Nuviun
Register with nuviun FREE Log in
Register with nuviun Log in
  • digital health
    • Big Data
    • eHealth
    • EHR - EMR
    • Gamification
    • Health 2.0-Social Media in Healthcare
    • Health and Wellness Apps
    • Health IT
    • Interoperability
    • Medical Imaging
    • mHealth
    • Personal Genomics
    • Quantified Self
    • Sensors and Wearables
    • Telehealth/Telemedicine/Connected Health
    • Betting Sites UK
  • content library
    • Series
  • dashboard
  • directory
    • people
    • companies
  • events
nuviun
Content library
Massive Hospital Data Breach Linked To Heartbleed Bug

Massive Hospital Data Breach Linked To Heartbleed Bug

Published 25/08/2014 at 00:00 nuviun digital health Electronic Health Records (EHRs) Electronic Medical Records (EMRs) Health IT Security Privacy 0 comments

Using the computer bug called ‘Heartbleed’ -- hackers recently launched an unprecedented cyber attack on a large U.S. hospital system and stole the personal health data of 4.5 million patients.

The recent cyber attack on the computer systems of U.S. hospital group Community Health Systems (CHS) resulted to the theft of the personal health information of some 4.5 million patients. The data stolen included names, addresses, phone numbers, birth dates and social security numbers of patients in the hospital network, which operates at least 206 hospitals across 29 states.

Now, an information security expert claims that hackers had used the OpenSSL encryption security flaw called Heartbleed to stealthily gain access to the demographic records of CHS patients. OpenSSL is used by thousands of websites, data centers, mobile phones, and telecommunications systems to protect sensitive personal information. 

In a blog post, David Kennedy of TrustedSec, citing an anonymous and credible source close to the official investigation on the hacking, wrote that the “attackers were able to glean user credentials from memory on a CHS Juniper device via the Heartbleed vulnerability (which was vulnerable at the time) and use them to login via a VPN [virtual private network].” 

If verified, the breach is the largest attack carried out successfully using the Heartbleed bug since it was publicly disclosed in April. The vulnerability allows hackers unfettered and untraceable access to electronic health records (EHRs), patient portals, medical devices, insurance exchanges and telemedicine apps.

Kennedy told Reuters that the hackers used equipment made by Juniper Networks Inc. to hack CHS. The hackers used fake employee log-in credentials to tap into CHS’ database and steal millions of social security numbers and other information.

Shortly after the CHS disclosure, the FBI issued a warning to healthcare organizations and facilities of ongoing and impending cyber security threats. In a flash alert, the agency said, “The FBI has observed malicious actors targeting healthcare related systems, perhaps for the purpose of obtaining Protected Healthcare Information (PHI) and/or Personally Identifiable Information (PII).” 

“These actors have also been seen targeting multiple companies in the healthcare and medical device industry typically targeting valuable intellectual property, such as medical device and equipment development data,” the warning stated, according to Reuters.

CHS did not identify Heartbleed in its SEC filing about the hacking incident. However, the filing described the attack that happened in April and June emanated from China.

A patch has been made shortly after the Heartbleed flaw was discovered in April, and many companies scrambled to have the patch installed. But four months later, the attack on CHS is a reminder that many systems are still vulnerable. 

The FBI had warned in April that the healthcare industry’s computer security practices are not up to par with other industries, such as the financial sector. The recent data breach at CHS underscores that threat. 

But even though the criticism on the healthcare sector is warranted, updating massive systems in a short span of time may be logistically difficult, according to a cybercrime expert.

“Even though a patch might exist, it can be difficult to implement,” Lillian Ablon of RAND Corp. recently told Modern Healthcare. “Doing so may require slowing down or stopping business or a critical piece of equipment for testing or compliance requirements. So it's not as though people don't want to patch—they may just be hampered by other external issues. This leaves many still open and vulnerable.”

Nevertheless, the incident had given renewed urgency to the matter of vulnerable computer systems used in the healthcare industry.

“We’ve not been on the front lines as long as defense or finance… but I’m slowly starting to see that shift as I talk to my peers,” Reid Stephan, director of IT security at St. Luke’s Health System, said in a Wall Street Journal article.

Speaking during a monthly cyber threat briefing, Roy Mellinger, vice president and chief information security officer at insurance company WellPoint, acknowledged that the sector should beef up its security measures, and pointed out that what is crucial is to get “information across the sector to let healthcare executives know what is going on and if they are taking the right steps to keep data secure,” according to a FierceHealthIT report.

  

Log in or register for FREE for full access to ALL site features

As a member of the nuviun community, you can benefit from:

  • 24/7 unlimited access to the content library
  • Full access to the company and people directories
  • Unlimited discussion and commenting privileges
  • Your own searchable professional profile

Not yet a member?

Register now

Already a member?

Log in for immediate access:

Login failed, check your credentials and try again.

Author:

nuviun digital health
nuviun digital health View profile
Categorised:

Categorised:

  • Electronic Health Records (EHRs)
  • Electronic Medical Records (EMRs)
  • Health IT
  • Security
  • Privacy
Share with friends and colleagues
Discuss this post You must be logged in to comment on this post.
  • Most popular
  • Most recent
  • Oculus Rift in the Operating Room

  • One way healthcare providers can use big data to generate revenue fast

  • Why 2015 is the pivotal year for #digitalhealth

  • Talent to Task: The Digital Health Accelerator Dilemma

  • 7 Best Gamification Fitness Apps For 2015

  • 90 Healthcare Leaders Discuss Opportunities in Digital Health

  • nuvi & mo episode 9

  • Mitigating Hope and Hype: The Evolving Role of the Physician in the Era of eHealth

  • “You Click, We Care.” Profile in Digital Health: Raouf Khalil, CEO of Mobile Doctors 24/7

  • Solving the Innovation Puzzle with Partnerships: Our Second Day in India

  • The gaping privacy hole in healthcare data is not where you think

  • “Make them use it” is not a valid EMR adoption strategy

More by this author
  • Massive Hospital Data Breach Linked To Heartbleed Bug

    nuvi & mo episode 9

  • Massive Hospital Data Breach Linked To Heartbleed Bug

    nuvi & mo episode 8

  • Massive Hospital Data Breach Linked To Heartbleed Bug

    nuvi & mo episode 7

  • Massive Hospital Data Breach Linked To Heartbleed Bug

    nuvi & mo episode 6

  • Massive Hospital Data Breach Linked To Heartbleed Bug

    nuvi & mo episode 5

Related posts
  • Massive Hospital Data Breach Linked To Heartbleed Bug

    The gaping privacy hole in healthcare data is not where you think

  • Massive Hospital Data Breach Linked To Heartbleed Bug

    “Make them use it” is not a valid EMR adoption strategy

  • Massive Hospital Data Breach Linked To Heartbleed Bug

    Digital Health Rounds: Editor’s Progress Notes—March2015, Friday #2

  • Massive Hospital Data Breach Linked To Heartbleed Bug

    What you don’t know about digital health in Canada can help you

  • Massive Hospital Data Breach Linked To Heartbleed Bug

    Doctors don't NEED Digital Health

  • Massive Hospital Data Breach Linked To Heartbleed Bug

    Digital Health Rounds: Editor’s Progress Notes—March2015, Friday #1

Digital Health Live 2015

Dubai World Trade Center

May 5th - 7th 2015

Doctors 2.0 and you - Paris 4th and 5th of June 2015
Explore nuviun
  • Home
  • About nuviun
  • Join our team
  • Contact nuviun
  • Site map
  • Privacy and cookies
  • Terms and conditions
Dashboard
  • Dashboard
  • Content Library
  • Subscriptions
  • Directory
  • Edit profile
  • My account
Connect with us
facebook linkedin twitter
© 2015 Nuviun. All rights reserved. MintTwist CMS Websites

nuviun.com uses cookies to enhance your experience. By using this site you agree to have cookies placed on your computer. To learn more, please see our cookies policy and privacy policy pages. Thanks for reading.

Apologies

These features are reserved for registered users of nuviun.com. Registration is FREE.

It's simple to:

  • log in if you've already registered
  • or super quick to register a new account if you don't have one yet.
Log inRegister with nuviun

You have unfavourited the article [title]