Events Calendar

Mon
Tue
Wed
Thu
Fri
Sat
Sun
M
T
W
T
F
S
S
30
31
1
2
3
4
5
6
7
8
9
10
11
13
14
15
17
18
20
21
22
23
24
26
27
28
29
30
1
2
3
2015 HIMSS Annual Conference & Exhibition
2015-04-12 - 2015-04-16    
All Day
General Conference Information The 2015 HIMSS Annual Conference & Exhibition, April 12-16 in Chicago, brings together 38,000+ healthcare IT professionals, clinicians, executives and vendors from [...]
2015 CONVENTION - THE MEDICAL PROFESSION: TIME FOR A NEW SOCIAL CONTRACT
The 17th QMA's convention will be held April 16-18, 2015. The Québec Medical Association (QMA) invites you to share your opinion on the theme La profession médicale : vers un nouveau [...]
HCCA's 19th Annual Compliance Institute
2015-04-19 - 2015-04-22    
All Day
April 19-22, 2015 Lake Buena Vista, FL Early Bird Rates end January 7th The Annual Compliance Institute is HCCA’s largest event. Over the course of [...]
AAOE Annual Conference 2015
2015-04-25 - 2015-04-28    
All Day
AAOE Annual Conference 2015 The AAOE is the only professional association strictly dedicated to orthopaedic practice management. Currently, our membership has over 1,300 members in [...]
63rd ACOG ANNUAL MEETING - Annual Clinical and Scientific Meeting
2015-05-02 - 2015-05-06    
All Day
The 2015 Annual Meeting: Something for Every Ob-Gyn The New Year is a time for change! ACOG’s 2015 Annual Clinical and Scientific Meeting, May 2–6, [...]
Events on 2015-04-12
Events on 2015-04-19
Events on 2015-04-25
AAOE Annual Conference 2015
25 Apr 15
Chicago, IL 60605
Articles

Dec 13: VA Takes Action After Grad Student Finds Flaw in EHR System

ipatientcare

Federal officials have released a software patch to fix a flaw in the Department of Veterans Affairs’ VistA electronic health record (EHR system) that was discovered by a Georgia Institute of Technology graduate student, GCN reports (Hickey, GCN, 12/10).

Details of Security Flaw

Graduate student Doug Mackey found the remote access security flaw while working on a final project for his master’s degree.

He said the flaw means “some remote messages are not properly security checked, and a remote unauthenticated or unauthorized user can execute any of thousands of database operations.”

However, Mackey noted that “an adversary would first have to stage an operation to gain access to an internal network” before taking advantage of the flaw because VistA is not connected to the Internet.

Mackey said he was particularly concerned that the vulnerability was introduced in 2002 and not found by anyone for more than a decade (Ouellette, Health IT Security, 12/9).

He said the flaw could have been used to perform “thousands” of remote commands within the VistA system without authorization (GCN, 12/10).

VA, OSEHRA Response

VA and the not-for-profit Open Source Electronic Health Record Agent worked from June to early November to create a software patch to fix the flaw.

Don Hewitt, vice president of business operation at OSEHRA, said Mackey’s discovery “was the first time that we’ve seen a security issue arise from the [open-source] community.”

Hewitt added, “We view this as a validation of the fact that you can get better security with open source as you get more sets of eyes on the code”

source