Most Popular Stories
Featured Jobs
-
NH Nurse Counselor-Managed Care
StaffPointe, LLC - near Salem , NH -
Kansas PMR Physician
StaffPointe, LLC - northeast , KS -
Georgia Nurse Unit Director
StaffPointe, LLC - Atlanta , GA -
Iowa Occupational Therapist
StaffPointe, LLC - north , IA -
Indiana OB/GYN JH1002
StaffPointe, LLC - central , IN
Events
- CIO Healthcare Summit
May 10-13 — Scottsdale, AZ - Four Seasons - Healthcare Conference at Harvard Business School on January 17, 2009
- National Health Policy Conference (NHPC)
Feb 2-3, 2009 — Washington, DC
Paid Research Reports
- Stakeholder Opinions: Percutaneous Coronary Intervention - Adverse events with drug-eluting stents demand a new safety standard
- Impact of Pharmacogenomics on Public Healthcare Policy
- The Cardiovascular Disorders Market Outlook to 2012
- 2008 Trends to Watch: Pharmaceutical Technology
- Pharmaceutical Pricing and Reimbursement: Strategies for market access across the US, Europe, Japan and other key geographies
- Emerging markets series: Benchmarking key countries Brazil, Russia, India, China and Turkey
Free Newsletter
FierceHealthIT is the leading source of Healthcare IT news with a special focus on CPOE, EMR adoption, HIPAA compliance and other critical areas. Join 25,000+ healthcare industry insiders who get FierceHealthIT via weekly email for their must know IT news. Sign up today!
About | View Sample | Privacy
Latest News
Popular Topics
Whitepapers
- Premerus Issues Study Addressing Medical Misdiagnosis in America 2008
- Opening the Doors to India: Opportunities and Challenges of Offshoring Medical Device
- Palm Valley Health Care finds the right support Rx for smartphones
- New from IBM! Healthcare 2015: The Future of Care Delivery
- HIPAA Compliance and Smart Cards: Solutions to Privacy and Security Requirements
- EMR Return on Investment: Improving Efficiency and Quality with an Electronic
CMS security holes expose patient data
A new study by the Government Accountability Office has concluded that the systems used by the Centers for Medicare and Medicaid Services (CMS) to send and receive bills and communicate with providers are riddled with at least 47 security holes. According to the GAO, the CMS network hasn't implemented sufficiently secure user identification and authentication, user authorization, system boundary protection, cryptography, and auditing and security event monitoring. CMS also failed to make sure that network users' duties were adequately segregated and that network devices were configured securely, GAO said. It seems that the contractor managing the CMS network--for how much longer, we wonder?--has not always followed CMS security guidelines.
As a result, intruders could theoretically have accessed highly confidential data, including a patient's name, sex, date of birth, Social Security number, mailing address, diagnosis, prescribed drugs and physician's name. In a public statement responding to the report, CMS administrator Mark McClellan said that 22 of the holes have been patched since the audit was done in late 2005, though he admitted that as many as 17 others might not be fixed until January 2007 or beyond. McClellan did insist that no one had discovered and exploited these vulnerabilities as of yet. Still, something is definitely broken: in fact, a previous GAO study found that 40 percent of CMS Medicaid, Medicare and Tricare contractors had seen breaches of private healthcare information. Would security-lax contractors still have a job if they were working for private industry? If not, why are they still getting tax dollars? Your guess is as good as mine.
To get more details on CMS's security woes:
- check out this piece from TechWeb
- read the GAO report (.pdf)
Related Stories
- Massive data loss at HCA
- GAO says HHS isn't protecting medical data privacy adequately
- Maine struggles with Medicaid billing system
- HHS grants improve Medicaid data management
- HHS backs genetics-driven, HIT-focused healthcare
- VA could spend $20M on data breach response
- Major problems remain with quality data collection
- MN requires insurers, providers to file electronically
- GAO warns of widespread ID security breaches
- GAO: Gov't HIT efforts lack privacy, security
Comments
Post new comment
Home
| Subscribe | Advertise | Mobile Edition | RSS |
Privacy
| Site MapTHE FIERCEMARKETS NETWORKFierceFinance | FierceFinanceIT | FierceSarbox | FierceHealthcare | FierceHealthFinance | FierceHealthIT | Hospital Impact | FierceCIO | FierceCIO:TechWatch | FierceContentManagement | FierceMobileIT | FierceBiotech | FierceBioResearcher | FiercePharma | FierceVaccines | FierceIPTV | FierceOnlineVideo | FierceTelecom | FierceVoIP | FierceBroadbandWireless | FierceDeveloper | FierceMobileContent | FierceWireless | FierceWireless:Europe© 2008 FierceMarkets, Inc. All rights reserved. |
![]() |





