports companies in uncertain business and economic climates. Get expert advice on how to create a strategy that fits your organization's needs and budget and see how quickly it can pay for itself.
    Click Here
     
    Security and Availability Essentials for Running Your Business in the Cloud
    Are you moving to the cloud? Find out what every IT professional should know about security and availability before moving to the cloud. Hear what a security provider’s own CSO has to say.
    Watch Video
    A new algorithm automatically identifies relationships between variables to help reduce researcher prejudice.
    Click HereAdvertisement