Modern Australian
Men's Weekly

.

The latest health data breach is one reason why I’ll be opting out of MyHealthRecord

  • Written by Robert Merkel, Lecturer in Software Engineering, Monash University
The latest health data breach is one reason why I’ll be opting out of MyHealthRecord

Family Planning NSW has taken its website offline for a “security update” after learning that hackers breached its booking system two weeks ago. The organisation notified its clients via email, and journalist Lauren Ingram, who was personally affected by the data breach, shared the notification on Twitter.

The letter stated that:

These databases contained information from around 8,000 clients who had contacted Family Planning NSW through our website in the past two and a half years, seeking appointments or leaving feedback.

Read more: After the Medicare breach, we should be cautious about moving our health records online

Family Planning NSW offers reproductive and sexual health services, and the breach has sparked fears that sensitive personal information about clients could have been compromised.

In this case, the risk to patients is not as severe as it could have been. Medical practices typically keep the actual medical records of patients separate from online booking systems.

However, the information in the booking system is still sufficient to assist with identity fraud. Furthermore, for some patients, there are very serious risks merely in disclosing that they are patients of such services:

Ransomware is a common form of cybercrime

According to the notification, hackers exploited a weakness in the web-based booking system of Family Planning NSW and demanded a Bitcoin ransom.

We don’t know the full details of this particular attack, but the information in the notification letter indicates the attackers may have used some kind of ransomware. Ransomware is malicious software that electronically locks up (encrypts) the data on a computer system. If no backup is available, the only way to access the data is to pay the ransom for the key to unlock (decrypt) the data.

Read more: Defending hospitals against life-threatening cyberattacks

Ransomware authors do not typically attempt to read the contents of the information they hold to ransom – their business model involves denying access to information, not making use of it. However, ransomware that has sufficient access to scramble data, has sufficient access to steal that information. Therefore, while it is more likely than not that no information was actually copied, it cannot be guaranteed.

Technically sophisticated attackers will sometimes use what appears to be one type of attack (such as ransomware) to disguise their real intentions. Security professionals who specialise in “incident response” (IR), are able to assess this risk when an apparent ransomware attack has occurred. I expect that in a high-profile data breach like this, IR specialists have been consulted.

Oversight of medical privacy could be inadequate

It is not feasible for patients of a medical practice to assess the adequacy of the security and privacy processes – and nor should they. Patients aren’t expected to assess the skill of a surgeon to operate, or whether the instrument sterilisation processes are adequate!

Instead it is the legal and ethical obligation of medical practices, and the bodies that accredit them, to ensure their technology and processes are adequate to protect privacy and security. All medical practices are required to implement the Australian Privacy Principles specified in the Privacy Act, regardless of size (most other small businesses are not). Medical practices are also subject to mandatory reporting of data breaches.

Some of the representative bodies of medical specialities attempt to assess privacy and security as part of practice accreditation. In the case of general practitioners, the Royal Australian College of General Practitioners’ accreditation standards require practices to develop privacy and security procedures and policies. They also provide a more detailed information security standard.

Unfortunately, it’s not at all clear how rigorously these policies and procedures are actually checked, both for their adequacy and whether they are actually followed.

My informal inquiries in the sector suggest that at the very least accreditation processes do not focus heavily on the technical aspects of privacy and security. My own general practitioner is fully accredited by the RACGP via one of its approved accreditation assessment partners, but does not even have a privacy policy on its website.

More evidence that the health sector has work to do in this area comes from the new mandatory notification requirement for data breaches. Since its introduction earlier this year, the health sector has had more notifications than any other sector.

What can patients do?

As in many other aspects of healthcare, patients generally have to place their trust in the competence and diligence of the professionals. But patients who believe they face particularly high risks do have some options to protect themselves.

The Australian Privacy Principles require that, where practicable, patients should be able to interact with a medical practice anonymously, or under a pseudonym. The RACGP accreditation material (PDF link) recommends practices set up procedures to support this.

Even if a pseudonym is not for you, it is prudent to consider minimising the amount of information you provide on medical booking services, which are inherently more vulnerable than medical record systems not exposed to the public internet.

Read more: Why has healthcare become such a target for cyber-attackers?

A major change to the way your medical data is managed is on the way – and one with serious privacy implications. The My Health Record is a centralised repository of personal healthcare information, maintained by the Australian government. It is designed to improve healthcare by improving access to patient information for doctors, as well as facilitate research.

However, the combination of improved access to records and less-than-perfect information security practices in the health sector is likely, in my view, to increase the risk of privacy breaches.

You have the chance to opt out of the My Health Record system during a three-month window between July 16 and October 15. After this date, a record can be rendered inaccessible but not completely deleted. This data breach, and the rate at which they are occurring throughout the healthcare sector, further reinforces my intention to opt out.

Authors: Robert Merkel, Lecturer in Software Engineering, Monash University

Read more http://theconversation.com/the-latest-health-data-breach-is-one-reason-why-ill-be-opting-out-of-myhealthrecord-96644

5 Essential Tips for Hiring Gold Coast Plumbers

Finding the best plumber on the Gold Coast can be as complex as navigating a network of pipes, requiring an expert who is capable, reliable, and s...

Hidden Costs of Moving You Need to Budget For (And How to Avoid Them)

Moving house ranks among life's most busy experiences, and discovering unexpected expenses along the way certainly doesn't help with stress levels. Wh...

Understanding Australian Building Regulations: What Every Mornington Builder Wants You to Know

If you live on the Mornington Peninsula, you likely already feel the risk of bushfires,hot, dry summers, nearby bushland, and epic wind events. That...

Top 5 Home Exercises Recommended by Chiropractors for Better Posture

In today’s world of endless screen time and back-to-back Zoom meetings, it’s no surprise that posture-related issues are on the rise. From achin...

Simple Home Exercises to Manage Chronic Pain and Improve Mobility

Living with chronic pain doesn’t have to mean a life of limitation. Many people struggling with persistent discomfort find themselves moving less...

Smart Renovation Tips for a Sleek, Low-Maintenance Interior

In a world where time is tight and stress is high, our homes should feel like a refuge not another to-do list. That’s why smart renovations are tr...

Stay Cool in Queensland: The Complete Guide to Choosing the Right Air Conditioner

Introduction Queensland’s warm, humid climate makes a reliable air conditioning system an essential part of daily life. Whether you’re creating a...

Proving Partner Visas with Lawyers and Solid Evidence

You’re ready to build a life with your partner in Australia but the visa process quickly turns something personal into something official. Suddenl...

The History and Philosophy Behind Osteopathic Medicine

Osteopathy is more than just a hands-on approach to relieving pain—it’s a holistic health philosophy with roots in history, science, and a deep ...

Common Bathroom Renovation Mistakes and How to Avoid Them

Renovating a bathroom can be one of the most rewarding home improvement projects, offering both enhanced functionality and a fresh aesthetic. Howeve...

5 Simple Home Modifications to Support Occupational Therapy Goals

Every year, thousands of Australians face mobility challenges, chronic pain, or sensory issues that make daily tasks difficult. Simple changes at ho...

The Cost of Converting a Shipping Container into a Liveable Space

Container conversions often require more planning and labour than expected Early costs include foundations, framing, and structural reinforceme...

Marriage Celebrant for Modern Lovers Who Want Something Different

Many couples today feel pressure to follow the same wedding traditions their parents or grandparents did. They might sit through long ceremonies that ...

Why Everyone’s Signing Up for Fitstop’s 6-Week Challenge (Again)

Hint: It’s not just for the gains. Somewhere between the endless TikTok fitness hacks and the unrealistic “30-day shred” promises, we forgot ...

The Mental & Financial Benefits of Minimalist Caravan Travel

Minimalist caravan travel has grown in popularity, not just for its practical appeal but also for the sense of freedom it brings. With the rise of c...

Sydney Property Lawyers: Your Complete Guide to Smooth Transactions

Navigating the Sydney property market can feel like traversing a minefield, can't it? The process, laden with legal jargon and complex procedures, o...

Electrician Perth: Your Go-To Guide for Home Electrical Safety

When it comes to keeping your home safe and sound, electricity is something you simply can't afford to ignore. Faulty wiring, outdated switchboards...

Why More Homes and Businesses Are Choosing an Electric Sliding Door

Convenience, aesthetics, and technology often go hand in hand when it comes to architectural choices. One solution that delivers all three is the el...