Protect you computer and your data
 

Welcome to our computer security Archive. Have fun browsing!

 

Article #181: Instant Messaging And P2p Vulnerabilities For Health Organizations

(Browse for more articles)

 
Because of HIPAA legislation, health IM and P2P also expose end-user equipment
organizations have to be particularly to worms, viruses and other backdoor
careful about the vulnerability of the software that -once introduced, can
patient data they maintain. Exposing infect a network and inflict damage on a
patient data to the Internet through IM wide scale. Employee abuse of their
exchanges or P2P file sharing can computer privileges can be the silent
jeopardize their compliance with a destroyer of networks. Whether it is a
variety of state and federal regulations. dramatic problem such as denial of
The popularity of IM and P2P protocols service or the downloading of backdoor
has penetrated every aspect of our worms and viruses, the misuse can be
society including those organizations dangerous and damaging and ultimately
entrusted with sensitive data such as undermines network security.
health records. The opportunity for data Managers of network security need to take
to be exposed to eyes outside an advantage of hardware appliance solutions
organization has increased whether such in order to fully protect their networks
exposure is intentional or not and from employee abuse and misuse. The
organizations bound by HIPAA regulations damage to productivity and profits of a
are required to protect their patient company are only the tip of the iceberg.
data or suffer the consequences. Introducing a filtering option that does
Often in hospital situations, employees not have a single point of failure, or
on different shifts are sharing cause latency in network traffic is
workstations. Many of them may be critical. Equally important, a solution
communicating with family and friends, that doesn't need to share memory or
outside the organization, via Instant processing power with another device is
Messaging or P2P and can unknowingly the best choice to protect networks
download a malicious agent that can against security breaches and legal
damage not only individual workstations, liability and to help preserve the
but entire networks. Because many people corporation's good reputation.
may have access to the same computer, Legal Liabilities
this activity is difficult to trace and P2P and IM file sharing can be dangerous
can occur with alarming ease. applications that quickly devour
When a malicious program is downloaded, bandwidth and jeopardize company finances
it can exploit a back door in the system because companies can be held liable for
and proliferate across the network. employee actions such as downloading
Depending on the nature of the parasitic copyrighted song material. In addition,
code, patient information may be accessed P2P and IMs can contain malicious
and transmitted from behind the firewall software that downloads and installs
to a designated IP address or it may itself into the host network; a company's
launch an attack against the host computers and networks may be used to
network. These types of attacks can bring launch denial of service (DoS) attacks on
the network down. Even short downtime can other companies and networks.
cause significant financial and data There is an established legal precedent
loss. that will hold a company liable in part
Public Communications for the damages inflicted on another
Adding more complexity to the situation, company if their computers or networks
the Securities and Exchange Commission were used to stage the attack. Because of
(SEC) and the National Association of this legal precedent, the danger to a
Securities Dealers Inc. (NASD) identify host network is not just the loss of
Instant Messaging traffic as bandwidth and subsequent breakdown in
communications with the public that communications, but also the legal
companies must save and monitor. The liabilities involved can result in damage
Sarbanes-Oxley Act requires even those to a company or organization's
instant messages that are casual and reputation, and even threaten its
personal to be saved and recorded as financial stability.
formal correspondence. It's important to note that the damage to
Many companies capture and store the data an organization's reputation can be more
as required by law. Because this costly in the long run, especially if the
information can be used as legal organization is supposed to be secure and
evidence, there are several instances web savvy or if security vulnerabilities
where data contained on message boards can threaten to expose sensitive data
and via IMs were submitted to support or such as health records. For hospitals,
defeat a case being adjudicated. Imagine health insurance and dedicated health
if medical advice were contained in an care providers, such damage can result in
IM, even something as innocuous as a loss of business over time that
advising Tylenol for a feverish child. devastates their long term prospects and
Such correspondence could be used to make when combined with -short term fines, can
a medical malpractice case against a even mean going out of business or
nurse or physician. experiencing a takeover by another health
Network Security care company.






1- A- B- C- 2- 3- 4- 5- 6- 7- 8- 9- 10- 11- 12- 13- 14- 15- 16- 17- 18- 19- 20- 21- 22- 23- 24- 25- 26- 27- 28- 29- 30- 31- 32- 33- 34- 35- 36- 37- 38- 39- 40- 41- 42- 43- 44- 45-