Pages

Showing posts with label Security. Show all posts
Showing posts with label Security. Show all posts
Medical Identity TheftAlexis Moore got a surprise a few years ago when she went to the doctor, and it had nothing to do with her physical health. "I needed a CT scan of my head and sinus, and when I handed them my insurance card, they told me I had no coverage," she recalls.

Her identity had been stolen. The addresses on her credit card and bank accounts had been changed without her authorization, and her health and auto insurance had been canceled. "I spent over 100 hours on the phone in one month trying to get help from the insurance company and to find out what was going on," says Moore. Meanwhile insurance payments were delayed, or radiologists, pharmacies and doctor's office got letters saying she had no coverage.

"I was not only humiliated, I was having to advocate and plead with these providers to rebill my insurance and help me. Frustrated with having to rebill, they wouldn't and my medical bills skyrocketed," says Moore, who estimates the confusion over the bills cost her $10,000 to $20,000 out of pocket. But even higher, was the emotional cost of the more than two years it took to get her life back in order.

Her response to the ordeal puts it in perspective: Moore founded Survivors in Action, a national nonprofit advocacy group that supports victims of any crime.
Posing as You to Suck Your Benefits Dry

What happened to Moore was a less well-known type of identity theft called identity theft as abuse, but she's just one of an ever-growing number of victims of medical identity theft. According to a recent Ponemon Institute study, about 1.5 million Americans have suffered from medical identity theft, at a total cost of about $29 billion, or approximately $20,000 per person.

Medical identity theft begins when someone gains access to a victim's personal information, and fraudsters can rack up medical charges quickly, leaving insurance companies and Medicare on the hook, and victims owing co-pays for services they never received. Not only can this result in huge financial losses, but the co-mingling of two patients' information can lead to serious errors in records (blood types can change, allergies appear or disappear), misdiagnosis and fatalities.

It's not that hard for a medical identity thief to get started: Items can be taken out of your home or office that make it fairly easy for someone to pose as you and drain your medical benefits, warns John Sileo, author of Privacy Means Profit: Prevent Identity Theft and Secure You and Your Bottom Line. Then too, such data theft can also be an inside job.
Sponsored Links
"There is a case of a Boston psychiatrist and another of a receptionist in Cleveland who were stealing patient information. The Los Angeles police stated once that gang members were getting their wives and girlfriends jobs in pharmacies, medical and dental offices, with the goal of thieving patient information," says Levin. A major home health care ring in New Jersey was misusing patient information. And the risk goes beyond medical providers: Insurance agencies, government agencies, private sector human resource departments and outside consultants often retain digitized medical records to keep track of their clients and employees. In one high profile case in 2009, a hacker stole 8.3 million patient records and demanded a $10 million ransom, reports Adam Levin, co-founder of Identity Theft 911, a data breach management company.

"Paper medical records create serious privacy threats for patients," says Ryan Howard, CEO of Practice Fusion, which provides free electronic medical record systems to physicians. "They can be easily be lost or stolen, accessed inappropriately with no safeguards. Patient medical data is safer with electronic medical records than with paper charts. Period."

Then too, sometimes the perpetrator is someone close to the victim.
Emily, who declined to provide her last name, says she had no clue how her medical identity was stolen. "I only discovered it when I got a bill in the mail for an emergency room visit. I've never been to the ER in my life," she says.

You may be keenly aware of the need to safeguard your financial information: The same care is required of your medical records. Here are some steps to take to protect yourself.

Be savvy about how your information can be misused. Opportunities abound. An article in DarkReading talks about emerging social networking sites for people with medical conditions like PatientsLikeMe.com, DailyStrength.org and HealthyPlace.com, where people can post profiles similar to those on Facebook. Users are posting photos, hometowns and personal health information -- information that in the wrong hands can be abused. Don't provide your insurance information to anyone over the phone or Internet unless you are absolutely positive that the person with whom you are communicating is legitimate.

"Scam artists posing as insurance companies, doctor's offices or pharmacies may contact you and sound legitimate, but the best course of action is to never give your information out unless you are absolutely convinced it is legitimate. Be skeptical," says Steve Weisman, a professor at Bentley University and author of The Truth About Avoiding Scams.

Review medical bills closely. Medical bills and insurance statements may contain important signs that you are a victim of medical identity theft. Check the itemized costs. If something look suspicious, investigate by calling right away, advises Levin.

Check your medical records. You check your credit report, and you should do the same with your medical records. Always review your Explanation of Benefits. If you find activity that appears to be incorrect, call your insurer and your medical provider. Also obtain, once a year, a "benefits request" from your insurance company. This is a list of benefits paid for in your name by the health insurance. Follow up with the insurer if you find anything suspicious, advises Jeremy Miller, director of operations at Kroll Fraud Solutions. If you receive a collections notice for medical services or equipment that you never received, call your medical services provider.

Ask questions. You're the customer here. Be informed and understand what slice of your information and identity is secured. Ask your doctors if they do ePrescribing, whether they store your information electronically, and if they do, how is it protected? And if they are still using paper, how is that information disposed? These are just some of the questions you should ask, says Dave Miller of Covisint, a company that provides health care IT services.

Speak up. You can request that your health care company use an identification number other than your social security number. "The provider has to comply with your request, since according to the Social Security Administration rules, only the SSA and the IRS can require you to use your true SSN," says Jon Heimerl, director of strategic security at Solutionary, an information security company. Just be aware that using an "alternate ID" can extend claim processing by months, Heimerl warns. Decide if it's worth it for your peace of mind.

Sign with care. Don't automatically sign anything. Read the HIPAA forms in full. You're signing away your rights to privacy -- essentially, enabling the doctor to share your information with whomever she wants. Know where your data will be stored and how it may be shared. "If you don't like it, tell your doctor your concerns before signing it," says Dave Miller. You can also request that your health care providers send you a HIPAA Accounting of Disclosure, which is a list of entities that have received your health care information for uses unrelated to treatment and payment. A disclosure is available to you every 12 months, and it's free.

Know your rights. If you are a victim of medical identity theft, you have a right to get a copy of your records from any of your medical care providers. Get those records and review them. Federal law provides you with the right to have your records amended to remove inaccurate information, says Weisman. This is particularly important because information in your medical report that reflects the condition of someone else could effect your own medical care.

Also, request an accounting of disclosures so you know everyone who has received a copy of your medical records. This way, you can identify who has received the compromised records and contact them to correct their records. You should also file a police report and put a freeze on your credit report, adds Weisman. He also recommends checking out the Identity Theft Resource Center, which offers information on medical identity theft.
"This is just the early stages of becoming a problem," warns Sileo. "It will continue to increase exponentially over the coming years."

[Source]
Windows LogoMicrosoft has been constantly boosting the security capabilities of its Windows clients, and the company has the numbers to prove it.

In the Microsoft Security Intelligence Report Volume 9 (for the first half of 2010) released at RSA Europe, the Redmond company points out that users running Windows 7 are less susceptible to infections with malware designed to transform their PCs into zombie machines than customers that continue to use Windows Vista or Windows XP.
There are less Windows 7 computers compromised and made part of botnets than Vista and XP, even if the two platforms have the latest service pack installed, as users can see in the graphic included in this article, courtesy of Microsoft.

“The botnet infection rate for Windows 7 and Windows Vista is significantly lower than that of their desktop predecessor Windows XP with any service pack installed, which reflects the security improvements that have been made to the more recent versions of Windows,” the company explained.

“Considering only computers that have had the most recent service pack for their operating systems installed, the infection rate for Windows XP SP3 is twice as high as that of Windows Vista SP2 and more than four times as high as that of the release-to manufacturing (RTM) version of Windows 7.”

Bot Related MalwareThe fact of the matter is that Windows XP SP3 and XP SP2 have the highest infection rate out of all Windows operating systems, even higher than XP SP1 and XP RTM.

Microsoft has dropped support for older versions of Windows XP, and this how the company explains the drop in infection rates, as MSRT is not installed and executed on non-supported platforms.

“As IT departments and computer users move to more recent service packs or Windows versions, computers running older operating system versions are often relegated to non-production roles or other specialized environments, which may explain the lower infection rates,” the company stated.

SIRv9 comes to prove, if there was any need, that customers are better off running the latest version of Windows, at least when it comes down to taking advantage of the security enhancements delivered by the Redmond company.

“The features and updates available with different versions of the Windows operating system, along with the differences in the way people and organizations use each version, affect the infection rates seen with different versions and service packs,” the software giant said.

Windows 7 RTM Enterprise 90-Day Evaluation is available for download here.

[Source]
Intel Office
(Credit: James Martin)

In the future, you may not have to buy antivirus software for your laptops and mobile devices if Intel is able to live up to the promise of integrating technology from acquisition target McAfee, experts said on Thursday.

In announcing its plans to acquire security company McAfee for $7.68 billion, Intel executives said they see security as being as critical to computing as performance and connectivity and that they plan to combine security with its hardware and expand further into the mobile market.

While Intel has been pushing more and more functionality down into the chips, a marriage with McAfee will mark a shift away from the security firm's traditional product strategy, experts told CNET.

"Delivering security in Intel products and platforms is a huge departure from the way McAfee has delivered security technology in the past, as an add-on software product to an insecure platform," said Chris Wysopal, chief technology officer at Veracode. "This is where security needs to be, baked in."

The strategy dovetails nicely with the fast adoption of mobile devices and the more guarded move to cloud computing, where data is stored on remote servers instead of on local computers and accessed over the Internet, he said.

"I think this acquisition shows the critical importance of security in our now mobile, increasingly cloud-based, everything-always-connected world," he added. "Everyone building hardware and software needs to be thinking about the security of those products from the very beginning of their design, and customers are going to demand it. Anything less is not going to cut it in the computing environment of today."

For businesses in the mobile security market, the deal is seen as further validation that they are on the right track.

"Intel's acquisition of McAfee signals to the industry that smartphones and other connected devices are joining the web of devices we trust with critical data and that these devices need to be protected," said John Hering, chief executive of Lookout. "We have seen threats rising across the major mobile platforms and expect this trend to increase as mobile devices continue to become the dominant computing platform."

Don't expect to see security software hardwired onto the chip, said Tim Bajarin, president of analyst company Creative Strategies. Rather, there will likely be a bridge on the core CPU (central processing unit) to a security element, much like there are bridges to additional graphics chips and modems, he said.

"This particular deal allows Intel and McAfee to work together to tie future generations of software security to the processor via some sort of SOC (system-on-a-chip) solution," Bajarin said. "Today if a hacker wants to come into a system it almost always is done through software. But Intel and McAfee are capable of adding even another level of security, which would make a hacker have to break the hardware code as well as the software code."

McAfee will still sell antivirus and other security software, but their work with Intel could change the technology landscape fundamentally down the road, according to Bajarin.

"Intel becomes their strategic partner for them to innovate with on next-generation security software that can go all the way down to the chip level, and that has not been done yet by anybody," he said. "It will be fascinating to watch not only how they innovate, but how they go about securing everything from servers and PCs to wireless devices. That will be their challenge."

Marc Maiffret, chief technology officer at eEye Digital Security, predicted Intel would add the security in hardware at the device level but not necessarily at the chip level, while eventually phasing out McAfee's software-based products.

"TVs and other devices and cars continue to have more and more embedded Internet connectivity and really are becoming computers, and Intel sees the opportunity to bring McAfee's intrusion prevention and antivirus across all the devices," he said. "Intel was in the antivirus security market in the late '90s with the LANDesk product, but they sold it off to Symantec, so they definitely are not going to be getting back into that classic security software business."

Several analysts questioned why Intel executives felt they need to acquire McAfee to get the security enhancements in future products when they already have development partnerships with McAfee and others.

"I think it's going to be more of a chipset assist than embedding everything in the chip," said Josh Corman, research director for enterprise security at The 451 Group. "And many of those opportunities will be open to McAfee's competitors...and have been happening with joint development. They are going to continue to have multiplatform support."

Peter Firstbrook of Gartner was similarly skeptical.

"If Intel creates some firmware hooks for McAfee to exploit, then other security vendors can exploit those APIs as well," he said. "Most significantly, all the antimalware vendors have had security products for cell phones for years, but nobody has been willing to pay for it because the threat environment has been relatively benign and the ISPs or device manufactures are building security into the network or the device."

The shift to "baked-in" security and the focus on integration that the deal will require will definitely impact McAfee's existing business, Chris Silva, a senior vice president of research and service delivery for research firm IANS, predicted in a blog post.

"We'll see a stagnation of innovation for McAfee's existing product line and a drain of talent who leave the company seeking greener pastures at smaller, more-focused vendors that are iterating on a product and security approach," he said.

[Source]