Nuviun
Register with nuviun FREE Log in
Register with nuviun Log in
  • digital health
    • Big Data
    • eHealth
    • EHR - EMR
    • Gamification
    • Health 2.0-Social Media in Healthcare
    • Health and Wellness Apps
    • Health IT
    • Interoperability
    • Medical Imaging
    • mHealth
    • Personal Genomics
    • Quantified Self
    • Sensors and Wearables
    • Telehealth/Telemedicine/Connected Health
    • Betting Sites UK
  • content library
    • Series
  • dashboard
  • directory
    • people
    • companies
  • events
nuviun
Content library
Health IT Security Shellshocked by Bash Bug

Health IT Security Shellshocked by Bash Bug

Published 14/10/2014 at 00:00 Jof Enriquez, RN Electronic Health Records (EHRs) Electronic Medical Records (EMRs) Health IT Security Privacy 0 comments

Potentially more dangerous than Heartbleed, the Bash computer bug could be exploited by hackers who may be able to access a wide range of digital health systems—including computers running electronic medical records, websites, hospital equipment and medical devices.

With stolen medical records now worth 10-20 times more than credit card information on the black market, the discovery of another vulnerability that hackers can exploit does little to allay patients’ fears about the use of digital health services—as well as digital health and wellness devices.

Computer security experts recently discovered a bug in Unix-based operating systems that run:

  • Healthcare websites
  • Electronic medical records
  • Health IT systems
  • Hospital equipment
  • Medical devices

It’s yet another warning for a healthcare industry that’s getting increasingly vulnerable to cyber attacks.

Health IT Industry Shellshocked by Bash Bug

The bug—called “Bash” or “Shellshock”—can be exploited by hackers to potentially interact with a system, rather than to merely gain access and spy on data like what the Heartbleed bug allows, said a Reuters report.

Linux distribution companies and security firms have scrambled to release patches to address the Bash bug, and medical device makers are expected to do the same in coming weeks.

“An unknown number of devices may contain the flaw, including millions of stand-alone Web servers, Unix and Mac OS X systems, and numerous other Internet-connected devices,” according to a Healthcare Info Security report.

Apache servers—which run half of the 1 billion servers connected to the Internet—run Linux and the Bash command shell installed with it by default.

“It's quite common for embedded devices with Web-enabled front-ends to shuttle user input back and forth via Bash shells, for example - routers, SCADA/ICS devices, medical equipment, and all sorts of webified gadgets are likely to be exposed,” Tod Beardsley, engineering manager at Rapid7, told Healthcare Info Security. 

Multiple Warnings Issued

The US-CERT (United States Computer Emergency Readiness Team) had issued a statement saying that it is:

“aware of a Bash vulnerability affecting Unix-based operating systems such as Linux and Mac OS X. Exploitation of this vulnerability may allow a remote attacker to execute arbitrary code on an affected system.”

The HITRUST Cyber Threat Intelligence and Incident Coordination Center (C3) likewise issued an alert:

“to ensure healthcare organizations are appropriately informed and taking steps to safeguard their systems and have sufficient information to communicate the background and implications to others in their organizations.”

HITRUST cited security analyst Troy Hunt, who said that:

“50 percent of web servers use Bash to run commands and that many Internet of Things (IoT) devices and OS X-based servers use Bash—suggesting that even more servers have the Shellshock vulnerability.”

Health IT Security Troubles

The discovery of the Bash bug comes a month after officials discovered that a hacker breached a server of the HealthCare.gov insurance exchange portal.

Weeks earlier, hackers used the Heartbleed flaw to steal 4.5 million patient records of U.S. hospital group Community Health Systems (CHS), which operates 206 hospitals in 29 states.

In another investigation, an unidentified large U.S. healthcare organization with 3,000 doctors and 2,000 other workers was found to be leaking data, making hospital equipment such as defibrillators and insulin pumps vulnerable to outsiders.

According to a survey by the Ponemon Institute, the percentage of healthcare organizations that have reported criminal cyber attacks has doubled to 40% in 2013 from 20% in 2009.

About 90% of the facilities it surveyed encountered hacking attempts last year alone.

The FBI’s Warning to Healthcare

The spike in the number of cyber attacks has prompted the FBI to issue a warning to healthcare organizations:

"The FBI has observed malicious actors targeting healthcare related systems, perhaps for the purpose of obtaining Protected Healthcare Information (PHI) and/or Personally Identifiable Information (PII)," the FBI said in an alert. "These actors have also been seen targeting multiple companies in the healthcare and medical device industry typically targeting valuable intellectual property, such as medical device and equipment development data."

The FDA Addresses Medical Device Security

Meanwhile, the U.S. Food and Drug Administration (FDA), in coordination with the U.S. Department of Homeland Security, is holding a workshop/conference in October to address cybersecurity.

According to a Washington Post article, the gathering of cybersecurity experts is to engage in:

"identifying cybersecurity gaps and challenges, especially end-of-life support for legacy devices and interconnectivity of medical devices."

The FDA is stepping up efforts to strengthen the medical device industry against hacking attempts since hackers broke into the computer networks of Medtronic, St. Jude Medical and Boston Scientific last year.

Government authorities and computer experts continue to encourage healthcare organizations to beef up their Health IT cybersecurity measures amid increasing threats. Heartbleed and Bash are likely to be the first of many exploits that are yet to be discovered.

Hackers who covet medical information will have plenty of targets as more facilities and providers shift to using electronic health records (EHR), ehealth technologies, and other applications of digital health innovation in the future.

Log in or register for FREE for full access to ALL site features

As a member of the nuviun community, you can benefit from:

  • 24/7 unlimited access to the content library
  • Full access to the company and people directories
  • Unlimited discussion and commenting privileges
  • Your own searchable professional profile

Not yet a member?

Register now

Already a member?

Log in for immediate access:

Login failed, check your credentials and try again.

Author:

Jof Enriquez, RN
Jof Enriquez, RN View profile
Categorised:

Categorised:

  • Electronic Health Records (EHRs)
  • Electronic Medical Records (EMRs)
  • Health IT
  • Security
  • Privacy
Share with friends and colleagues
Discuss this post You must be logged in to comment on this post.
  • Most popular
  • Most recent
  • Oculus Rift in the Operating Room

  • One way healthcare providers can use big data to generate revenue fast

  • Why 2015 is the pivotal year for #digitalhealth

  • Talent to Task: The Digital Health Accelerator Dilemma

  • 7 Best Gamification Fitness Apps For 2015

  • 90 Healthcare Leaders Discuss Opportunities in Digital Health

  • nuvi & mo episode 9

  • Mitigating Hope and Hype: The Evolving Role of the Physician in the Era of eHealth

  • “You Click, We Care.” Profile in Digital Health: Raouf Khalil, CEO of Mobile Doctors 24/7

  • Solving the Innovation Puzzle with Partnerships: Our Second Day in India

  • The gaping privacy hole in healthcare data is not where you think

  • “Make them use it” is not a valid EMR adoption strategy

More by this author
  • Health IT Security Shellshocked by Bash Bug

    Doxunity: A Collaboration Platform For Physicians In The Middle East

  • Major Healthcare Initiative Forecasts the Future of Digital Health in the U.K.

  • Health IT Security Shellshocked by Bash Bug

    Dubai’s Smart City a Smart Model for Others

  • A Paradigm Shift for Healthcare Partnerships: EHRs and Mobile Apps

  • Digital Health in Japan: Medical and Personal Care Robots for a Rapidly Aging Society

Related posts
  • Health IT Security Shellshocked by Bash Bug

    The gaping privacy hole in healthcare data is not where you think

  • Health IT Security Shellshocked by Bash Bug

    “Make them use it” is not a valid EMR adoption strategy

  • Health IT Security Shellshocked by Bash Bug

    Digital Health Rounds: Editor’s Progress Notes—March2015, Friday #2

  • Health IT Security Shellshocked by Bash Bug

    What you don’t know about digital health in Canada can help you

  • Health IT Security Shellshocked by Bash Bug

    Doctors don't NEED Digital Health

  • Health IT Security Shellshocked by Bash Bug

    Digital Health Rounds: Editor’s Progress Notes—March2015, Friday #1

Digital Health Live 2015

Dubai World Trade Center

May 5th - 7th 2015

Doctors 2.0 and you - Paris 4th and 5th of June 2015
Explore nuviun
  • Home
  • About nuviun
  • Join our team
  • Contact nuviun
  • Site map
  • Privacy and cookies
  • Terms and conditions
Dashboard
  • Dashboard
  • Content Library
  • Subscriptions
  • Directory
  • Edit profile
  • My account
Connect with us
facebook linkedin twitter
© 2015 Nuviun. All rights reserved. MintTwist CMS Websites

nuviun.com uses cookies to enhance your experience. By using this site you agree to have cookies placed on your computer. To learn more, please see our cookies policy and privacy policy pages. Thanks for reading.

Apologies

These features are reserved for registered users of nuviun.com. Registration is FREE.

It's simple to:

  • log in if you've already registered
  • or super quick to register a new account if you don't have one yet.
Log inRegister with nuviun

You have unfavourited the article [title]