MAY 14, 2010 5:15am ET

Related Links

New Product News – May 17, 2013
May 16, 2013
8 Risks Inherent to All Organizations
May 14, 2013
Second World Risk Day Takes a Project-Minded Path
May 9, 2013

Web Seminars

Data Protection in the Cloud: What You Need to Know About Security and Compliance—Right Now
Available On Demand

Security: Strive for 'Defensive Depth'

Print
Reprints
Email

Good data security means having "defensive depth" embedded in information systems, says Alain Sheer, an attorney in the Federal Trade Commission's division of privacy and identity protection. "Relying on one defense is problematic."

Speaking at the Safeguarding Health Information Conference in Washington, Sheer gave examples of the need for multiple levels of defense. An organization, for instance, may encrypt data but have weak user authentication controls. This enables a hacker to access the encryption module and find the decryption key.

Sheer also gave several examples of major breaches of well-known retailers who were amazingly lax in protecting sensitive consumer information. Petco Animal Supply, for instance, on its Web site collected consumers' names, addresses, and payment card numbers with expiration dates. The Web site stated that data was encrypted, but it was not. The FTC charged the company with deception and in a settlement order mandated a comprehensive information security plan and independent assessments of Petco's security measures every three years for 20 years.

Pharmacy chain CVS was assessed similar but broader sanctions for a low-tech breach. Across the nation, its pharmacies were disposing of paper records--including identifiable medical and payment card information--in public dumpsters. CVS had represented to the public that it would protect information, so the FTC charged the company with deception, as well as unfair practices. CVS' settlement order with the FTC called for comprehensive information security measures and long-term independent assessments, but the order also covered personnel information collected by any part of the company, including its Caremark pharmacy benefit management firm. The Department of Health and Human Services' Office for Civil Rights further imposed a $2 million fine and a three-year collective action plan on CVS.

Sheer also warns of the security risks of online peer-to-peer file sharing programs, which often have not protected information. The FTC, Sheer says, informed more than 100 P2P companies that personal information was being improperly shared. "We found health information, drivers' licenses, financial information and Social Security numbers, among other information."

This article can also be found at HealthDataManagement.com.

Joseph Goedert is news editor at Health Data Management.

Filed under:

Advertisement

Comments (0)

Be the first to comment on this post using the section below.

Add Your Comments:
You must be registered to post a comment.
Not Registered?
You must be registered to post a comment. Click here to register.
Already registered? Log in here
Please note you must now log in with your email address and password.

Where do young IT professionals (30 and under) obtain information to aid with daily role responsibilities and career development?

Trade publication websites 14%
Social media 23%
Vendor websites 4%
Vendor/community forums 7%
Newsletters 1%
Trade conferences/meetups 2%
RSS feeds 6%
Web search 44%

 

Twitter
Facebook
LinkedIn
Login  |  My Account  |  White Papers  |  Web Seminars  |  Events |  Newsletters |  eBooks
FOLLOW US
Please note you must now log in with your email address and password.