Events Calendar

Mon
Tue
Wed
Thu
Fri
Sat
Sun
M
T
W
T
F
S
S
30
1
2
3
4
5
6
7
8
9
10
11
12
13
14
15
16
17
18
19
20
21
24
25
26
27
28
29
30
1
2
3
MedInformatix Summit 2014
2014-07-22 - 2014-07-25    
All Day
MedInformatix is excited to present this year’s meeting! 07/22 Tuesday Focus: Product Development Highlights:Latest Updates in Product Development, Interactive Roundtables, and More. 07/23 Wednesday Focus: Healthcare Trends [...]
MMGMA 2014 Summer Conference
2014-07-23 - 2014-07-25    
All Day
Mark your calendar for Wednesday - Friday, July 23-25, and join your colleagues and business partners in Duluth for our MMGMA Summer Conference: Delivering Superior [...]
This is it: The Last Chance for EHR Stimulus Funds! Webinar
2014-07-31    
10:00 am - 11:00 am
Contact: Robert Moberg ChiroTouch 9265 Sky Park Court Suite 200 San Diego, CA 92123 Phone: 619-528-0040 ChiroTouch to Host This is it: The Last Chance [...]
RCM Best Practices
2014-07-31    
2:00 pm - 3:00 pm
In today’s cost-conscious healthcare environment every dollar counts. Yet, inefficient billing processes are costing practices up to 15% of their revenue annually. The areas of [...]
Events on 2014-07-22
MedInformatix Summit 2014
22 Jul 14
New Orleans
Events on 2014-07-23
MMGMA 2014 Summer Conference
23 Jul 14
Duluth
Events on 2014-07-31
Latest News

Apr 15: ‘Heartbleed’ Bug Could Affect Health Care Industry, Experts Warn

ehr replacement

Hospitals’ and providers’ online networks — including email accounts, electronic health records and remote monitoring devices — could be vulnerable to an encryption bug called “Heartbleed,” according to security experts, Modern Healthcare reports (Conn, Modern Healthcare, 4/11).

About the Bug

Last week, a Google engineer and another security team discovered the bug and found that it infiltrates systems through a Web encryption program known as OpenSSL, which is used by hundreds of thousands of websites including Amazon and Google (Finkle, Reuters, 4/10). Experts say that hackers could potentially use the program to get sensitive information from:

  • Email servers;
  • Laptops;
  • Mobile phones; and
  • Security firewalls.

Potential Implications

At this point, it is unclear if the nation’s health care providers are especially vulnerable. For example, CynergisTek CEO Mac McMillan said Web networks that rely on two- or three-factor password authentication should be safe (Wicklund, mHealthNews, 4/11).

However, David Harlow, principal of health care law Harlow Group, warned that health groups that do not rely on OpenSSL should be worried about ramifications of the massive breach. He said, “Heartbleed can set back trust in health IT that has been building as it proliferates, and as the protections under HIPAA/HITECH are baked into the policies and procedures of more and more vendors” (Bowman, FierceHealthIT, 4/11).

Further, security vendor Trend Micro in a blog post on Thursday raised concerns about threats to mobile phone applications, such as health care applications that use individuals’ personal and financial data (Vijayan, ComputerWorld, 4/11).

No Threat to Federal Websites, Officials Say

Meanwhile, officials from the Department of Homeland Security noted that the government’s main public websites were not affected by the bug.

Specifically, CMS on Thursday said the vulnerability did not affect consumer accounts on the federal health insurance exchange or the Medicare website, MyMedicare.gov (Sternstein, NextGov, 4/11).

Comments

McMillan said the issue “is huge … it’s servers, it’s appliances, it’s devices,” adding that the bug has been around for about two years and that experts do not know how many breaches may have already happened.

Although government agencies and private companies are rushing to fix vulnerabilities, breaches may not be detected for a long time, if at all.

“It’s going to be a long, long time before they truly understand the scope of this,” McMillan said.

CloudFlare CEO Matthew Prince called Heartbleed “the worst bug the Internet has ever seen,” adding, “If a week from now we hear criminals spoofed a massive number of accounts of financial institutions, it won’t surprise me” (mHealthNews, 4/11). Source