This is really beginning to get to me. With the proliferation of laptops in our society, you would think that knowledge of security would begin to rapidly spread as well. However, this is the second story in less than a week of a laptop being stolen from a car. Now, if this was an office of some sort, with semi-inconsequential data it would be understandable. But it seems that more and more, Healthcare IT staff are carrying around patient data on their personal laptops. These are people who are carrying around credit card info, banking numbers, social security numbers, Names, dates of birth. And i still wouldn't have a problem with it if they would take some sort of rudimentary precautions to ensure the protection of the data. However, there have been cases of IT staff storing full system backup tapes, laptops, USB Crypto keys, and entire servers in the back of their cars. They are then completely amazed when these top-level security measures are thwarted by a crook with a crowbar. This latest incident occured after a British IT worker for the NHS trust left his laptop unsecured in his car, along with 21,000 patients details. To make things worse, none of the information was encrypted. So the thief now has complete access to any and all patient data. The NHS trust reinforced the now common perception that they were completely technologically incompetent by stating (trying to make the situation better) "the data will almost certainly by wiped by the thief"
What steps should you take in order to secure a system from theft?
A. Set a Bios Level Password
B. Set at least a 14 digit password.
C. Require some sort of Biometric Authorization for Access
D. Always keep your data in an encrypted folder
E. If practical, Hide private data inside of another file
F. Keep any backups in humidity controlled, insulated environment.
G. Rule of Thumb: If your system can be seen, its public data.
H. Thumb of Rule: If your system is in your car, it deserves to be stolen.
My New Blog
July 1, 2008
British Health Records Stolen
Posted by
Gillis57
at
5:08 PM
0
comments
Labels: backdoor, backups, Biometric, Bios, Britain, data, doctor, Gillis Jones, Hack Stole, Healthcare, hospital, IT, Laptop, Leo Laporte, NHS Trust, Password, patients, Security, Stolen, theft
June 4, 2008
University Students Scammed- Is your info secure?
A data breach at United Healthcare Services Inc. has led to a rash of identity-theft crimes at the University of California, Irvine.
So far, Nearly 155 medical students have had their information stolen. The attackers stole the social security numbers stolen from an internal database. This breach affects nearly 1300 students, putting them at risk for Credit Card fraud as well as Tax scams. So far, the spammers have stolen 155 students Tax returns.
"In February, the police began getting reports from graduate students that when they filed their income tax returns, they were being told that their returns had already been filed using their Social Security numbers," she said.
So all that the attacker needed was a simple set of numbers, and they took students for hundreds, even thousands of dollars. All because of crappy security measures.
This is why people, This is why.
Checklist To ask your school IT Department
[] What security measures do you have in place for physical IT Infrastructre?
[] What security measures are in place to ensure the confidentiality of my information
[] If there is a unapproved access of my information- How promptly will I be notified?
[] Do you have set guidelines for partners of the university to follow in virtual exchanges?
[] WHO has access to my information and WHEN/WHY can they access it?
Posted by
Gillis57
at
5:23 PM
0
comments
Labels: Computer, Credit Card, FBI, Graduate, Hacked, Hacker, Hacking, Healthcare, IRS, Medical, Police, Rebate, Security, Server, Surgery, Tax, Vulnerability