Monday, 10 November 2014

Device loss, not hacking, poses greatest risk to health care data

healthcare cio

California DOJ report on data breaches shows most losses in health care revolve around stolen devices, due to weak use of encryption

If you're dealing with the security of a health care provider, hacking isn't your biggest worry, but rather the loss of devices storing your data. Lack of encryption on devices plus the value of stolen health care data combine to make for tempting targets.
The October 2014 California Data Breach Report, compiled by the California Department of Justice, analyzed data breaches across multiple industry sectors in California for the year 2013. Of all the industries profiled, two stood out with the greatest share of losses for a given type of breach. One was retail, where 88 percent of the losses came by way of malware or hacking, as opposed to physical thefts, misuse, or human error. (The largest share of losses in government, by the way, were human error -- 48 percent of the sector's total.)
But with health care, more than two-thirds of the losses -- 70 percent -- were attributable to physical theft, which the report defines as "lost or stolen hardware or portable media containing unencrypted data."
Bitglass, a security vendor that provides data-sanitization solutions, crunched Health and Human Services data to come up with similar figures. In health care, the company found, only 23 percent of data breaches since 2010 were hack-related; the rest were through "loss or theft of employee mobile devices with information on them."
Other sectors showed different breakdowns in the California report. The hospitality industry, for instance, was the second-largest vertical where malware/hacking was a source of breaches (58 percent of all incidents reported), and human error was attributed to almost half of the breaches in government and a third of the breaches in education.

California 2013 data breaches by industry  California Department of Justice
Data breaches in California for 2013, by industry and breach type. Health care's large number of physical breaches has been attributed to the theft or loss of devices that are mainly unencrypted.
But health care came in as the biggest source of physical breaches -- 40 percent -- among all industry types surveyed, with the vast majority coming from stolen hardware, both desktops and notebooks alike, and missing media, such a disks or USB drives. (Mobile devices were not implicated.)
The larger question is why health care providers are such vigorous targets for physical theft. Bitglass CEO Nat Kausik believes the answer lies in how effectively the stolen data can be monetized.
According to other research seen by Kausik, most stolen credit card numbers -- the type of data typically filched in a retail hack -- are worth only "50 cents or a dollar each" on the black market, in big part because credit card numbers can be invalidated and charges made on them can be reversed.
"But health care records are worth something like $50 each," he said in a phone interview, "because you actually get the person's identity. You can't really change a Social Security number, and that has lasting value to the thief."
To that end, as the California report noted, about 50 percent the time during any breach, the theft of a Social Security number was involved, with payment card thefts taking place in about 40 percent of the breaches.
Another complicating factor is the inconsistent mitigation of the loss or theft of Social Security numbers. The California report found that "in 29 percent of breaches of Social Security or driver's license numbers, where a mitigation service such as credit monitoring or a security freeze would have been helpful, the breached entity failed to offer such a service."
In a list of 12 recommendations to all industries, the California report said health care providers in particular "consistently use strong encryption to protect medical information on laptops and on other portable devices and should consider it for desktop computers."
Drive makers have stumped for full-disk encryption being less expensive and difficult to implement, with the costs being negligible and the encryption itself typically invisible to the end user. In an earlier 2013 California breach report (which covered data breaches in 2012), California Attorney General Kamala Harris warned that she "will make it an enforcement priority to investigate breaches involving unencrypted personal information," putting pressure on businesses -- regardless of their sector or vertical -- to encrypt or else.

Source: http://www.infoworld.com

Tech believes children are the future

baby on headset at laptop

Teach them well and let them lead the way, then throw them six-figure startup sums. Meet the baby Einsteins who make Zuckerberg look old

What were you doing when you were 13? I was busy discovering that girls weren’t disgusting after all, which led to a new appreciation for a locked bathroom door. Then there was the Dungeons & Dragons monkey that would ride my back for the next decade, an addiction fed by all the paperbacks in the fantasy and science-fiction section, as well as 10+ visits to the cineplex devoted solely to memorizing "Star Wars" and giving my Dad migraines.  

In other words, I belly-flopped into the deep end of Nerd World and pre-college celibacy. What wasn’t I doing? Raising funds for my first commercial venture, for starters.

Unlike Shubham Banerjee, the teenager who took in an undisclosed six-figure infusion from Intel’s VC arm to back the startup he founded using $35,000 from his mom and a big box of Lego. Worst of all, I can't even ding Intel for yet another blindingly stupid Silicon Valley-style money bath.

 

The youth brigade


Banerjee’s venture consists of a low-cost Braille printer, not a useless viral phone pollution that sends “yo” messages back and forth. He expects to eventually sell the prototype he built out of -- no kidding -- a Lego variant for about $350. That’s a double-scoop of cost-effectiveness when compared to most current Braille printers, which can run as high as $4,000. Intel surprised the kid with its support because he was working to incorporate the company's Edison chip into his invention.

It makes you wonder why Microsoft isn’t showering Pakistani Briton Ayan Qureshi with money now that he’s become the youngest Microsoft Certified professional ever, with another month to go before his sixth birthday. It also makes you wonder why Microsoft Learning hasn’t published a line of pop-up books entitled "How to Pass Our Oh-So-Challenging Exams if You’re Too Young to Read."

If I were still living with Pammy, I could expect another skillet-shaped dent in my forehead and a “Slacker” tattoo on my left buttock (once I regained consciousness) in response to this news. Then again, Silicon Valley and the tech industry in general have always bowed to the mythical genius of youth, due in part to tyke-turned-tycoons like the Zuck, who was once quoted as saying, “Young people are just smarter.” I'm sure a legion of AARP members would have a word or two for him, if only we could remember where we put our reading glasses.

Although I’m pretty sure 12 has to be a new funding record, it’s not surprising with financial freaks like Zuck setting the MegaPowerballLotto VC success standard. Based on that trend, my wrinkled behind is locked out of any self-respecting VC’s office permanently. On the other hand, this VC pederasty has also resulted in big chunks of our economy going down the flusher, thanks to disasters like Crinkle, Blippy, BricaBox, and LivingSocial, as well as demon-worshipping arrogance factories like Sean Rad or Jonathan Mills.

At least the aging techie demographic won't be alone in being usurped by a never-ending line of tweeners. President Obama should be sweating, too, now that Saira Blair entered the political game this past Tuesday at the tender age of 18 as a fiscally conservative Republican with an NRA endorsement and gleeful support from the antiabortion set. She’s in the West Virginia state senate for now, but once the Zuck backs her as part of his Old People Suck initiative, she’ll surely be going for the White House in 2034. Elise Stefanik and Tom Cotton also made political news as the youngest knife fighters ever elected to Congress and the Senate, respectively, but they’re both over 30, so they probably didn’t make Zuckie’s radar.

 

Help the aged


I could cite other examples of ageism in sports, entertainment, fashion, and weed farming, but I’m only redundant on the weekends. The trend gives new meaning to Amber Alert, and it’s very clear: Kids are worshipped no matter how great or ridiculous their startups might be, while old farts like me will soon be placed into barrels of amniotic fluid and launched into space to make room for an even younger generation of VC dazzlers.

I’d protest, but I’m too tired and I might miss the senior's dinner discount at Applebee's. Go ahead and launch me into space. I’m OK with it as long as Pammy’s skillet stays on earth and someone promises to beam me a YouTube video of Zuckerberg’s expression the day Facebook gets flattened by a middle-schooler’s social networking epiphany. 

Source: http://www.infoworld.com