Health-ISAC Hacking Healthcare 2-11-2020
TLP White: In this edition of Hacking Healthcare, we begin with an analysis of the coronavirus that tries to cut through the media sensationalism to explore a more nuanced perspective of its impacts. Next, we examine why the anonymization of data is often more marketing myth than security fact. Finally, we look at how a new suit against a university medical center fits into a larger conversation around privacy, research, and technological change in the healthcare sector.
As a reminder, this is the public version of the Hacking Healthcare blog. For additional in-depth analysis and opinion, become a member of H-ISAC and receive the TLP Amber version of this blog (available in the Member Portal.)
Welcome back to Hacking Healthcare.
1. Coronavirus in Context:
As the coronavirus continues to dominate media coverage, it is worthwhile to put the scale and cost of its effects into context. This is not to minimize the very real threats and damage being done, nor to belittle the genuinely heroic efforts of countless caregivers and healthcare professionals who willingly risk their own safety, and sometimes give their lives, to combat the disease. Putting the coronavirus in context is important to ensure that uninformed and sensationalist depictions don’t inadvertently harm the effectiveness of responses. This overload of coverage can misrepresent and oversimplify the extent to which the coronavirus impacts individuals and the global economy. As anyone who works in risk and crisis management can attest, only by objectively assessing threats can resources be allocated, and strategies put in place, that effectively and efficiently mitigate human and economic costs.
If one were to judge the coronavirus outbreak by media attention alone, you could be forgiven for fearing the outbreak is an unstoppable viral scourge. Hourly updates on the fate of quarantined ships[1], emergency evacuations of foreign nationals[2], facemask shortages[3], and travel bans[4] are regularly pushed to televisions, smartphones, and computers. As of Tuesday, more than 43,000 people worldwide are believed to have been infected by the coronavirus, with roughly 1,000 deaths attributed to it.[5], [6] These numbers are not trivial, and they will certainly continue to rise over the coming weeks and months. But without a frame of reference, it is difficult to discern its impact relative to other healthcare and public health issues.
The human cost is the most immediate concern. While it is likely too early to accurately estimate the fatality rate, early estimates suggest that the coronavirus is at less than 3%.[7], [8] This would put the coronavirus well behind the fatality rate of the two other well-known members of its family, SARS (~10%) and MERS (~35%).[9] Furthermore, while the coronavirus has already been responsible for more deaths than the early 2000’s SARS outbreak, it pales in comparison to the number of deaths attributed to seasonal influenza. According to the CDC, the seasonal flu is responsible for anywhere from 12,000-61,000 deaths a year in the United States alone, and recent studies estimate global deaths attributed to the flu range between 290,000-650,000 annually.[10], [11] Furthermore, it is worth noting that these deaths disproportionately affect those with weakened immune systems, such as children and the elderly, and those who do not have access to quality medical care.
Where the coronavirus is also making a seriously significant impact is on the global economy. As policies are enacted to slow the spread of the virus, the second order effects include shuttered offices and manufacturing plants, as well as halted transportation networks. China’s importance to the global supply chain in any number of industries cannot be overstated, and Wuhan is a major logistics hub. According to a Bloomberg report, “China is the largest exporter of intermediate manufactured goods,” and global reliance on those goods reached 20% in 2015.[12]
With this in mind, the coronavirus will certainly cause havoc on the complex supply chains that underlie many of today’s products, especially in electronics. Due to the complex nature of many of these supply chains, it may not be readily apparent just how disruptive the coronavirus will end up becoming. However, if containment policies become more severe or continue for an extended period, the effects will become increasingly noticeable and will be felt globally.
Additionally, travel bans and restrictions create circumstances where personnel that rely on international travel for their business suddenly find themselves unable to do their jobs, or at least suffer from negative impacts to productivity and project delays. Major global events, such as the Mobile World Congress, are already suffering from multiple companies pulling out entirely.[13] Given the economic cost of implementing these measures, it is notable that the International Health Regulations Emergency Committee, convened by the World Health Organization, “does not recommend any travel or trade restriction based on the current information available.”[14], [15]
2. How Anonymous is Anonymized Data?
A common defense thrown out by organizations to mitigate the backlash following the disclosure that they have been selling user data or in the wake of a breach, is the assertion that because they have anonymized the data, there is limited risk to the affected individuals. A soon to be released paper from a team of Harvard University students will allegedly demonstrate just how easy it can be to deanonymize data. In an age of near limitless interconnected information, data anonymization in many cases might be more of a marketing myth than security and privacy reality.
Data anonymization is defined by U.S. National Institute of Standards and Technology (“NIST”) as the “process that removes the association between the identifying dataset and the data subject.”[16] It is also sometimes used interchangeably with terms like de-identification and is standard practice in many organizations the hold sensitive information about individuals. In some cases, anonymization is even required by rules and regulations in certain industries. In a vacuum, data anonymization can work well. By removing any extra identifiers that go above and beyond a dataset’s purpose, it can be extremely difficult to reidentify who the data belongs to.
In practice however, the problem with anonymization lies with the vast quantities of data that is available all over the internet. Last summer, researchers from Imperial College London published results in Nature Communications demonstrating that by using machine learning, researchers were able to accurately reidentify 99.98% of individuals in their dataset.[17] Their method involved collating data from 210 data sets to cross-reference them with each other.[18] In another example, Massachusetts Institute of Technology (“MIT”) scientists and urban planners were able to reidentify individuals in Singapore with 95% accuracy using only datasets of mobile phone logs and transit trips.[19] The Harvard University students detailed that their method involves a “tool that combs through vast troves of consumer datasets exposed from breaches,” before ultimately reintegrating them like puzzle pieces.[20]
3. University Medical Center Accused of Sharing Patient Data:
The University of Pittsburgh Medical Center (“UPMC”) is defending itself from a civil lawsuit that claims that a web-based tool that they use may have been sending patient data to third party companies. The plaintiffs in the suit are seeking payment for what they believe is a misuse of their patient data. UPMC has denied the allegations stating that they “rigorously [protect] the medical information our patients have entrusted to us and complies fully with all laws, rules and regulations governing such information.”[21]
The tool in question is intended to help patients find a doctor that suits their particular search criteria. The plaintiffs allege that the tool is embedded with tracing codes that can “redirect the user’s personal information and the contents of communications to third parties including Microsoft, Google, and Facebook.”[22] Furthermore, the suit alleges that this exchange of data is part of an advertisement agreement between UPMC and the third parties.[23] UPMC would provide the data and in return could expect that those third parties would advertise UPMC services to targeted demographics.[24] UPMC denies it has fallen afoul of any regulations and laws and has promised that what information it does share has been sufficiently anonymized. As we have just explored, claiming to have anonymized any shared data should not be a relief to those potentially impacted by UPMC’s policies.
Congress –
Tuesday, February 11th:
– Senate – Committee on Homeland Security and Governmental Affairs: Hearings to examine a roadmap for effective cybersecurity, focusing on what states, locals, and the business community should know and do.
Wednesday, February 12th:
– House – Committee on Financial Services: Hearing: Task Force on Artificial Intelligence: Equitable Algorithms: Examining Ways to Reduce AI Bias in Financial Services
Thursday, February 13th:
– No relevant hearings
International Hearings/Meetings –
EU –
Monday, February 17th
European Parliament – Committee on Environment, Public Health and Food Safety
Tuesday, February 18th
European Parliament – Committee on Environment, Public Health and Food Safety
Conferences, Webinars, and Summits –
–The Evolution of Authentication by HYPR – Webinar (2/13/2020)
The Evolution of Authentication by HYPR
–H-ISAC Member Meet-Up at RSA Conference – San Francisco, CA (2/25/2020)
https://h-isac.org/hisacevents/h-isac-member-meet-up-at-rsa-conference-2/
–H-ISAC Analysts Security Workshop – Titusville, FL (3/4/2020)
https://h-isac.org/hisacevents/h-isac-analysts-security-workshop-titusville-fl/
–H-ISAC Member Meet-Up at HIMSS Global Conference – Location TBA (3/11/2020)
https://h-isac.org/hisacevents/h-isac-member-meet-up-at-himss/
–H-ISAC Security Workshop – Chennai, India (3/27/2020)
https://h-isac.org/hisacevents/h-isac-security-workshop-india/
–H-ISAC Monthly Member Threat Briefing – Webinar (3/31/2020)
H-ISAC Monthly Member Threat Briefing – Mar 31 2020
–2020 APAC Summit – Singapore (3/31/2020-4/2/2020)
/summits/
–H-ISAC Security Workshop – Cambridge, MA (4/7/2020)
https://h-isac.org/hisacevents/h-isac-security-workshop-cambridge-ma/
–H-ISAC Security Workshop – Atlanta, GA (4/14/2020)
https://h-isac.org/hisacevents/h-isac-security-workshop-atlanta/
–Healthcare Cybersecurity Forum – Mid-Atlantic – Philadelphia, PA (4/20/2020)
https://endeavor.swoogo.com/2020_healthcare_innovation_cybersecurity_forums/426497
–H-ISAC Security Workshop – Frederick, MD (6/9/2020)
https://h-isac.org/hisacevents/h-isac-security-workshop-frederick-md/
–AAMI Exchange – New Orleans, LA (6/12/2020-6/15/2020)
https://h-isac.org/hisacevents/aami-exchange/
–Healthcare Cybersecurity Forum – Rocky Mountain – Denver, CO (7/20/2020)
https://endeavor.swoogo.com/2020_healthcare_innovation_cybersecurity_forums/426499
–Healthcare Cybersecurity Forum – Southeast – Nashville, TN (9/9/2020)
https://endeavor.swoogo.com/2020_healthcare_innovation_cybersecurity_forums/426517
–Healthcare Cybersecurity Forum – Northeast – Boston, MA (9/22/2020)
https://endeavor.swoogo.com/2020_healthcare_innovation_cybersecurity_forums/427126
–Summit on Security & Third Party Risk – National Harbor, MD (9/28/2020-9/30/2020)
GRF Summit on Security & Third Party Risk Digital Series
–Healthcare Cybersecurity Forum – Texas – Houston, TX (10/8/2020)
https://endeavor.swoogo.com/2020_healthcare_innovation_cybersecurity_forums/428840
–Healthcare Cybersecurity Forum – Pacific Northwest – Seattle, WA (10/28/2020)
https://endeavor.swoogo.com/2020_healthcare_innovation_cybersecurity_forums/428886
–Healthcare Cybersecurity Forum – California – Los Angeles, CA (11/12/2020)
Sundries –
–Justice Department Attributes Equifax Hack to Chinese Military Officers
–Veterans Affairs Launches Its First 5G-Enabled Hospital
–Scammers are trying to exploit coronavirus concerns to breach companies
https://www.cyberscoop.com/coronavirus-phishing-emails-proofpoint-research/
–Why is the healthcare industry still so bad at cybersecurity?
Contact us: follow @HealthISAC, and email at contact@h-isac.org
[1] https://www.cbsnews.com/live-updates/coronavirus-usa-confirmed-cases-news-cruise-ship-death-toll-evacuations-latest-2020-02-07/
[2] https://www.nytimes.com/2020/02/05/us/coronavirus-flights-wuhan.html
[3] https://www.nytimes.com/2020/02/06/business/coronavirus-face-masks.html
[4] https://www.cnn.com/2020/02/07/health/coronavirus-travel-ban/index.html
[5] https://www.worldometers.info/coronavirus/
[6] https://www.who.int/docs/default-source/coronaviruse/situation-reports/20200210-sitrep-21-ncov.pdf?sfvrsn=947679ef_2
[7] https://www.cdc.gov/csels/dsepd/ss1978/lesson3/section3.html
[8] https://www.nytimes.com/interactive/2020/world/asia/china-coronavirus-contain.html
[9] https://www.nytimes.com/interactive/2020/world/asia/china-coronavirus-contain.html#virulence
[10] https://www.cdc.gov/flu/about/burden/index.html
[11] https://www.ncbi.nlm.nih.gov/pmc/articles/PMC6815659/
[12] https://www.bloomberg.com/graphics/2020-global-economic-impact-of-wuhan-novel-coronavirus/
[13] https://www.theverge.com/2020/2/10/21131118/mwc-2020-coronavirus-intel-sony-amazon-cancel
[14] https://www.who.int/news-room/detail/30-01-2020-statement-on-the-second-meeting-of-the-international-health-regulations-(2005)-emergency-committee-regarding-the-outbreak-of-novel-coronavirus-(2019-ncov)
[15] https://www.wired.com/story/travel-bans-and-quarantines-wont-stop-coronavirus/
[16] https://csrc.nist.gov/glossary/term/anonymization
[17] https://gizmodo.com/researchers-reveal-that-anonymized-data-is-easy-to-reve-1836629166
[18] https://gizmodo.com/researchers-reveal-that-anonymized-data-is-easy-to-reve-1836629166
[19] https://www.fastcompany.com/90278465/sorry-your-data-can-still-be-identified-even-its-anonymized
[20] https://www.vice.com/en_us/article/dygy8k/researchers-find-anonymized-data-is-even-less-anonymous-than-we-thought
[21] https://www.post-gazette.com/business/healthcare-business/2020/02/05/UPMC-denies-lawsuit-s-charges-that-websites-share-information-with-Facebook-Google/stories/202001310116
[22] https://www.post-gazette.com/business/healthcare-business/2020/02/05/UPMC-denies-lawsuit-s-charges-that-websites-share-information-with-Facebook-Google/stories/202001310116
[23] https://www.law360.com/articles/1237523/upmc-accused-of-giving-private-patient-info-to-advertisers
[24] https://www.law360.com/articles/1237523/upmc-accused-of-giving-private-patient-info-to-advertisershttps://www.law360.com/articles/1237523/upmc-accused-of-giving-private-patient-info-to-advertisers
- Related Resources & News
- 2024 Newsletter – November
- How Healthcare Facilities Can Prepare for All Types of Emergencies
- Health-ISAC Hacking Healthcare 10-24-2024
- UnHack (the Podcast): Generating Cyber Resilience Through Collaboration with Errol Weiss
- Newfangled and Fastest-Growing Phishing Cyberattacks: Updated Guide for Healthcare Leaders
- Health-ISAC Hacking Healthcare 10-15-2024
- Health-ISAC Welcomes Booz Allen Hamilton to the Ambassador Program
- Health-ISAC Hacking Healthcare 10-9-2024
- Monthly Newsletter – October 2024
- Health ISAC leads effort to transform SBOM information sharing under CISA-facilitated community work