Close
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
Read Down
Sign in
Close
Welcome!Log into your account
Forgot your password?
Read Down
Password recovery
Recover your password
Close
Search
Logo
Subscribe
Logo
  • Latest News
  • Artificial Intelligence
  • Video
  • Big Data and Analytics
  • Cloud
  • Networking
  • Cybersecurity
  • Applications
  • IT Management
  • Storage
  • Sponsored
  • Mobile
  • Small Business
  • Development
  • Database
  • Servers
  • Android
  • Apple
  • Innovation
  • Blogs
  • PC Hardware
  • Reviews
  • Search Engines
  • Virtualization
More
    Subscribe
    Home Cybersecurity
    • Cybersecurity

    GAO Report: Medicare Patient Data Vulnerable

    Written by

    M.L. Baker
    Published October 10, 2006
    Share
    Facebook
    Twitter
    Linkedin

      eWEEK content and product recommendations are editorially independent. We may make money when you click on links to our partners. Learn More.

      The personal data of Medicare patients is at risk because Centers for Medicare and Medicaid Services has not held its network contractor to its own security standards, according to a report issued by the Government Accountability Office.

      The GAO concluded that information on the network could be disclosed without authorization and that vulnerabilities could be used to disrupt CMS services.

      A security breach could allow “unauthorized access to personally identifiable medical data, seriously diminishing the publics trust in CMS ability to protect the sensitive beneficiary data it is entrusted with.” The report comes at a time when worries about medical identity theft are growing.

      Besides personally identifiable information like name, address, and social security number, potentially compromised information could include treatments for psychiatric disorders and substance abuse problems.

      According to the GAO, Medicare helps over 42 million patients obtain health care from over 1 million providers, collecting droves of sensitive data in the process.

      To reach its conclusions, GAO researchers visited three network contractor sites that transmit CMS information, examining “routers, network management servers, switches, firewalls and administrator workstations.”

      CMS did not always encrypt medical data or other sensitive information traveling over these networks, according to the report. CMS also allowed its contractor to use passwords that were too simple and gave workers more access than they needed to do their jobs. These and other vulnerabilities “provide more opportunities for an attacker to escalate their privileges and make unauthorized changes to files” as well as “to gain unauthorized access to network resources,” the report said.

      /zimages/3/28571.gifClick here to read about Centers for Medicare and Medicaid Services decision to test the use of personal health records.

      The situation did not surprise one manager at a network security firm, who asked not to named. “Its a standard set of problems.” The manager had not worked with the CMS network but has worked with other government systems.

      In a statement, CMS Administrator Mark McClellan, in Baltimore, said CMS had been aware of and was addressing many of the problems. He downplayed their significance, saying that about half of the identified problems had already been fixed, and that there are no signs that any of the vulnerabilities had been exploited. Because the network transmits rather than houses information, intercepting the information would be difficult, he said.

      However, the network security manager said, “Its harder to get the data because you have to watch for it, but the data are still vulnerable.” In particular, thieves could monitor for authentication codes that they could then use to gain access to particular information they want.

      Sensitive information throughout the network is at risk, the GAO report concluded. Such information is communicated between diverse agencies, said the report, “including the CMS central office and data center, CMS regional offices, financial institutions, Medicare intermediaries and carriers, Medicare data centers, skilled nursing facilities and home health agencies, CMS contractors, state Medicaid offices, other federal agencies, quality information organizations, and CMS disaster recovery services.”

      The identified vulnerabilities fell into several categories including user identification, authentication and authorization. Additionally, “security-related events” were not monitored or audited, provisions to make sure network configurations were secure were flawed, and different components of the network were not physically or logistically separated, so that people with legitimate access to one part of the network could have an easier time reaching areas for which they are unauthorized.

      In some cases, said the report, “certain network devices did not have any users defined, allowing for the execution of unauthorized commands without any means of designating individual accountability for the action.”

      The study was conducted at the request of the Senate Finance Committee. The full report is available as a pdf.

      /zimages/3/28571.gifCheck out eWEEK.coms for the latest news, views and analysis of technologys impact on government and politics.

      M.L. Baker
      M.L. Baker
      Monya Baker is co-editor of CIOInsight.com's Health Care Center. She has written for publications including the journal Nature Biotechnology, the Acumen Journal of Sciences and the American Medical Writers Association, among others, and has worked as a consultant with biotechnology companies.

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      Get the Free Newsletter!

      Subscribe to Daily Tech Insider for top news, trends & analysis

      MOST POPULAR ARTICLES

      Artificial Intelligence

      9 Best AI 3D Generators You Need...

      Sam Rinko - June 25, 2024 0
      AI 3D Generators are powerful tools for many different industries. Discover the best AI 3D Generators, and learn which is best for your specific use case.
      Read more
      Cloud

      RingCentral Expands Its Collaboration Platform

      Zeus Kerravala - November 22, 2023 0
      RingCentral adds AI-enabled contact center and hybrid event products to its suite of collaboration services.
      Read more
      Artificial Intelligence

      8 Best AI Data Analytics Software &...

      Aminu Abdullahi - January 18, 2024 0
      Learn the top AI data analytics software to use. Compare AI data analytics solutions & features to make the best choice for your business.
      Read more
      Latest News

      Zeus Kerravala on Networking: Multicloud, 5G, and...

      James Maguire - December 16, 2022 0
      I spoke with Zeus Kerravala, industry analyst at ZK Research, about the rapid changes in enterprise networking, as tech advances and digital transformation prompt...
      Read more
      Video

      Datadog President Amit Agarwal on Trends in...

      James Maguire - November 11, 2022 0
      I spoke with Amit Agarwal, President of Datadog, about infrastructure observability, from current trends to key challenges to the future of this rapidly growing...
      Read more
      Logo

      eWeek has the latest technology news and analysis, buying guides, and product reviews for IT professionals and technology buyers. The site’s focus is on innovative solutions and covering in-depth technical content. eWeek stays on the cutting edge of technology news and IT trends through interviews and expert analysis. Gain insight from top innovators and thought leaders in the fields of IT, business, enterprise software, startups, and more.

      Facebook
      Linkedin
      RSS
      Twitter
      Youtube

      Advertisers

      Advertise with TechnologyAdvice on eWeek and our other IT-focused platforms.

      Advertise with Us

      Menu

      • About eWeek
      • Subscribe to our Newsletter
      • Latest News

      Our Brands

      • Privacy Policy
      • Terms
      • About
      • Contact
      • Advertise
      • Sitemap
      • California – Do Not Sell My Information

      Property of TechnologyAdvice.
      © 2024 TechnologyAdvice. All Rights Reserved

      Advertiser Disclosure: Some of the products that appear on this site are from companies from which TechnologyAdvice receives compensation. This compensation may impact how and where products appear on this site including, for example, the order in which they appear. TechnologyAdvice does not include all companies or all types of products available in the marketplace.