Online health records at risk from malware
- 25 August, 2011 20:34
- Comments
AusCERT general manager Graham Ingram has questioned the wisdom of Australia's National E-Health Strategy plans to make medical records available online, pointing to the difficulty of securing end-users' computers.
"I do not believe that personal health records should be available over the internet to end machines until they can secure them," Ingram told the Security 2011 Expo and Conference in Sydney this week.
"If I had a machine in a Medicare office that I could go into that was dedicated to that function, I'd be happy with that. But popping on my home machine or the Qantas lounge and looking at my health records is not something that I am going to be ecstatic about."
Online banking led to phishing attacks, says Ingram, and that led in turn to more sophisticated malware that relied on social engineering techniques and thence to advanced persistent threats (APTs) or, as Ingram prefers to call them, covert enterprise intrusions (CEIs). He envisages the same evolution playing out in attacks on health records.
One scenario could be noting that someone was allergic to peanuts, and changing that.
"Maybe that's on the paranoia end, and maybe I've no reason to have that paranoia," Ingram said, but nevertheless he is concerned that it would be possible to view someone's health records through simple attacks.
"The e-health people say, 'No, our databases are secure.' That's not what I'm talking about. They don't seem to get that," Ingram said. "They seem to think that if we can secure the back-end databases they've secured the system. No you haven't."
According to Ingram banks now assume that transactions might be compromised, and employ sophisticated algorithms to help detect and prevent fraud. This can include introducing delays in processing to allow time for investigation. That might not be as easy to do with health records that might be acted upon in real-time emergencies with potentially fatal consequences if mistakes are made.
"The successful attack is now almost guaranteed," Ingram said. "How do you then start to say, 'How can I reduce the damage from a successful attack? How can I detect it and mitigate it?"
Security 2011 Expo Conference Slideshow, the best from the day..
Contact Stilgherrian at stil@stilgherrian.com, or follow him on Twitter at @stilgherrian.
- Bookmark this page
- Share this article
- Got more on this story? Email TechWorld
- Follow TechWorld on twitter
-
CSIRO develops hands-free technology for mining repairs
-
Broadband Forum to improve IPTV performance with new spec
-
Amazon Web Services moves backups to cloud with new appliance
-
Callforfree.net.au offers free calls to 70 countries
-
Intel ponders solar-powered CPU tech in graphics, memory
-
Excel 2007 All-In-One Desk Reference for Dummies
-
Windows 7 for Seniors for Dummies®
-
Teach Yourself Visually Windows 7
-
Office 2007 for Dummies
-
Computers for Seniors for Dummies, 2nd Edition
-
Microsoft Office
-
Windows 7 for Dummies®
-
Windows 7 for Dummies® Dvd+book Bundle
-
MYOB Software for Dummies 6E Australian Edition








Comments
Post new comment