The sensitive health information maintained by health care providers and health plans has become an increasingly attractive target for cyberattacks. The need for health care organizations to up their game on health data security has never been greater. To help health care organizations covered by the Health Insurance Portability and Accountability Act (HIPAA) to bolster…
Category: Of Note
Patient monitors altered, drug dispensary popped in colossal hospital hack
Scary stuff. Darren Pauli reports: Security researchers have exploited notoriously porous hospital networks to gain access to, and tamper with, critical medical equipment in attacks they say could put lives in danger. In tests, hospital hackers from the Independent Security Evaluators research team popped patient monitors, making them display false readings which could result in…
Individual Convicted of an Offence under the Health Information Act
A woman was recently convicted of knowingly accessing health information of seven people in contravention of the Health Information Act (HIA). On Feb. 5, Denise Tourneur pleaded guilty to illegitimately accessing the health information of seven individuals on 44 separate occasions at the Kaye Edmonton Clinic where she worked. The situation stemmed from a breach discovered by…
ASUS Settles FTC Charges That Insecure Home Routers and “Cloud” Services Put Consumers’ Privacy At Risk
Taiwan-based computer hardware maker ASUSTeK Computer, Inc. has agreed to settle Federal Trade Commission charges that critical security flaws in its routers put the home networks of hundreds of thousands of consumers at risk. The administrative complaint also charges that the routers’ insecure “cloud” services led to the compromise of thousands of consumers’ connected storage devices, exposing…
Thinking about incident response
So I woke up to find that uKnowKids had issued a statement yesterday about their exposed database, an exposure that had been uncovered by and reported to them by Chris Vickery. Regular readers of this blog will recognize Chris’s name by now, as he’s uncovered a number of misconfigured databases that have been investigated by…
uKnowKids responds to reports of exposed database
uKnowKids has responded to reports that their database was exposed. As reported yesterday on this site, the details of 1,740 children being tracked by their software as well as other details were exposed in a misconfigured MongoDB installation. The exposed data included text messages and images from and to the children. The exposure was discovered by Chris…