Showing posts with label cybersecurity. Show all posts
Showing posts with label cybersecurity. Show all posts

Tuesday, July 28, 2015

ACA/Obamacare: And About Those Secuirty Issues at Healthcare.gov

Friday, February 6, 2015

Anthem Hacked With Private Health Records Targeted

"The massive computer breach against Anthem, the nation’s second-largest health insurer, exposes a growing cyberthreat facing health-care companies that experts say are often unprepared for large attacks.
 
Hackers gained access to the private data of 80 million former and current members and employees of Anthem in one of the largest medical-related cyber-intrusions in history.

Authorities said the breach, which was discovered late last month and disclosed this week, did not involve private health records or credit card numbers but did expose Social Security numbers, income data, birthdays, and street and e-mail addresses.

Investigators suspect Chinese hackers may be responsible for the breach, according to an individual briefed on some aspects of the probe. There are also some indications that other health-care companies may have been targeted, said the individual, who spoke on the condition of anonymity to discuss the ongoing investigation.

Security experts said health care has become one of the ripest targets for hackers because of its vast stores of lucrative financial and medical information. Health insurers and hospitals, they added, have often struggled to mount the kinds of defenses­ used by large financial or retail companies, leaving key medical information vulnerable." - China suspected in major hacking of health insurer, Washington Post, 02/06/2015


Link to the entire article appears below:

http://www.msn.com/en-us/news/politics/china-suspected-in-major-hacking-of-health-insurer/ar-AA92tc3

Wednesday, January 28, 2015

Healthcare.gov, Third-party Embedded Websites and Information Security





‘A little-known side to the government's health insurance website is prompting renewed concerns about privacy, just as the White House is calling for stronger cybersecurity protections for consumers.

It works like this: When you apply for coverage on HealthCare.gov, dozens of data companies may be able to tell that you are on the site. Some can even glean details such as your age, income, ZIP code, whether you smoke or if you are pregnant.

The data firms have embedded connections on the government site. Ever-evolving technology allows for individual Internet users to be tracked, building profiles that are a vital tool for advertisers.

Connections to multiple third-party tech firms were documented by technology experts who analyzed HealthCare.gov, and confirmed by The Associated Press. There is no evidence that personal information from HealthCare.gov has been misused, but the number of outside connections is raising questions.

"As I look at vendors on a website...they could be another potential point of failure," said corporate cybersecurity consultant Theresa Payton. "Vendor management can often be the weakest link in your privacy and security chain."’ - New privacy concerns over government's health care website, myway.com, 01/20/2015

Link to the entire article appears below:

http://apnews.myway.com/article/20150120/us--health_overhaul-privacy-8b7c5d925b.html

Wednesday, September 17, 2014

ACA/Obamacare: GAO Reports that CMS Hasn’t Paid Proper Attention to Healthcare.gov Security Risks

‘HealthCare.gov has continuing security frailties that put users' sensitive personal information at risk, a government watchdog is set to tell Congress this week.

Despite the federal government's efforts to protect the website from breaches, "weaknesses remained in the security and privacy protections applied to HealthCare.gov and its supporting systems," said the Government Accountability Office.

The agency released a report Tuesday on the security of the site, through which millions of Americans bought coverage under the health law last year and which millions more will be urged to use.

"Until these weaknesses are fully addressed, increased and unnecessary risks remain of unauthorized access, disclosure, or modification of the information collected and maintained by Healthcare.gov and related systems, and the disruption of service provided by the systems," according to the GAO report, published ahead of testimony to be given at a Thursday hearing of the Republican-led House Oversight and Government Reform Committee.

The warnings come two weeks after the Department of Health and Human Services disclosed that a hacker had broken into part of the site and uploaded malicious software during the summer.’

‘GAO said the CMS failed to ensure system-security plans were complete and was relying on a draft data-use agreement with a contractor tasked with verifying users' identities.

Moreover, the agency skipped some assessments of privacy risks and didn't perform comprehensive security testing of the HealthCare.gov system that used all of the security controls specified by the government ahead of the site's launch. Testing remained incomplete as of June 2014, GAO said.

The agency also hadn't set up an alternate processing site for HealthCare.gov systems that would allow them to be recovered in the event of a disruption, the watchdog found.

Other weaknesses included lax enforcement of password-strength requirements and inconsistent application of security patches to the system.

Certain systems supporting the site's infrastructure weren't restricted from accessing the Internet, which increased the risk that unauthorized users could get to data.

Moreover, one of the federal agency's contractors hadn't properly secured its administrative network, which could allow unauthorized access to the HealthCare.gov system.

Many of the problems stemmed from the agency's disagreements about security roles and responsibilities with the various contractors, states and federal agencies that exchange information as part of the HealthCare.gov system, the watchdog said.’ - Federal Health Care Website Faces Security Risks, Watchdog Finds, WSJ, 09/16/2014

 

Link to the entire article appears below:

http://online.wsj.com/articles/federal-health-care-website-faces-security-risks-watchdog-finds-1410895828



Update 09/18/2014: Government Insider Warned of HealthCare.gov Security Risks: ‘I Am Tired of the Cover Ups’, dailysignal.com

http://dailysignal.com/2014/09/18/government-insider-warned-healthcare-gov-security-risks-tired-cover-ups/?utm_source=heritagefoundation&utm_medium=email&utm_campaign=morningbell&mkt_tok=3RkMMJWWfF9wsRons63JZKXonjHpfsX56OgvWa%2BylMI%2F0ER3fOvrPUfGjI4DSMBlI%2BSLDwEYGJlv6SgFQrLBMa1ozrgOWxU%3D

Friday, August 22, 2014

ACA/Obamacare: The Ongoing Saga of Cyber Security and the ACA Web Site

Make special note of 3:04 to 3:39 of the video regarding the description of the pathways along which one's sensitive personal information travels.

Sunday, July 13, 2014

ACA/Obamacare: Where Web Security is Job 57

‘A Romanian attacker hacked the Vermont health exchange’s development server last December, gaining access at least 15 times and going undetected for a month, according to records obtained by National Review Online.

CGI Group, the tech firm hired to build Vermont Health Connect, described the risk as “high” in a report about the attack. It also found possible evidence of sophisticated “counter-forensics activity performed by the attacker to cover his/her tracks.” ‘ - Another Security Breach for Obamacare, NRO, 07/01/2014

Link to entire article appears below:

http://www.nationalreview.com/article/381640/another-security-breach-obamacare-jillian-kay-melchior

Sunday, December 8, 2013

Healthcare.gov: Stop Sending Paper Applications! Use Our Unsecured Website! Damn the Cybersecurity, Full Speed Ahead!

'So it's come to this. During the past week, the Associated Press reported today, "Federal health officials," meaning "the Obama administration," began "urging" (i.e., "telling") counselors and navigators around the country to stop using paper applications for Obamacare coverage, "because of concerns those applications would not be processed in time." It seems that either Team Obama or AP (my money is on AP) doesn't mind risking criticism for waiting to let this news out until a weather- and sports-dominated Saturday. It's apparently okay to keep those who don't know any better, i.e., those who went to the trouble of printing a paper app on their own, in the dark.

So you shouldn't use paper. But the vastly under-reported but inarguable fact is that HealthCare.gov isn't secure; experienced IT security experts strongly warn against using it. So consumers shouldn't be going online either, meaning that there's no defensible way to apply for coverage before the end of the year.’ - As Feds Say to Stop Using Paper Obamacare Apps, AP Again 'Forgets' That HealthCare.gov Is Not Secure, Newbusters, 12/07/2013


‘For the love of Jiminy Cricket, how much cybersecurity incompetence are American citizens expected to accept and excuse while also footing the $660 million bill? Online security experts say the “new and improved” Healthcare.gov site may actually be more insecure now than before it was fixed!

An operational progress report quoted Jeffrey Zients, a management consultant on repairs to the Obamacare site, as stating, “The bottom line -- HealthCare.gov on December 1st is night and day from where it was on October 1st.” Well if this is “day,” then it’s an Arctic Alaskan daytime with no sunlight as “experts” blindly attempt to bolt on security to a system that was developed without a care about the security or privacy of Americans.

David Kennedy, founder and principal security consultant of TrustedSec, warned that the Healthcare.gov was not secure. In fact, Kennedy previously told CNBC that it’s hard to bolt on security after a site is developed and that “no security was ever built into the Obamacare site.”

So how many of the security risks were eliminated now that the administration “fixed” the site? None according to what Kennedy told the Washington Free Beacon. “It doesn’t appear that any security fixes were done at all.” He added:

“There are a number of security concerns already with the website, and that’s without even actually hacking the site, that’s just a purely passive analysis of [it]. We found a number of critical exposures that were around sensitive information, the ability to hack into the site, things like that. We reported those issues and none of those appear to have been addressed at all.”

“They said they implemented over 400 bug fixes,” he said. “When you recode the application to fix these 400 bugs—they were rushing this out of the door to get the site at least so it can work a little bit—you’re introducing more security flaws as you go along with it because you don’t even check that code.”

Well that’s just peachy keen and that’s before considering the “hacker” threat. But, hey, it’s not like the feds are required to notify citizens if there is a breach; after all, it’s so much easier to leave that headache to each state. Just ask Vermont, since Vermont Health Connect had to admit to a security breach that allowed “improper access to another user’s Social Security number and other data.”

Kennedy also said that:

the team working on Healthcare.gov is more likely to hide its security flaws than address them. When it was revealed that the most popular searches on the website were hack attempts—confirmed by entering a semicolon in the search bar—the website simply removed the tool.

“The top results were hacker attempts,” Kennedy said. “Their fix for it wasn’t, ‘Hey let’s restrict people from inputting malicious code into the website,’—because that’s how hackers break into websites—it was, ‘we’re just going to completely disable that entire function completely, and not even show the search results back.’”

“We’ve deployed 12 large, dedicated servers,” states the operation progress report. Oh goodie gumdrops, it “can now handle about as many shoppers as the average custom T-shirt site,” pointed out Human Events. The site has “a remodeled 404 Error page that pretends to be a ‘waiting room,’ where you can ‘queue up’ and leave an email address to be notified” when it’s your turn to fill out all your private info.

Julie Bataille, Director of Communications, Centers for Medicare & Medicaid Services, summed up the newly “fixed” site’s progress report [pdf] as having an upgraded and reconfigured firewall that protects the system while allowing “more than five times the network throughput.” The “improved shopping” experience on Healthcare.gov supposedly can handle 50,000 people logged on to the website at once, and “more than 800,000 visitors a day;” but even with a lower number of “shoppers,” the Associated Press reported that many visitors faced “the same old sputters and even crashes.” ‘ - Healthcare.gov more vulnerable to hacking & privacy breaches after 'fix', Computerworld, 12/03/2013



Links to above mentioned articles appear below:

http://newsbusters.org/blogs/tom-blumer/2013/12/07/feds-say-stop-using-paper-obamacare-apps-ap-again-forgets-healthcaregov-

http://blogs.computerworld.com/application-security/23226/healthcaregov-more-vulnerable-hacking-privacy-breaches-after-fix









Healthcare.gov: Where Information Security is Job 57!