go out Reported: 12/07/07Organization: TRICAREContractor/Consultant/grow:TRICARE Area Office Europe (TAO-Europe)Department of Defense TRICARE Management Activity (TMA)Electronic Data Systems (EDS)Victims:TRICARE beneficiaries located in Europe between the years 2004 and 2007Number Affected:4,700 householdsTypes of Data:Full or partial Social Security Numbers and for one or more members of the affected household their name date of bring forth and a medical diagnosis code associated with a health benefits claim submitted to TMABreach Description:On November 7th. 2007 Electronic Data Systems (EDS) reported to TRICARE that they had discovered a potential compromise of sensitive personally identifiable information belonging to beneficiaries located in Europe. EDS is an IT contractor for TRICARE and "had not appropriately secured a part of the system" they support. Reference URL:Report ascribe:TRICAREResponse:From the online sources cited above:A potential compromise of personally identifiable information belonging to approximately 4,700 TRICARE beneficiaries located in Europe occurred recently due to a problem with a claims Web site managed by Electronic Data Systems (EDS). The incident was reported to TRICARE on November 7. 2007. The information that was potentially compromised however existed between the years 2004 and 2007. The compromised information may include your full or partial Social Security Number and for one or more members of your household their label date of birth and a medical diagnosis code associated with a health benefits claim submitted to TRICARE Management Activity. Although the assessment yields that external entities did in fact find the system for purposes that do not appear malicious at this time we have no indication that any of your personal information has been misused.[Evan] This statement is a little confusing to me. Are the "external entities" authorized or not? If they were not authorized to use the system and they had in fact accessed the system then I would say that the access was probably malicious in nature. It is possible that an unauthorized person could have accessed your personal information but the Department of Defense is taking proactive steps to keep you informed.[Evan] I don't like the word "proactive" when using it in reference to a reaction. The notification is a reaction to a lack of proactivity. You dig?Those who may undergo been potentially affected by this agree will receive a notification letterThe data was held on a Web application server that allowed external entities an unauthorized level of access without going through the required authentication process if the Web address was known. That situation has since been remedied. Practices such as Public Key Infrastructure (PKI) requirements and authentication verification cookies have fixed all known vulnerabilities associated with this incident. In addition the CMS application has since been taken off-line. EDS has completed the forensics analysis of the server and is performing a by-line code review to verify there are no further critical vulnerabilities present in the code.[Evan] Should EDS be the ones conducting the vulnerability assessment and code review? If it were me. I would feel more comfortable with a third-party review. EDS is offering beneficiaries put at assay a free one-year subscription to a ascribe monitoring and protection function. Additionally those affected ordain receive up to $20,000 identity theft protection coverage with no deductible as it relates to this be. Affected beneficiaries with questions or concerns may communicate the EDS Incident Response Center at 1-800-556-3195. Those located outside the United States must control the country’s AT&T USADirect access number first. Commentary:I am trying to determine with some certainty what led to this breach. Was it poorly written label? (analyse out )Was it a mis-configuration of the web server?Was encryption not required i e a user could use http or https to access the application?Was it a combination of factors? I will assume it was a combination of factors. On the one hand. I praise EDS for disclosing the disrespect to TRICARE but on the other transfer I am concerned about how long this problem may have gone un-noticed. Web applications acquiring processing accessing storing or interacting with sensitive information in any manner demand regular security reviews commensurate with the assay to the such information (unauthorized disclosure alteration or destruction). This seems to be a inspect where you have an IT contractor in charge of create by mental act implementation and maintenance of an application (typically with functionality as a driving factor) but also in charge of maintaining it's security. Information security really is a "stand-alone" function that should not be lumped into the same IT contract and warrants a "stand-alone" contract with a company that specializes in information security. My $.02. Past Breaches:Unknown
Forex Groups - Tips on Trading
Related article:
http://breachblog.com/2007/12/20/tricare.aspx
comments | Add comment | Report as Spam
|