Showing posts with label Washington. Show all posts
Showing posts with label Washington. Show all posts

June 22, 2008

Millions of Health Records stolen. Again.

And here I am, Sitting at my desk in the middle of a storm, watching twitlive, browsing the internation. What do I come across? Another, Another, Another, Another, Theft of CONFIDENTIAL information. Did the criminal slide in under the cover of darkness, bypass laser security, and swiftly crack into a safe containing a base of backups? Nope, the ever intelligent Network Admin decided to keep the backups in, the back-of his car. Do you want more info on the massacre of confidential information? If you must, read on:

The University of Utah Hospitals & Clinics is currently notifying 2.2 million patients about the theft of medical billing records. On June 2, a box of backup tapes containing patient and guarantors billing records was stolen out of a car belonging to a contracted independent storage company. The tapes contained the personal information on 2.2 million patients and guarantors including patient names, related demographic information and diagnostic codes. In addition, these records contained the Social Security numbers of 1.3 million patients. The Salt Lake County Sheriff’s Department, the FBI and the U.S. Postal Service are investigating the theft. According to Lorris Betz, M.D., Ph.D, Senior Vice President for Health Sciences, University of Utah Hospitals & Clinics is taking aggressive steps to protect patient confidentiality including notifying all 2.2 million individual through postal mail, offering one year of free credit monitoring to those whose SSNs were on the tapes and offering a $1,000 reward for the return of the tapes, no questions asked. The University of Utah Hospitals & Clinics has also setup a hotline - 866-581-3599 - and a web site - healthcare.utah.edu/billingrecordstheft - to help answer any questions and provide more information about the theft.

May 19, 2008

Dear God

Recently, I was browsing government websites to see if there were any new articles to read. However when I came to www.NSA.gov (National Security Agency), their website was offline. Baffled by this National Security Issue,  seeing as how the NSA is supposed to be the pinnacle of Intelligence and Technology, I decided to do some digging.

So who was the "Super hacker" that executed such a technologically advanced, planning intensive attack upon the US government? Well, as it turns out the super hacker was a incompetent mole. No, not a double agent. Someone who was hired,  because there was extra room in the Budget.  DNS misconfiguration in my NSA? Its more likely than you think.

              First, a web server was running on the same computer or the same IP address as one of the so-called authoritative name servers for nsa.gov. The authoritative name servers are the primary and secondary servers that translate the web addresses humans understand (i.e., NSA.gov) to machine-readable IP addresses (in the NSA.gov case, 189.182.93.126).

             Moreover, the primary and secondary authoritative name servers were both downstream from the Qwest edge access router in Washington, D.C. They should have been separated topologically within the network infrastructure, according to McPherson.

Come On Guys, thats basic network design. If the Top Security Agency can't design a network properly- what does that say about our national network infrastructure.