E-health records a 'nightmare', says AusCERT

Powered by SC Magazine
 

Health records need to be more secure than bank data.

View larger image View larger image View larger image

See all pictures here »

The Government's plan to introduce electronic health records is a "nightmare" for security according to the head of industry group AusCERT

AusCERT boss Grahame Ingram said information security risks were amplified because of the highly sensitive nature of patient data held under the e-health scheme.

"It is a nightmare scenario," Ingram said. "That they think they have the security to safeguard the data is just a nightmare."

The Government had compared e-health security to systems used by major banks, but to Ingram, that fell short.

Bank security was not flawless, he said, and financial transactions were considered "compromised" -- a state that could not be extended to sensitive e-health records.

He said security should be thought of as damage mitigation not intrusion prevention because of the complexity of attacks.

"Banks examine risk profiles, they have accepted risk," he said. "If there was a better system out there to secure their data, I'm sure they would be using it."

Ingram warned that compromises of patient data were likely from insecure end user machines, and said there was a "misplaced trust" in technology.

"The end user attack capability is now fully deployable against the enterprise and is much harder to mitigate," he said.

Copyright © SC Magazine, Australia


 
 
 
Top Stories
ATO shaves $4m off IT contractor panel
Reform cuts admin burden, introduces KPIs.
 
Turnbull introduces data retention legislation
Still no definition of metadata to be stored.
 
Crime Commission prepares core systems overhaul
Will replace 30 year-old national criminal database.
 
 
Sign up to receive iTnews email bulletins
   FOLLOW US...
Latest Comments
Polls
In which area is your IT shop hiring the most staff?




   |   View results
IT security and risk
  27%
 
Sourcing and strategy
  13%
 
IT infrastructure (servers, storage, networking)
  21%
 
End user computing (desktops, mobiles, apps)
  14%
 
Software development
  25%
TOTAL VOTES: 440

Vote
Would your InfoSec team be prepared to share threat data with the Australian Government?

   |   View results
Yes
  54%
 
No
  46%
TOTAL VOTES: 211

Vote