SlideShare una empresa de Scribd logo
1 de 2
Descargar para leer sin conexión
Charleston Area Medical Center (CAMC)
Data Breach – What Can Be Learned?
It’s always educational to review a data security breach to see what can be learned. In the case of
the Charleston Area Medical Center (CAMC) last month a number of lessons can be learned. First lets
review what we know (and don’t know) about the data breach which happened at CAMC subsidiary
CAMC Health Education Research Institute (CHERI).

What Happened

It was a pretty straight forward breach. Last month someone doing an online search for an address
found that the name of a relative and their ePHI was readily accessible on a CAMC website via a
Google search. He immediately notified the relative who in turn contacted the State of West Virginia
Attorney General. The Attorney General’s Consumer Protection Division quickly had the offending site
shut down. In all 3655 patients were involved with the breach whose data had been accessible on
the site since September of 2010. The site was created by a contractor who inadvertently enabled
access to the data.

More Questions than Answers

      If the contractor had access to ePHI, were they treated as a Business Associate (BA)?
      Was there a Business Associate Agreement (BAA) in place?
      Was protecting ePHI specified as an upfront feature/requirement of the site created by the contractor?
      Was any application penetration testing performed on the site before it went live?
      As a result of the breach CAMC has agreed to additional safeguards including a security assessment –
       does this imply that CAMC had not previously performed a HIPAA Risk Analysis?!?!

Lessons Learned

An ounce of prevention…: While we don’t know details of this particular vulnerability, it appears that
an application penetration test would have identified the risk and enabled trivial remediation before
an incident. That would be a fraction of the cost of this breach. Its hard to determine the CAMC
brand damage and staff costs associated with a breach like this. And its too early to tell if the hospital
will see HIPAA / HITECH Act fines associated with the incident. The Equifax credit monitoring cost is
also unclear, though calculating the retail cost from their site at $15 per month per user for each of
the 3655 individuals affected by the breach for a year tallies to over $54,000 per month and over
$650,000 for the year …. a pound of cure.



                     WEB                           PHONE                        EMAIL

              WWW.REDSPIN.COM                  800-721-9177               INFO@REDSPIN.COM
Security Assessments have more value before a breach: Well I am stating the obvious here, but
there’s more to the point than the obvious fact that identifying this particular vulnerability early would
be much less painful on the organization. The point is that, in our experience, incident-driven
assessments are often knee-jerk reactions to a compliance issue that are completed more to show
reaction and publicize respect for client ePHI rather than a core value-driven approach to secure
operations. These types of assessments often cost way more and the value can be limited. The value
of a security assessment is proportional to an organizations bandwidth to absorb the findings and
willingness for organizational improvement. An event-driven assessment for CAMC will not yield a lot
of value if the health IT staff is not ready to react to the findings.

Ensure BAs are aware of the need to protect ePHI: When you outsource to a vendor, you are
outsourcing the actual labor, but also to a certain extent security management. While you want to
expect that a vendor would be aware of information security best practices you can’t always trust the
BA to be secure. A robust BAA shows you care? While requiring a BA to complete a Business
Association Self Assessment Questionnaire may not be appropriate for a web site developer, quizzing
them on a secure software development life cycle might filter out incompetent developers and send a
message that you care about their performance.




                     WEB                         PHONE                       EMAIL

              WWW.REDSPIN.COM                 800-721-9177             INFO@REDSPIN.COM

Más contenido relacionado

Más de Redspin, Inc.

Más de Redspin, Inc. (20)

HIPAA Security Audits in 2012-What to Expect. Are You Ready?
HIPAA Security Audits in 2012-What to Expect. Are You Ready?HIPAA Security Audits in 2012-What to Expect. Are You Ready?
HIPAA Security Audits in 2012-What to Expect. Are You Ready?
 
Healthcare IT Security Who's Responsible, Really?
Healthcare IT Security Who's Responsible, Really?Healthcare IT Security Who's Responsible, Really?
Healthcare IT Security Who's Responsible, Really?
 
Healthcare IT Security - Who's responsible, really?
Healthcare IT Security - Who's responsible, really?Healthcare IT Security - Who's responsible, really?
Healthcare IT Security - Who's responsible, really?
 
Redspin Webinar - Prepare for a HIPAA Security Risk Analysis
Redspin Webinar - Prepare for a HIPAA Security Risk AnalysisRedspin Webinar - Prepare for a HIPAA Security Risk Analysis
Redspin Webinar - Prepare for a HIPAA Security Risk Analysis
 
Redspin Webinar Business Associate Risk
Redspin Webinar Business Associate RiskRedspin Webinar Business Associate Risk
Redspin Webinar Business Associate Risk
 
Redspin HIPAA Security Risk Analysis RFP Template
Redspin HIPAA Security Risk Analysis RFP TemplateRedspin HIPAA Security Risk Analysis RFP Template
Redspin HIPAA Security Risk Analysis RFP Template
 
Mobile Device Security Policy
Mobile Device Security PolicyMobile Device Security Policy
Mobile Device Security Policy
 
Financial institution security top it security risk
Financial institution security top it security riskFinancial institution security top it security risk
Financial institution security top it security risk
 
Managing Windows User Accounts via the Commandline
Managing Windows User Accounts via the CommandlineManaging Windows User Accounts via the Commandline
Managing Windows User Accounts via the Commandline
 
Redspin February 17 2011 Webinar - Meaningful Use
Redspin February 17 2011 Webinar - Meaningful UseRedspin February 17 2011 Webinar - Meaningful Use
Redspin February 17 2011 Webinar - Meaningful Use
 
Redspin Report - Protected Health Information 2010 Breach Report
Redspin Report - Protected Health Information 2010 Breach ReportRedspin Report - Protected Health Information 2010 Breach Report
Redspin Report - Protected Health Information 2010 Breach Report
 
Redspin & Phyllis and Associates Webinar- HIPAA,HITECH,Meaninful Use,IT Security
Redspin & Phyllis and Associates Webinar- HIPAA,HITECH,Meaninful Use,IT SecurityRedspin & Phyllis and Associates Webinar- HIPAA,HITECH,Meaninful Use,IT Security
Redspin & Phyllis and Associates Webinar- HIPAA,HITECH,Meaninful Use,IT Security
 
Email hacking husband faces felony
Email hacking husband faces felonyEmail hacking husband faces felony
Email hacking husband faces felony
 
Meaningful use, risk analysis and protecting electronic health information
Meaningful use, risk analysis and protecting electronic health informationMeaningful use, risk analysis and protecting electronic health information
Meaningful use, risk analysis and protecting electronic health information
 
Understanding the Experian independent third party assessment (EI3PA ) requir...
Understanding the Experian independent third party assessment (EI3PA ) requir...Understanding the Experian independent third party assessment (EI3PA ) requir...
Understanding the Experian independent third party assessment (EI3PA ) requir...
 
Top 10 IT Security Issues 2011
Top 10 IT Security Issues 2011Top 10 IT Security Issues 2011
Top 10 IT Security Issues 2011
 
Beginner's Guide to the nmap Scripting Engine - Redspin Engineer, David Shaw
Beginner's Guide to the nmap Scripting Engine - Redspin Engineer, David ShawBeginner's Guide to the nmap Scripting Engine - Redspin Engineer, David Shaw
Beginner's Guide to the nmap Scripting Engine - Redspin Engineer, David Shaw
 
Ensuring Security and Privacy in the HIE Market - Redspin Information Security
Ensuring Security and Privacy in the HIE Market - Redspin Information SecurityEnsuring Security and Privacy in the HIE Market - Redspin Information Security
Ensuring Security and Privacy in the HIE Market - Redspin Information Security
 
Mapping Application Security to Business Value - Redspin Information Security
Mapping Application Security to Business Value - Redspin Information SecurityMapping Application Security to Business Value - Redspin Information Security
Mapping Application Security to Business Value - Redspin Information Security
 
Step by Step Guide to Healthcare IT Security Risk Management - Redspin Infor...
Step by Step Guide to Healthcare IT Security Risk Management  - Redspin Infor...Step by Step Guide to Healthcare IT Security Risk Management  - Redspin Infor...
Step by Step Guide to Healthcare IT Security Risk Management - Redspin Infor...
 

Último

Call Girl in Indore 8827247818 {LowPrice} ❤️ (ahana) Indore Call Girls * UPA...
Call Girl in Indore 8827247818 {LowPrice} ❤️ (ahana) Indore Call Girls  * UPA...Call Girl in Indore 8827247818 {LowPrice} ❤️ (ahana) Indore Call Girls  * UPA...
Call Girl in Indore 8827247818 {LowPrice} ❤️ (ahana) Indore Call Girls * UPA...
mahaiklolahd
 

Último (20)

Trichy Call Girls Book Now 9630942363 Top Class Trichy Escort Service Available
Trichy Call Girls Book Now 9630942363 Top Class Trichy Escort Service AvailableTrichy Call Girls Book Now 9630942363 Top Class Trichy Escort Service Available
Trichy Call Girls Book Now 9630942363 Top Class Trichy Escort Service Available
 
8980367676 Call Girls In Ahmedabad Escort Service Available 24×7 In Ahmedabad
8980367676 Call Girls In Ahmedabad Escort Service Available 24×7 In Ahmedabad8980367676 Call Girls In Ahmedabad Escort Service Available 24×7 In Ahmedabad
8980367676 Call Girls In Ahmedabad Escort Service Available 24×7 In Ahmedabad
 
Premium Call Girls In Jaipur {8445551418} ❤️VVIP SEEMA Call Girl in Jaipur Ra...
Premium Call Girls In Jaipur {8445551418} ❤️VVIP SEEMA Call Girl in Jaipur Ra...Premium Call Girls In Jaipur {8445551418} ❤️VVIP SEEMA Call Girl in Jaipur Ra...
Premium Call Girls In Jaipur {8445551418} ❤️VVIP SEEMA Call Girl in Jaipur Ra...
 
Most Beautiful Call Girl in Bangalore Contact on Whatsapp
Most Beautiful Call Girl in Bangalore Contact on WhatsappMost Beautiful Call Girl in Bangalore Contact on Whatsapp
Most Beautiful Call Girl in Bangalore Contact on Whatsapp
 
Pondicherry Call Girls Book Now 9630942363 Top Class Pondicherry Escort Servi...
Pondicherry Call Girls Book Now 9630942363 Top Class Pondicherry Escort Servi...Pondicherry Call Girls Book Now 9630942363 Top Class Pondicherry Escort Servi...
Pondicherry Call Girls Book Now 9630942363 Top Class Pondicherry Escort Servi...
 
VIP Hyderabad Call Girls Bahadurpally 7877925207 ₹5000 To 25K With AC Room 💚😋
VIP Hyderabad Call Girls Bahadurpally 7877925207 ₹5000 To 25K With AC Room 💚😋VIP Hyderabad Call Girls Bahadurpally 7877925207 ₹5000 To 25K With AC Room 💚😋
VIP Hyderabad Call Girls Bahadurpally 7877925207 ₹5000 To 25K With AC Room 💚😋
 
Best Rate (Patna ) Call Girls Patna ⟟ 8617370543 ⟟ High Class Call Girl In 5 ...
Best Rate (Patna ) Call Girls Patna ⟟ 8617370543 ⟟ High Class Call Girl In 5 ...Best Rate (Patna ) Call Girls Patna ⟟ 8617370543 ⟟ High Class Call Girl In 5 ...
Best Rate (Patna ) Call Girls Patna ⟟ 8617370543 ⟟ High Class Call Girl In 5 ...
 
Call Girls Rishikesh Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Rishikesh Just Call 8250077686 Top Class Call Girl Service AvailableCall Girls Rishikesh Just Call 8250077686 Top Class Call Girl Service Available
Call Girls Rishikesh Just Call 8250077686 Top Class Call Girl Service Available
 
Jogeshwari ! Call Girls Service Mumbai - 450+ Call Girl Cash Payment 90042684...
Jogeshwari ! Call Girls Service Mumbai - 450+ Call Girl Cash Payment 90042684...Jogeshwari ! Call Girls Service Mumbai - 450+ Call Girl Cash Payment 90042684...
Jogeshwari ! Call Girls Service Mumbai - 450+ Call Girl Cash Payment 90042684...
 
Low Rate Call Girls Bangalore {7304373326} ❤️VVIP NISHA Call Girls in Bangalo...
Low Rate Call Girls Bangalore {7304373326} ❤️VVIP NISHA Call Girls in Bangalo...Low Rate Call Girls Bangalore {7304373326} ❤️VVIP NISHA Call Girls in Bangalo...
Low Rate Call Girls Bangalore {7304373326} ❤️VVIP NISHA Call Girls in Bangalo...
 
Call Girls in Delhi Triveni Complex Escort Service(🔝))/WhatsApp 97111⇛47426
Call Girls in Delhi Triveni Complex Escort Service(🔝))/WhatsApp 97111⇛47426Call Girls in Delhi Triveni Complex Escort Service(🔝))/WhatsApp 97111⇛47426
Call Girls in Delhi Triveni Complex Escort Service(🔝))/WhatsApp 97111⇛47426
 
Coimbatore Call Girls in Coimbatore 7427069034 genuine Escort Service Girl 10...
Coimbatore Call Girls in Coimbatore 7427069034 genuine Escort Service Girl 10...Coimbatore Call Girls in Coimbatore 7427069034 genuine Escort Service Girl 10...
Coimbatore Call Girls in Coimbatore 7427069034 genuine Escort Service Girl 10...
 
💕SONAM KUMAR💕Premium Call Girls Jaipur ↘️9257276172 ↙️One Night Stand With Lo...
💕SONAM KUMAR💕Premium Call Girls Jaipur ↘️9257276172 ↙️One Night Stand With Lo...💕SONAM KUMAR💕Premium Call Girls Jaipur ↘️9257276172 ↙️One Night Stand With Lo...
💕SONAM KUMAR💕Premium Call Girls Jaipur ↘️9257276172 ↙️One Night Stand With Lo...
 
Call Girls Madurai Just Call 9630942363 Top Class Call Girl Service Available
Call Girls Madurai Just Call 9630942363 Top Class Call Girl Service AvailableCall Girls Madurai Just Call 9630942363 Top Class Call Girl Service Available
Call Girls Madurai Just Call 9630942363 Top Class Call Girl Service Available
 
(Low Rate RASHMI ) Rate Of Call Girls Jaipur ❣ 8445551418 ❣ Elite Models & Ce...
(Low Rate RASHMI ) Rate Of Call Girls Jaipur ❣ 8445551418 ❣ Elite Models & Ce...(Low Rate RASHMI ) Rate Of Call Girls Jaipur ❣ 8445551418 ❣ Elite Models & Ce...
(Low Rate RASHMI ) Rate Of Call Girls Jaipur ❣ 8445551418 ❣ Elite Models & Ce...
 
Call Girls Vasai Virar Just Call 9630942363 Top Class Call Girl Service Avail...
Call Girls Vasai Virar Just Call 9630942363 Top Class Call Girl Service Avail...Call Girls Vasai Virar Just Call 9630942363 Top Class Call Girl Service Avail...
Call Girls Vasai Virar Just Call 9630942363 Top Class Call Girl Service Avail...
 
Call Girls Service Jaipur {8445551418} ❤️VVIP BHAWNA Call Girl in Jaipur Raja...
Call Girls Service Jaipur {8445551418} ❤️VVIP BHAWNA Call Girl in Jaipur Raja...Call Girls Service Jaipur {8445551418} ❤️VVIP BHAWNA Call Girl in Jaipur Raja...
Call Girls Service Jaipur {8445551418} ❤️VVIP BHAWNA Call Girl in Jaipur Raja...
 
Models Call Girls In Hyderabad 9630942363 Hyderabad Call Girl & Hyderabad Esc...
Models Call Girls In Hyderabad 9630942363 Hyderabad Call Girl & Hyderabad Esc...Models Call Girls In Hyderabad 9630942363 Hyderabad Call Girl & Hyderabad Esc...
Models Call Girls In Hyderabad 9630942363 Hyderabad Call Girl & Hyderabad Esc...
 
Night 7k to 12k Chennai City Center Call Girls 👉👉 7427069034⭐⭐ 100% Genuine E...
Night 7k to 12k Chennai City Center Call Girls 👉👉 7427069034⭐⭐ 100% Genuine E...Night 7k to 12k Chennai City Center Call Girls 👉👉 7427069034⭐⭐ 100% Genuine E...
Night 7k to 12k Chennai City Center Call Girls 👉👉 7427069034⭐⭐ 100% Genuine E...
 
Call Girl in Indore 8827247818 {LowPrice} ❤️ (ahana) Indore Call Girls * UPA...
Call Girl in Indore 8827247818 {LowPrice} ❤️ (ahana) Indore Call Girls  * UPA...Call Girl in Indore 8827247818 {LowPrice} ❤️ (ahana) Indore Call Girls  * UPA...
Call Girl in Indore 8827247818 {LowPrice} ❤️ (ahana) Indore Call Girls * UPA...
 

Charleston area medical center (camc) data breach – what can be learned

  • 1. Charleston Area Medical Center (CAMC) Data Breach – What Can Be Learned? It’s always educational to review a data security breach to see what can be learned. In the case of the Charleston Area Medical Center (CAMC) last month a number of lessons can be learned. First lets review what we know (and don’t know) about the data breach which happened at CAMC subsidiary CAMC Health Education Research Institute (CHERI). What Happened It was a pretty straight forward breach. Last month someone doing an online search for an address found that the name of a relative and their ePHI was readily accessible on a CAMC website via a Google search. He immediately notified the relative who in turn contacted the State of West Virginia Attorney General. The Attorney General’s Consumer Protection Division quickly had the offending site shut down. In all 3655 patients were involved with the breach whose data had been accessible on the site since September of 2010. The site was created by a contractor who inadvertently enabled access to the data. More Questions than Answers  If the contractor had access to ePHI, were they treated as a Business Associate (BA)?  Was there a Business Associate Agreement (BAA) in place?  Was protecting ePHI specified as an upfront feature/requirement of the site created by the contractor?  Was any application penetration testing performed on the site before it went live?  As a result of the breach CAMC has agreed to additional safeguards including a security assessment – does this imply that CAMC had not previously performed a HIPAA Risk Analysis?!?! Lessons Learned An ounce of prevention…: While we don’t know details of this particular vulnerability, it appears that an application penetration test would have identified the risk and enabled trivial remediation before an incident. That would be a fraction of the cost of this breach. Its hard to determine the CAMC brand damage and staff costs associated with a breach like this. And its too early to tell if the hospital will see HIPAA / HITECH Act fines associated with the incident. The Equifax credit monitoring cost is also unclear, though calculating the retail cost from their site at $15 per month per user for each of the 3655 individuals affected by the breach for a year tallies to over $54,000 per month and over $650,000 for the year …. a pound of cure. WEB PHONE EMAIL WWW.REDSPIN.COM 800-721-9177 INFO@REDSPIN.COM
  • 2. Security Assessments have more value before a breach: Well I am stating the obvious here, but there’s more to the point than the obvious fact that identifying this particular vulnerability early would be much less painful on the organization. The point is that, in our experience, incident-driven assessments are often knee-jerk reactions to a compliance issue that are completed more to show reaction and publicize respect for client ePHI rather than a core value-driven approach to secure operations. These types of assessments often cost way more and the value can be limited. The value of a security assessment is proportional to an organizations bandwidth to absorb the findings and willingness for organizational improvement. An event-driven assessment for CAMC will not yield a lot of value if the health IT staff is not ready to react to the findings. Ensure BAs are aware of the need to protect ePHI: When you outsource to a vendor, you are outsourcing the actual labor, but also to a certain extent security management. While you want to expect that a vendor would be aware of information security best practices you can’t always trust the BA to be secure. A robust BAA shows you care? While requiring a BA to complete a Business Association Self Assessment Questionnaire may not be appropriate for a web site developer, quizzing them on a secure software development life cycle might filter out incompetent developers and send a message that you care about their performance. WEB PHONE EMAIL WWW.REDSPIN.COM 800-721-9177 INFO@REDSPIN.COM