Home Warner seeks answers to negligent cybersecurity by healthcare company
Politics

Warner seeks answers to negligent cybersecurity by healthcare company

Chris Graham

mark warner newU.S. Sen. Mark Warner (D-VA) wrote to the CEO of TridentUSA Health Services today to ask about the company’s data security practices as they relate to Health Insurance Portability and Accountability Act (HIPAA) compliance.

The letter comes in light of a report that MobileXUSA – an affiliate of TridentUSA Health Services – left an unencrypted server online, exposing the medical data of millions of Americans.

“It appears that the information held by MobileXUSA was made accessible due to sloppy cybersecurity practices— no software vulnerabilities were involved, and no explicit hacking was required,” wrote Sen. Warner. “While HIPAA lays out some guidelines for secure data storage and transfer, it is not always clear who bears responsibility for securing the data and ensuring the use of proper controls. However, it is certainly the responsibility of companies like yours to control and secure sensitive medical data, maintain an audit trail of medical images, and to ensure the information is not publicly accessible.”

According to recent reports, many unsecured picture archiving and communication servers (PACS) left the names, dates of birth, medical images, and medical procedures of more than one million Americans accessible to anyone with basic computer expertise. As part of the report, researchers identified 187 servers in the U.S. – including that of MobileXUSA – that were unprotected by passwords or basic security precautions.

In the letter to TridentUSA Health Services, Sen. Warner stressed the importance of protecting Americans’ privacy and personal health information. He also posed the following questions for TridentUSA Health Services:

  1. HIPAA requires audit trails for PACS, which stores the data in centralized auditing databases with multiple audit layers. What audit and monitoring tools do you use to analyze the data to remain HIPAA compliant?
  2. PAC server vulnerabilities are well known, however, their use of the DICOM protocol makes them easily accessible via the Internet. DICOM also enables PACS to communicate with neighboring systems in a medical or clinical process within a network of IP-enabled devices. Does your company require neighboring systems to comply with current standards and use access management controls?
  3. What are your identity and access management controls for IP-addresses and/or port filters?
  4. Do you require VPN or SSL to communicate with your PACS?
  5. What is the frequency of your vulnerability scans and HIPAA-compliant audits?
  6. What are your server encryption practices?
  7. Do you have an internal security team or do you outsource it?

Sen. Warner has been a champion for cybersecurity throughout his career, and has been an outspoken critic of poor cybersecurity practices that have led to the compromise of Americans’ personal information. Last week, Sen. Warner demanded answers from U.S. Customs and Border Protection (CBP) and South Korean company Suprema HQ, following separate incidents that affected both entities and exposed the personal, permanently identifiable data of many Americans.

Warner also introduced legislation earlier this year to empower state and local government to counter cyberattacks, and to increase cybersecurity among public companies.

Support AFP

Chris Graham

Chris Graham

Chris Graham is the founder and editor of Augusta Free Press. A 1994 alum of the University of Virginia, Chris is the author and co-author of seven books, including Poverty of Imagination, a memoir published in 2019. For his commentaries on news, sports and politics, go to his YouTube page, TikTok, BlueSky, or subscribe to Substack or his Street Knowledge podcast. Email Chris at [email protected].

Latest News

baseball richmond flying squirrels
Baseball

CW Richmond to broadcast six Richmond Flying Squirrels games in 2026

joe rogan
Arts, Culture, Media

The right-wing comedy grift: Joe Rogan pivots towards the center

Joe Rogan — podcaster, UFC commentator, "comedian" — has spent years building the most valuable brand in media on a single premise: what you see is what you get.

solar farm
Local News

Bill Rogers: Examining the options for DIY solar for your barns, outbuildings

SVEC is asking the State Corporation Commission for an increase in electric rates of $6.25 per 1,000 kilowatts of power starting May 1, 2026. And increases will only continue. DIY off-grid solar power stops the ongoing increases from SVEC.

tess majors
Arts, Culture, Media

Tess Majors Foundation funds scholarships for Rockbridge County-based Nature Camp

mail in ballot absentee election vote voting
Politics

Add trying to fix the 2026 midterms to the list of Trump’s impeachable offenses

uva baseball sam harris
Baseball

UVA Baseball: #10 ‘Hoos get healthy in 16-2 midweek win over ODU

zachary harger hburg teacher
Local News

Harrisonburg: Preschool teacher arrested for taking photos of child in school bathroom