Healthcare IT NewsHealthcare IT News
TwitterFacebookLinkedInHealthcareITNews International
  • Home
  • Topics
    • Business Intelligence
    • Claims Processing
    • Data Warehousing
    • EDIS
    • Election 2012
    • Electronic Health Records
    • Enterprise Content Management
    • Enterprise Resource Planning
    • ePrescribing
    • Financial/Revenue Cycle Management
    • Health Information Exchange (HIE)
    • ICD-10
    • Meaningful Use
    • Mobile/Wireless
    • Network Infrastructure
    • Policy and Legislation
    • Privacy and Security
    • Quality and Safety
    • RIS and PACS
    • RTLS
    • Telehealth
    • Workforce Management
  • Issues
    • May 2012
    • April 2012
    • March 2012
    • February 2012
    • January 2012
    • December 2011
  • Webinars
    • Upcoming Webinars
    • On Demand Webinars
  • White Papers
  • Blog
  • Events
  • HIMSS JobMine
  • RSS
  • Press Releases
  • Slideshows
  • Videos
  • Podcasts
  • Supplements
  • Survey Analyses
  • Newsletters
  • Advertise
  • Login
  • Register
  • SUBSCRIBE
    • Newspaper
    • Email Newsletter
Home » Blogs » RIS and PACS

  • del.icio.us
  • Digg
  • StumbleUpon
  • Reddit
  • Facebook
  • Google
  • RSS Icon
  

Update on Conficker

February 04, 2009 | John Halamka, Life as a Healthcare CIO

Suggested Content

  • Joslin Diabetes Center, Phytel launch CME research project
  • Smartphones, iPads may be distracting, Halamka warns
  • Mostashari rankled over HIT survey conclusions
  • Blumenthal steps down from ONC
  • Berwick's top 5 successes at CMS

 

Last week, I wrote about the effort to proactively protect BIDMC and Harvard from the Conficker virus.

Our efforts continue with the following:

1. IT Security is verifying whether or not the MS08-067 vulneribilty shows up on our scan on an infected machine. We have been assuming that machines showing the vulnerability are the only machines we need to worry about. It is possible the virus does some type of masking once it is introduced to make the machine look like it has been patched.

2. We are verifying that the update of the anti-virus agent on an infected machine cleans the virus. If not, the machine will need to be rebuilt from scratch.

3. The daily reports of virus activity will be closely monitored to identify any sign of infected machines. So far, we have seen only one in the entire enteprise. Infected machines try to infect other machines on the same subnet so they get reported by our intrusion detection tools.

4. To add more surveillance to the data center, Security is engineering a report that will list all active IP's in the data center and disaster recovery site. This list will be compared to those registered in McAfee ePolicy Orchestrator (EPO). Any exception, i.e. data center device not registered in EPO or device not up-to-date with anti-virus per EPO, will be immediately pursued. Our expectation is that all Windows hosts in the data center are updated daily.

5. We are examining what is typical in the Active logs for account lockouts, similar to what we do for patient access. If we can establish what's typical, we can threshold it and create an alert when something unusual occurs.

6. We now have a list of devices that the scan showed do not have the MS08-067 patch. We are pushing them out to managed machines and contacting others who have private machines. Some of the latter are medical devices, e.g. GE PACS, etc.

7. We are using this incident to fine tune our virus incident response process. It's been awhile (good news/bad news) since we had such a notable virus in the field. When you don't exercise, you get out of tune.

8. We continue to learn more about the sophistication of the virus and its ability to hide, morph, and so forth. There continues to be questions as to what it's ultimate intentions will be.

One thing this episode reinforces is the need to have security in depth, i.e. layers. Although we discovered many devices with the vulnerability, our anti-virus was up-to-date on them. For some hosts, we also had the host-based intrusion detection and prevent (Third Brigade) turned on. The combination of aggressive patching, constant monitoring, daily anti-virus updates, and host based intrustion prevention has limited the impact of Conficker on our networks thus far.

John Halamka blogs regularly at Life As a Healthcare CIO.

Related Topics:
  • EPO
  • Harvard
  • Windows
  • RIS and PACS

Reader Comments (0)Login to Post a Comment

receive news by email

Most Popular

Latest Headlines
Most Popular
  • 14 Ways Social Media May Soon Change Your Doctor's Visit
  • No 'bubble' for healthcare IT, analysts say
  • 6 reasons physicians need to be on social media
  • Lawsuit seeks Allscripts CEO's removal
  • AMA calls for 2-year extension of ICD-10 deadline
  • 14 Ways Social Media May Soon Change Your Doctor's Visit
  • AMA claims it wants to delay ICD-10 implementation 2 years
  • Examining Healthcare Costs
  • Like it or not, MU is underway
  • Rethinking 'clinical transformation'
more Blog

WEBINARS AND WHITE PAPERS

  • ON DEMAND WEBINARS
    Case Study: Sentara Healthcare Completes an Award-Winning EHR with Enterprise Content Management
  • UPCOMING WEBINARS
    June 5th @ 1PM ET--Get Control of Your Medical Images with a Cloud-Based Vendor-Neutral Archive
  • UPCOMING WEBINARS
    May 23rd @ 2PM ET--Providers’ Perceptions: EMR Impressions & Strategies, Post-Implementation
  • WHITE PAPERS
    The Christ Hospital Case Study: Improving Operations and Ensuring the Best Possible Patient Care with ECM
  • WHITE PAPERS
    Business Intelligence for Hospitals: Empowering Healthcare Providers to Make Informed Decisions
More Resources
Syndicate content

HIMSS JOBMINE

  • Biostatistician II - Saudi Aramco - Dhahran, Saudi Arabia
  • Chief Information Officer - West Virginia - InfoPartners, Inc. - West Virginia
  • IT Technical Services Director - Genesis HealthCare System - Zanesville, OH
  • VP, CLINICAL INFORMATICS - The Methodist Hospital System - Houston, TX
  • Senior Radiology Information Systems Analyst - Universal Health Services - King of Prussia, PA
more jobs

Marketplace

Follow Healthcare IT News on TwitterFan Healthcare IT News on FacebookJoin Healthcare IT News on LinkedInRSS Subscriptions
Digital EditionBlogEvents
JobsMobile SiteMobile App
 
Healthcare Finance News Government Health IT EHRWatch Healthcare Payer News HITECHWatch ICD10Watch mHIMSS PhysBizTech NHINWatch
©2012 MedTech Media Healthcare IT News is a publication of MedTech Media
Subscribe Advertise About Us Privacy Policy