New York Tech Media
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital
No Result
View All Result
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital
No Result
View All Result
New York Tech Media
No Result
View All Result
Home News

Third-party health apps are vulnerable to hacks, report finds

New York Tech Editorial Team by New York Tech Editorial Team
October 18, 2021
in News
0
Third-party health apps are vulnerable to hacks, report finds
Share on FacebookShare on Twitter

Third-party health apps that pull patient data from electronic health record systems are vulnerable to hacks, according to a new report. The electronic health records themselves, which are housed at health centers and subject to the federal privacy law HIPAA, are well protected. But as soon as a patient gives permission for their data to leave the health record and head toward a third-party app — like programs that track people’s medications, for example — it’s easy for hackers to access.

Hospitals and health care systems are a major target for hackers, and attacks have only escalated over the past few years. Patient health data is some of the most valuable information to hackers: each record can be worth hundreds of dollars on the dark web, in part because they can’t be changed easily and it’s harder to detect when the data is used fraudulently. Credit card numbers, on the other hand, can easily be changed and are only worth a few dollars.

For this new report sponsored by app security company Approov, cybersecurity analyst Alissa Knight checked for vulnerabilities in apps built using the Fast Healthcare Interoperability Resources (FHIR) standard, which was set up to encourage information exchange in healthcare. She started by checking apps built within the electronic health records themselves and didn’t find weaknesses. But when she tested third-party programs that link up with health records to pull out data, she found major problems. Knight was able to access over 4 million patient and clinician records from over 25,000 providers through those holes.

“She didn’t need to use advanced cybersecurity hacking,” John Moehrke, an interoperability expert and member of the FHIR management group, told STAT News. “She just used basic stuff that your freshman year of cybersecurity would have stressed.”

Third-party applications and data aggregators are important for healthcare — they help doctors and patients by pulling health records into more accessible formats, or they aggregate information from different appointments into one place. The Department of Health and Human Services has rules that encourage health systems to make sure they can talk to each other electronically — it’s important to help give people access to their own health information and to help doctors coordinate care.

But there needs to be more care and security around those applications, Knight wrote in the report. Once data leaves a health record and enters a third-party application, it isn’t covered by HIPAA, so it isn’t subject to HIPAA’s standards around data protection or on how people should be notified if their data is accessed. The Federal Trade Commission recently clarified that the third-party apps do have to notify users about data breaches, but the commission can’t add on additional privacy or security regulations for those apps.

“There needs to be some separate oversight mechanism to protect patients and the apps that they use,” the new report recommended.

Credit: Source link

Previous Post

Warburg Pincus to sell stake in mortgage fintech Newfi to Athene

Next Post

After $100M round, RTP startup Kryia Therapeutics spins out new group focusing on eye diseases

New York Tech Editorial Team

New York Tech Editorial Team

New York Tech Media is a leading news publication that aims to provide the latest tech news, fintech, AI & robotics, cybersecurity, startups & leaders, venture capital, and much more!

Next Post
After $100M round, RTP startup Kryia Therapeutics spins out new group focusing on eye diseases

After $100M round, RTP startup Kryia Therapeutics spins out new group focusing on eye diseases

  • Trending
  • Comments
  • Latest
Meet the Top 10 K-Pop Artists Taking Over 2024

Meet the Top 10 K-Pop Artists Taking Over 2024

March 17, 2024
Panther for AWS allows security teams to monitor their AWS infrastructure in real-time

Many businesses lack a formal ransomware plan

March 29, 2022
Zach Mulcahey, 25 | Cover Story | Style Weekly

Zach Mulcahey, 25 | Cover Story | Style Weekly

March 29, 2022
How To Pitch The Investor: Ronen Menipaz, Founder of M51

How To Pitch The Investor: Ronen Menipaz, Founder of M51

March 29, 2022
Japanese Space Industry Startup “Synspective” Raises US $100 Million in Funding

Japanese Space Industry Startup “Synspective” Raises US $100 Million in Funding

March 29, 2022
UK VC fund performance up on last year

VC-backed Aerium develops antibody treatment for Covid-19

March 29, 2022
Startups On Demand: renovai is the Netflix of Online Shopping

Startups On Demand: renovai is the Netflix of Online Shopping

2
Robot Company Offers $200K for Right to Use One Applicant’s Face and Voice ‘Forever’

Robot Company Offers $200K for Right to Use One Applicant’s Face and Voice ‘Forever’

1
Menashe Shani Accessibility High Tech on the low

Revolutionizing Accessibility: The Story of Purple Lens

1

Netgear announces a $1,500 Wi-Fi 6E mesh router

0
These apps let you customize Windows 11 to bring the taskbar back to life

These apps let you customize Windows 11 to bring the taskbar back to life

0
This bipedal robot uses propeller arms to slackline and skateboard

This bipedal robot uses propeller arms to slackline and skateboard

0
The Future of “I Do”: How Technology is Revolutionizing Weddings in 2025

The Future of “I Do”: How Technology is Revolutionizing Weddings in 2025

March 19, 2025
Eldad Tamir

AI vs. Traditional Investing: How FINQ’s SEC RIA License Signals a New Era in Wealth Management

March 17, 2025
Overcoming Payment Challenges: How Waves Audio Streamlined Transactions with BridgerPay

Overcoming Payment Challenges: How Waves Audio Streamlined Transactions with BridgerPay

March 16, 2025
Arvatz and Iyer

PointFive and Emertel Forge Strategic Partnership to Elevate Enterprise FinOps in ANZ

March 13, 2025
Global Funeral Traditions Meet Technology

Global Funeral Traditions Meet Technology

March 9, 2025
Canditech website

Canditech is Revolutionizing Hiring With Their New Product

March 9, 2025

Recommended

The Future of “I Do”: How Technology is Revolutionizing Weddings in 2025

The Future of “I Do”: How Technology is Revolutionizing Weddings in 2025

March 19, 2025
Eldad Tamir

AI vs. Traditional Investing: How FINQ’s SEC RIA License Signals a New Era in Wealth Management

March 17, 2025
Overcoming Payment Challenges: How Waves Audio Streamlined Transactions with BridgerPay

Overcoming Payment Challenges: How Waves Audio Streamlined Transactions with BridgerPay

March 16, 2025
Arvatz and Iyer

PointFive and Emertel Forge Strategic Partnership to Elevate Enterprise FinOps in ANZ

March 13, 2025

Categories

  • AI & Robotics
  • Benzinga
  • Cybersecurity
  • FinTech
  • New York Tech
  • News
  • Startups & Leaders
  • Venture Capital

Tags

3D bio-printing acoustic AI Allseated B2B marketing Business carbon footprint climate change coding Collaborations Companies To Watch consumer tech cryptocurrency deforestation drones earphones Entrepreneur Fetcherr Finance Fintech food security Investing Investors investorsummit israelitech Leaders LinkedIn Leaders Metaverse news OurCrowd PR Real Estate reforestation software start- up startupnation Startups Startups On Demand startuptech Tech Tech leaders technology UAVs Unlimited Robotics VC
  • Contact Us
  • Privacy Policy
  • Terms and conditions

© 2024 All Rights Reserved - New York Tech Media

No Result
View All Result
  • News
  • FinTech
  • AI & Robotics
  • Cybersecurity
  • Startups & Leaders
  • Venture Capital

© 2024 All Rights Reserved - New York Tech Media