Read The Times Australia

Daily Bulletin

Questions still need answering in Australia's largest health data breach

  • Written by: David Glance, Director of UWA Centre for Software Practice, University of Western Australia
image

In what is Australia’s biggest data breach of medical information, more than 550,000 customers of the Australian Red Cross Blood Service had personal and medical details exposed online and leaked to an anonymous hacker last week.

According to the Blood Service, the data leaked was contained in a backup of a database of its online web site. One part) of the database contained the answers to an online questionnaire which donors complete in order to book an appointment with the service. The questionnaire covers information about the donor’s name, age and address but also medical questions related to the donor’s current health, state of pregnancy and finally about whether the donor has in the last 12 months, engaged in at-risk sexual behaviour.

The backup database had been left, not on the Blood Service website, but on a server managed by the Blood Services’s website developer, Precedent. The database was found there by an anonymous hacker who had been scanning sites for security vulnerabilities and stumbled across the completely unprotected database. On realising what the data was, the hacker contacted a consultant, Troy Hunter, who runs a site called “have i been pwned”. Have i been pwned allows people to see if there email address and other details have been leaked and made publicly available in previous data breaches. Hunter’s and his wife’s details were included in the Blood Service database because they had both donated blood in Australia. Hunter contacted AusCert, a cyber emergency response team located at the University of Queensland and informed them of the breach and the data he had been sent.

AusCert in turn contacted the Blood Service who then notified its donors of the breach. Hunter and the anonymous hacker both deleted their copies of the backup database. Security specialists that the Blood Service had employed to review the breach determined that it was likely that the database had not been discovered by anyone else in the time it was available on the internet.

For the time being, it looks like the Blood Service has managed to dodge what could have been an even more devastating blow to its credibility. Whilst most donors (including Troy Hunter) may not let this incident stop them from donating in future, the incident does bring into question the overall capability of the Blood Service to protect and keep safe extremely sensitive information about its customers. A question it should be addressing is why it was collecting and saving this information through its website in this manner in the first place. An even bigger question is whether it will continue to collect and save this information in the same way.

What the Blood Service should be asking itself is:

[1] Do I really need to collect this information? In the case of the Blood Service the answer is probably no. Whilst it seems like it is being efficient to ask screening questions on the appointment questionnaire, none of the information needs to be saved if the point is simply to give feedback to people that they are unlikely to be eligible to donate blood.

[2] Do you know where all of your data is? In the case of the Blood Service, and indeed its contractor Precedent, the answer was clearly no. A developer had taken a backup of the live system which he or she shouldn’t have needed access to, and put it on an unsecured server that was exposed to the internet. Considering the type of sensitive information the Blood Service dealt with, to entrust that information to a web developer without putting any checks or process in place to prevent access to this information highlights the inexperience of the Blood Service.

[3] Do you know who has access to all of your data? Again, the Blood Service clearly didn’t know that developers at Precedent would have access to its production data. Given that this data was unencrypted, it meant that people outside of the Blood Service would have had the ability to look at the data and potentially leak this information through informal channels. A developer or other staff member at Precedent could have searched the data for a relation, friend, colleague or celebrity to see if they had engaged in risky sex for example. There seemed to be no protections built into the website itself to manage or restrict access. This is possibly because the Blood Service didn’t treat the questionnaire as part of its core systems, erroneously trying to reassure donors that: “The website forms used to collect this information do not connect to our secure internal databases which contain more sensitive donor medical information”. The Blood Service clearly felt, incorrectly, that the personal information collected as part of the questionnaire was not sensitive.

There are of course, more direct cyber security measures that need to be implemented but they are of little use if a company isn’t even aware of the fact that they have data that needs protecting.

By comparison with the US, this data breach is still moderate. A hack earlier this year of 21st Century Oncology affected 2.2 million patients. Another case this year saw details 950,000 of Centene’s patients lost on 6 computer hard drives.

In the US, 21st Century Oncology is facing a US $57 million class action lawsuit over the breach. US federal regulators recently fined Advocate Health Care Network US $5.55 million over three separate breaches that could have affected 4.1 million patients.

The Australian Red Cross Blood Service, and its contractor Precedent, potentially faces fines of up to AU $1.7 million for this breach if it is deemed to have violated the Privacy Act. In the past however, Australian telco Telstra was fined a mere AU $10,000 for exposing the details of 16,000 of its customers online.

If the Blood Service continues with the questionnaire for appointments on its website, it will be clear that it hasn’t learned any lessons from this breach. Precedent in turn, needs to demonstrate to the Blood Service and all of its other clients that it actually can live up to its privacy statement which says: “We store your information securely on our computer system, we restrict access to those who have a need to know, and we train our staff in handling the information securely”.

Authors: David Glance, Director of UWA Centre for Software Practice, University of Western Australia

Read more http://theconversation.com/questions-still-need-answering-in-australias-largest-health-data-breach-67916

Business News

How Immigration Lawyers Can Help

Introduction Visa decisions can shape employment, family life, study plans, travel, and future residence. A small omission can lead to delay, added expense, or refusal. Immigration lawyers assess l...

Daily Bulletin - avatar Daily Bulletin

How Industrial Drying Equipment Supports Efficient Processing

Many industrial processes require moisture to be removed from compressed air, products or process materials before they move to the next stage. Excess moisture can affect equipment performance, produc...

Daily Bulletin - avatar Daily Bulletin

Practical Ways a Whiteboard Can Improve Workplace Communication

Effective communication helps teams stay organised, share ideas and keep track of important information. While digital tools are now common in many workplaces, a whiteboard continues to provide a simp...

Daily Bulletin - avatar Daily Bulletin

Designing Eco-Friendly Custom Water Bottles for Your Next Event

The Evolution of Sustainable Event Merchandise Event planning has undergone a massive transformation over the last decade. Gone are the days when organizers could hand out cheap, single use plastic...

Daily Bulletin - avatar Daily Bulletin

Why Choosing a Professional Florist Melbourne Makes Flower Delivery Impactful

Flowers have a great power to speak when humans cannot express their feelings with right words. Flowers are the best gifts when you are celebrating a birthday or welcoming a newborn child into your fa...

Daily Bulletin - avatar Daily Bulletin

The Business Case for Choosing Australian Fabricators Over Imported Alternatives

For a long time, you might have defaulted to overseas suppliers when sourcing fabricated metal components for a project. The unit price was lower on paper, and the maths seemed straightforward. That...

Daily Bulletin - avatar Daily Bulletin

Australian organisations are relying on business continuity plans built for a far more predictable world

Tariff escalations, supply chain fragility, geopolitical events, and the ongoing threat of cyber disruption have reshaped the risk environment facing Australian organisations. The problem is that ma...

Daily Bulletin - avatar Daily Bulletin

How to Rent a Car for Uber in Melbourne: What Every New Driver Needs to Know

Starting out as an Uber driver in Melbourne is not as complicated as it sounds but getting the vehicle right is where most new drivers get stuck. Uber has strict requirements around vehicle age, condi...

Daily Bulletin - avatar Daily Bulletin

When Should You Speak to a Lawyer About a Legal Issue?

Legal issues can begin with a simple question, then become harder to manage once formal steps are involved. Many people wait until a matter feels urgent before seeking guidance, even though earlier ...

Daily Bulletin - avatar Daily Bulletin

The Daily Magazine

Why Accurate Measurements Matter When Ordering Flatpack Cabinets

Ordering flatpack cabinets can make a renovation or storage project more manageable, but the proce...

How Long Does Interstate Freight Take in Australia?

If you have ever arranged for stock, equipment or materials to travel from one Australian state to a...

How AEC Firms Can Scale Faster Without Sacrificing Project Quality

Growth presents a fundamental dilemma for architecture, engineering, and construction firms: expan...

What Makes an Aesthetic Clinic Worth Going Back To?

Trying an aesthetic clinic for the first time can feel like a bit of a gamble. You can read review...

Elevate Your Morning Routine with Cafe-Style Coffee at Home with the Right Coffee Machine

There's something magical about that first sip of coffee in the morning. It’s more than just a bev...

Top Garment Steamers for Busy Professionals in Australia

The gap between garment steamers built for a quick touch-up and ones built to keep pace with a wor...

Correct Sleeping Posture to Minimize Back Strain

Most people don’t pay much attention to how they sleep until they start waking up with a stiff bac...

Why Product Longevity Matters for Sustainable Australian Buildings

Sustainability in building design is often associated with recycled materials, renewable resources a...

NDIS Support Coordination Explained: What Does a Support Coordinator Actually Do?

NDIS support coordination explained means understanding how a professional can help participants n...