Friday, August 16, 2013

How One Contractor's Forgetfulness Affected People in 48 States

Patients in 48 states are vulnerable, not to disease, but to their information getting into the wrong hands. An article in The Tennessean newspaper reported that a medical transcription contractor left a firewall down between May 5 and June 24. 

That's a long time for to discover this. M2ComSys of India was hired by Cogent Healthcare to transcribe the notes dictated by physicians. As part of the contract, it was supposed to store the patient information, which was supposedly protected, on a secure website, but the firewall was down. Who is responsible? It's not just the contractor, in my opinion, but Cogent is also at fault. This HIPAA breach is the second one for Cogent, and it's not something to be pooh-poohed. The data includes patients' names, birth dates, medical record numbers, medical history, diagnosis and treatment. Usually, medical records at practices include patients' addresses and Social Security numbers, as well, completing the information that hackers need to steal people's identity.

There was a case study done by HealthCareInfoSecurity, which outline efforts of CaroMont Health of North Carolina to track down all its contracts. That could be a few or it could be a lot of people. But here's the scary thing: experts in the security field say that there is an increase in the number of health data breaches and that are not accidental. Moreover, hospitals and practices don't take action until after a breach occurs.

Many contractors are required to take out Errors and Omissions insurance in case something happens on their tour of duty at a company that hires them as contract workers. But when it comes to identity theft, the error can't be remedied by an insurance payment. Identity theft is the only crime in which the victim has to prove that he or she did not commit the crime, e.g., buying thousands of dollars worth of jewelry or electronics on a credit card.

A poll by the Ponemon Institute reported that 94 percent of 80 participating health care organizations had at least one security breach in the past two years. Those breaches cost them a total of $6.78 billion annually. Collectively, those organizations could have paid for new firewalls, new penetration testing, oh, and enough staff, and still have a lot of money left over -- and no egg on their faces.

Monday, February 4, 2013

Super Redunancy


I have to admit that I didn't watch the Superbowl last night. Hey, I've got two young kids, and I'd rather spend time with them. But I heard about the power outage that came about during Beyonce's number.

Apparently, Twitter is all aflutter with comments about how her hair dryer blew out the power during the Superbowl. (Actually, this happened when I was on my honeymoon and my wife blow dried her hair!)

But I digress. Several years ago I applied for a job with the National Basketball Association. It would have been a bear of a commute had I gotten a job offer. Nevertheless, I was very much interested in the job because it involved an aspect of redundancy I never thought of before: broadcasting. It's bad enough to have a lack of continuity during a game, but it could be an unmitigated disaster if it happens while trading.

So, redundancy is good. Super redundancy is even better.

Saturday, January 12, 2013

The Power of Networking

There is an article in The New York Times about five people who are past 50 and surviving the recession. I am one of those five people.

Here is the link:

http://www.nytimes.com/2013/01/13/business/how-5-older-workers-saw-a-chance-to-remake-their-careers.html?ref=business

This is not the first time I've been interviewed about employment. Several years ago a reporter from the Connecticut Jewish Ledger interviewed me when I was laid off from Gartner. Always networking, I mentioned my plight to my rabbi, who then sent out an email blast to the congregation to try to get some job leads.

I am still believe in networking. I have joined several networking groups and try to stay in touch with people when I can't go to those meetings for months at a time. Some people think that networking meetings are just pity parties or support groups. Sure, you go to them and realize that you are not alone and that there is nothing wrong with you. You did not lose your job because of a performance issue. You lost it because of budget cuts or takeovers or, often, bad management.

Here are some of the things I learned from networking:

1) You meet people who worked at a company where you wish to work. You can find out more about the corporate culture and maybe even get the contact manager of someone who is in a position to hire you.

2) Many networking groups have a session on elevator pitches. Most people feel uncomfortable doing them, but it's one of the skills you need to have.

3) When the facilitator left the group because he or she got a paying job, it's a good idea to volunteer to run a meeting or two. Most people shy away from this. It was one of the best things I ever did because it helped me improve my public speaking, presentation and leadership skills. Sure enough, the next time I had a group interview, I didn't feel intimidated.

4) Your network can't be too large. Invite everyone you meet to join your professional network on LinkedIn. I once heard that someone who applied for a job that required community outreach got the job over her competitors because she had a 180 people in her LinkedIn network. That number is low actually. It should definitely be 500 plus. But it's not just about collecting people. You can easily share job leads in your updates. When you get an interview with someone, you can often find his profile on LinkedIn. When you go into the interview, you don't go in "cold" because you have an idea about his background. If he went to an Ivy League college and you didn't, you know the chances are not in your favor. If he went to the same college your cousin did, you have an icebreaker.

5) You can find someone who can help you upgrade your skills, from Microsoft Office to using social media.

I used to go to a networking meeting where I would meet a man who was unemployed and convinced that no one would want to date him until he got a job. My advice to him was not to put his life on hold. Good things can happen. Not long after I was laid off from Gartner, I got married. The Times article has a picture of me with my younger son. Good things and bad things can happen. I just go with the flow.

How did I get to be interviewed for the article in The New York Times? Networking. Caitlin Kelly, who is in wife's LinkedIn network, sent out a request for leads on people who are over 50 and surviving the recession. My wife responded and told the reporter about me.

Want more ideas about networking? Read Harvey Mackay's book, Dig Your Well Before You're Thirsty.

Tuesday, November 13, 2012

An Invitation to Hack

Sometimes you just wonder about the decision making process. The SEC told the New York Stock Exchange that computers which have sensitive information about its Trading and Markets Division were left open to cyber attacks. It gets worse. The people who have those computers brought them unprotected to a Black Hat conference, a convention that computer hacking experts love to attend to learn about the latest trends. 

What an invitation to hack! The SEC claims there is no evidence that data was compromised, but we've heard that before, usually followed by a company's promising free credit monitoring for a year to its customers. Just to be sure, the SEC spent at least $200K and hired a third-party firm to conduct an exhaustive analysis to determine if any data was indeed compromised.


What I can't wrap my head around is that this is government. There are policies. Or so there should be. People who work on laptops in the office tend to take them home because they don't want to incur the costs of buying their own. But. It's. Not. Their. Personal. Property. Also, the SEC isn't sure why their staffers brought their computers to the convention. My guess? WiFi. They wanted to check their personal email and Facebook.

It's a tough call, but someone in every organization has to set up rules, and employees should use their judgment. Even though it's a nuisance, I carry two smartphones and my personal iPad with me. I do not want my personal email on my company devices. For me, it's about separation of church and state. But enough about me. I don't want to be called into a group meeting and be told to be careful. Put it in an employee handbook in the first place. No company laptops or tablets may be removed from the premises without prior authorization. No unprotected devices may leave the building. Ever. How difficult is that?

Wednesday, October 24, 2012

A Book, A Nook and A Crook

Pity Barnes and Noble. While Borders was going belly-up and Amazon released the Kindle Fire, Barnes and Nobel started to look for a buyer for itself and took its eyes off security. It doesn't take long for bad things to happen. Recently the bookseller admitted that hackers hit 63 of its stores in nine states, including at least nine stores in the New York area.

Barnes and Noble first learned of the attack in mid-September and happily complied with the Justice Department's request not to disclose the problem yet, but wait until December 24 to tell its customers so that the FBI can conduct an investigation.

That would have been one nasty Christmas present. Barnes and Noble explained that the hackers "planted bugs in tampered PIN pad devices" and when credit cards were swiped for payment, so were credit card and pin numbers.

Flashback to 30 years ago when capsules of Extra-Strength Tylenol were tampered with and laced with cyanide. In theory, McNeil Consumer Products, the subsidiary of Johnson and Johnson, was not responsible for the tampering. The product left their distribution centers and they had no control once the product was placed on the shelves. But the company immediately pulled the product, halted advertising and changed their packaging to regain customers' trust. 

Note to Barnes and Noble's CEO: Take a page from that playbook. When a crisis happens, manage it and fix it. Don't hide it.

Every individual who has a credit card, should spend time looking online at the account activity. Most major credit cards now post pending transactions in real time. I get notices when my card is being used. I even spooked my wife by calling her and asking what she just bought at a particular store.

One more thing, Barnes and Noble. Don't skimp on security. It doesn't make you look good.

Get ready for Halloween: Scareware, Scams and other Nasty Tricks!

Top 4 Scary Internet Threats Users NEED to Know
Guest Blog Post by Nick Nascimento

Amid a season of Halloween horrors, the scariest thing most of us will contend with are the litany of Internet threats that can readily crash our computer system and wreak havoc on our personal and business lives.

To compute with confidence this season, heed this hit list of "scareware"-the 4 creepiest threats Internet surfers should be aware of right now:

1. The FBI MoneyPak Trojan. This is in a class called "ransomware." which are Trojans or Virus' that force you to PAY for them to "remove it " and of course after you pay they never do, If while surfing the Internet your computer screen is filled with a FBI warning page that claims you have to pay the $100 fine, you're infected! Most of the time, ransomware locks up the user's desktop, disables task manager and other system utilities to avoid the termination of the process by the user as well. However, FBI MoneyPak ransomware takes it to the entirely new level by adding a little video recording square in the top right corner of the fake FBI warning page. It supposed to be your built-in web camera. Curiously, this little square shows up even if your laptop doesn't have a built-in camera.

FBI MoneyPak is a very convincing looking scam. It has the official FBI logo at the top and lists victim's IP address, location, and the name of their ISP. The fake warning claims that your PC has been locked by FBI because you downloaded or distributed copyrighted material or viewed child pornography. Creepy, isn't it? And, it asserts that if you don't pay the fine you will go to jail. Simply visiting an infected web site is enough to trigger this exploit kit which will download a malicious DLL file onto your computer. This is an Advanced level Bug to deal with so if you are not familiar with more advanced parts of your computers operating system such as editing the registry etc. it's advisable to consult a professional Removal Specialist.

2) Malicious 'eventvwr' SCAM from Offshore Call Centers. This second troublemaker doesn't START with your computer but it very well ends there. This scam can be especially dangerous for unsuspecting, less computer-savvy target victims. The scam goes like this: You get a call from a guy with a generic name such as "Adam Smith" who explains to you that he's a registered Microsoft technician and received a call alerting him that your IP address is the source for serious attacks on their servers due to multiple computer virus infections on your end. If you ask for any information on the source or target IP addresses involved, the person will attempt to deflect the question, and inform you that he/she is unauthorized to provide you that information!

They will proceed to try convincing you that your computer is full of viruses (based on some standard status and error messages automatically generated by your computer), and they try to get you to grant them complete access to your entire computer, including passwords, credit cards, and other sensitive information, via the free "Ammyy Admin" remote desktop control software. If you don't agree to buy their useless, thieving "support services", they'll use the computer access you openly granted them to damage your computer and randomly delete files.

3) Fake Virus Alerts / Scareware. One of the most virulent is known as "MSREMOVAL TOOL".?It is just ONE of the Fake Virus removal programs that install themselves onto your PC and request Money to make them work.?THEY WILL NOT WORK AND IF YOU PAY THEM THEY WILL NOW HAVE YOUR CREDIT CARD INFORMATION. Here are the two most common ways they are distributed:

(a) Via Infected IMAGES you may view Via Search engines!
(b) Via Pop - UNDERS (pop-ups that hide behind the page you are viewing.) When you see that FLASH be sure to LOOK QUICKLY. You just may see a very small window that is downloading the Malware CLOSE IT!! If it completes its task it will then launch that warning window. That is the other way they are delivering this malware.

4) FakeInst SMS Trojan and its variants. Now we turn to the most overlooked segment for attacks: mobile users. Mobile users are MUCH easier to attack, not just because of their cell phone vulnerabilities but the fact that people do not even THINK about their phones as the Small Computers they are.

"FakeInst disguises itself as popular apps like Instagram, Opera Browser, and Skype, and sends SMS messages to premium-rate numbers. There are more than a dozen variants of this bug and growing. There are well-known companies that produce security software for mobile phones and many of them have FREE versions that can and do help keep you safe from these types of attacks. Remember, by simply getting your apps from the OFFICIAL app sources, either your phone's app store or the app developer's own site, you can virtually eliminate this type of threat all together.

"Computer users need not despair," Nick notes. "Sometimes we do win the fight as was the case when a Federal court imposed a $163 million judgment on a woman who the FTC says helped run a scareware ring that tricked more than one million consumers across six countries into purchasing fake security software. But it's imperative to be vigilant and 'in the know' as dangers definitely lurk."

Nick Nascimento is Chief Executive Geek at aGeek2Go LLC Computer Repair, San Diego's most trusted provider of IT Services & Support as well as computer repair for home and business users both on-site and remote. He may be reached online at www.ageek2go.com.

Sunday, October 21, 2012

Standardize That!

Recently I bought an iPad and I must admit that I love it. My Crackberry contract has been up for several months, but I wanted to wait until the new iPhone came out. Still, I've been postponing it because of the cost.

The demand for iPhones continues to be strong and, surprisingly, many businesses are giving into the demands of employees who prefer them to BlackBerry devices. The iPhones are much cooler than any other smartphone, and that's why, I think, most people want them. Really want them. To the point where they will shell out their own money for both the phone and the plan if their employers won't supply them with them and they'll carry the company-issued phone as well.

But I'm digressing. The real issue is that no matter who provides the phone, security is key. Ditto for the iPad. Recently I spoke to someone at a financial firm who said his sales staff members are using the iPad for everything and they need to address this potential problem. 

The real problem is that there are no standards for security on mobile devices because there are multiple plan providers. It seems to me that wireless companies spend more time figuring out how they can get more and more in revenues than how to protect their clients' data when they shop online via smartphones. I hope that the company that never stops working for you is working on security.