Showing posts with label computer security. Show all posts
Showing posts with label computer security. Show all posts

Friday, November 9, 2012

Why It's Crazy to Want Your Most Confidential Information Put into An Electronic Medical Records System

Besides the reasons I outlined in posts retrievable by these query links (link, link), there's this from ZDNet.com:

Microsoft warns of first critical Windows 8, RT security flaws

It's been less than a month since Windows 8 and Windows RT-powered Surface tablets were launched and went on sale, but Microsoft is already warning that the two next-generation operating systems contain critical security vulnerabilities that are due to be patched this coming Tuesday.

Among the various flaws, versions from Windows XP (Service Pack 3) all the way through to Windows 8 are affected, including versions of the Office suite, and versions of Windows Server. Released only in September, Windows Server 2012 requires patching to maintain maximum security.

The latest vulnerabilities include three critical security vulnerabilities for Windows 8, and one critical security vulnerability for the Surface-based Windows RT operating system. These flaws are considered "critical" and could allow remote code execution on vulnerable systems.

I note that Windows XP was released worldwide for retail sale on October 25, 2001, which was more than eleven years ago.  That security vulnerabilities are still being patched in 2012 is stunning.  Also, many enterprise information systems and most hospital clients (workstations) run on Windows-based servers and Windows installed local machines (UNIX, MacOS and other OS's are very rare on general-purpose hospital workstations).

From a Microsoft website here:


This partial list includes many very large HIT sellers.  There are many others as well.

By simple reckoning, it's likely we'll be seeing critical security vulnerabilities in Windows 8 - in 2023.

It goes without saying that these security problems will continue to be exploited by identity thieves, medical information merchants, and others with no rights to "protected" information.

In my opinion, the (still not yet realized) convenience of being able to have one doctor transmit your record to another, thus avoiding a FAX machine, the Postal Service or the telephone, and the trillion-dollar "solution" to the nearly non-existent problem of being found unconscious in some foreign land with no ID, no companions, and some hidden, critical medical condition not findable on physical exam and bloodwork, EKG, x-rays etc. that will cause death if not treated in minutes, is not worth the risk of having one's most private information spilled all over the Internet.

EHR's should not be accessible on networks beyond a physician's office or the robustly encrypted network of a hospital, and the information security personnel kept on very short leashes, for the foreseeable future.

I am unwilling to cede my own privacy to cybernetic utopians who ignore alarming evidence - plain to see at the aforementioned query links at the top of this post - nor can I in good faith recommend doing so to the public in 2012.

Considering the information in the many posts at the aforementioned query links (as here: link, link -- be aware you need to hit "older posts" at the bottom of each page to see all of them), that position is straightforward.

-- SS

11/9/2012 Addendum:

Also see my Oct. 2012 post "Computer Viruses Are 'Rampant' on Medical Devices in Hospitals."

-- SS

Wednesday, October 17, 2012

Computer Viruses Are "Rampant" on Medical Devices in Hospitals

As if there weren't enough problems with hospitals as computing backwaters, now there's this:

Computer Viruses Are "Rampant" on Medical Devices in Hospitals

A meeting of government officials reveals that medical equipment is becoming riddled with malware.

Technology Review
Published by MIT
David Talbot
Wednesday, October 17, 2012

Computerized hospital equipment is increasingly vulnerable to malware infections, according to participants in a recent government panel. These infections can clog patient-monitoring equipment and other software systems, at times rendering the devices temporarily inoperable.

While no injuries have been reported, the malware problem at hospitals is clearly rising nationwide, says Kevin Fu, a leading expert on medical-device security and a computer scientist at the University of Michigan and the University of Massachusetts, Amherst, who took part in the panel discussion.

I note the seemingly universal refrain "no injuries have been reported" once more (see this query link to similar statements regarding IT malfunctions), which is irrelevant since reporting mechanisms for medical errors are noted to be deficient.

Software-controlled medical equipment has become increasingly interconnected in recent years, and many systems run on variants of Windows, a common target for hackers elsewhere. The devices are usually connected to an internal network that is itself connected to the Internet, and they are also vulnerable to infections from laptops or other device brought into hospitals.  [I note that it should be impermissible to connect "alien" machines to a hospital's network without authorization, and that attaining that level of security protection is not difficult - ed.]  The problem is exacerbated by the fact that manufacturers often will not allow their equipment to be modified, even to add security features.

In a typical example, at Beth Israel Deaconess Medical Center in Boston, 664 pieces of medical equipment are running on older Windows operating systems that manufactures will not modify or allow the hospital to change—even to add antivirus software—because of disagreements over whether modifications could run afoul of U.S. Food and Drug Administration regulatory reviews, Fu says.

In other words, let's run at high risk if it avoids the time and expense of FDA reviews that would ensure the equipment is safe and operates as expected with the software updates.

As a result, these computers are frequently infected with malware, and one or two have to be taken offline each week for cleaning, says Mark Olson, chief information security officer at Beth Israel.

It is unclear how the servers running the hospital information system, electronic health records systems, physician order entry systems etc. are immune to spread of the malware.

"I find this mind-boggling," Fu says. "Conventional malware is rampant in hospitals because of medical devices using unpatched operating systems. There's little recourse for hospitals when a manufacturer refuses to allow OS updates or security patches."

The worries over possible consequences for patients were described last Thursday at a meeting of a medical-device panel at the National Institute of Standards and Technology Information Security and Privacy Advisory Board, of which Fu is a member, in Washington, D.C. At the meeting, Olson described how malware at one point slowed down fetal monitors used on women with high-risk pregnancies being treated in intensive-care wards.

In its face, that is potentially catastrophic depending on the degree of "slowdown" and whether data is lost.

"It's not unusual for those devices, for reasons we don't fully understand, to become compromised to the point where they can't record and track the data," Olson said during the meeting, referring to high-risk pregnancy monitors. "Fortunately, we have a fallback model because they are high-risk [patients]. They are in an IC unit—there's someone physically there to watch. But if they are stepping away to another patient, there is a window of time for things to go in the wrong direction."

The reasons seem obvious to anyone who's had a serious malware infection on their PC.  I've only had one - a computer I bought at a fleamarket for $7 was so severely infected it was unusable for even basic tasks, and was resistant to virus removal.  I solved that problem by installing a fresh copy of the OS, immediately followed by all patches and the latest anti-malware software.

The computer systems at fault in the monitors were replaced several months ago by the manufacturer, Philips; the new systems, based on Windows XP, have better protections and the problem has been solved, Olson said in a subsequent interview.

This implies the older systems were running on Win 98 or earlier or an old version of Win NT.  Amazing.

At the meeting, Olson also said similar problems threatened a wide variety of devices, ranging from compounders, which prepare intravenous drugs and intravenous nutrition, to picture-archiving systems associated with diagnostic equipment, including massive $500,000 magnetic resonance imaging devices.

Olson told the panel that infections have stricken many kinds of equipment, raising fears that someday a patient could be harmed. "We also worry about situations where blood gas analyzers, compounders, radiology equipment, nuclear-medical delivery systems, could become compromised to where they can't be used, or they become compromised to the point where their values are adjusted without the software knowing," he said. He explained that when a machine becomes clogged with malware, it could in theory "miss a couple of readings off of a sensor [and] erroneously report a value, which now can cause harm."

I opine that harm could already have occurred; it just may not been recognized as such nor reported.  Disappearing data and other EHR failure modes known to have caused harm and/or deaths could be related to malware, for example.

... Malware problems on hospital devices are rarely reported to state or federal regulators, both Olson and Fu said. This is partly because hospitals believe they have little recourse. Despite FDA guidance issued in 2009 to hospitals and manufacturers—encouraging them to work together and stressing that eliminating security risks does not always require regulatory review—many manufacturers interpret the fine print in other ways and don't offer updates, Fu says. And such reporting is not required unless a patient is harmed. "Maybe that's a failing on our part, that we aren't trying to raise the visibility of the threat," Olson said. "But I think we all feel the threat gets higher and higher."

I note that health IT related problems are also rarely reported, with only one vendor being the exception (see my post on the FDA MAUDE voluntary reporting database here).  The reasons likely are not because "hospitals believe they have little recourse" - the real reasons may be fear, complacency and/or incompetence.

Speaking at the meeting, Brian Fitzgerald, an FDA deputy director, said that in visiting hospitals around the nation, he has found Beth Israel's problems to be widely shared. "This is a very common profile," he said. The FDA is now reviewing its regulatory stance on software, Fitzgerald told the panel. "This will have to be a gradual process, because it involves changing the culture, changing the technology, bringing in new staff, and making a systematic approach to this," he said.

Changing the culture would be nice, considering we are now entering a national rollout of complex enterprise clinical resource and workflow control systems anachronistically known as "electronic medical records."

In an interview Monday, Tam Woodrum, a software executive at the device maker GE Healthcare, said manufacturers are in a tough spot, and the problems are amplified as hospitals expect more and more interconnectedness. He added that despite the FDA's 2009 guidance, regulations make system changes difficult to accomplish: "In order to go back and update the OS, with updated software to run on the next version, it's an onerous regulatory process."

My comment is, if you can't take the heat of work in the real-world medical setting, if you cannot be part of the medical team, then get out of the clinic.  You're likely to do more harm than good.

John Halamka, Beth Israel's CIO and a Harvard Medical School professor, said he began asking manufacturers for help in isolating their devices from the networks after trouble arose in 2009: the Conficker worm caused problems with a Philips obstetrical care workstation, a GE radiology workstation, and nuclear medical applications that "could not be patched due to [regulatory] restrictions." He said, "No one was harmed, but we had to shut down the systems, clean them, and then isolate them from the Internet/local network."

He added: "Many CTOs [chief technology officers - ed.] are not aware of how to protect their own products with restrictive firewalls. All said they are working to improve security but have not yet produced the necessary enhancements."

Then why are they CTO's?  Is this the phenomenon of generic or underqualified managers rearing its head?


Fu says that medical devices need to stop using insecure, unsupported operating systems. "More hospitals and manufacturers need to speak up about the importance of medical-device security," he said after the meeting. "Executives at a few leading manufacturers are beginning to commit engineering resources to get security right, but there are thousands of software-based medical devices out there."

One can only wonder if others have done a Ford Pinto cost-benefit analysis and decided the costs of settlement from injured and dead patients is less than the cost of remediation.

-- SS

Saturday, July 7, 2012

Manipulation of 12,000 Medical Records Made Easy by EHR

This from a hospital in Canberra, Australia using a common ED EHR in that part of the world, iSOFT:

Canberra Hospital embroiled in data scandal
SBI Magazine (Secure Business Intelligence)
Jul 5, 2012 

A Canberra Hospital executive has admitted to manipulating Emergency Department records to make wait times and stays appear shorter than they were.

The executive told the Director-General of the Health Directorate they had made "approximately 20 to 30 changes to hospital records" a day from "late 2010" onwards.

ABC [Australian Broadcasting Corp.] News reported that the matter has been referred to police, while the executive has been suspended without pay.

Though the data manipulation was initially said to be motivated by concerns over job security, changes in 2011 and early 2012 were said to have been made due to "managerial pressure" to improve publicly-reported performance statistics.

This raises the issue that data manipulation might have been performed not just to improve reported statistics, but to cover up medical error, computer related or not, and thus deny injured patients or their heirs the right to legal redress.

"The only thing that worked to achieve benchmark targets was to alter the data," the executive later told investigators at PricewaterhouseCoopers (PwC), which was engaged by Health to perform a forensics analysis. The analysis is detailed in a new Auditor-General report (pdf).

In total, PwC found 11,700 performance records - about six percent of all records stored in the hospital's iSOFT emergency department information solution (EDIS) - had been altered.

It is believed more staff at Canberra Hospital altered records than the executive that has so far admitted responsibility.  "While an executive has admitted to changing EDIS records, it is probable that EDIS records have also been manipulated by other persons with access to the system," the federal auditor-general noted overnight.

This is another area where electronic records make possible tasks that are probably impossible with paper.  Altering 11,000+ records would be hard in paper charts, as the alterations would likely stick out in a pronounced manner.

"The executive’s admission to Audit does not appear to account for all of the changes to EDIS records that have been made to improve timeliness performance."

For example, changes to EDIS records, albeit a much smaller number, appear to have been made on days when the executive was on leave (seven days in total in 2010-11 and early 2011-12). 

I am saddened to note, a proper term for this activity might indeed be "conspiracy":  a conspiracy is an agreement between two or more persons to break the law at some time in the future.

User access control, IT security failures

Poor controls such as generic logins and inadequate user and password security made it easy for insiders to game the data.

While EDIS was on approximately 259 workstations across the hospital and 253 users had permission to run the software, there were only 23 user accounts.

Of these user accounts, only eight were in regular use, including four named administrator accounts (specific to administrative staff) and four generic user accounts: CLERK, NURSE, DOCTOR and BEDMAN.

The generic accounts could be used by personnel across the hospital, not just within the Emergency Department.

Passwords for the four generic user accounts were "very poor" and had "never been changed". Password expiry was set at a default 999 days.

Audit logs were equally poor, not proactively checked and unreliable.

The proper term for these arrangements might be "gross mismanagement" of clinical information technology.

"A feature of the logging record is that it logs the changed field in EDIS and a number of other fields simultaneously, while not identifying which field was changed and what its original value was," auditors noted.

"Audit also notes that the logging record is also ineffective, because every entry in EDIS is logged from “Workstation 14”.  

"Although EDIS has been disseminated widely throughout the Canberra Hospital each of these users logs into EDIS using the common “Workstation 14”.

"This practice, combined with the use of generic user accounts, makes the EDIS logging information useless for investigations of unauthorised activity."

Furthermore, it was possible to edit EDIS records up to 72 hours after a patient’s treatment, providing a generous window for later unauthorised changes to the records.

These "features" sound like seller misdesign with regard to the metadata (logging records).

Noticing anomalies

It was only in April this year that a full inquiry was commissioned after "anomalies" in performance figures were spotted by the Australian Institute of Health and Welfare (AIHW).

The AIHW found an unusually high number of emergency patients that were reported to have been seen at exactly within the required time for their illness category.

For example, there was an unusually high number of patients who were reported to have been seen at exactly 30 minutes or 60 minutes.

In addition, an unusually high number of people checked out of the Emergency Department precisely 240 minutes after their recorded arrival.

If you're going to engage in this type of activity, at least be competent at it...instead of setting up a red flag bigger than the flag that used to fly over the Kremlin.

The records that were manipulated mean that publicly reported information relating to the timeliness of access to the Emergency Department and overall length of stay in the Emergency Department have been inaccurately reported.

The report could not ascertain the level of over‐estimation due to the lack of a clear audit trail identifying what were legitimate and what were fabricated entries in patients’ records.  

Timelines can be critical to proving medical negligence in court.  Further, if time data could have been manipulated, it seems clinical data could have been manipulated as well.

EHR data manipulation is of unknown magnitude worldwide, but I can imagine if it's easy to do and the benefits potentially substantial, electronic records could possibly be less trustworthy than paper records.

-- SS

Addendum:  while on the topic of clinical IT Down Under, there's also this:

Coast medical records system 'dangerous'
Stephanie Bedo
Goldcoast.com.au


Doctors have complained about the system, saying some patient documents are missing, it has log-in problems and 10-minute delays in accessing critical information.

Gold Coast Health was the first region in the state to move to electronic record-keeping, rolled out progressively from October last year.

Queensland Health spent about $200 million on the electronic medical record roll-out last year, which was delayed by 12 months because of problems with the software provider.

... Hospital cardiologist Dr Greg Aroney raised concerns about the system at a Griffith University forum on the future of health on the Gold Coast this week.

"Our system is totally inadequate and dangerous," Dr Aroney said.


Read the whole story at this link:   http://www.goldcoast.com.au/article/2012/07/06/429621_gold-coast-news.html

A similar story from the states where the doctors' complaints were actually ignored is at my Sept. 2011 post "Blake Medical Center (Bradenton, Fla.) Ignores Health IT Warning Letter From 100 Staff Physicians." 

Let's hope the Australian physicians' complaints are taken more seriously.

-- SS

Wednesday, June 27, 2012

Banking as the Standard Healthcare Should Look Up To On Medical Information Security?

At past posts "Don't Worry, Your Electronic Medical Records Are Getting Safer With Every Passing Day", "Another Episode of "But Don't Worry, Your Records are Safe..." and "Still More Electronic Medical Data Chaos, Pandemonium, Bedlam, Tumult and Maelstrom: But Don't Worry, Your Data is Secure", "Don't Worry, Your Records are Safe - Part IV" and others, I wrote on the issue of medical record security.

Banking has been held as the standard as to which medicine has been compared, with medicine being called archaic and behind the times for its reliance on paper.  Banking security is cited as a reason why electronic medical records can also be secured.

There's this:

Fraud Ring In Hacking Attack On 60 Banks 

June 27, 2012

Some 60m euro is stolen from bank accounts in a massive cyber raid, after fraudsters raid dozens of banks around the world.

By Pete Norman, Sky News Online


Sixty million euro has been stolen from bank accounts in a massive cyber bank raid after fraudsters raided dozens of financial institutions around the world.

According to a joint report by software security firm McAfee and Guardian Analytics, more than 60 firms have suffered from what it has called an "insider level of understanding".

"The fraudsters' objective in these attacks is to siphon large amounts from high balance accounts, hence the name chosen for this research - Operation High Roller," the report said.

"If all of the attempted fraud campaigns were as successful as the Netherlands example we describe in this report, the total attempted fraud could be as high as 2bn euro (£1.6bn)."

The automated malicious software programme was discovered to use servers to process thousands of attempted thefts from both commercial firms and private individuals.

The stolen money was then sent to so-called mule accounts in caches of a few hundreds and 100,000 euro (£80,000) at a time.

Credit unions, large multinational banks and regional banks have all been attacked.

Sky News defence and security editor Sam Kiley said: "It does include British financial institutions and has jumped over to North America and South America.

"What they have done differently from routine attacks is that they have got into the bank servers and constructed software that is automated.

"It can get around some of the mechanisms that alert the banking system to abnormal activity."

The details of the global fraud come just a day after the MI5 boss warned of the new cyber security threat to UK business.

McAfee researchers have been able to track the global fraud, which still continues, across countries and continents.

"They have identified 60 different servers, many of them in Russia, and they have identified one alone that has been used to steal 60m euro," Kiley said.

"There are dozens of servers still grinding away at this fraud – in effect stealing money."

That's all very reassuring.   Let's put all of our personal medical secrets online ASAP.  Don't worry, your information's safe and secure.

-- SS


Friday, March 30, 2012

Don't Worry, Your Electronic Medical Records Are Getting Safer With Every Passing Day

At my Oct. 2011 post "Still More Electronic Medical Data Chaos, Pandemonium, Bedlam, Tumult and Maelstrom: But Don't Worry, Your Data is Secure" and others in this query link on medical record privacy, http://hcrenewal.blogspot.com/search/label/medical%20record%20privacy I wrote:

"Don't worry, your medical data's safe."

In Jan 2012 I then posted about Joseph Conn of ModernHealthcare.com's article "2011 Closes on a Note of Electronic Medical Record Privacy Breach Shame."

Don't worry, though; the IT industry's leader, finance, to which medicine is always compared, has gotten closer to getting the situation under control:

From MSNBC:

MasterCard, Visa confirm credit card data theft described as 'massive'
March 30, 2012
By Bob Sullivan

Law enforcement officials are investigating what appears to be a massive theft of U.S. consumers' credit card data, MasterCard and Visa confirmed Friday. The computer security expert who first reported the theft said it might involve as many as 10 million MasterCard and Visa accounts, making it one of the largest known credit card heists.

"MasterCard is currently investigating a potential account data compromise event of a U.S.-based entity and, as a result, we have alerted payment card issuers regarding certain MasterCard accounts that are potentially at risk," that association said in a statement. "Law enforcement has been notified of this matter and the incident is currently the subject of an ongoing forensic review by an independent data security organization."

The theft was first reported by well-known computer security journalist Brian Krebs on his blog, KrebsonSecurity.com. Krebs said the crime involves compromise of a credit card payment processor — a "middle man" that handles transactions between retailers and banks [like these middlemen in medicine? - ed.]

The name of that institution is unknown, but processors have long been a target of identity thieves because of the enormous amounts of data they control. In 2008, Princeton, N.J.,-based Heartland Systems was hacked, exposing tens of millions of credit card account numbers to theft.

Krebs reported that hackers had access to the unknown processors data from Jan 21 through Feb 25, and were able to siphon off enough data to easily create counterfeit cards. His sources called the leak "massive."

...
Gartner security expert Avivah Litan said she's been told that the stolen data is already being used on the street by identity thieves.

"I’ve spoken with folks in the card business who are seeing signs of this breach mushroom. Looks like the hackers have started using the stolen card data more recently," she said.


Read the whole article at the link.

Don't let this trouble you, however. The problem is getting closer to a solution with each mega-break in.

They'll have it fixed any day now, so have no fear telling your EHR-equipped doctor all your private and most sensitive medical business.

-- SS

Sunday, February 26, 2012

Proposed new Consumer Privacy Bill of Rights: Is It Too Late For Healthcare?

From the White House:
http://www.whitehouse.gov/the-press-office/2012/02/23/fact-sheet-plan-protect-privacy-internet-age-adopting-consumer-privacy-b

The White House
Office of the Press Secretary
For Immediate Release
February 23, 2012

Plan to Protect Privacy in the Internet Age by Adopting a Consumer Privacy Bill of Rights

CONSUMER PRIVACY BILL OF RIGHTS

The Consumer Privacy Bill of Rights applies to personal data, which means any data, including aggregations of data, that is linkable to a specific individual. Personal data may include data that is linked to a specific computer or other device. The Administration supports Federal legislation that adopts the principles of the Consumer Privacy Bill of Rights. Even without legislation, the Administration will convene multi-stakeholder processes that use these rights as a template for codes of conduct that are enforceable by the Federal Trade Commission. These elements—the Consumer Privacy Bill of Rights, codes of conduct, and strong enforcement—will increase interoperability between the U.S. consumer data privacy framework and those of our international partners.

  1. INDIVIDUAL CONTROL: Consumers have a right to exercise control over what personal data companies collect from them and how they use it. Companies should provide consumers appropriate control over the personal data that consumers share with others and over how companies collect, use, or disclose personal data. Companies should enable these choices by providing consumers with easily used and accessible mechanisms that reflect the scale, scope, and sensitivity of the personal data that they collect, use, or disclose, as well as the sensitivity of the uses they make of personal data. Companies should offer consumers clear and simple choices, presented at times and in ways that enable consumers to make meaningful decisions about personal data collection, use, and disclosure. Companies should offer consumers means to withdraw or limit consent that are as accessible and easily used as the methods for granting consent in the first place.
  2. TRANSPARENCY: Consumers have a right to easily understandable and accessible information about privacy and security practices. At times and in places that are most useful to enabling consumers to gain a meaningful understanding of privacy risks and the ability to exercise Individual Control, companies should provide clear descriptions of what personal data they collect, why they need the data, how they will use it, when they will delete the data or de-identify it from consumers, and whether and for what purposes they may share personal data with third parties.
  3. RESPECT FOR CONTEXT: Consumers have a right to expect that companies will collect, use, and disclose personal data in ways that are consistent with the context in which consumers provide the data. Companies should limit their use and disclosure of personal data to those purposes that are consistent with both the relationship that they have with consumers and the context in which consumers originally disclosed the data, unless required by law to do otherwise. If companies will use or disclose personal data for other purposes, they should provide heightened Transparency and Individual Control by disclosing these other purposes in a manner that is prominent and easily actionable by consumers at the time of data collection. If, subsequent to collection, companies decide to use or disclose personal data for purposes that are inconsistent with the context in which the data was disclosed, they must provide heightened measures of Transparency and Individual Choice. Finally, the age and familiarity with technology of consumers who engage with a company are important elements of context. Companies should fulfill the obligations under this principle in ways that are appropriate for the age and sophistication of consumers. In particular, the principles in the Consumer Privacy Bill of Rights may require greater protections for personal data obtained from children and teenagers than for adults.
  4. SECURITY: Consumers have a right to secure and responsible handling of personal data. Companies should assess the privacy and security risks associated with their personal data practices and maintain reasonable safeguards to control risks such as loss; unauthorized access, use, destruction, or modification; and improper disclosure.
  5. ACCESS AND ACCURACY: Consumers have a right to access and correct personal data in usable formats, in a manner that is appropriate to the sensitivity of the data and the risk of adverse consequences to consumers if the data is inaccurate. Companies should use reasonable measures to ensure they maintain accurate personal data. Companies also should provide consumers with reasonable access to personal data that they collect or maintain about them, as well as the appropriate means and opportunity to correct inaccurate data or request its deletion or use limitation. Companies that handle personal data should construe this principle in a manner consistent with freedom of expression and freedom of the press. In determining what measures they may use to maintain accuracy and to provide access, correction, deletion, or suppression capabilities to consumers, companies may also consider the scale, scope, and sensitivity of the personal data that they collect or maintain and the likelihood that its use may expose consumers to financial, physical, or other material harm.
  6. FOCUSED COLLECTION: Consumers have a right to reasonable limits on the personal data that companies collect and retain. Companies should collect only as much personal data as they need to accomplish purposes specified under the Respect for Context principle. Companies should securely dispose of or de-identify personal data once they no longer need it, unless they are under a legal obligation to do otherwise.
  7. ACCOUNTABILITY: Consumers have a right to have personal data handled by companies with appropriate measures in place to assure they adhere to the Consumer Privacy Bill of Rights. Companies should be accountable to enforcement authorities and consumers for adhering to these principles. Companies also should hold employees responsible for adhering to these principles. To achieve this end, companies should train their employees as appropriate to handle personal data consistently with these principles and regularly evaluate their performance in this regard. Where appropriate, companies should conduct full audits. Companies that disclose personal data to third parties should at a minimum ensure that the recipients are under enforceable contractual obligations to adhere to these principles, unless they are required by law to do otherwise.

For an example of some of the major problems with healthcare data, see my Oct. 2009 post "Health IT Vendors Trafficking in Patient Data?"

I like the proposals.

The question is, regarding electronic health data: are these Federal proposals too little, too late?

Complex systems such as massive computer networks (with myriad stakeholders seeking to 'game' the system, skirt the boundaries of the law, and make handsome profits) can become uncontrollable.

-- SS

Saturday, January 14, 2012

2011 Closes on a Note of Electronic Medical Record Privacy Breach Shame

At my Oct. 2011 post "Still More Electronic Medical Data Chaos, Pandemonium, Bedlam, Tumult and Maelstrom: But Don't Worry, Your Data is Secure" and others in this query link on medical record privacy, http://hcrenewal.blogspot.com/search/label/medical%20record%20privacy I wrote:

"Don't worry, your medical data's safe."

Joseph Conn of ModernHealthcare.com apparently disagrees (with my sarcasm, that is) and states the obvious outright. I post his story with few comments and several emphases which are mine:

Year closes on a note of breach shame
Modern Healthcare
Dec. 2012

Three-eighty. Three-eighty. Do I hear four hundred?

With 2011 winding down, there are now 380 major data breaches involving 500 or more patients' records listed on the "wall of shame" website kept by HHS' Office for Civil Rights.

So far, from the first wall postings in September 2009 through the latest on Dec. 8 this year, there have been 18,059,831 "individuals affected," and even that massive number is an undercount of the breach problem.

First, the civil rights office hasn't yet released the records of tens of thousands of breaches it has received under a federal reporting mandate on breaches affecting fewer than 500 patients per incident. I've been asking for electronic copies of those records since June. I hope to hear soon on an appeal of a decision last fall by HHS, claiming that the civil rights office can hide those reports while it "investigates" an estimated 30,000 or more breaches they describe.

Second, even the OCR's posted numbers are low.

A Nov. 4 public notice on a breach reported by the UCLA Health System states that "some personal information on 16,288 patients" was stolen, but the wall of shame lists the "individuals affected" in the UCLA incident as 2,761.

UCLA spokeswoman Dale Tate said in an e-mail that the nearly six-times-larger number in its notice "represents the number of individuals who had some information on the hard drive," while the 2,761 figure sent to the OCR "represents the number of people that met the specific criteria" under the federal breach notification rule.

Under the federal rule, Tate says, "the information for these individuals could possibly cause more than a minimal amount of financial, reputational or other harm." Information on the rest of the individuals, Tate said, did not meet the criteria.

Not to get too harpy, but this breach stuff is long past being ridiculous.

The lawyers are already all over it, and maybe that's what it will take for the industry to finally start addressing the problem. Brian Kabateck, a California lawyer, thinks so.

In the past three months, his Los Angeles law firm has filed a pair class-action breach suits against two of the most highly regarded healthcare systems in the state, University of California, Los Angeles and Stanford, as well as one of the latter's business associates, Multi-Specialty Collection Services.

"I think this is a short blip on the radar," Kabateck said. As the settlement costs pile up, he said, "I think big institutions are going to learnfive years from now, these lawsuits are going to be obsolete."

Class-action lawsuits are needed as much for health IT risk and safety issues causing near-misses, injuries and death as for security breaches, I note.

I think five years is highly overoptimistic as well on the breach issue, considering the degree of "institutional learning" that's occurred on how to do health IT "right" over the past ~ three decades, and considering that the breaches that are increasing, not decreasing, in intensity and severity across all industry sectors. That includes industry sectors far better equipped to manage IT security than hospitals.

Right now, though, Kabateck says, "This is not to the level of being an epidemic, but it's close."

I think it is epidemic.

Rather than being a miracle that will revolutionize medicine, health IT is like any other information and communication technology (ICT): it has unintended consequences (UC's) that can dilute or even negate its advantages. The issue of damaged medical record privacy, confidentiality and security is but one UC of health IT.

-- SS

Thursday, February 24, 2011

Windows 7 Service Pack 1 "Glitches": Why Personal Computers are Problematic, and Perhaps Should Not Be Mission Critical Components in Hospitals

A technical note on computer unreliability, and a series of followup critical questions relative to health IT:

I run Windows 7 Professional on one of my computers, a very unspecial 4-5 year old Micro Center machine, the PowerSpec 6001, using conventional components. The machine was upgraded with 2 Gb RAM and an ATI Radeon 9600 series video card, to run the Aero "eye candy."

It has run satisfactorily since I installed Windows 7 Professional (32-bit version) on it last year.

I am not a computer amateur. [I do, however, admit to being a Radio Amateur - Extra class - ed.] Further, I meticulously keep the machine current with Microsoft security patches, use Symantec anti-virus which I also keep updated, check my disk for errors, and only visit major well-known, nationally prominent websites using the machine.

So yesterday, Windows 7 Service Pack 1 appeared in my "Software updates" list from Microsoft, after being released to the general public.

It was explained that this Service Pack improves performance, reliability and security [i.e., it is intended to update all the many, many bugs, unreliabilities and security holes of the operating system since its inception - ed.]

I confirmed my machine met the specs for it, and allowed the computer to download and install Service Pack 1.

That was my mistake.

After installation, the machine could no longer reboot Windows.

The flying color patches of the first screen appeared ... and then the machine suffered a hard reboot (going back to the BIOS-initiated memory checks and screens, etc.), as if I'd pressed the front panel hardware RESET button this machine has.

An automated "wizard" that came up and tried to figure out why the machine would not restart failed to do so.

I asked the machine, therefore, to roll back to the state it was in prior to the Service Pack 1 (SP1) "upgrade" via a "Restore Point", a feature Windows permits using the "system restore" capability. The SP1 installation automatically creates a Restore Point (image of the prior state of the OS) on the machine just before installing itself.

The machine works again, but ... (and that is a big "but"):

  • The Service Pack is not installed. Therefore I am not running the latest protections, and do not know what will happen in the future with respect to patches and upgrades. Maybe the Service Pack will get its own Service Pack at some point to fix it, so it can fix my computer;
  • The Service pack installation, without warning and rather rudely, erased my prior computer Restore Points of the past few weeks, leaving only the Restore Point it created just before inflicting itself on my machine. Just to thumb its nose at me, it also left two Restore Points from back in November, which would require me to then re-install a lot of software and updates at the very least. I cannot even try a Restore Point of, say, last week after other updates;
  • I attempted to view the system error logs to determine what caused the failed Service Pack Install. Surprise! The Event Viewer and Task Scheduler management consoles I use to review system operation no longer operated, instead producing this lovely, extremely explanatory message: "MMC cannot initialize the snap-in", followed by hexadecimal gibberish that any doctor or citizen can easily decipher:

Such explanatory error messages! "MMC cannot initialize the snap-in. The snap-in might not have been installed correctly. Name: Event viewer. CLSID: FX: {b05566ad-fe9c-4363-be05-7a4cbb7cb510}." Click to enlarge.

  • Attempts to look up the error on the Web produce gobs and gobs of amateurish "legible gibberish", indirection, misdirection, guesswork, and speculation, some of it from Microsoft itself;
  • To add insult to injury, typical of poor user interaction design, I could not copy-and-paste the error, but had to type it (partially, fortunately, thanks to Google);
  • Much of the material was in very broken English (where's those language translators promised to us for some 50 years now by computer scientists?)
  • My attempts at repairing the damage by running the command "SFC /scannow" (system file check) to check and repair critical windows files showed that the Service Pack "Upgrade" also corrupted a number of critical Windows system files - despite the "Restore Point" rollback. Great Scott!
  • SFC repaired the files and produced a log of gibberish that's thousands of pages long for me to ferret out what got damaged (ironically, just like the records from a few weeks of a relative's EMR-error-related hospitalization, at appx. 2,900 pages of legible gibberish);
  • The repair did not restore the missing functionality;
  • Attempts to reinstall supporting packages such as .Net framework also do not restore the functionality;
  • Attempts to reinstall the Service Pack produce the same results, a crash on initial restart after the installation and need to roll back, erasure of several Restore Points I manually created, along with re-corruption of the critical system files previously repaired by the SFC /scannow command.
  • I have no way of knowing what else is broken or may malfunction;

Russian Roulette, anyone?

All this was after many months of Microsoft "Beta testing" the Service Pack. (Perhaps it was really "Alpha testing?")

Similar issues occurred with the former Microsoft OS, Windows XP (now in its third major service pack since its release in 2002, with patches still coming on an almost weekly basis).

Fortunately, I have backup images of my entire disk, but the inconvenience and time wasted is quite irritating - and I will still not have the latest security patches after I roll back my machine to my latest disk image.


One should note that these "glitches" are just in the Operating System (OS) itself. Third-party applications (such as EMR and CPOE sytems, middleware, interfaces, etc.) suffer the same type of problems...for instance, the life-and-limb-threatening "glitches" that occurred at Trinity Healthcare after an EMR "upgrade."

Further, OS "glitches" can cause unexpected application "glitches", and vice versa. Complexity on top of complexity...

Note that machines running similar software are on the "servers" that are the heart of major enterprise systems such as EMR's and CPOE's, that communicate with enduser workstations.

Now, several simple questions:

  • Who knows what other "glitches" the Service Pack introduced to my machine, that will "bite me" (or patients) later?
  • Are these the machines we want our doctors and nurses to depend upon, since they increasingly regulate every medical transaction that occurs?
  • Has the software become too complex to be entirely reliable, maintainable and secure?
  • Does the average hospital have the staff to effectively deal with issues such as the above?
  • Do these "glitches" raise the risk and the cost - therefore reducing the ROI, already low (see reading list) - of experimental health IT to even more unsatisfactory levels?

Finally:

  • Would the average person tolerate such behavior from their car? In their aircraft? (Oops, the brakes don't work properly in 13.5% of cars after the parts upgrade, and that altimeter is simply crazy ...)
-- SS

Feb. 24 late night addendum:

Deciding to play with this mayhem, and knowing I was going to be wasting a lot of time, I first backed up my deranged machine to an external disk (~ half an hour) to preserve my files. I then restored my machine from an external disk backup image to its condition in mid-Nov. 2010 [thinking perhaps something more recent caused the SP1 to fail]. That took another half an hour. I then attempted to install the SP1 again. That took another hour or more.

Same results - machine crash after the "circling window panes" display.

I let the "Startup Repair" wizard run. It failed with the following informative messages. In a superb example of poor user design, I had to jot the messages down on paper, as it made no offer to print them, or load them into a thumb drive, etc. - although it did offer to send the error messages to Microsoft, a neat trick as the software components to drive the computer's wireless network adapter were not loaded:

Problem details - System Repair
Problem signature:

1- 6.1.7600.16385
2- 6.1.7600.16385
3 - unknown
4 - 21201077
5- AutoFailure
6 - 3
7 - BadPatch

OS version - 6.1.7600.2.0.0
Local ID - 1033256.1
Root cause - a patch is preventing the system from starting [no fooling - ed.]
Repair Action
System file integrity check and repair
Result = Failed.
Error code = 0xa

Then for added fun, I started the machine up in 'Safe Mode' (using the F8 key at startup). It came up, but told me it was doing a System Restore due to the failure to configure the Service Pack. After about 20 minutes of frantic disk activity, the machine rebooted - and immediately crashed as before.

I am rerunning the Startup Repair wizard again, asking it to restore my system, but I predict it will do so with the original remaining problems of non-functioning components that started this whole mess - if it works at all.

This is all absurd. It is a massive waste of time, a result of poor programming, uninformative, cryptic error messages (what? computers don't have enough storage for useful error messages?), poor (nonexistent) documentation, inadequate attention to the user experience, condescension of the user, inability to report the problems back to HQ automatically due to lack of forethought about a compromised machine's ability to access the network, software unreliability, and probably a host of other issues I haven't thought of yet because I'm tired after all this fritter.

Not to mention, it is potentially destructive of data to those who suffer this problem but did not keep backups. They warn you beforehand - but the installation agreement you "sign" is of the Ross Koppel/David Kreda "hold the vendor harmless" variety.

This experience is a metaphor for the state of health IT (with "glitches", "workarounds", unexplained errors, etc.), and of the dangers of computer worship.

-- SS

Feb 25 addendum - further experimentation based on web comments about SP1, such as running a pre-SP1 readiness checking utility by Microsoft, emptying the /temp folders, renaming the "software distribution" folder, clean booting, etc. all produce the same result: crash of the machine on reboot.

And there's no computer doctor to call for an appointment to fix the problem.

-- SS

Monday, December 6, 2010

Annals of Electronic Information Security

At The Hill, former House Speaker Newt Gingrich raises a good point about the leak of hundreds of thousands of diplomatic cables and other private information:

"You have a private first class who downloads a quarter million documents, and the system doesn't say, 'Oh, you may be over extended?' I mean, this is a system so stupid that it ought to be a scandal of the first order," Gingrich said.

Regardless of which administration(s) are responsible (these systems probably took many years to reach their current form), one wonders if commercial EMR's suffer from the same oversights.

-- SS

Friday, November 19, 2010

Insurers Test Data Profiles to Identify Risky Clients

Stories like this one today at the WSJ disturb me.

Insurers Test Data Profiles to Identify Risky Clients
Wall Street Journal
Nov. 19, 2010

From that story:

Life insurers are testing an intensely personal new use for the vast dossiers of data being amassed about Americans: predicting people’s longevity.

Insurers have long used blood and urine tests to assess people’s health—a costly process. Today, however, data-gathering companies have such extensive files on most U.S. consumers—online shopping details, catalog purchases, magazine subscriptions, leisure activities and information from social-networking sites—that some insurers are exploring whether data can reveal nearly as much about a person as a lab analysis of their bodily fluids.

In one of the biggest tests, the U.S. arm of British insurer Aviva PLC looked at 60,000 recent insurance applicants. It found that a new, “predictive modeling” system, based partly on consumer-marketing data, was “persuasive” in its ability to mimic traditional techniques.

The research heralds a remarkable [alarming? -ed.] expansion of the use of consumer-marketing data, which is traditionally used for advertising purposes.


Read the entire article.

The reason I find this article disturbing is that it can and probably should be looked at as another example of technophiles and opportunists with no knowledge of (or lack of caring about) Social Informatics, a decades-old discipline with a focus on studying the unintended consequences of new information and communications technologies (ICT's), enabling our society to move one step closer to centralized control.

Social Informatics (SI) refers to the body of research and study that examines social aspects of computerization, including the roles of information technology in social and organizational change, the uses of information technologies in social contexts, and the ways that the social organization of information technologies is influenced by social forces and social practices.

Stories such as the above WSJ story, and others in their running series on Internet privacy, also dampen my enthusiasm about the possibility that electronic medical information will be kept private, confidential and secure.

-- SS

Thursday, October 21, 2010

Medical data breach of the week - but your EMR data is secure, trust us, we're IT experts

I have written frequently about the pipe dream of secure national electronic medical records, such as in February 2010 at my post "Networked EMR's and Healthcare Information Security: Practical When Massive IT Security Breaches Continue?", my post "Networked, Interoperable, Secure National Medical Records a Castle in the Sky?", as well as "Operation Aurora And a Widespread Reluctance to Discuss IT Flaws: Is Universal Healthcare IT Really a Good Idea in 2010?" and others.

I was also quoted on July 30, 2010, in a Philadelphia Inquirer story about the theft of a laptop computer with data on 21,000 patients from Thomas Jefferson University Hospital here, and also interviewed August 2 by local NPR station WHYY-91FM, where I stated:

"There is almost no excuse for unencrypted data to be sitting on any computer at a hospital or any organization," said Scot Silverstein, a Drexel University expert on health-information technology.

In the latest health-data-on-computer-theft-of-the-week, the Inquirer ran this story today about a local theft ten times as large as July's:

Medical-data breach said to be major
A computer flash drive containing the names, addresses, and personal health information of 280,000 people is missing - one of the largest recent security breaches of personal health data in the nation.

"We deeply regret this unfortunate incident," said Jay Feldstein, the president of the two affiliated Philadelphia companies, Keystone Mercy Health Plan and AmeriHealth Mercy Health Plan.

The breach, which involves the records of Medicaid recipients, is the first such Medicaid data breach in Pennsylvania since at least 1997, according to the state's Department of Welfare, which has oversight.

There is little more I can add to my prior postings on this issue except the words of privacy advocate, psychiatrist Dr. Deborah Peel:

The security failure, one of the several largest in nearly two years, involves nearly two-thirds of the insurers' subscribers. It became known only after The Inquirer requested information Tuesday evening. The insurers said the drive was missing from the corporate offices on Stevens Drive in Southwest Philadelphia. It noted that the same flash drive was used at community health fairs.

"That seems grossly irresponsible," said Dr. Deborah Peel, a Texas psychiatrist who heads Patient Privacy Rights, an advocacy group.

"Why would you be hauling around private patient information to a health fair," she said. "I can't imagine what they were thinking, taking this data out of a locked room at company headquarters.

"What's tragic is that this is a particularly vulnerable group of people," Peel said. "They tend to be vulnerable to identity theft, vulnerable to discrimination." Medicaid recipients are low-income people.


As to encryption (a built-in feature of the upper tier versions of Windows and of Mac OS X):

They [the companies] would not comment on the riskiness of taking the drive to health fairs, nor would they say whether the data on the drive was encrypted.

Highly likely translation: no.

The companies issued an apology:

"At Keystone Mercy Health Plan and AmeriHealth Mercy Health Plan, our number one priority is our members. Since reporting this unfortunate incident to the Department of Public Welfare, we have actively and responsibly executed a multifaceted plan to inform those affected, while also evaluating and enhancing our security measures to ensure this does not happen again."

[Did any employee have their "privileges revoked" -- the medical term of art for a physician who is 'fired' -- I wonder? - ed.]

Perhaps the executives in charge of this data, as well as the IT department, should read stories like the aforementioned July 30, 2010 story.

However, I fear there are those who are ineducable or hopelessly irresponsible when it comes to acting cautiously and responsibly regarding computer-based medical information, in the poorly bounded, complex, unpredictable world of healthcare.

That is not to even mention deliberate theft for personal gain.

This is why the dream of
secure national electronic medical records seems a pipe dream for the foreseeable future.

-- SS

10/23 Addendum

in an updated story, the Inquirer reports the data was indeed unencrypted, although the companies claimed an encryption project was in progress.

Thursday, February 18, 2010

Networked EMR's and Healthcare Information Security: Practical When Massive IT Security Breaches Continue?

At "Networked, Interoperable, Secure National Medical Records a Castle in the Sky?" I wrote that the holy grail of electronic medical record efforts - the creation of a networked, interoperable, secure national medical records system - may be far more difficult than anyone expected due to vulnerabilities in current, widespread IT networking and OS platforms.

Now we hear the situation is even worse than in the articles I cited at that post:


Wall Street Journal
Feb. 18, 2010
Broad New Hacking Attack Detected

Global Offensive Snagged Corporate, Personal Data at nearly 2,500 Companies; Operation Is Still Running

Hackers in Europe and China successfully broke into computers at nearly 2,500 companies and government agencies over the last 18 months in a coordinated global attack that exposed vast amounts of personal and corporate secrets to theft, according to a computer-security company that discovered the breach.

The damage from the latest cyberattack is still being assessed, and affected companies are still being notified. But data compiled by NetWitness, the closely held firm that discovered the breaches, showed that hackers gained access to a wide array of data at 2,411 companies, from credit-card transactions to intellectual property.

One can only imagine how internet-connected hospitals, generally an IT backwater, might fare under such an onslaught.

... In more than 100 cases, the hackers gained access to corporate servers that store large quantities of business data, such as company files, databases and email.

They also broke into computers at 10 U.S. government agencies. In one case, they obtained the user name and password of a soldier's military email account, NetWitness found. A Pentagon spokesman said the military didn't comment on specific threats or intrusions.

At one company, the hackers gained access to a corporate server used for processing online credit-card payments. At others, stolen passwords provided access to computers used to store and swap proprietary corporate documents, presentations, contracts and even upcoming versions of software products, NetWitness said.

Data stolen from another U.S. company pointed to an employee's apparent involvement in criminal activities; authorities have been called in to investigate, NetWitness said. Criminal groups have used such information to extort sensitive information from employees in the past.


Read the while article. These breaches are an unpleasant reality in 2010, but what's worse is there really are no solid metrics for the true extent of this 'disease.'

Perhaps future Internet technologies will reduce or eliminate the problem, as one reader suggested in a comment to my aforementioned post. I do not believe, however, that patients and their medical records should be used as guinea pigs until those new networking and security technologies are widely deployed and well-proven.

In effect, this is probably not a good time for actual records-level interoperability to be deployed in any manner other than in consideration of a future strategy. Operationalizing that strategy should probably await a time when the "digital ether" in which the data resides and moves is more mature, unless proprietary networks and technology are to be used and without connection to the Internet. Planning data-level compatibility between systems, on the other hand, is work that should continue.

Finally, the layoffs and staffing levels in today's IT departments (at both vendor and user shops), plus the outsourcing of critical IT functions to overseas contractors where workers' loyalty to the primary firm is questionable at best, may be a contributing factor to the nakedness of corporate America's information systems.

-- SS

Thursday, February 4, 2010

Networked, Interoperable, Secure National Medical Records a Castle in the Sky?

The holy grail of electronic medical record efforts of late is the creation of networked, interoperable, secure national medical records that would allow a physician in Palo Alto to retrieve the records of a patient from Hoboken if that patient moved or was found (in the hackneyed and somewhat histrionic scenario) unconscious on the streets of San Francisco.

Recent events have made me skeptical we are anywhere near ready for such a technological accomplishment:

McAfee: Big Business Under Constant Cyber Attack
01.29.10

At the World Economic Forum Annual Meeting in Switzerland, McAfee announced the results of a survey of 600 IT security execs in "critical infrastructure enterprises worldwide": that is, in places such as utility companies, banks, and even oil refineries. And apparently, they're constantly under cyber attack and also extortion related to those attacks.


It's a real battlefield out there.

The report, written by the Center for Strategic and International Studies (CSIS), says that 54 percent of those surveyed have already been attacked. The culprits behind the cyber-attacks are listed as "organized crime-gangs, terrorists, or nation-states."

In other words, not simply teenage hackers or cyber-papparazi interested in the medical condition of a movie star.

Only one-fifth of the IT execs surveyed believe their systems are currently secure. One-third say things are worse now, vulnerability-wise, than a year ago, due to budget cuts.

What constitutes a cyber attack? A distributed denial of service (DDoS) is the most typical ... mitigation can be hampered by the local laws, working in multiple countries, or the economics of where they operate. For example, half of those surveyed claim the laws in their countries don't do enough to prevent or deter cyber attacks. That's especially true for Russia, Mexico, and Brazil.

Other attack vectors include DNS poisoning where Web traffic is redirected, SQL injection attacks on back-end data via a public Web site, and plain old theft of services.

If you need a plot for your new thriller novel, keep in mind that 20 percent of these companies are not just cyber-attacked, but have also been threatened with attacks in the last two years in "low-level extortion" attempts.

... Those surveyed said the money loss is the worst part, second is the loss of reputation, and (if you thought you weren't important) loss of customers' personal information is third.

This is a worldwide survey, and almost two-thirds of those surveyed believe foreign governments were responsible in some way for previous attacks. The two countries considering the biggest threats: China (by 33 percent of those surveyed) and the good ol' U.S. of A. (by 36 percent). China believes it's the biggest target.

The full report, called In the Crossfire: Critical Infrastructure in the Age of the Cyber War is free on McAfee's Web site in PDF format.

I note that Google recently called in the National Security Agency to help analyze a major corporate espionage attack:

The attacks targeted Google source code -- the programming language underlying Google applications -- and extended to more than 30 other large tech, defense, energy, financial and media companies. The Gmail accounts of human rights activists in Europe, China and the United States were also compromised.

Then there's this:

Intelligence Chief: U.S. at Risk of Crippling Cyber Attack

Feb. 4, 2010

The United States is at risk of a crippling cyber attack that could "wreak havoc" on the country, Director of National Intelligence Dennis Blair said.

"What we don't quite understand as seriously as we should is the extent of malicious cyberactivity that grows, that is growing now at unprecedented rates, extraordinary sophistication," Blair said.

... He said one critical "factor" is that more and more foreign companies are supplying software and hardware for government and private sector networks. "This increases the potential for subversion of the information in ... those systems," Blair said. [Outsourcing our HIT development overseas sounds like a great idea - ed.]


Read the linked articles in their entirety.

Perhaps we should focus on the local at present. National networked EMR's are a great concept, but there are a few social-technical details that remain to be worked out beforehand.


A Castle in the Sky...

-- SS