Most Popular Stories
- BIDMC leadership ripped for inaction against Levy
- Doctors and hospitals must play together or risk extinction
- Mayo tells more than 3,000 patients of possible Hepatitis C infection
- Unlicensed doc's multistate abortion operation under investigation
- Resident work hours need more regulation, advocacy groups argue
- Inventor of single-electrode wireless EEG monitor named to MIT innovators list
- Leading health plan CEO paychecks
- 15 Free Healthcare Apps for the iPhone
- Aetna is best health plan, UnitedHealthcare is worst, hospital execs say
- Nurses' jobs at risk for allegedly posting patient info on Facebook
- UnitedHealthcare contracts stop making no-warning fee changes
- WI nurses fired over cell photos of X-ray
Featured Jobs
-
Pharmacist opening
CompHealth - Metropolitan area, IA -
Director of Sales for Fast Growing CA Start-up
BAM Labs, Inc. - San Jose, CA
Featured Jobs from Healthcare IT Central
Events
Paid Research Reports
- Electronic health records: getting it right first time
- Cloud Computing Adoption In The APAC Life Sciences Industry
- Stakeholder Opinions: Ophthalmology - Leading brands under threat
- Genomics, Proteomics and Metabolomics in Diagnostics: Market landscape, innovative technologies and future outlook
- Healthcare Regulatory Update: The United Arab Emirates
- Point of Care Testing: Evaluating the return to evidence based medicine, novel technologies and the competitive landscape
Be sure to checkout FierceEMR for Meaningful Use updates!
Latest News
Free Newsletter
FierceHealthIT is the leading source of Healthcare IT news with a special focus on CPOE, EMR adoption, HIPAA compliance and other critical areas. Join 30,000+ healthcare industry insiders who get FierceHealthIT via weekly email for their must know IT news. Sign up today!
About | View Sample | Privacy
Top Tags
Headlines from HIStalk News
Whitepapers
- Member Correspondence: 8 Things You Need to Know
- High-Impact Hospitality: Creating Experience-Based Differentiation
- Enterprise Security for the Healthcare Industry – Assuring Regulatory Compliance, ePHI Protection and Secure Healthcare Delive
- Healthcare Megatrends: The Future of Healthcare Financing and Delivery
- Can a National Healthcare Information Network Work?
- The Hidden Benefits (and Costs) of Electronic Provider Payment - More Than Saving a Stamp?
We never sell or give away your contact information. Our reader's trust comes first.
CMS security holes expose patient data
A new study by the Government Accountability Office has concluded that the systems used by the Centers for Medicare and Medicaid Services (CMS) to send and receive bills and communicate with providers are riddled with at least 47 security holes. According to the GAO, the CMS network hasn't implemented sufficiently secure user identification and authentication, user authorization, system boundary protection, cryptography, and auditing and security event monitoring. CMS also failed to make sure that network users' duties were adequately segregated and that network devices were configured securely, GAO said. It seems that the contractor managing the CMS network--for how much longer, we wonder?--has not always followed CMS security guidelines.
As a result, intruders could theoretically have accessed highly confidential data, including a patient's name, sex, date of birth, Social Security number, mailing address, diagnosis, prescribed drugs and physician's name. In a public statement responding to the report, CMS administrator Mark McClellan said that 22 of the holes have been patched since the audit was done in late 2005, though he admitted that as many as 17 others might not be fixed until January 2007 or beyond. McClellan did insist that no one had discovered and exploited these vulnerabilities as of yet. Still, something is definitely broken: in fact, a previous GAO study found that 40 percent of CMS Medicaid, Medicare and Tricare contractors had seen breaches of private healthcare information. Would security-lax contractors still have a job if they were working for private industry? If not, why are they still getting tax dollars? Your guess is as good as mine.
To get more details on CMS's security woes:
- check out this piece from TechWeb
- read the GAO report (.pdf)
Related Stories
- VA could spend $20M on data breach response
- MN requires insurers, providers to file electronically
- GAO warns of widespread ID security breaches
- Massive data loss at HCA
- GAO says HHS isn't protecting medical data privacy adequately
- Major problems remain with quality data collection
- HHS backs genetics-driven, HIT-focused healthcare
- HHS grants improve Medicaid data management
- Maine struggles with Medicaid billing system
- GAO: Gov't HIT efforts lack privacy, security
Comments
Post new comment
Home
| Subscribe | Advertise | Mobile Edition | RSS |
Privacy
| Site Map | List in Marketplace | Supplier in MarketplaceTHE FIERCEMARKETS NETWORKFierceFinance | FierceFinanceIT | FierceComplianceIT | FierceHealthcare | FierceHealthFinance | FierceHealthIT | Hospital Impact | FierceMobileHealthcare | FierceHealthPayer | FiercePracticeManagement | FierceCIO | FierceCIO:TechWatch | FierceContentManagement | FierceMobileIT | FierceGovernmentIT | FierceBiotech | FierceBiotech Research | FiercePharma | FierceVaccines | FierceBiotechIT | FiercePharma Manufacturing | FierceMedicalDevices | FierceDrugDelivery | FierceIPTV | FierceOnlineVideo | FierceTelecom | FierceVoIP | FierceBroadbandWireless | FierceDeveloper | FierceMobileContent | FierceWireless | FierceWireless:Europe | FierceCable© 2010 FierceMarkets. All rights reserved. |
![]() |
