Security in Context: The BeyondTrust Blog

Welcome to Security in Context

Bringing you news and commentary on solutions and strategies for protecting critical IT infrastructure in the context of your business.

Disgruntled Dave Snoops Your Healthcare Records

Posted August 17, 2011    Peter McCalister

I introduced you to Disgruntled Dave as an archetype for the type of insider villain who may already be infiltrating your extended enterprise a couple of weeks ago and guess what? Almost every day I see an article that represents “Dave” as manifesting in another company with some measurable harm that was newsworthy.

The latest article I found was at HealthcareInfoSecurity.comand showed that “Survey: Insider Threats #1 Concern.” and reported that “early results from the Healthcare Information Security Today survey shows that insider threats, such as records snooping and ID theft, are perceived to be the most significant security threats to healthcare organizations.
So it’s not surprising that, so far, the most frequently mentioned information security investment priority for the fiscal year ahead is audit logs/log management, which can be used to detect insider threats.”

What should be scary to the average healthcare consumer is that every detail of your personal information is completely available to the systems admin of your healthcare provider’s patient records system. Whether these are local to the healthcare provider’s office or stored out in the cloud, someone with full administrative privilege to that system can ultimately do whatever they want with your healthcare records, including:
copying for sale, blackmail or intimidation purposes
editing for malicious intent
deleting for covering their tracks on mismanaged care.
As we have repeatedly shown here, implementing a least privilege solution is the best way to mitigate this potential misuse of privilege and invasion of privacy.

Leave a Reply

Additional articles


Scottrade Breach: Identified by Federal Officials

Posted October 5, 2015    Morey Haber

Late afternoon on October 2nd, news leaked out of another large security breach, now at Scottrade. The identity count of records, in the millions again (4.6 million is the latest). This breach comes on the second day of national CyberSecurity month, the first being Experian/T-Mobile breach.

3d image Data Breach issues concept word cloud background

Experian/T-Mobile Data Breach: When 2 Days is not Enough

Posted October 2, 2015    Morey Haber

On October 1, Experian admitted full responsibility for the loss of T-Mobile customer data. 15 million user records dating back to 2013 were effected in the breach, with data including sensitive information that may be decryptable like social security numbers and drivers licenses.


Who Moved My Front Door? (What is Privileged Account Management?)

Posted October 1, 2015    Nigel Hedges

Not too long ago, I was sitting in a room with a very fluffy sales guy. In between words such as “we’ll make this happen” and “leave it with me, I’ll get it sorted” he asked the question “What is Privileged Account Management”?