It Took a Massachusetts Hospital 14 Years To Detect a Data Breach (grahamcluley.com)
An anonymous reader shares a report: To make matters worse, even after all that time -- it wasn't the medical center itself that discovered the incident. Tewksbury Hospital learned of the breach in the spring of 2017. It hasn't found any evidence to suggest the security incident resulted in attackers misusing patients data. Even so, it believes the event compromised the security of affected individuals' personal and medical information. As the state-run institution explains in a statement: "In April of this year, a former patient expressed concern that someone may have accessed their electronic medical record inappropriately. A review conducted in response to this complaint revealed that one hospital employee appeared to have accessed the former patient's records without a good reason to do so. This discovery led to a broader review of the employee's use of the electronic medical records system at Tewksbury Hospital. As a result of this review, we were able to determine that the employee appeared to have inappropriately accessed the records of a number of current and former Tewksbury Hospital patients."
Data breaches happen, but 14 years to detect an ongoing breach is ridiculous. That's weapons grade negligence. The people who were responsible for information security should receive the death penalty for such egregious negligence.
Coming to Slashdot today, new evidence, the most compelling to date, showing that the 9/11 attacks and the controlled demolitions of three World Trade Center buildings were orchestrated and carried out by Jews under the direction of Israel. Stay tuned as the information is released this afternoon, which will call into question everything you thought you knew about the 9/11 attacks and our government's response.
Isn't there a Trump tweet to argue over, or something?
for them to detect the patient died?
Remember that. Business doesn't give a rat's ass about us or our data security.
And when it is stolen and abused, we have no recourse because we are peons. And all the damage that is caused has to be cleaned up by us, the victim.
We must have European style data and privacy protection laws and regulations in this country because it has been proven that businesses are incapable and unwilling to do anything.
And if any business doesn't like it, they can go do something else: they shouldn't be in a business that handles private information.
BTW, did you know that Bank of America's data services are all in India and other third world countries?
According to the Boston Glove, it was a female clerk at the hospital reading people's medical records for no other reason than snooping. No identity theft involved. The person that reported possible data breach to the hospital refused to state what led him to believe a breach had occurred. If I had to guess, based on my time working for the California State Compensation Insurance Fund, the lady was reading records out of curiosity and gossiping about people behind their backs. She probably told someone that ended up telling the man or either herself or someone she gossiped with accidentally let slip out some knowledge of the guy's medical issue(s). Medical records can be crazy interesting to read, so many fake insurance claims and such. Doctor's can't write worth shit though, toddlers have better penmanship.
Cars, the final solution to the millennial question.
Cause I like humping your mommy
and getting caught by your dad
if your not into poota
and you have half a nad
If you like humping butts at midnight
in the smooth anal gape
then i'm the one that you searched for
come to me and assrape
-Helen Gurley Brown
*Boston Globe* Lack of post-comment submission editing at Slashdot strikes again.
Data is useless if it is inaccessible. Eventually, one of your authorized users will break an access rule, and on occasion they will do so in a way that gets them caught.
Other massive data breaches have happened yet there's never been a public announcement. I'm talking on the scale of Yahoo's data breach.
This sounds like a curious nurse who forgot a couple of details about HIPPA. Nothing to see here, move along..
It sounds like this was an insider who was just accessing someone's records for fun or to find something out about someone. I'm not surprised it took them 14 years to detect it either -- Tewksbury Hospital is a psychiatric hospital. Every state, even ones like Massachusetts, has been running away screaming from the obligation to provide mental health services ever since Thorazine was invented. They probably have even less budget than a typical hospital's IT department. Where I live in New York, inpatient mental health care barely exists; you need to be truly dangerous to end up in a psychiatric hospital -- even too dangerous for prison or jail.
I'm not in healthcare IT so I don't know...are electronic health record systems designed to not allow random snooping through people's information? You would think, with HIPPA and everything, that record access would be limited to people who have reason to look at it, and of course the system admins. In my experience in other fields though, no one goes looking through system access logs until someone has reason to suspect something, so usually it takes someone reporting something like what happened here.
I guess patient record security would have limited this, but I'm sure there are still ways around it. Back in my client support days, I did a lot of work with HR -- talk about the world's worst gossip clique! HR people love snooping through peoples' files, basically just for the lulz.
... I was dating a medical resident, and met her in the hospital.
She showed me how easy it was for any staff to look up patient info in the hospital's system - she showed me my records.
I doubt the hospital ever did anything about it...
While I have never directly worked in hospital IT, I know plenty of folks who have. I did work for a PACS/RIS/HIS vendor, and I spent about 6 years working beside them. Not only do hospital IT teams chronically get underfunded and understaffed, they have to deal with vendors who give absolutely asinine support requirements ("no, our software only runs on windows NT!" or "Sorry, HP only allows you to use windows server for storage appliances for this device, why no, microsoft has never released a service pack for it, why do you ask?"). Worse, a lot of their extremely expensive equipment has embedded OS's that will likely never see an update because the vendors simply don't supply them, or because risking a bad update can quite literally cost lives. It's a really, really tough IT segment. People like to derp at them "well why don't you just update things!" without realizing that in many cases they simply can't because of the vendors who release the hardware not providing adequate support. Preventative measures would be their best bet, but boards of trustees rarely see it as worthwhile to give those IT departments funding to implement those preventative measures well. It's a shit sandwich.
mumps software is old and may not have much security. Or security just get's in the way of it being linked to other systems.
Usenet is roughly Suuport GNAA, Roots and gets on community. The
They are still on Windows 95.
Now we know why the "average time to detection" is 271 days or some such nonsense.
This posting is provided 'AS IS' without warranty of any kind, implied or otherwise.
was apparently an individual clerk abusing his authorization to poke around in patient files. The "14" years timing is interesting; HIPAA's privacy rules took effect in 2003, in other words 14 years ago.
So while by modern standards this event is a breach, it's not the kind of technical breach people seem to think it was. What's more at the time it may not even have resulted from violations of then-current standard practices. Back in the day it was common to simply trust people who needed access to records to use that access responsibly.
Post may contain irony: discontinue use if experiencing mood swings, nausea or elevated blood pressure.
Well, that is still much shorter that it takes Massachusetts to build a simple Bridge.
no glove, no love.