Health exchange privacy concerns overblown, experts say

With convenience comes risk — and too much of it when it comes to patient privacy in health care, says Danny Lieberman, CTO of Software Associates, a software security consultancy in Israel, and a founder of Pathcare, a private social network for physicians and patients.
The risk factor, he said, is Health Information Exchanges (HIEs), required under the Patient Protection and Affordable Care Act, which are designed to enable the sharing of electronic health records by physicians and other health care providers.
The goals of such a system are efficiency and accuracy of data. But Lieberman contended in a post last week on both Pathcare and Infosec Island, where he is a long-time contributor, that “a U.S. national HIE network will be the death of patient privacy.”
Such a network will be highly vulnerable to malicious attacks, he said, largely for two reasons: “[A] huge, unmitigated threat surface of transactions that are transported inside health care organizations and between healthcare business units using message queuing technology,” and the fact that Microsoft is “a near-monopoly controlling the overwhelming majority of systems.”
“Since everyone is using the same technologies and the same HIPAA (Health Insurance Portability and Accountability Act) compliance checklist — life is sweet for attackers — who know exactly what vulnerabilities everyone has,” Lieberman quotes a friend saying.
[See also: 6 ways we gave up our privacy]
Lieberman told CSO Online that the goals of the law are fine, but that its execution is the problem. “The Obama administration has given states until 2014 to implement HIE systems,” he said. “Otherwise, the federal government will implement a national HIE.”
“So what is worse — a bunch of state systems strung loosely together with bailing wire or a federally-run system? Neither alternative is attractive from a data security perspective,” he said.
But Lieberman’s fellow information security experts do not all share his sense of impending doom. Some of them say he is overreacting, and is basing his argument on conditions that existed about a decade ago, but which have improved since then.
Lieberman’s major focus is the technology of exchanges, which he said is being modeled on the retail industry supply chain. “A highly connected stem of networked message queues is a convenient and vulnerable entry point from which to launch attacks; these attacks can and do cascade. If these attacks cascade, the entire healthcare system will crash.”
Jody Westby, CEO of Global Cyber Risk, said Lieberman’s asess was too much “gloom and doom,” although she, like others, acknowledges there is no such thing as 100% security.

Visit link: Health exchange privacy concerns overblown, experts say

have a look at this

Author: Jagdeep

Share This Post On
468 ad