Secure Medical Data Hacked
May 17, 2009 – 15:50 by Dani Iswara. Words count: 299.Last updated: Wednesday, May 20, 2009 at 19:32.
According to Wikileaks.org, Over 8M Virginian patient records held to ransom, Virginian government site was hacked on April 30, 2009.
The Virginia PMP (Prescription Monitoring Program)–site currently unavailable or under federal investigation, is used to records prescription drug abuse. It has a secure and password protected database for those patient’s medical data. Some private information saved in those database. Is it useful for the black market? What is government’s responsibility? How to resolve this problem?
Here is the ransom:
Attention Virginia
I have your shit! In *my* possession, right now, are 8,257,378 patient records and a total of 35,548,087 prescriptions. Also, I made an encrypted backup and deleted the original. Unfortunately for Virginia, their backups seem to have gone missing, too. Uhoh
![]()
For $10 million, I will gladly send along the password…
The critical issues are identity theft and data hijacking. Its personal data included name, age, address, social security number, driver’s license number. FBI (Federal Bureau Investigation) is under their jobs.
Other stories:
- Hacker says he stole confidential medical data on 8 million Virginia residents, from HealthcareITNews.com.
- The Virginia prescription record security breach: The big picture, and using this case as a learning experience by David Harlow (HealthBlawg). He told us about its health law perspective:
- What is the scope of personal data insecurity in this country?
- What preventive maintenance and design steps must or should be taken by all holders of personal data in order to minimize the likelihood of a breach?
- In the event of a security breach, what communication is required by law, and what should “best practices” communications strategy look like, beyond what is required by the letter of the law?
The moral messages:
- Prepare with the backup, backup, and backup.
- There is no 100% secure system.
- Respect for them (hackers community).
Comment by Cahya on May 19, 2009 at 13:54:41
using Mozilla Firefox 3.0.10 on Windows Vista
Tuh kan…, coba kalau ditulis dengan rekam medis tradisional, sanggup apa menggondol delapan juta rekam medis …, cape’ deh ^_^
Comment by Dani Iswara on May 19, 2009 at 14:23:27
using Mozilla Firefox 3.0.10 on Gentoo Linux
Cahya,
di atas langit masih ada langit..situs hacker juga pernah disusupin hacker..
Comment by nomercy on May 19, 2009 at 18:45:00
using Safari 525.1 on GNU/Linux
nah yg seperti ini hacker gak bener … gila … uang segitu buat bikin apaan ya … ck ck ck … kalau ditabung tinggal pesiar aja ke mana-mana … sekalian ke neraka …
ada-ada saja orang jahat ini … gak milih-milih sasarannya …
dahulu juga situs pentago, fbi, us gov di amrik diserang … belum lagi negara-negara lain … satu obat buat menciptakan penyakit lainnya … internet memang seperti dua sisi mata uang …
Comment by a! on May 19, 2009 at 22:48:40
using Mozilla Firefox 3.0.10 on Windows XP
wow, banyak jg ya data orang sakit yg dicolong. bener2 sarap nok hackernya.
Comment by dani on May 20, 2009 at 08:03:01
using Internet Explorer 4.01 on Microsoft PocketPC
nomercy, a!,
namanya usaha..
Comment by Triyono on May 20, 2009 at 13:57:14
using Mozilla Firefox 3.0.10 on Windows XP
Wah bikin back up ah, jangan-jangan blogku dicolong orang (ha ha ha)
Comment by ammadis on May 21, 2009 at 07:52:47
using Mozilla Firefox 3.0.6 on Windows XP
For Indonesian, I think, It’s not generally to save with online, isn’t it! Always be manually…
But for government, that is a learn how to save with full security documents…
Comment by Dani Iswara on May 21, 2009 at 10:09:43
using Mozilla Firefox 3.0.10 on Gentoo Linux
Triyono,
bukan cuman masalah dicolong, pak, tapi juga utk jaga-2 thd hal-2 tak terduga
ammadis,
I do not know the system for that case in here.
Comment by rismaka on May 21, 2009 at 21:53:25
using Mozilla Firefox 3.0.10 on Windows XP
Maaf mas dani, OOT banget nih.
, itu baru dipasang atau memang saya yg baru nyadar ya??
Saya banyak belajar dari blog mas dani, ad yg mau saya tanya dan juga sarankan.
1. Kenapa dlm tampilan halaman depan (homepage) hanya ditampilkan satu post saja? Apakah tidak lebih baik dg banyak link masuk yg menuju postingan yg ada?
2. Apa motivasi daniiswara.net dibangun? Secara saya melihat mas dani tidak berorientasi pada trafik pengunjung, ataupun earning.
3. Saran, klo bisa dilengkapi dengan threaded comment dan comment mail, sehingga balasan dari admin (mas dani sendiri) dapat segera terkirim ke email sang komentator, tanpa perlu follow-up komentar dari orang lain. Jadi tidak perlu pakai “notify me of follow-up….” yg dapat memenuhi inbox email
4. Terakhir, saya lihat ada sebaris link dan tombol social bookmark
Comment by nomercy on May 21, 2009 at 22:24:07
using Mozilla Firefox 3.5b4 on GNU/Linux
mas Dani,
urgent nih … kemarin saya tes rss komentar … tahunya tampil pesan error … tulisannya begini:
XML Parsing Error: XML or text declaration not at start of entity
Location: http://feeds2.feedburner.com/CommentsForSumberIde
Line Number 1, Column 34:
<rss version="2.0"
---------------------------------^
sudah saya cek berkali-kali rasanya gak ada yg salah … saya pakai editor kate dan phpeditor untuk cek kali aja ada whitespace tetapi juga gak ada … sudah saya kembalikan ke asal masih juga … kira-kira apa ya? ada pengalaman seperti ini gak?
/* maaf jadinya konsultasi di sini */
Comment by nomercy on May 21, 2009 at 22:48:51
using Mozilla Firefox 3.5b4 on GNU/Linux
udah bisa mas … ternyata ada bentrok dengan plugin … memang harus banyak dikurangi plugin2 ini … hehehe
Comment by Dani Iswara on May 21, 2009 at 23:26:55
using Mozilla Firefox 3.0.10 on Gentoo Linux
rismaka,
jawabannya mungkin akan saya tulis di topik menjadi tidak penting
Comment by uwiuw on May 23, 2009 at 14:52:25
using Mozilla Firefox 3.0.10 on Windows XP
dan, kayaknya mereka lebih mirip bandit daripada plain hacker dalam definisi tradisional. Masak main culik data gitu aja, lalu minta tebusan. bukankah itu mah bandit ? don’t have respect for those asshole.
sy ingat seorang hacker. one of the best. namanya inferno. respect him karena sekali pun bajiangan (kata temen sih), dia menemukan bug di server google lalu melaporkannya diam diam sama pihak google agar mereka menutup cela itu
konon, perbaikan server google akhir2 ini atas masukan dia. well, respect him not those bastard
Comment by Dani Iswara on May 23, 2009 at 15:00:34
using Mozilla Firefox 3.0.10 on Gentoo Linux
ah iya..makasi koreksinya, mas aulia..maksudnya sih menghargai mereka yg memiliki keterampilan menemukan celah keamanan itu. mengenai moral tebusannya…jangan ditiru..