Home Warner demands answers following exposure of medical data belonging to servicemembers
Politics

Warner demands answers following exposure of medical data belonging to servicemembers

Chris Graham

mark warnerU.S. Sen. Mark Warner, D-Va., has urged the Defense Health Agency to remove sensitive medical data belonging to servicemembers exposed online, where it remains vulnerable due to insecure data practices at Ft. Belvoir Medical Center, Ireland Army Health Clinic, and the Womack Army Medical Center.

“As a matter of national security, the sensitive medical information of our men and women of the armed services is particularly vulnerable and should be, at a minimum, protected by robust security controls and routine scans,” wrote Sen. Warner. “The exposure of this information is an outrageous violation of privacy and represents a grave national security vulnerability that could be exploited by state actors or others.”

He continued, “We owe an enormous debt to our armed forces, and at the very least, we ought to ensure that their private medical information is protected from being viewed by anyone without their express consent. Whenever data moves from one entity to another it should be protected by encryption, proper hashing, segmentation, identity and access controls, and vulnerability management capabilities that include diligent monitoring, auditing, and logging practices.”

In September, Sen. Warner sought answers from TridentUSA Health Services regarding reports that many unsecured picture archiving and communication servers (PACS) left the names, dates of birth, medical images, and medical procedures of more than one million Americans accessible to anyone with basic computer expertise. Following that letter, the images were removed but millions of records were left online.

Nearly two months later, Sen. Warner called out the U.S. Department of Health and Human Services (HHS) for its failure to act following the exposure.

Since the letter to HHS, 16 systems, 31 million images and 1.5 million exam records have been removed from the internet. However, a significant number of personally identifiable and sensitive medical information belonging to servicemembers remains online, due to unsecured Army PACS.

In his letter to the Assistant Secretary, Sen. Warner asked the agency to remediate the situation immediately and posed the following questions for Assistant Secretary Thomas McCaffery:

  1. Please describe the information security management practices at military medical hospitals. Do you require organizations to operate on a segmented network? To implement micro-segmentation? To implement access controls? If so, what kind? Do you require the hospitals to implement multifactor authentication, logging, and monitoring?
  2. Do you audit and monitor logs?
  3. Do you require full-disk encryption and authentication for PACS?
  4. Do you require the hospitals to have a Chief Information Security Officer?
  5. Please describe what steps you took to address this issue, and when you were able to remove these systems from the internet.

Support AFP




Chris Graham

Chris Graham

Chris Graham is the founder and editor of Augusta Free Press. A 1994 alum of the University of Virginia, Chris is the author and co-author of seven books, including Poverty of Imagination, a memoir published in 2019. For his commentaries on news, sports and politics, go to his YouTube page, TikTok, BlueSky, or subscribe to Substack or his Street Knowledge podcast. Email Chris at [email protected].

Latest News

ben cline
Politics, Virginia

Ben Cline wants your photos for some dumb congressional time capsule

artificial intelligence
Local

Bridgewater College program will help students become AI literate

AI is destined to put us all out of work, but that might be a while. In the meantime, Bridgewater College is offering coursework to help its students be conversant in AI literacy, on their way to irrelevance.

american flag
Politics, U.S. & World

Un-Happy Birthday, USA: It’s hard to celebrate an America in regress

I was 4 years old the summer of the 1976 bicentennial, and because of that, I don’t remember all that much about it. I remember the fireworks. My hazy memories of the summer of ’76 are: it was an exciting time!

chris feifs uva lacrosse
Etc.

UVA Lacrosse: Cassese hires Vermont head coach Chris Feifs to staff

AR15 firearm
Politics, Virginia

Hospitals, sheriffs and prosecutors, and their different approaches to gun violence

FIFA world cup soccer
Etc.

Mbappe vs Haaland: The World Cup group stage clash that defines a new era

road with double yellow line, no passing
Local

Rockingham County: Updated VDOT road work, maintenance schedule