Sunday, May 15, 2011

A View From The Top

My current job involves preparing for disaster recovery, going beyond just preventing issues with firewalls and other security measures. I recently read an article about the Veterans Affairs Department’s low priority of documenting a detailed view of its IT architecture.

This came out in the testimony Roger Baker, the VA’s CIO on May 11. Baker told Congress that the VA has 62 data centers and approximately 37,000 servers, but admitted that some of those servers could be “virtual instances running on a single physical server.”

How big an issue is this? Beyond the obvious of not having standard up-to-date hardware and software for security, there is another potential problem. The VAD is supposed to work with the Department of Defense to implement joint systems as well as to developing and securing information systems.

The irony is that from a medical records standpoint, the VA hospitals have their system right. A VA hospital in Florida can access a patient’s records in a VA hospital in Connecticut. This is something that computer savvy doctors understand. (Note: many doctors are still not committed to electronic medical records. Sometimes it’s because they don’t want to spend the money, but sometimes it’s because of the lack of standards outside VA hospitals.)

Back to the VAD's architecture, Baker's concern is because things are not being handled as they would in a private company. Joel Willemssen, managing director for IT at the Government Accountability Office, said it’s absolutely critical to get a picture of the VA’s architecture. Baker is planning to cancel failing programs and restructure the way VA's IT department operates instead of focusing on the broader architecture. Willemssen admits that Baker is going to have to cut up the problem like a sausage and deal with it in chunks. Realistically, it's the only thing that can be done for now.

Learn more from: http://veterans.house.gov/hearings/hearing.aspx?NewsID=2325

Tuesday, March 15, 2011

Unhealthy Operations

Californians, take note. If your health insurer is Health Net, watch your credit report. Somehow, Health Net cannot account for nine of its server drives which contains the personal information needed for identity theft. Almost 900,000 Health Net "subscribers" may be at risk.

It gets worse. Health Net failed to encrypt the data.

Now two state agencies are investigating what happened (or, in this case, what didn't happen).
Beth Givens, director of Privacy Rights Clearinghouse, said Health Net didn't even go through the basic steps of security.

Of course, Health Net will now offer its "members" free credit monitoring and identity theft insurance. What does that cost? Last year I blogged that someone assigned a cost to each case of a security breach -- $204.00 per lost record. This is not actual money being spent, but if that is indeed an accurate number, Health Net's security breach is valued at $172,380,000 - thousands of times more than the salary someone with my expertise earns. Some of this cost is real. Depending on the outcome of the investigations, Health Net could face fines to the tune of millions of dollars. There's precedence for this. Hospitals in Massachusetts and Arizona were fined for HIPAA violations. The people who steal identities are not interested in your health, just your wealth.

http://www.kpbs.org/news/2011/mar/15/state-regulators-launch-investigations-health-net-/

Thursday, December 16, 2010

How Viral Is That?

In my earlier post today, I blogged about the loss of memory cards at an Arizona hospital that had information on some 2,200 patients who had endoscopies. Now the California Department of Public Health reported that it lost data for more than 2,500 facility residents, department employees and other healthcare workers. How viral is that?

This past year the CDPH fined hospitals guilty of losing patient records. It was supposed to beef up its efforts to protect this from happening again, but that hasn't happened. In this case, the information that was lost was stored on magnetic tape that was not encrypted. The data on this tape contained more information than the memory cards in the Arizona health center. Names, Social Security numbers, e-mail addresses, background and medical health information -- all you need, and then some, for identity theft.

Two things happened to compromise the safety of this data. First, the field office, where the tape originated, failed to encrypt the files, as per normal procedure. Then they sent it to the central office via USPS instead of by courier. The envelope arrived, but it was unsealed and empty.

When there is vulnerability in security, it's often because a company doesn't want to spend the money on upgrades. As everyone knows, California is in dire financial straits. But this time lack of sufficient funding wasn't the culprit. It was just a lack of following proper procedures. All that's really required are reminders everywhere -- on posters and on every computer monitor:

MIND THE SECURITY GAP

On the Alert

Call me paranoid, but I believe that people have to be alert 24/7 about their personal data. Recently I posted a blog about how information stolen in Fort Hood, Texas about 20 soldiers led to more than 2,000 attempts to use their identities to make money. Here's a more staggering statistic: 2,284 endoscopy patients' information is missing because two data cards were lost or misplaced at the Mountain Vista Medical Center in Meza, Arizona two months ago.

People tend to think in a linear fashion. Health care workers concentrate on their patients, as they should, but they need to be trained to think of every component in their workplace as cash to be guarded. No doubt they are careful about the equipment they use insofar as they try to avoid physical damage. But, like every worker I've dealt with in offices, they don't think too much about the IT part. If there's a problem, they just call IT to fix it. In this case, the issue is the privacy of the patients' medical information (names, dates of birth, ages and genders), not their addresses, Social Security numbers and credit card information. Still, it was enough for the medical center to notify patients of the incident and to offer them the standard patch -- one year of free credit monitoring services.

Fortunately, the hospital has revised security procedures for storing compact memory cards and are retraining employees on procedures related to confidentiality and security. That said, there is reason to be concerned about other security vulnerabilities at the hospital. Hackers don't give up. Just yesterday, my wife was at a small credit union in Stamford and one of the top employees said, "You can't simply throw out papers anymore. You have to shred them." She went on to explain that if a hacker isn't successful right away, he or she will wait a few months to use the information he has. Time is on the side of the hackers.

Wednesday, December 8, 2010

Think Your Money Is Safe? Read This.

Loss of savings is a daily concern for many people since the economic meltdown more than two years ago. Lately, there have been more threats of loss of savings due to security vulnerabilities in the U.S. government. A new report by the Government Accountability Office states that the Federal Deposit Insurance Corporation lacks adequate encryption of "sensitive information transmitted over its network." It also found that the FDIC has "inconsistent identification and authentication user controls" and needs to beef up its internal monitoring and auditing practices. One example the GAO cited was the existence of default installation user ideas on some of its UNIX servers. Another is that the data network and voice network are both on the same network.
I'm not a heavy duty UNIX administrator, but I know enough about UNIX. It's an open system that is widely used in servers, on workstations and in mobile devices. It's critical that companies have policies and firewalls in place to avoid unauthorized penetration of their systems.

It's ironic that after all these years, the FDIC increased its insurance protection in case banks went under. Now people have to worry that their savings might be lost because of inadequate data security.

Monday, December 6, 2010

Identity Theft Problem Goes Global

Some people think I go overboard in trying to protect my Social Security number. Several weeks ago I blogged about an audit in the Social Security department which uncovered issues in the process of procuring and installing software. Now West Point Professor Lt. Col. Gregory Ponti, a former Army intelligence officer, released a scathing report about the appalling careless in the military with regards to personal information.

Apparently, since the 1960s, military personnel use their Social Security numbers in everyday settings. Checking out sports equipment? Your Social Security number, please. Yes, sir. Flu shot? We need your Social Security number. Yes, sir. The New York Times reported that "thousands of soldiers in Iraq even stencil the last four digits onto their laundry bags." Although the Department of Defense claimed two years ago that it would limit the use of Social Security numbers, it hasn't happened. Only last week did the Defense Department put an end to using Social Security numbers on military ID cards, and that isn't scheduled for another five months. Moreover, Col. Conti noted, "The farther you get away from the flagpole at headquarters, these policies get overturned by operational realities."

I have never served in the military or navy, but it doesn't take much imagination to think of scenarios in which soldiers the idea of identity theft is the last thing on their mind. But soldiers don't have to be in combat to be at a heightened risk for identity theft. Last June, a Staten Island D.A. indicted a gang who stole the identities of 20 soldiers in Fort Hood, Texas.The theft was traced to a former Army member who moved to New York. The gang made more than 2,500 attempts to use the soldiers' identities.
20 soldiers, 2,515 attempts total = 125 attempts per identity theft victim
It gets worse. It's not just the possible carelessness of a soldier or the bureaucracy of the military. Children as young as 10 years old whose parents are in the military carry ID cards that have Social Security numbers. As every parent knows, young children aren't always careful.

The Defense Department is trying a new campaign to make its personnel aware of the problem but, in my opinion, it's moving at snail's pace. The biggest threat is to those who are stationed overseas. They have no control over what's going on here if someone has their Social Security numbers. If the Defense Department asked me, I would immediately issue new identity cards without Social Security numbers and have the old ones shredded and have the bags of shredded paper hauled away with a military police escort.

Call me paranoid about identify theft, but I don't want to have the burden of proof on me that I didn't authorize credit card charges. I'm proud of my credit rating and want to keep it perfect.

http://www.nytimes.com/2010/12/07/technology/07identity.html
http://smallwarsjournal.com/blog/2010/12/the-militarys-cultural-disrega/

Thursday, November 4, 2010

Audit!

It wasn't anything like an IRS audit. It was far worse. According to an evaluation late last month by none other than the Office of the Inspector Attorney General of the Social Security Administration, two Trojan horses and five keyloggers penetrated all the way onto agency workstations. That's right. Everyone's Social Security number is at risk and everyone is more vulnerable than ever to being a victim of identity theft.

These penetrations came via unauthorized installation of non-standard software, according to the report. Non-standard software doesn't mean it's bad. It just means than it was either not developed by in-house programmers or that it wasn't bought through the agency's regular acquisition process. Still, the story gets worse. Two of the workstation workers knew that the software they were installing were potentially unsafe. The other five installed it unintentionally. The SSA uses Microsoft tools to inventory executable files on Windows machines used by both employees and contractors. This tool scans well over 100,000 devices every week to detect unauthorized software. The policy at the SSA permits non-standard software to be installed as long as agency security officers approve it. Some users simply believed that all they had to do was submit their request to the CIO. OK, they were wrong, but it appears that the CIO simply rubber stamped the request instead of issuing reminders about the standard operating procedures of the department.

This makes me wonder what other protocols exist at the SSA. Who writes the policies? Why aren't they being implemented correctly Do the contract workers have Errors & Omissions Insurance? Are they using other firewalls? How often is testing done to detect vulnerabilities? Are they going to make the CIO accountable for this potential disaster?

Everyone who reads this blog knows that I am a fanatic about my personal security. I'm horrified that seniors' Social Security numbers are on their Medicare cards. Many company websites require job applicants to type in their Social security numbers. I mentioned this to someone in my network who works in HR. She said smart applicant type in 000-00-0000. I give my EIN when I'm hired as a consultant. Unless a job offer is on the table, no prospective employer even knows my real birthday. It's just not something that I'm going to make easily available. Suppose my resume or on-line application is printed out and tossed into a waste paper basket instead of shredded? I also block my credit report so that in case my personal information gets out, along with my address and checking account number (for direct deposit), no one can apply for credit in my name. It's easy to block and unblock and the fee is far less than what it would cost me to deal with my identity being stolen.

As for my birthday, just send me presents all year long. One of these days you'll get it right!

http:www.ssa.gov/oig/ADOBEPDF/A-14-10-21082.pdf