• Skip to main content

DistilGovHealth

DistilNFO GovHealth Advisory

  • Publications
    • Home
    • DistilINFO HealthPlan
    • DistilINFO HospitalIT
    • DistilINFO IT
    • DistilINFO Retail
    • DistilINFO POPHealth
    • DistilINFO Ageing
    • DistilINFO Life Sciences
    • DistilINFO GovHealth
    • DistilINFO EHS
    • DistilINFO HealthIndia
    • Subscribe
    • Submit Article
    • Advertise
    • Newsletters

OIG Finds Vulnerabilities in HHS Security Controls, Detection

Share:

March 19, 2019

An OIG audit at eight HHS Operating Divisions found flaws in its configuration management, access controls, software patching, and data input controls.

The Department of Health and Human Services’ Operating Divisions needs to improve its security controls to more effectively detect and prevent cyberattacks, according to a new Office of Inspector General report.

Officials said they conducted audits during fiscal years 2016 and 2017 at eight OPDIVs sites by pen testing network and web applications. The goal was to determine the effectiveness of HHS security controls in preventing cyberattacks, as well as how sophisticated an attack needs to be to compromise the network.

OIG also assessed the ability of these sites to detect and respond to cyberattacks, by contracting with Defense Point Security to conduct the pen testing. Officials found that the security controls of all eight sites needed improvement to better detect and prevent attacks.

Want to publish your own articles on DistilINFO Publications?

Send us an email, we will get in touch with you.

The pen testing revealed vulnerabilities in access controls, configuration management, data input controls, and software patching. Officials provided HHS with the root causes for these vulnerabilities and four recommendations the agency should implement across its enterprise to remediate the issues.

What’s notable is that while OIG did not reveal the specific vulnerabilities nor the recommendations, officials said they’ve initiated a new series of “audits looking for indicators of compromise on HHS and OPDIV systems to determine whether an active threat exists on HHS networks or whether there has been a past breach by threat actors” – based on its most recent audit findings.

HHS was also provided separate reports that detailed the specific recommendations for each OPDIVs site. The officials concurred with OIG’s findings and recommendations and provided the watchdog with the actions it is taking or plans to take to address the vulnerabilities.

“HHS also indicated that the OPDIVs have incorporated actions to address their individual vulnerabilities and that HHS will follow up with them to ensure that these have all been addressed,” officials wrote.

OIG is responsible for conducting routine audits on security measures for all federal agencies. Last March, an audit of HHS found the agency had improved its security program, but it still struggled with risk management, identity and access management, and other areas.

Most recently, an OIG audit of the National Institutes of Health found security risks in NIH data sharing processes and controls. But NIH did not concur with the findings to develop a security framework, conduct a risk assessment, or implement additional data and security controls.

Date: March 20, 2019

Source: HealthITSecurity

Coffee with DistilINFO's Morning Updates...

Sign up for DistilINFO e-Newsletters.

Just a little bit more about you...
PROCEED
Choose Lists
BACK

Related Stories

  • Major Payers Find HHS Finalized Nondiscrimination Rule Too NarrowMajor Payers Find HHS Finalized Nondiscrimination Rule Too Narrow
  • New Clinically Validated Sleepcheck App LaunchesNew Clinically Validated Sleepcheck App Launches
  • Apple Still has a Lot of Room to Grow in the $3.5 Trillion Health Care SectorApple Still has a Lot of Room to Grow in the $3.5 Trillion Health Care Sector
  • Google Moves Further Into Healthcare: a Timeline of the Last YearGoogle Moves Further Into Healthcare: a Timeline of the Last Year
  • Superb Healthcare At Ultra-Low Prices? How Singapore Does ItSuperb Healthcare At Ultra-Low Prices? How Singapore Does It
  • AI, Machine Learning, and Blockchain are Key for Healthcare InnovationAI, Machine Learning, and Blockchain are Key for Healthcare Innovation

Trending This Week

Sorry. No data so far.

About Us

DistilINFO is media company that publishes Industry news, views and Interviews. We distil the information for you – saving time and keeping you up to date on your interest areas.

More About Us

Follow Us


Useful Links

  • Subscribe
  • Contact
  • Advertise
  • Privacy Policy
  • Terms of Service
  • Feedback

All Publications

  • DistilINFO HealthPlan Advisory
  • DistilINFO HospitalIT Advisory
  • DistilINFO IT Advisory
  • DistilINFO Retail Advisory
  • DistilINFO POPHealth Advisory
  • DistilINFO Ageing Advisory
  • DistilINFO Life Sciences Advisory
  • DistilINFO GovHealth Advisory
  • DistilINFO EHS Advisory
  • DistilINFO HealthIndia Advisory

© DistilINFO Publications