The Government's plan to introduce electronic health records is a "nightmare" for security according to the head of industry group AusCERT
AusCERT boss Grahame Ingram said information security risks were amplified because of the highly sensitive nature of patient data held under the e-health scheme.
"It is a nightmare scenario," Ingram said. "That they think they have the security to safeguard the data is just a nightmare."
The Government had compared e-health security to systems used by major banks, but to Ingram, that fell short.
Bank security was not flawless, he said, and financial transactions were considered "compromised" -- a state that could not be extended to sensitive e-health records.
He said security should be thought of as damage mitigation not intrusion prevention because of the complexity of attacks.
"Banks examine risk profiles, they have accepted risk," he said. "If there was a better system out there to secure their data, I'm sure they would be using it."
Ingram warned that compromises of patient data were likely from insecure end user machines, and said there was a "misplaced trust" in technology.
"The end user attack capability is now fully deployable against the enterprise and is much harder to mitigate," he said.
Copyright © SC Magazine, Australia
Issue: 335 | January/February 2015
Access CRN's extensive online resources including; email bulletins, community discussions and unique online news.
Processing registration... Please wait.
This process can take up to a minute to complete.
A confirmation email has been sent to your email address - SUPPLIED GOES EMAIL HERE. Please click on the link in the email to verify your email address. You need to verify your email before you can log on to the CRN website or start posting comments on articles.
If you do not receive your confirmation email within the next few minutes, it may be because the email has been captured by a junk mail filter. Please ensure you add the domain '@crn.com.au' to your white-listed senders.