Live data from Hacker News

“Anthem was the target of a very sophisticated external cyber attack”

anthemfacts.com

111–120 of 206 posts

Re: “Anthem was the target of a very sophisticated external cyber attack”

#111
post #63

Having spent almost 4 years in healthcare IT. Very few healthcare organizations take security seriously. There is very much a security by anonymity ideal. I worked for a small medical company that had access to 20,000 PHI records, and I was explicitedly told, "why would anyone want to hack us, we are small potatoes." I left that company shortly there after. Yet companies I work with now big and small look at security…

You should be upvoted way more. I also worked in healthcare IT for three years and security was basically an exercise in checking boxes to claim HIPAA compliance. So long as everyone could avoid fines or being sued by the office of civil rights we were considered secure.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#112

Earlier quoted context omitted.

Thanks for the advice. Can you give some specific steps on how to "monitor your child's SSN for activity"? How would I go about doing this?

Start with Trans Union, they have a child specific application so you can find out if your child's SSN has been used by identity thieves: http://www.transunion.com/corporate/personal/fraudIdentityTh... If they don't have any reports, there's a good chance you're probably ok. You can also apply to put a security freeze on your child's SSN. State by state laws and application process here: http://consumersunion.org/res…

Just filled out the Trans Union site with dummy data to check, and none of the transaction is over SSL. So, to kind out if my child's identity has been stolen I have to expose them to identity theft....

Re: “Anthem was the target of a very sophisticated external cyber attack”

#113
post #71

I'm just thrilled to recently be downgraded to an Anthem customer. I miss my old insurance.

They're fantastically better than any other insurance I've had. What they cover for my family is easily another income every year. What did you have before?

Re: “Anthem was the target of a very sophisticated external cyber attack”

#114
post #40
post #20

It makes me wonder. For several years the US government, Medicare, and private insurers have been pushing hard for health care providers to adopt Electronic Health Record systems. Now in the current phase "interoperability" of EHR systems is the catchword. A question to ask is how secure is a large network of EHRs going to be? I don't know of data showing the frequency or severity of EHR security breaches but it woul…

"A question to ask is how secure is a large network of EHRs going to be?" LOL, everyone 'on the inside' (by that I mean: at least anyone who works on computers, software or networks professionally) knows the answer to that question: it's going to be a train wreck. There is not a single person on this planet who really understands just 1% of the software, hardware and network infrastructure they/we work on every day;…

No, you're about right. On the bigger corporate side, security is at least the big buzzword. The VP- and C-level positions want to be sure that action is being taken to improve security, but day to day requests to poke holes in the walls come in. That is not to even mention the huge, ancient systems that are in the middle of multi-year replacement processes that began before security was so important. That means at best the replacement will have the security best practices of the last few years stapled on awkwardly, but more likely nothing will change given the millions poured in already.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#115
post #109
post #63

Having spent almost 4 years in healthcare IT. Very few healthcare organizations take security seriously. There is very much a security by anonymity ideal. I worked for a small medical company that had access to 20,000 PHI records, and I was explicitedly told, "why would anyone want to hack us, we are small potatoes." I left that company shortly there after. Yet companies I work with now big and small look at security…

Most security decisions aren't taken by senior management. I am sure it is not Sony's senior management who decided to store passwords in clear text in the PSN. Management focus would ensure everyone in the organisation focuses on security but most security breaches are the result of IT people doing stupid things or making stupid decisions on the ground. It's not senior management's role to check that you didn't intr…

That's just not true. The direction of IT certainly is set by upper management, as well as the budget. If IT says 'we need an IDS' and management says 'it's not in the budget', what can IT do about it? If IT says 'it will take this long and this much money to change our password policy' and management say 'work on new things, not changing old things', what can IT do about it?

Senior management might not directly set the password policy, but they do say what you should work on, and by proxy, what you're not going to have the time to work on. And besides, what is the role of management if not keeping track of their employees? If an employee fucks up that bad, it's their managers fault.

And yes, if the accounting department was that incompetent, SOX says it's senior management's fault. That's what the yearly attestation is for.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#116

I feel most for those who have young children. If you consider the long term viability of SSN over the life-span of a person who is under the age of 5 today they'll likely have been exposed to a breach that will contain their dox a few times over by the time they reach a legal age - that is likely a conservative estimate given the frequency of these events. SSN is broken and we're going to see a lot of push back goin…

We really do need to find a better way of authenticating and identifying people. SSNs were never meant for this and they clearly don't fill the role successfully. I've long been a proponent of the government announcing that they will publish everyone's SSN 2 years from now. Banks, insurance companies, the govt, etc have until then to figure better methods.

There are plenty of better ways already. A simple public/private keypair would go a long way towards this goal.

The problem is that everyone working on crypto products focuses on just developing technology, often attempting to make existing crypto systems easier to use for ordinary people. This is fine, but it's only a partial solution. We need to educate people who don't know and don't care about proper security. Nobody is going to use the most secure and easy to use crypto system if they don't see the benefit and think that a SSN or a driver's license is a good way to show their identity.

There is a lot of hand wringing about how hard it is to get ordinary people to take security seriously, but honestly this is a problem that will solve itself given enough time and enough breaches such as this. Until people understand that only secret information--which they and only they know--can be used to authenticate them and protect their information, this will just keep happening.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#117

Earlier quoted context omitted.

Start with Trans Union, they have a child specific application so you can find out if your child's SSN has been used by identity thieves: http://www.transunion.com/corporate/personal/fraudIdentityTh... If they don't have any reports, there's a good chance you're probably ok. You can also apply to put a security freeze on your child's SSN. State by state laws and application process here: http://consumersunion.org/res…

Just filled out the Trans Union site with dummy data to check, and none of the transaction is over SSL. So, to kind out if my child's identity has been stolen I have to expose them to identity theft....

That shocked me as well. Doesn't exactly give you a warm fuzzy feeling about a major credit reporting agency's security measures. Do some of these companies just view these breaches/vulnerabilities as a joke?

Re: “Anthem was the target of a very sophisticated external cyber attack”

#118
post #33
post #25

Earlier quoted context omitted.

>It's great that they "made every effort to close the security vulnerability". I love that quote, they try to cover their asses by saying we closed the vulnerability. My question is why did you wait till it was taken advantage of?

Even better is that they didn't explicit state that they did close the vulnerability -- simply that they put forth every effort to do so.

If we combine the Check Point firewall job posted on the Anthem Inc's website on 1/30/2015, add in the "discovery" on 1/29/2015, and think about Check Point's vulnerability to Heartbleed and Shellshock last year, one might also guess that a VPN stolen-credential compromise (like the major CHS breach last year) or a generic firewall compromise (via shellshock) are in the running as possibilities.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#119
post #63

Having spent almost 4 years in healthcare IT. Very few healthcare organizations take security seriously. There is very much a security by anonymity ideal. I worked for a small medical company that had access to 20,000 PHI records, and I was explicitedly told, "why would anyone want to hack us, we are small potatoes." I left that company shortly there after. Yet companies I work with now big and small look at security…

During an auto accident & court case everyone- doctors, lawyers, insurance- used my SS# as a case identifier even though I never gave it out. If a few percent of these are sloppy, them one could be screwed. Some meth people like to dumster dive insurance companies and the like.

Re: “Anthem was the target of a very sophisticated external cyber attack”

#120

Earlier quoted context omitted.

In Sweden we have a personal number. It's unique to every person but its not secret at all. You use an official identity card or passport or the electronic variant to identify yourself. I'm guessing its some kind of privacy issue behind there not being a similar system in US? Because it works pretty well.

Well, the US has States and that complicates things quite a bit for this type of thing. Most states will give you a driver's license number as an id (with the appropriate "ID Only" mark). There is also the Real ID Act[1] that trying to establish federal id requirements. This is going to cause some problems and look for it in the news. It is a DHS enforced national ID law. And yes, some of the folks in the US believe…

some of the folks in the US believe a national ID that is needed to buy, sell, or get a job would be a little too close to the Bible's mark of the beast.

You're exaggerating a bit into a strawman.

I strongly oppose REAL ID (which, by the way, was around for a while before the DHS existed). And as a "tooth fairy agnostic" as Dawkins would say, I'm not the least bit concerned about the number of the beast.

What I am concerned about - and this goes the same for anyone else with whom I've discussed the issue - is, why is it the federal government's business at all when and how I "buy, sell, or get a job"? This seems like a tool for the federal government to get its grubby mitts into more stuff that's not within its enumerated powers.

Post reply on HN