If your health insurance is through BlueCross BlueShield of Tennessee, your personal information may have been exposed.
Blue Cross will be contacting customers this week whose personal information was exposed when hard drives were stolen. Someone stole 57 hard drives from a storage closet at one of their training centers near Chattanooga. BlueCross Blue Shield continues to investigate what happened. newschannel5
Monday, January 11, 2010
Heartland to pay up to $60M for Visa data breach
Heartland Payment Systems Inc., a New Jersey-based payments processor, has agreed to pay up to roughly $60 million to cover losses caused to Visa Inc. credit and debit cardholders as a result of a huge 2008 security breach, the companies have announced.
The settlement agreement is contingent upon acceptance by financial institutions representing 80 percent of the eligible issuers' U.S. accounts that Visa says were put at risk during the Heartland intrusion, which Heartland disclosed in January 2009 had exposed more than 130 million credit and debit card numbers.
bizjournals
The settlement agreement is contingent upon acceptance by financial institutions representing 80 percent of the eligible issuers' U.S. accounts that Visa says were put at risk during the Heartland intrusion, which Heartland disclosed in January 2009 had exposed more than 130 million credit and debit card numbers.
bizjournals
Hacking Takes Lead as Top Cause of Data Breaches
Hacking has topped human error as the top cause of reported data breaches for the first time since such tracking began in 2007, according to the Identity Theft Resource Center's 2009 Breach Report.
In its report, titled "Data Breaches: The Insanity Continues," the non-profit ITRC found that 19.5 percent of reported breaches were due to hacking, with insider theft as the second most common cause at 16.9 percent. For the past two years, "data on the move," a typically human-error loss of a portable devices such as laptops or even briefcases, was the most common reported cause.
The ITRC is careful to note that its statistics are based on incomplete data, as differing laws and practices among different states mean that some breaches are not reported publicly, and the cause of the breach is not listed for about one third of those that are reported.
But according to the data available, the number of reported data breaches dropped since 2008, but was still more than in 2007. Last year, there were 498 breaches recorded by the ITRC, with 657 in 2008 and 446 in 2007.
With 41.2 percent of reported breaches, the business sector was the most likely to suffer a breach. But "the financial and medical industries, perhaps due to stringent regulations, maintain the lowest percentage of breaches," according to the report. pcworld
In its report, titled "Data Breaches: The Insanity Continues," the non-profit ITRC found that 19.5 percent of reported breaches were due to hacking, with insider theft as the second most common cause at 16.9 percent. For the past two years, "data on the move," a typically human-error loss of a portable devices such as laptops or even briefcases, was the most common reported cause.
The ITRC is careful to note that its statistics are based on incomplete data, as differing laws and practices among different states mean that some breaches are not reported publicly, and the cause of the breach is not listed for about one third of those that are reported.
But according to the data available, the number of reported data breaches dropped since 2008, but was still more than in 2007. Last year, there were 498 breaches recorded by the ITRC, with 657 in 2008 and 446 in 2007.
With 41.2 percent of reported breaches, the business sector was the most likely to suffer a breach. But "the financial and medical industries, perhaps due to stringent regulations, maintain the lowest percentage of breaches," according to the report. pcworld
Sunday, January 10, 2010
Should HIPAA compliance be outsourced?
CynergisTek, a computing and security consultant, reported on its blog recently that HIPAA compliance audits will be increased this year, thanks to a contract the government signed with PriceWaterhouseCoopers.
I admit that the significance of this went right by me at first. Then I went, “whaah?”
The government’s enforcement process has just been privatized.
Admittedly there is a huge backlog of audits. CynergisTek reports that the government has a list of over 100 active complaints concerning lax HIPAA compliance, which have to be checked out before anyone knocks on your door.
According to iHealthBeat, PWC is going to review 10-20 organizations under the one-year contract, so unless someone has an outstanding complaint against you you’re probably safe.
But the knock will come, CynergisTek promises. Oh, they work in that area and will be glad to hear from you.
Perhaps you think nothing of this. Nothing gets done on law enforcement until the government hires some private firm to do it. The assumption is the private firm will do it efficiently.
But I know how much a good PWC auditor costs, and I know how much the average civil service auditor makes. I guarantee the latter costs less, unless PWC itself is outsourcing this work to India or someplace.
And would it be too much to ask for the public, or at least the industry, to get a gander at that contract? On what basis is PWC being paid? What is their incentive? Is it a fixed price per audit, is it hourly, or is it based on the fines they collect?zdnet
I admit that the significance of this went right by me at first. Then I went, “whaah?”
The government’s enforcement process has just been privatized.
Admittedly there is a huge backlog of audits. CynergisTek reports that the government has a list of over 100 active complaints concerning lax HIPAA compliance, which have to be checked out before anyone knocks on your door.
According to iHealthBeat, PWC is going to review 10-20 organizations under the one-year contract, so unless someone has an outstanding complaint against you you’re probably safe.
But the knock will come, CynergisTek promises. Oh, they work in that area and will be glad to hear from you.
Perhaps you think nothing of this. Nothing gets done on law enforcement until the government hires some private firm to do it. The assumption is the private firm will do it efficiently.
But I know how much a good PWC auditor costs, and I know how much the average civil service auditor makes. I guarantee the latter costs less, unless PWC itself is outsourcing this work to India or someplace.
And would it be too much to ask for the public, or at least the industry, to get a gander at that contract? On what basis is PWC being paid? What is their incentive? Is it a fixed price per audit, is it hourly, or is it based on the fines they collect?zdnet
HIPAA Authentication Strategies
Some health care organizations have yet to take significant action to comply with the original HIPAA privacy and security rules, which were never vigorously enforced. Now that those rules have been beefed up under the American Recovery and Reinvestment Act, with increased enforcement and tougher penalties, many observers expect more hospitals, physician groups and others to gear up their data security assurance efforts.
Under the updated rules, state attorneys general now have the right to enforce the HIPAA privacy and security regulations. Plus, those harmed by a security breach can seek financial damages, Borten says. "I can just see the lawyers getting ready," she says. "We are going to see a real ramping up of complaints now as a result of all the changes."
Two Key Steps
Of course, the best way to comply with the privacy and security rules is to make sure only authorized individuals have access to patient information. Borten argues that all organizations should encrypt all patient data and adopt two-factor user authentication, such as a password paired with a fingerprint scanner. But she contends that many-perhaps most-organizations have yet to take either step.
And any data security effort should start with a thorough risk assessment, as required under federal law, notes Eric Nelson, privacy practice leader at the Lyndon Group, a Newport Beach, Calif.-based consulting firm.
What technologies are needed to ensure patient data is secure depends on the size of the organization, Nelson says. "A small group practice where only a few people have access to the information probably doesn't need a high-tech security solution," Nelson says. "It could be as simple as encrypting the information on the computers and installing locks on the doors. A large organization is a completely different matter."
The updated federal regulations, in fact, do not specify the security technologies providers must use. "The law says that if you don't want to have to notify the government of security breaches, then you should use new technologies to prevent breaches," Borten notes. "But I regret that the law doesn't require the use of the technologies."
As they ramp up efforts to implement clinical information systems, many hospitals, clinics and other provider organizations are investing in a variety of user authentication technologies to help safeguard clinical information.
These include:
* biometric systems, such as fingerprint scanners, iris scanners or palm vein pattern detectors;
* hardware tokens, small devices, often in the form of a key fob, that generate random passwords that then must be typed;
* proximity badges containing chips that, when placed next to a reader, automatically confirm the user's ID;
* phone-based authentication, which uses a clinician's telephone, cell phone, pager or PDA to help verify their identity; and
* adaptive authentication, which uses specialized software to assess a user's risk potential and pose a series of questions based on personal information they've provided.
In many cases, providers are pairing two-factor authentication with single sign-on systems, which enable physicians, nurses and others to access all appropriate systems once they authenticate themselves.
healthdatamanagement
Under the updated rules, state attorneys general now have the right to enforce the HIPAA privacy and security regulations. Plus, those harmed by a security breach can seek financial damages, Borten says. "I can just see the lawyers getting ready," she says. "We are going to see a real ramping up of complaints now as a result of all the changes."
Two Key Steps
Of course, the best way to comply with the privacy and security rules is to make sure only authorized individuals have access to patient information. Borten argues that all organizations should encrypt all patient data and adopt two-factor user authentication, such as a password paired with a fingerprint scanner. But she contends that many-perhaps most-organizations have yet to take either step.
And any data security effort should start with a thorough risk assessment, as required under federal law, notes Eric Nelson, privacy practice leader at the Lyndon Group, a Newport Beach, Calif.-based consulting firm.
What technologies are needed to ensure patient data is secure depends on the size of the organization, Nelson says. "A small group practice where only a few people have access to the information probably doesn't need a high-tech security solution," Nelson says. "It could be as simple as encrypting the information on the computers and installing locks on the doors. A large organization is a completely different matter."
The updated federal regulations, in fact, do not specify the security technologies providers must use. "The law says that if you don't want to have to notify the government of security breaches, then you should use new technologies to prevent breaches," Borten notes. "But I regret that the law doesn't require the use of the technologies."
As they ramp up efforts to implement clinical information systems, many hospitals, clinics and other provider organizations are investing in a variety of user authentication technologies to help safeguard clinical information.
These include:
* biometric systems, such as fingerprint scanners, iris scanners or palm vein pattern detectors;
* hardware tokens, small devices, often in the form of a key fob, that generate random passwords that then must be typed;
* proximity badges containing chips that, when placed next to a reader, automatically confirm the user's ID;
* phone-based authentication, which uses a clinician's telephone, cell phone, pager or PDA to help verify their identity; and
* adaptive authentication, which uses specialized software to assess a user's risk potential and pose a series of questions based on personal information they've provided.
In many cases, providers are pairing two-factor authentication with single sign-on systems, which enable physicians, nurses and others to access all appropriate systems once they authenticate themselves.
healthdatamanagement
Transgendered cybersecurity appointee makes history
Amanda Simpson made history yesterday in her first day on the job as the Senior Technical Advisor to the Department of Commerce Bureau of Industry and Security. Formerly test pilot Mitchell Simpson, the first openly-transgendered Presidential appointee is now responsible for the promotion of homeland, economic and cyber security. Simpson is a former Deputy Director in the Advanced Technology Development division of Raytheon.
The country of Cameroon started the New Year as home to the world's riskiest Internet sites according to cyber-security firm McAfee. VOA reports the country's government says it is drafting new laws to punish Internet fraud. McAfee says more than one-third of Web sites hosted in Cameroon are suspicious, putting the West African nation ahead of China, Samoa, the Philippines and the former Soviet Union as the world's riskiest destination for Internet surfers.
The Energy Department gears up to launch a group charged with protecting the nation's electric grid from hackers. A spokeswoman for Energy tells NextGov that soon, her department will start a competitive solicitation to identify potential participants. Goals for the independent task force will include setting policies and protocols to protect the grid. Congress mandated its creation in Energy's spending bill, and the department has until February 27th to get the group running. federalnewsradio
The country of Cameroon started the New Year as home to the world's riskiest Internet sites according to cyber-security firm McAfee. VOA reports the country's government says it is drafting new laws to punish Internet fraud. McAfee says more than one-third of Web sites hosted in Cameroon are suspicious, putting the West African nation ahead of China, Samoa, the Philippines and the former Soviet Union as the world's riskiest destination for Internet surfers.
The Energy Department gears up to launch a group charged with protecting the nation's electric grid from hackers. A spokeswoman for Energy tells NextGov that soon, her department will start a competitive solicitation to identify potential participants. Goals for the independent task force will include setting policies and protocols to protect the grid. Congress mandated its creation in Energy's spending bill, and the department has until February 27th to get the group running. federalnewsradio
Friday, January 8, 2010
Cellular group says mobile calls safe from hackers
A wireless industry group said mobile phone conversations are safe from eavesdropping, even after a German security expert released the code for unscrambling calls made using most of the world's cell phones.
Concerns spread last week that cell phone calls could easily be intercepted after encryption expert Karsten Nohl unveiled his research at Europe's largest hacking conference, in Berlin.
The London-based GSM Association said on Thursday that it has spent the past few years figuring out ways to thwart hackers who might try to tap into wireless calls using Nohl's research, which it first learned of in 2007.
GSM Association engineers have figured out a short-term solution to block eavesdroppers, said James Moran, head of security for the association. It involves making slight changes to the settings in each wireless operator's network. reuters
Concerns spread last week that cell phone calls could easily be intercepted after encryption expert Karsten Nohl unveiled his research at Europe's largest hacking conference, in Berlin.
The London-based GSM Association said on Thursday that it has spent the past few years figuring out ways to thwart hackers who might try to tap into wireless calls using Nohl's research, which it first learned of in 2007.
GSM Association engineers have figured out a short-term solution to block eavesdroppers, said James Moran, head of security for the association. It involves making slight changes to the settings in each wireless operator's network. reuters
Subscribe to:
Posts (Atom)







