Protect you computer and your data


Instant Messaging And P2p Vulnerabilities For Health Organizations

Because of HIPAA legislation, health
organizations have to be particularly carefulIM and P2P also expose end-user equipment to
about the vulnerability of the patient dataworms, viruses and other backdoor software
they maintain. Exposing patient data to thethat -once introduced, can infect a network
Internet through IM exchanges or P2P fileand inflict damage on a wide scale. Employee
sharing can jeopardize their compliance withabuse of their computer privileges can be the
a variety of state and federal regulations.silent destroyer of networks. Whether it is a
The popularity of IM and P2P protocols hasdramatic problem such as denial of service or
penetrated every aspect of our societythe downloading of backdoor worms and
including those organizations entrusted withviruses, the misuse can be dangerous and
sensitive data such as health records. Thedamaging and ultimately undermines network
opportunity for data to be exposed to eyessecurity.
outside an organization has increased whether
such exposure is intentional or not andManagers of network security need to take
organizations bound by HIPAA regulations areadvantage of hardware appliance solutions in
required to protect their patient data ororder to fully protect their networks from
suffer  the  consequences.employee abuse and misuse. The damage to
productivity and profits of a company are
Often in hospital situations, employees ononly the tip of the iceberg. Introducing a
different shifts are sharing workstations.filtering option that does not have a single
Many of them may be communicating with familypoint of failure, or cause latency in network
and friends, outside the organization, viatraffic is critical. Equally important, a
Instant Messaging or P2P and can unknowinglysolution that doesn't need to share memory or
download a malicious agent that can damageprocessing power with another device is the
not only individual workstations, but entirebest choice to protect networks against
networks. Because many people may have accesssecurity breaches and legal liability and to
to the same computer, this activity ishelp preserve the corporation's good
difficult to trace and can occur withreputation.
alarming  ease.
Legal  Liabilities
When a malicious program is downloaded, it
can exploit a back door in the system andP2P and IM file sharing can be dangerous
proliferate across the network. Depending onapplications that quickly devour bandwidth
the nature of the parasitic code, patientand jeopardize company finances because
information may be accessed and transmittedcompanies can be held liable for employee
from behind the firewall to a designated IPactions such as downloading copyrighted song
address or it may launch an attack againstmaterial. In addition, P2P and IMs can
the host network. These types of attacks cancontain malicious software that downloads and
bring the network down. Even short downtimeinstalls itself into the host network; a
can cause significant financial and datacompany's computers and networks may be used
loss.to launch denial of service (DoS) attacks on
other  companies  and  networks.
Public  Communications
There is an established legal precedent that
Adding more complexity to the situation, thewill hold a company liable in part for the
Securities and Exchange Commission (SEC) anddamages inflicted on another company if their
the National Association of Securitiescomputers or networks were used to stage the
Dealers Inc. (NASD) identify Instantattack. Because of this legal precedent, the
Messaging traffic as communications with thedanger to a host network is not just the loss
public that companies must save and monitor.of bandwidth and subsequent breakdown in
The Sarbanes-Oxley Act requires even thosecommunications, but also the legal
instant messages that are casual and personalliabilities involved can result in damage to
to be saved and recorded as formala company or organization's reputation, and
correspondence.even  threaten  its  financial  stability.
Many companies capture and store the data asIt's important to note that the damage to an
required by law. Because this information canorganization's reputation can be more costly
be used as legal evidence, there are severalin the long run, especially if the
instances where data contained on messageorganization is supposed to be secure and web
boards and via IMs were submitted to supportsavvy or if security vulnerabilities can
or defeat a case being adjudicated. Imaginethreaten to expose sensitive data such as
if medical advice were contained in an IM,health records. For hospitals, health
even something as innocuous as advisinginsurance and dedicated health care
Tylenol for a feverish child. Suchproviders, such damage can result in a loss
correspondence could be used to make aof business over time that devastates their
medical malpractice case against a nurse orlong term prospects and when combined with
physician.-short term fines, can even mean going out of
business or experiencing a takeover by
Network  Securityanother health care company.



1 A B C 50 51 52 53 54 55 56 57 58 59 60 61 62 63 64 65 66 67 68 69 70 71 72 73 74 75 76 77 78 79 80 81 82 83 84 85 86 87 88 89 90 91 92 93 94 96 97 98 99 100 101 102 103 104 105