TMI OCR Settlement, Gerry’s Healthcare Research Revealed, Mirrorthief Supply Chain Risks




InfoSec ICU show

Summary: Steve and Gerry discuss a recent $3M OCR settlement with Touchstone Medical Imaging (TMI) and how foundational security controls are commonly missed. Gerry finally shares his Ph.D. research with the show and digs into the main issues facing small healthcare practices. Finally, the guys discuss Supply Chain risk using the recent MirrorThief card skimming attacks to illustrate.<br> As always they end with One Cool Thing.<br> <a href="https://podcast.musc.edu/podcast/infosec/e74-infosecicu/" target="_blank" rel="noopener noreferrer">Show Notes</a><br> <br> Resources:<br> TMI OCR Settlement<br> <a href="https://www.hhs.gov/sites/default/files/tennessee-diagnostic-medical-imaging-services-ra-cap.pdf" target="_blank" rel="noopener noreferrer">https://www.hhs.gov/sites/default/files/tennessee-diagnostic-medical-imaging-services-ra-cap.pdf</a><br>  <br> <br> Flashlight in a Dark Room Theory – Dr Gerald Auger research dissertation<br> <a href="https://scholar.dsu.edu/theses/329/" target="_blank" rel="noopener noreferrer">https://scholar.dsu.edu/theses/329/</a><br>  <br> <br> Mirrorthief Credit Card Skimming Attack<br> <a href="https://www.scmagazine.com/home/security-news/mirrorthief-card-skimming-attack-steals-card-data-from-online-college-stores/" target="_blank" rel="noopener noreferrer">https://www.scmagazine.com/home/security-news/mirrorthief-card-skimming-attack-steals-card-data-from-online-college-stores/</a><br>  <br> One Cool Thing<br> Google adding privacy tools to Chrome<br> <a href="https://www.wsj.com/articles/googles-new-privacy-tools-to-make-cookies-crumble-competitors-stumble-11557151913" target="_blank" rel="noopener noreferrer">https://www.wsj.com/articles/googles-new-privacy-tools-to-make-cookies-crumble-competitors-stumble-11557151913</a><br>  <br> 15th Academic Medical Center Security and Privacy Conference, June 3-4, 2019<br> <a href="https://nchica.org/conferences/amc2019/" target="_blank" rel="noopener noreferrer">https://nchica.org/conferences/amc2019/</a><br> Contact<br> Email <a href="mailto:infosecicu@musc.edu">infosecicu@musc.edu</a><br> Twitter:<br> <br> * <a href="https://twitter.com/Gerald_Auger" target="_blank" rel="noopener noreferrer">Gerry Auger (@Gerald_Auger)</a><br> * <a href="https://twitter.com/sgcardinal" target="_blank" rel="noopener noreferrer">Steven Cardinal (@sgcardinal)</a><br> <br>