Enlarge / Frank Abagnale, as played by Leonardo DiCaprio in Catch Me If You Can, once pretended to be a doctor. Now he's teaching the health industry about the threat of identity theft.
Dreamworks
Frank Abagnale is world-famous for pretending to be other people. The former teenage con man, whose exploits 50 years ago became a Leonardo DiCaprio film called Catch Me If You Can, has built a lifelong career as a security consultant and advisor to the FBI and other law enforcement agencies. So it's perhaps ironic that four and a half years ago, his identity was stolenalong with those of 3.6 million other South Carolina taxpayers.
"When that occurred," Abagnale recounted to Ars, "I was at the FBI office in Phoenix. I got a call from [a reporter at] the local TV news station, who knew that my identity was stolen, and they wanted a comment. And I said, 'Before I make a comment, what did the State Tax Revenue Office say?' Well, they said they did nothing wrong. I said that would be absolutely literally impossible. All breaches happen because people make them happen, not because hackers do it. Every breach occurs because someone in that company did something they weren't supposed to do, or somebody in that company failed to do something they were supposed to do." As it turned out (as a Secret Service investigation determined), a government employee had taken home a laptop that shouldn't have left the office and connected itunprotectedto the Internet.
Government breaches of personal information have become all too common, as demonstrated by the impact of the hacking of the Office of Management and Budget's personnel records two years ago. But another sort of organization is now in the crosshairs of criminals seeking identity data to sell to fraudsters: doctors' offices. Abagnale was in Orlando this week to speak to health IT professionals at the 2017 HIMSS Conference about the rising threat of identity theft through hacking medical recordsa threat made possible largely because of the sometimes haphazard adoption of electronic medical records systems by health care providers.
Abagnale warned that the value of a medical record to identity thieves far surpasses that of just a name, date of birth, and social security number. That's because it provides an even bigger window into an individual's life. Abagnale saysthe responses of organizations (including the state government of South Carolina and the OPM) to theft of sensitive personal information is far from adequateand because there's no way to effectively change the data, it can be held for years by criminals and still be valuable.
Nikki Haley, the governor of South Carolina at the time of the breach, "ordered credit monitoring for every citizen in the state for free for one year," Abagnale said. "I wrote her a letter the next day that said one year of credit monitoring services was worthless, because people who steal mass data warehouse that data for sometimes three to five years. So they're not going to put it in the marketplace when you told them you're giving credit monitoring for one year." President Obama ordered free credit protection for those affected by the OPM breach for 10 yearsthough the original plan ran out in December, and it's on the shoulders of those whose information was exposed to re-up for the protection.
When credit card data is stolen, Abagnale explained, criminals "have to get rid of it right away"because credit cards can be replaced and fraud stopped quickly. "But if it is someone's name, Social Security Number, and date of birththey can't change [those things]. So the longer I keep the data, the more valuable it becomes when I go to sell it." Abagnale noted that some of the personal identity data stolen from the breach at TJ Maxx a decade ago is just starting to surface on the black market, for instance.
Abagnale said that there's been a surge in the past few years in medical identity theft. "It's as simple as, I'm in Orlando and I break my leg, I have no insurance, and I go to the hospital and say I'm you," he explained. "I give them your information, they treat me, they bill your insurance agency, and then your insurance company eventually notifies you because there was a deductible. And you say, 'wait a minute, I was never in Orlando, I never broke my leg.' But it's not that simpletrying to get that fixed, and trying to get it off your medical records, and then having collection agencies hounding you for that money is just unbelievable."
Such a scenario isjust the beginning of what's possible with the theft of medical data today. "Like every form of identity theft, if I can become you," said Abagnale, "what I can do as you is only limited by my imagination."
That's why Abagnale is particularly concerned about the security of smaller healthcare organizations, especially pediatricians' practices. "These days, we're very concerned about the theft of children'sidentities," he explained. "We see a huge uptick in people stealing the identities of children. The younger that child, the more valuable that identity isbecause if I can become that child, I can become that child for a long period of time before that child is going to begetting a credit report or applying for credit or a job. And a two-year-old's [stolen identity] is not going to look like a five-year-old a few years later, because someone can use that identity over and over."
The wave of ransomware attacks against hospitals last year served as a stark wake-up call to health providers that they had a security problem, according to Rod Piechowski, a senior director at HIMSS. "Ransomware got the most publicity," he said. "It put a sense of threats in people'sminds more than any conversation they'd had previously."
For many health organizations, those threats are well outside their wheelhouse. Healthcare organizations have faced a "real lift" in adopting electronic health systems over the past seven years, Piechowski explained, particularly for those that never had an information technology department before. It's "thousands of hospitals and hundreds of thousands of providers having to implement information technology," he says.
Regulations like those under the Health Insurance Portability and Accountability Act (HIPAA) have always placed privacy and security requirements on healthcare providers, but the Affordable Care Act's incentives were intended "to get people using and reporting that they were using these electronic systems," Piechowski explained. However, the focus wasn't on security practices. "So now all these companies find themselves in a situation where theyve become way more of a target. We're seeing an uptick in the intensity and aggression in targeting of healthcare specifically. There are attackers out there that are aware of the lack of real defense mechanisms in placeit's a new game."
Piechowski's description of what the healthcare industry now faces is similar to what many companies have been facing for much of the last decade"they're constantly seeing phishing attempts, constantly seeing malware," he said. And while there are technical means to screen against many of the more brute-force attacks, the value of data in hospitals has led to much more long-game attacks based on thorough reconnaissance and probing for weak points. "There's a longer road, where first they find out who you are, they learn more about you, and about the hierarchy of your organization," he told Ars. "We're seeing more sophisticated approaches to learning about your organization."
In other words, hospitals are ripe targets for social engineeringsomething Frank Abagnale remainsan expert in. "It's what I did 50 years ago as a teenager. I didn't have the access to computers, so I had to use the telephone. Social engineering is just as powerful today as it was 50 years ago when I used it." Abagnale believes that technology alone will never defeat a good social engineering game"the only answer is to absolutely educate your employees about how to protect themselves and how to protect their company."
To that end for the past eight years, Abagnalehas done "cyber awareness" training at major companies across the US to demonstrate just how vulnerable employees are to the most basic of social engineering tricks. "I don't park in the visitor parking lotI park in the employee parking lot, and then I remove from my pocket 25 or 30 memory sticks that say on them 'confidential' [and drop them in the parking lot]. Then at lunchtime, I'll open my laptop to see how many employees actually went to see what that memory stick had on it, and I can tell whether they put it in their computer and didn't open it or if they opened it. In the 7 or 8 years that I've been doing cyber awareness month, I've yet to be to a companyand they're all household nameswhere someone hasn't gone to see what the file on the stick says. And of course what it says is, 'this is a test and you've failed.'"
Abagnale's seminars hammer home the damage that employees can expose companies to by simply plugging in a USB drive they found in the parking lot. "I explain to them that I could have cost their company a billion dollars overnight. I could have destroyed the hundred-year-old brand of their company just by the act of their taking a look at that," he says. "That's the way you have to bring home that point, and you have to keep bringing it home. They will get it, but they need to understand how these things occur. You can't just say to them, 'Hey, people will hack in; you need to be careful.' You have to explain to them how they do it, why they do it, what they're trying to obtain. And once they understand it, they're smart enough to protect themselves from being a victim against that risk."
Abagnale and Piechowski believe the best defense against breaches is using this sort of reinforcement of the threat posed by not following policies and procedures. "What we're alluding to here," explained Piechowski, "is that it's not just technologythere's people involved, there's process involved, and if you don't have a process in place that people understand, then technology alone is not going to keep you safe." The only effective way to get people to understand and change to follow policies, he noted, is to spell out whats at risk.
"The culture of the organization will change in time once it recognizes the business threat," Piechowski said. "Because if the business isn't viable, that's their livelihood."
So the next time you're frustrated by the arcane processes of your health provider, rememberthey're in placefor everyone'sprotection.
Read the original post:
Frank Abagnale, world-famous con man, explains why technology won't stop breaches - Ars Technica
- Technology Synonyms, Technology Antonyms | Thesaurus.com [Last Updated On: January 7th, 2017] [Originally Added On: January 7th, 2017]
- Information technology - Wikipedia [Last Updated On: January 7th, 2017] [Originally Added On: January 7th, 2017]
- Technology and Electronics Reviews - USATODAY.com [Last Updated On: January 7th, 2017] [Originally Added On: January 7th, 2017]
- Technology Forum - reddit.com [Last Updated On: January 7th, 2017] [Originally Added On: January 7th, 2017]
- Technology: Industries: PwC [Last Updated On: January 22nd, 2017] [Originally Added On: January 22nd, 2017]
- National Education Technology Plan - Office of Educational ... [Last Updated On: January 22nd, 2017] [Originally Added On: January 22nd, 2017]
- Technology News - The New York Times [Last Updated On: January 24th, 2017] [Originally Added On: January 24th, 2017]
- Computer Business Review - Computer Business Review [Last Updated On: January 24th, 2017] [Originally Added On: January 24th, 2017]
- Technology - Pogue's Posts Blog - The New York Times [Last Updated On: February 2nd, 2017] [Originally Added On: February 2nd, 2017]
- What the Tech: Neuro-Bio Monitor Technology - KFDX [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Globalization failed too many people. Here's the technology that could help it work for everyone - Quartz [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Bill Nye forecasts next 50 years, says we're at a technological crossroad - Digital Trends [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Interview with Matt Nix about his new Fox show APB. - Slate - Slate Magazine [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- In This Year's Super Bowl Of Technology, Intel Led The Way With A Sky Full Of Drones - Forbes [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Learning From Last Year: Technology Funding Outlooks For 2017 - Forbes [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Ossia hires new CEO to help commercialize its wireless charging technology - GeekWire [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Microsoft's AI group debuts customizable speech-to-text technology, rapidly expanding 'cognitive services' for ... - GeekWire [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- A flare for self-destruction: How technology is the means, not the cause, of our demise - National Post [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Broadcaster dangles new technology for Winter Olympics - Reuters [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- These Four Black Women Inventors Reimagined the Technology of the Home - Smithsonian [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- How 3D and Self-Design Will Change Technology - Huffington Post [Last Updated On: February 7th, 2017] [Originally Added On: February 7th, 2017]
- Factory Boss Says Fishing Technology Could Improve Controversial US Border Wall - Voice of America [Last Updated On: February 8th, 2017] [Originally Added On: February 8th, 2017]
- Republicans Aim to Kill Election Technology Standards Agency - Gizmodo [Last Updated On: February 8th, 2017] [Originally Added On: February 8th, 2017]
- Solutions replace technology as the focus at ISE 2017 - Installation International [Last Updated On: February 8th, 2017] [Originally Added On: February 8th, 2017]
- Five Rules That Define The Technology Innovator - Forbes [Last Updated On: February 8th, 2017] [Originally Added On: February 8th, 2017]
- Three Ways That Digital Technology Can Help Chemical Producers - Forbes [Last Updated On: February 8th, 2017] [Originally Added On: February 8th, 2017]
- Cinematographers Deploy Innovative Technology to Create Better Images - Variety [Last Updated On: February 8th, 2017] [Originally Added On: February 8th, 2017]
- How Technology Transforms Dreamers Into Economic Powerhouses - Forbes [Last Updated On: February 8th, 2017] [Originally Added On: February 8th, 2017]
- Coming technology will likely destroy millions of jobs. Is Trump ready? - Washington Post [Last Updated On: February 8th, 2017] [Originally Added On: February 8th, 2017]
- Mysterious $5 Billion Biotech Moderna Hit With Legal Setback Related To Key Technology - Forbes [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- Berlinale: Jury Talks Up Art But Politics and Technology Enter Discussion - Variety [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- Opinion: Harry Boxer's stocks to watch: biotechnology and technology - MarketWatch [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- Nasdaq plans venture arm to invest in financial technology: sources - Reuters [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- A modern-day Rosie the Riveter campaign: Women in technology - The Hill (blog) [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- A growing concern: Technology and transportation - Florida Today [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- Top 10 Mobility Technologies Market by Technology & Geography - Global Forecast to 2022 - Yahoo Finance [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- Volvo melds technology and luxury in the XC90 T8 hybrid - Engadget [Last Updated On: February 9th, 2017] [Originally Added On: February 9th, 2017]
- CEFC warns against risky investment in 'clean coal' technology - The Guardian [Last Updated On: February 10th, 2017] [Originally Added On: February 10th, 2017]
- Scientist calls for industrial scale-up of greenhouse gas-eating microbe technology in UK - Phys.Org [Last Updated On: February 10th, 2017] [Originally Added On: February 10th, 2017]
- Software company introduces game-changing technology for Michigan Realtors - HousingWire [Last Updated On: February 10th, 2017] [Originally Added On: February 10th, 2017]
- New laser technology enables more sensitive gravitational-wave detectors - Phys.Org [Last Updated On: February 10th, 2017] [Originally Added On: February 10th, 2017]
- Why Quotient Technology Inc. Stock Surged 21% Higher on Friday - Fox Business [Last Updated On: February 10th, 2017] [Originally Added On: February 10th, 2017]
- How Technology Is Improving Influencer Marketing (And Can Help Improve Your Brand) - Forbes [Last Updated On: February 10th, 2017] [Originally Added On: February 10th, 2017]
- Hands-on: EVGA's sensor-laden iCX technology revolutionizes ... - PCWorld [Last Updated On: February 10th, 2017] [Originally Added On: February 10th, 2017]
- New Ground Technology uses digital graphics on turf - Golf Channel [Last Updated On: February 11th, 2017] [Originally Added On: February 11th, 2017]
- Facing State System review, Cal U to emphasize science and technology - Pittsburgh Post-Gazette [Last Updated On: February 11th, 2017] [Originally Added On: February 11th, 2017]
- International Game Technology: A Lottery Bet That's Paying Off - Barron's [Last Updated On: February 11th, 2017] [Originally Added On: February 11th, 2017]
- Our seas have become a plastic graveyard - but can technology turn the tide? - Telegraph.co.uk [Last Updated On: February 11th, 2017] [Originally Added On: February 11th, 2017]
- Technology identifying fastest checkout lanes comes to metro - KCCI Des Moines [Last Updated On: February 11th, 2017] [Originally Added On: February 11th, 2017]
- This Technology Could Be a Game-Changer for the Marijuana Industry - Fox Business [Last Updated On: February 11th, 2017] [Originally Added On: February 11th, 2017]
- Editorial: Higher education and technology are job creators, so why is the governor cutting their funding? - STLtoday.com [Last Updated On: February 12th, 2017] [Originally Added On: February 12th, 2017]
- BLAEDC: Entrepreneurs find a technology-friendly home in the Brainerd lakes area - Brainerd Dispatch [Last Updated On: February 12th, 2017] [Originally Added On: February 12th, 2017]
- Small cell technology is large endeavor for state - Crain's Cleveland Business [Last Updated On: February 12th, 2017] [Originally Added On: February 12th, 2017]
- Eye tracking technology will change these 4 domains - The Next Web [Last Updated On: February 12th, 2017] [Originally Added On: February 12th, 2017]
- The technology fixing Britain's parking problem - The Independent [Last Updated On: February 12th, 2017] [Originally Added On: February 12th, 2017]
- Tim Cook: Augmented Reality is as big of a technology as the smartphone - BGR [Last Updated On: February 12th, 2017] [Originally Added On: February 12th, 2017]
- How technology is encouraging society to be stupid - The Next Web [Last Updated On: February 12th, 2017] [Originally Added On: February 12th, 2017]
- IBM Adds Voice Help to Cybercrime-Fighting Watson-Powered Weaponry - Campus Technology [Last Updated On: February 13th, 2017] [Originally Added On: February 13th, 2017]
- Market Higher As 4 Key Steel, Technology Stocks Top Buy Points - Investor's Business Daily [Last Updated On: February 13th, 2017] [Originally Added On: February 13th, 2017]
- A look at North Korea's missile launches and technology - ABC News [Last Updated On: February 13th, 2017] [Originally Added On: February 13th, 2017]
- The CFO Imperative: Next-Gen Technology Drives Cost Optimization - Knowledge@Wharton [Last Updated On: February 13th, 2017] [Originally Added On: February 13th, 2017]
- Technology puts 'touch' into long-distance relationships - Phys.Org [Last Updated On: February 13th, 2017] [Originally Added On: February 13th, 2017]
- A New Angel Investing Platform Connects Deep Technology And Science Startups With Capital - Forbes [Last Updated On: February 13th, 2017] [Originally Added On: February 13th, 2017]
- Formula 1 now capable of 'internet' broadcasts with new technology - autosport.com [Last Updated On: February 14th, 2017] [Originally Added On: February 14th, 2017]
- How dangerous is technology? - OUPblog (blog) [Last Updated On: February 14th, 2017] [Originally Added On: February 14th, 2017]
- Apple's Eddy Cue says technology companies have a responsibility to combat fake news - Recode [Last Updated On: February 14th, 2017] [Originally Added On: February 14th, 2017]
- Valentine's day: what's your secret technology crush? - Naked Security [Last Updated On: February 14th, 2017] [Originally Added On: February 14th, 2017]
- Parents and technology How much is too much? - WGBA-TV [Last Updated On: February 14th, 2017] [Originally Added On: February 14th, 2017]
- Is Magic Leap Lying About Its Acid Trip Technology? - Vanity Fair [Last Updated On: February 14th, 2017] [Originally Added On: February 14th, 2017]
- BYU-Idaho dedicates and showcases new Science and Technology Center - LocalNews8.com [Last Updated On: February 15th, 2017] [Originally Added On: February 15th, 2017]
- Even Indian technology entrepreneurs think they are living in a ... - Quartz [Last Updated On: February 15th, 2017] [Originally Added On: February 15th, 2017]
- 3 tips for regulating our kids' technology use - The Herald-Times (subscription) [Last Updated On: February 15th, 2017] [Originally Added On: February 15th, 2017]
- Don Cunningham column: Technology giveth, and it taketh away - Allentown Morning Call [Last Updated On: February 15th, 2017] [Originally Added On: February 15th, 2017]
- Warren Buffett's Increasing Passion For Apple And Technology - Forbes [Last Updated On: February 15th, 2017] [Originally Added On: February 15th, 2017]
- DNA technology gives new face to decade-old cold case - The San Diego Union-Tribune [Last Updated On: February 15th, 2017] [Originally Added On: February 15th, 2017]
- Can Technology Really Solve China's Healthcare Crisis? - Forbes - Forbes [Last Updated On: February 15th, 2017] [Originally Added On: February 15th, 2017]
- Emerging technology is keyword: Demand for experts in robotics & big data up 50% - Economic Times [Last Updated On: February 16th, 2017] [Originally Added On: February 16th, 2017]
- Five technologies that will change how we live - Financial Times [Last Updated On: February 16th, 2017] [Originally Added On: February 16th, 2017]
- Football League agrees to use goalline technology in Championship - The Guardian [Last Updated On: February 16th, 2017] [Originally Added On: February 16th, 2017]
- Telecom operators navigate three technology transformation options - TechTarget [Last Updated On: February 16th, 2017] [Originally Added On: February 16th, 2017]