<?xml version="1.0" encoding="utf-8"?>
<rss xmlns:content="http://purl.org/rss/1.0/modules/content/" version="2.0">
  <channel>
    <title><![CDATA[[SecurityRatty] tag: umass]]></title>
    <link>http://securityratty.com/tag/umass</link>
    <description></description>
    <pubDate>Wed, 30 Apr 2008 11:54:48 +0000</pubDate>
    <generator>iRatty Engine</generator>
    <docs>http://blogs.law.harvard.edu/tech/rss</docs>
    <item>
      <title><![CDATA[Intrusion into UMass Amherst University Health Services network]]></title>
      <link>http://securityratty.com/article/bf47c63d3967bee3e9de22405605c51a</link>
      <guid>http://securityratty.com/article/bf47c63d3967bee3e9de22405605c51a</guid>
      <description><![CDATA[Technorati Tag: Security Breach

Date Reported
4/18/08

Organization
University of Massachusetts System

Contractor/Consultant/Branch
University of Massachusetts System at Amherst
University Health...]]></description>
      <content:encoded><![CDATA[Technorati Tag: <a href="http://technorati.com/tag/security+breach" rel="tag">Security Breach</a><br><br>
<img src="http://breachblog.com/images/95781-88451/umassam.jpg" align="right" height="108" width="96"><font size="2"><span style="font-weight: bold;">Date Reported: </span><br>4/18/08<br><br><span style="font-weight: bold;">Organization: </span><br><a href="http://www.massachusetts.edu/index.html?CFID=3057800&amp;CFTOKEN=55165067">University of Massachusetts System</a> <br><br><span style="font-weight: bold;">Contractor/Consultant/Branch:</span><br><a href="http://umass.edu/umhome/">University of Massachusetts System at Amherst</a> <br><a href="http://www.umass.edu/uhs/">University Health Services</a> <br><br><span style="font-weight: bold;">Victims:</span><br>Patients<br><br><span style="font-weight: bold;">Number Affected:</span><br>Unknown<br><br><span style="font-weight: bold;">Types of Data:</span><br>"personal information" and "medical records"<br><br><span style="font-weight: bold;">Breach Description:</span><br>"Hackers breached the computer system used by UMass Amherst's Health Services, potentially gaining access to thousands of medical records."<br><br><span style="font-weight: bold;">Reference URL:</span><br><a href="http://www.cbs3springfield.com/news/local/18021744.html">CBS Channel 3 News (Springfield)</a> <br><a href="http://umass.edu/newsoffice/newsreleases/articles/74339.php">UMass Amherst Press Release</a> <br><br><span style="font-weight: bold;">Report Credit:</span><br>Lesley Tanner, CBS Channel 3 News<br><br><span style="font-weight: bold;">Response:</span><br>From the online source cited above:<br><br>Hackers breached the computer system used by UMass Amherst's Health Services, potentially gaining access to thousands of medical records.<br><br>More than half of the student population at UMass Amherst are patients on record at the University Health Services.<br><span style="font-style: italic;">[Evan] According to the UMass Amherst web site, the school had an enrollment of 25,593 total undergraduate and graduate students in the fall of 2006.&nbsp; This just gives us a sense for how big the school is, not how many people may be affected by the supposed breach.</span><br><br>Though many of the most personal medical records are kept on paper files, officials say some personal information is available on the 150 computers used by the department.<br><br>The incident occurred April 11, and, after an initial investigation of the remote intrusion, the University decided to shut down the network<br><br>To date, about 30 workstations have been returned to service and officials project that the entire network will be operating within the next week.<br><br>The workstations in question contained limited patient information.<br><br>"What we're doing is going through as quickly as we can," says UMass Spokesperson Ed Blaguszewski. "And we are making an assessment and can't say for sure that the material wasn't breached."<br><br>Officials believe outside hackers wanted to use the server as a host for illegal music and video downloads, one that would make the culprits untraceable.<br><span style="font-style: italic;">[Evan] Firewalls, intrusion detection/prevention, logging, etc.?&nbsp; Outside "hackers" for the most part are amongst the easiest to protect confidential information from.&nbsp; "Hackers" looking for a place to store and distribute files are typically opportunists and script-kiddies, and these are even easier to protect against.&nbsp; Were the affected machines workstations, or servers?</span><br><br>"It wasn't a case from what we can tell of someone being in the office and breaking into a computer," says Blaguszewski. "These things are done remotely often times from countries all over the world."<br><br>A fact that's even more unsettling for patients who were unaware of the breach more than a week after it occurred.<br><span style="font-style: italic;">[Evan] It seems like the school doesn't know who may be affected and thus they don't know who to notify.</span><br><br>The University did post a notice on the Health Services website, and say they are notifying patients when they enter the clinic.<br><span style="font-style: italic;">[Evan] The </span><a style="font-style: italic;" href="http://umass.edu/newsoffice/newsreleases/articles/74339.php">notice</a><span style="font-style: italic;"> </span><br><br>Campus officials say it will be weeks before they are completely sure what information, if any, was taken off the computers.<br><br>The University has launched a detailed evaluation of the incident to find out if any of the files were accessed during the intrusion, and will keep the community advised of its findings.<br><br>They say the entire campus system is being looked at to avoid future breaches.<br><span style="font-style: italic;">[Evan] This should be a continuous effort.</span><br><br><span style="font-weight: bold;">Reaction from Students:</span><br>"I've been here every time I've been sick this semester," says Freshman Brooke Quinn.<br><br>"That's my doctor, it's where I go," says Senior Jennifer Scott.<br><br>"I think that it is scary that anybody on our campus could have our personal information and medical records," says Quinn. <br><br>"I wasn't aware of it, and no one I know was aware of it," says Scott. "If it's that easy for someone who just wanted to get music who knows what would happen for someone who was trying to get confidential information."<br><br><span style="font-weight: bold;">Commentary:</span><br>There is too much uncertainty surrounding this (apparent) breach.&nbsp; If you are a concerned and potentially affected person, I would encourage you to contact officials with the school and seek answers.&nbsp; You could also contact Ed Blaguszewski, his contact information is on the <a href="http://umass.edu/newsoffice/newsreleases/articles/74339.php">press release</a>.&nbsp; They should be done with their investigation by now. <br><br><span style="font-weight: bold;">Past Breaches:</span><br>Unknown</font><br><br>
<script src="http://feeds.feedburner.com/%7Es/breachblog?i=http://breachblog.com/2008/04/30/umassam.aspx" type="text/javascript" charset="utf-8"></script>]]></content:encoded>
      <pubDate>Wed, 30 Apr 2008 11:54:48 +0000</pubDate>
      <category domain="http://securityratty.com/tag/university health services">university health services</category>
      <category domain="http://securityratty.com/tag/university">university</category>
      <category domain="http://securityratty.com/tag/information">information</category>
      <category domain="http://securityratty.com/tag/personal information">personal information</category>
      <category domain="http://securityratty.com/tag/health services">health services</category>
      <category domain="http://securityratty.com/tag/protect confidential information">protect confidential information</category>
      <category domain="http://securityratty.com/tag/contact information">contact information</category>
      <category domain="http://securityratty.com/tag/amherst">amherst</category>
      <category domain="http://securityratty.com/tag/umass amherst">umass amherst</category>
      <source url="http://breachblog.com/2008/04/30/umassam.aspx">Intrusion into UMass Amherst University Health Services network</source>
    </item>
  </channel>
</rss>
