Indian Health Service fails testing of IT security

The Indian Health Service (IHS) failed a penetration test of its computer network conducted last June by the Department of Health & Human Services’ Office of Inspector General.

The June 2013 test was a follow-up to an IT general controls audit of IHS’ network security controls. The audit found that such controls were inadequate, according to the OIG’s report.  

HIS officials were aware of the penetration test but incident response staff were not notified of the testing to assess the effectiveness of IHS’ intrusion detection and response controls.

“Overall, IHS needs to address cyber vulnerabilities on its computer network,” according to OIG’s test results. The audit team was able to obtain unauthorized access to an IHS web server which allowed access to the internal IHS network and obtain user account and password data including user names and passwords to HIS databases. This failure is considered high risk.

The audit team also was able to gain control of an IHS computer which allowed access to the computer’s resources, including records in the file system. This is considered medium risk.

OIG made several recommendations to IHS including fix the vulnerability on the IHS web server, implement more effective procedures to protect its computer systems from cyber attacks and periodically measure adherence to IHS security policies and procedures. Due to the sensitive nature of specific findings identified during the test, detailed technical findings were provided only to IHS.

In January, HITRUST announced plans, dubbed CyberRx, to conduct exercises to simulate cyber attacks on healthcare organizations.

Read the complete OIG report on the IHS penetration test.

Beth Walsh,

Editor

Editor Beth earned a bachelor’s degree in journalism and master’s in health communication. She has worked in hospital, academic and publishing settings over the past 20 years. Beth joined TriMed in 2005, as editor of CMIO and Clinical Innovation + Technology. When not covering all things related to health IT, she spends time with her husband and three children.

Around the web

Compensation for heart specialists continues to climb. What does this say about cardiology as a whole? Could private equity's rising influence bring about change? We spoke to MedAxiom CEO Jerry Blackwell, MD, MBA, a veteran cardiologist himself, to learn more.

The American College of Cardiology has shared its perspective on new CMS payment policies, highlighting revenue concerns while providing key details for cardiologists and other cardiology professionals. 

As debate simmers over how best to regulate AI, experts continue to offer guidance on where to start, how to proceed and what to emphasize. A new resource models its recommendations on what its authors call the “SETO Loop.”