E-health records a 'nightmare', says AusCERT

By Darren Pauli on Aug 25, 2011 4:56 PM
Filed under Security

Health records need to be more secure than bank data.

The Government's plan to introduce electronic health records is a "nightmare" for security according to the head of industry group AusCERT

AusCERT boss Grahame Ingram said information security risks were amplified because of the highly sensitive nature of patient data held under the e-health scheme.

"It is a nightmare scenario," Ingram said. "That they think they have the security to safeguard the data is just a nightmare."

The Government had compared e-health security to systems used by major banks, but to Ingram, that fell short.

Bank security was not flawless, he said, and financial transactions were considered "compromised" -- a state that could not be extended to sensitive e-health records.

He said security should be thought of as damage mitigation not intrusion prevention because of the complexity of attacks.

"Banks examine risk profiles, they have accepted risk," he said. "If there was a better system out there to secure their data, I'm sure they would be using it."

Ingram warned that compromises of patient data were likely from insecure end user machines, and said there was a "misplaced trust" in technology.

"The end user attack capability is now fully deployable against the enterprise and is much harder to mitigate," he said.

 
Follow us on Facebook and Twitter
 

Copyright © SC Magazine, Australia

E-health records a 'nightmare', says AusCERT
Tags
 
 
 
 
 
Top Stories
 
Artis strikes maiden partnership with Dicker Data
Distie helps Sydney reseller expand SAP offering.
 
Data#3's VMware boss to run 52nd half-marathon in 52 weeks
Guess what he's wearing for the final one tomorrow.
 
Sign up to receive CRN email bulletins
   FOLLOW US...
Polls
Who had more wins in 2014?

Latest Comments
CRN Magazine

Issue: 334 | December 2014

CRN Magazine looks in-depth at the emerging issues and developments for the channel, and provides insight, analysis and strategic information to help resellers better run their businesses.