Showing posts with label medical. Show all posts
Showing posts with label medical. Show all posts

Wednesday, April 1, 2015

Healthcare in the Crosshairs

Is Healthcare the new Target?

bullseye-targetRecently I've received a number of 'I am writing to inform you that we were the target of a sophisticated cyber attack and some of your personal information may have been accessed by the attackers..' letters for myself and my family. I especially hate the ones that start, 'To the parents of...' because my daughter has a rare genetic condition. You probably got one of these letters too since the Anthem breach could have disclosed medical records for as many as 80 million people.

Medical identity theft is big business and has become a huge target over the last few years. The attackers are not really interested in that sprained ankle or those 25 stitches from last summer. They want the personally identifiable information. Names, addresses, birthdays, and social security numbers. Stuff you can actually use to open accounts, commit insurance fraud and create fake identities - using real information. Healthcare info also goes for a premium on black market sites. One expert noted that recently that at one underground auction, a patient medical record sold for $251 while credit cards are selling at .33 cents. With all the recent retail breaches, credit cards have flooded the underground, plus they can get cancelled quickly. I also know that fraudsters are already trying to entice people with fake emails and calls regarding the breaches - I've gotten a bunch of them recently. More than ever, do not click the email link unless you're expecting something.

The interesting phenomenon for me is all the identity theft protection offerings from various credit bureaus. One breach, sign up here...another breach, sign up there. It is important to take advantage of the services to stay alert on your identity but you also have to include the very same sensitive info that was just compromised to yet another entity. I'm waiting on the breach of one of these identity protection sites. I mean the thieves must be thinking, 'well, we missed them in the medical grab but maybe we can get them through the protection app.'

According to Ponemon Institute, about 90% of healthcare organizations have reported at least one data breach over the last two years with most due to employee negligence or system flaws but more, as we've seen recently, are due to criminal behavior. Certainly, there will be more of these healthcare hiccups in the coming years especially with the push to digitize medical records. Great for patient access but a huge risk for unauthorized peeks. With the Premera breach hot on Anthem's heels, I hope providers are getting the message that the bad guys are coming for ya.

ps

Related

.

 

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Wednesday, October 22, 2014

The Internet of...(Drum Roll Please)...Band-Aids?!?

Last week I told you about my family's experience with an under the skin glucose sensor that tracks blood sugar levels. While this Internet of Things trend often takes the form of a thermostat, light bulb or coffee machine, the medical field has been using sensors for a while and it is about to get even more connected with your skin.

We're talking skin tags of a different kind.

bandaid asile First up is a sensor filled smart bandage. Ed Goluch, an assistant professor of chemical engineering at Northeastern University is working on a smart band-aid that will monitor infections and alert the person. He was investigating how individual bacteria cells behave by using a sensor. The sensor measured the produced toxins and how cells reacted to antibiotics when the idea hit. Next they build an electrochemical sensor with computer chips to detect Pseudomonas aerug­i­nosa, a bacteria that commonly takes advantage of people with compromised immune systems. For this particular bacteria, it can detect of an infection is starting before symptoms show and the patient can put an antibiotic on the wound to heal it. So far the testing has only occurred in the lab and the next step is humans and animals. Pretty Cool.

In Japan, University of Tokyo, in cooperation with JST, has introduced the world’s very first flexible wireless organic sensor. This paper-thin, water proof sensor can also be used for band-aids but also a few other health situations. Like urine. OMG! Did he just write the word for pee in a blog post?!? Yup, we all do it but back to the story. The idea is to be able to detect the chemical compound for health related matters. The circuit was actually tested on a wet diaper where it was successfully able to transmit the needed data and receive power from a nearby source. The cool thing about this sensor is that they wanted to develop something that is easy to make, use, xNT_package_front-700x700 dispose and replace. Instead of expensive components, they went for simple detectors for thing like humidity and air pressure. Being small and low cost, they could be used for such disposable things like diapers or bandages.

Next up is a microchip that can now be printed directly on the skin. Originally designed for sports physicians, MC10 has created a health sensor that is formed with spray-on bandage material. Since it is essentially a second skin, it can detect hydration levels and temperature of the wearer. It lasts about two weeks on the body even while bathing or swimming and it is 1/30 the size of previous sticker sensors.

Lastly, the iPhone 6 and it's NFC (near field communications) chip has been one upped by a human. Robert J. Nelson has had a NFC chip implanted in his hand! We've seen stories the past couple years about body modification with chips so he isn't the first but for $99 he picked up a chipset and got someone to implant it. In his story he states,

'I should make it clear that I am not trying to become a cyborg or anything like that. For me, getting this implant came down to having a strong interest in technology and the connected space, and more to the point is that I am someone who likes seeing technology integrated into life. Or in this case, my body'

Seriously, wouldn't be cool if you twisted your ankle and your sock would tell you how bad the sprain was? And then sent the data to your doctor for an appointment if it was serious? Or just quickly cooled down so you have ice around the sprain? Dizzying, all the applications for this.

Forget about the internet being this thing we use to look up stuff and email...soon we all will be part of the internet with our connected bodies. The Internet of You!

ps

Related:

 

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Tuesday, October 14, 2014

My Sensored Family

The Important Things

IMG_1360 Lately I've been writing a bunch about the Internet of Things or IoT. You know, where everyday objects have software, chips, and sensors to capture data and report back. Household items like refrigerators, toilets and thermostats along with clothing, cars and soon, the entire home will be connected. Many of these devices provide actionable data - or just fun entertainment - so people can make decisions about whatever is being monitored. It can also help save lives.

Recently my daughter became a robot, at least according to her.

My daughter has a rare genetic disorder called HI/HA GDH - Hyperinsulinism/Hyperammonemia Syndrome in the Glutamate Dehydrogenase gene. Say that 3 times fast. Basically, she produces too much insulin (extreme hypoglycemic) and too much ammonia. She gets blood work done every couple months and recently we've had some concerning numbers on those reports. While we certainly check her blood multiple times a day, the doctor wanted to get a more precise reading over the course of a few days to determine a plan of action. Enter the sensor.

IMG_1358 The doctor installed a Medtronic Sof-Sensor Glucose meter which measured her blood sugars every 5 minutes and stored it on a chip. They also have models which transmit the BSL to a base for instant readings. Out of the package, the device has a needle almost tented over the sensor. You put it in an apparatus which punches the needle and sensor into the skin. You remove the needle and the sensor stays. You then connect it to a clam shell looking thing which houses the microprocessor. Tape over it, go on with your daily routine and the sensor does the rest. While she had hers in for 3 days, there are some that can be inserted for longer term measurements. After our three days, we pulled it out and retuned it to the doctor. Pulling the tape off her skin hurt more than yanking the sensor out.

They connected the storage to a computer and retrieved the data. We could match the charted times and readings (along with a daily food diary) with the regular meter readings to get a great overall picture of what might be causing some of the recent abnormalities. From that, we got our medical marching orders and so far it seems like things are moving in the right direction. The parental worries have also dwindled now that we know what's going on. That anxiety is part of the challenge whether you're a global business or a parent...the data and context to make informed, knowledgeable decisions about a path forward. Sometimes sensors can provide that.

This Internet of Nouns trend is still in the early stages and many of our already connected gadgets do provide human benefits over the typical infotainment. While IoT is certainly interesting and the wave is building, I'm not particularly rushing to get everything or everyone connected like that...except for our micro chipped dog. But in this instance, installing a sensor in my daughter's side for a few days made all the difference in the world.

And gave us some uncensored peace of mind.

ps

Related

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Wednesday, October 30, 2013

Identity Theft Hits Close to Home

While certainly not the likes of having SWAT show up at my house like Krebs or even Honan's fiasco, we've had some ID theft attempts occurring for the past few months...actually my wife has.

It all started innocently enough at a child's birthday party. 

We were invited to a now ex-friend's house for a kid's birthday party this past April.  We were told it would be a small gathering of a few close friends.  Usually, when we attend things like this, my wife will leave her purse covered, locked in the car.  In this instance, thinking it was a small group, she took her purse in.  To our surprise, this was not some small get-together, as we were told, but a big party with numerous parents, kids and jump bouncers in back.  Many people we had never met.  That's cool, meet some new families with kids around the same age.  Almost immediately, the 'host' told my wife that she would put her purse in the home office where it would be 'safe.'  At the time, we didn't think anything of it since we had been to this house numerous times and had trusted the family.

The following week, my wife mentioned that she couldn't find a couple credit cards but thought she had misplaced them.  'They gotta be around somewhere.'  You know the phrase.  After another week of not being able to locate them, she called the card companies and requested replacements.  At that point, nothing, as far we knew was amiss. 

A couple weeks later, we get a letter from the credit card company (the one we replaced) saying they were not able to change the mailing address of our cards since certain security verification was not provided.  This was for the old, just replaced card.  Clearly not knowing that we had already cancelled and replaced the card, the thief attempted to change the mailing address for our account.  What?!?  But couldn't provide a photo ID with the new address or the secret squirrel settings so it was denied.  Nice.  We asked the card company for details and they could only provide the basics: it happened, verification failed, it stopped.  But don't you have caller ID?...Can't you go back and look?....What question failed?  Nothing.  See, while potential fraud was potentially attempted, it never actually occurred since it was not successful...thus no investigation.  I can understand.

We locked and froze and alerted the credit community.

Another couple weeks go by and due to the alerting in place, my wife gets a call asking if she's currently attempting making a purchase of some high end sunglasses online.  She wasn't.  Add to that, whoever apparently entered the wrong billing address.  Denied.  This was a different credit card than the address change attempt.  We got the CC transaction ID and hoped, maybe, that the online vendor could correlate.  What address did they enter?...Can you get any meta information from the transaction logs?...Can I talk to your IT department?  As you probably know, CC transaction numbers do not always match the merchant's transaction ID and neither was able to correlate the other's.  They did their best providing what they could but nothing to connect the two incidents...even though we had our suspicions.

Change of address request could come from anywhere and purchasing online...well it is the world wide web.  There was no way to tentatively finger someone but we did file a police report. 

And then last week, my wife gets a call from our local pharmacy informing her that the doctor had denied her cough medicine refill and that she needed to make an appointment with the doctor if she needed the medicine.  The only problem was that she hadn't requested a refill.  This was for some codeine laced cough syrup that was scripted over a year ago.  The caller had her name, doctor and birthday...plus knew exactly what medication to request and which store to request it from.  Big mistake.  The geographic region of the perpetrator just shrunk from world wide to our area.  There was/is only one person who would have all that info - the host of the birthday party.  It was her doctor (recommended to my wife) and she went with my wife when the cough medicine was prescribed.  I told the pharmacy to just fill something with grape juice and hold whoever tries to pick it up.  Yeah, ahh, they don't do that.  I guess a sting operation is outside the realms of a pharmacy but sounded good to me.  Now we've added an 'attempted' medical ID theft with a controlled substance sidebar.  Another police report filed.

While we do not have a video of the individual attempting the crimes, all indications point to one person.  Some of you might know that my wife is a retired Federal Investigator.  She spent some time hunting fugitives as a US Marshall and protected past #2s while in the Secret Service.  So she went down every other possible investigative path. The only one who had access to her purse, who also likes to purchase expensive sunglasses and would know specifically my wife's birthday, our pharmacy, and that particular medication along with who prescribed it?  It finally sunk in.

According to ITAC, more than 1.5 million consumers were victims of familiar fraud, which is fraud when victims know the fraudster.  Back in 2006, the FTC Identity Theft report noted that 2% of thieves were co-workers of the victim, 6% were relatives or family members and 8% were friends, neighbors or in-home employees.  For medical ID theft, Ponemon's 2013 Survey on Medical Identity Theft said a family member took the personal identification or medical credentials without consent 28% of the time.  Unfortunately, many of these crimes go unreported due to the perpetrators being friends and family.

Identity theft is on the rise and if I remember correctly, medical ID theft is the fastest growing segment.  I'm certainly not suggesting to keep your personal secrets locked from your trusted, long time best friend or a family member.  But for us, this experience will make us think twice about divulging certain information to fly by friends.

ps

 

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]

Tuesday, October 8, 2013

The Hacker Will See You Now

More than 1.8 million medical ID theft victims in 2013

That's a 19% increase over last year according to the 2013 Survey on Medical Identity Theft.  More than 300,000 new medical identity theft cases were reported during the one-year period, the study found.  The 4th annual survey, conducted by the Ponemon Institute, defined medical identity theft as a person using an individual's name or personal identity “to fraudulently receive medical service, prescription drugs and goods, including attempts to commit fraudulent billing.”

One of the biggest contributors to the increase was fake or spoofed medical websites and spam emails.  Medical identity theft victims who reported that a cyber schemes caused their troubles doubled from 4% in 2012 to 8% in 2013.  It is clear that the amount and frequency of spear phishing specifically targeting medical ID theft has gone up.  This is not the simple 'Buy this personal enhancement drug here' emails but authentic looking emails from a provider.  You click the malicious link and either malware is installed to your computer or you are directed to a website that looks exactly like your medical provider's and you enter (give away) your credentials there.  You might even be able to log into something that will request you update your personal information.  Perfect, I get your credentials along with some additional Rx information or mailing address or SSN or date of birth anything that I can use to impersonate you.

As far as data breaches as a cause, only 7% (up 1 tick from last year) felt a data breach by their insurer, health care provider or related was linked to the fraud.

A separate but related survey, a new Deloitte report says healthcare organizations are in various stages of mitigating the security risks of medical devices.  These include patient monitors, infusion pumps, ventilators, pacemakers and imaging devices.  Deloitte interviewed the medical device security leaders at nine large hospital systems and they indicated that their organizations have a long way to go and that they need more cooperation from device manufacturers. 

The Food and Drug Administration (FDA) recently released a guidance on the "content of premarket submissions for management of cyber security in medical devices."  The guidance suggested that device makers incorporate security features into their products to limit access to only trusted users, trusted content, and use fail-safe and recovery devices. They want manufacturers to consider threats like hacking, malware and other vulnerabilities of the device's software and to work with providers on addressable scenarios.  This is certainly an area of importance for both providers and the device manufactures.  Remember all the wrangling with PCI and those payment devices?  Granted, the FDA guidance is a recommendation and not a regulation like PCI so there is reluctance to include security measures in purchasing contracts.

The other issue healthcare organizations face is trying to secure older proprietary devices.  These closed systems make it almost impossible to scan for vulnerabilities but they are still in widespread use.  For other devices that run on well know commercial operating systems, they are vulnerable to the same threats that any device with that software has.

Deloitte also asked the medical device security heads where their organizations stood in several areas of cyber security.  These included: organizational leadership, risk framework, identification and evaluation, data flow, vulnerability management, vendor agreements and manufacturer engagement.   Ken Terry over at Information Week goes into detail of each.

So far there have been no documented instances of "intentional threats" to medical devices, according to the report but healthcare providers are not required to report security incidents to the FDA or the device manufacturer unless a death or serious injury has occurred.

ps

 

Related:

 

 

Connect with Peter: Connect with F5:
o_linkedin[1] o_rss[1] o_twitter[1]   o_facebook[1] o_twitter[1] o_slideshare[1] o_youtube[1]