Commentary

George Hulme
 

President-Elect Barack Obama Offers InfoSec Bailout Plan

While the president-elect may not realize it's what he's working on -- he is. And savvy security vendors already should be revamping their marketing plans for the InfoSec Stimulus Package of 2009.

While the president-elect may not realize it's what he's working on -- he is. And savvy security vendors already should be revamping their marketing plans for the InfoSec Stimulus Package of 2009.Imagine what a new PCI DSS (Payment Card Industry Data Security Standard, for those of you who have been sleeping in class) or even a re-invigorated HIPAA (Health Insurance Portability and Accountability Act) would do to give the information security community a caffeinated jolt out of its malaise?

But that's what is coming, and the thought struck me like a double shot of RedBull while I was drafting this post about the president-elect's plans to add health IT to any stimulus package he crafts with Congress for signing come Jan. 20.


More Security Insights

White Papers

More >>

Reports

More >>

Webcasts

More >>

Here's the paragraph, from this Sunday's radio address, that got my synapses sparking:

In addition to connecting our libraries and schools to the Internet, we must also ensure that our hospitals are connected to each other through the Internet. That is why the economic recovery plan I'm proposing will help modernize our health care system -- and that won-t just save jobs, it will save lives. We will make sure that every doctor's office and hospital in this country is using cutting-edge technology and electronic medical records so that we can cut red tape, prevent medical mistakes, and help save billions of dollars each year.

Do you see that? Hospitals interconnected on the Internet. That's a long-winded way to spell RISK. Because, when you airdrop a crate of technology on a segment of the economy that's not accustomed to managing it, well, you're going to get a certain amount of mayhem.

There will be breaches. There will be servers with years of patient data on them stolen, and that data unencrypted. There will be doctors and other health care workers transferring patient data to USB drives, only to drop them in the parking lot to be found by a reporter working at the local newspaper. There's liable to be a marked increase in medical identity theft. There may even be a few stories of systems crashing and years of patient records left unrecoverable.

That is, unless this entire Health IT initiative is done right. That will happen if the big spirit of HIPAA meets the gory details prescribed by the PCI data security standard and infosec gets baked in from the jump.

But even if that doesn't happen right away, it's sure to happen after the new Health IT superhighway experiences a number of data wrecks. And the regulatory aftermath just may be the shot of B-12 the IT security market needs to get its mojo back.

(Now, don't get me wrong, I'm quite bullish on health IT. And I'm a big fan of electronic medical records. I often write about that over here. This stuff just needs to be handled with care, and deployed right.)


Related Reading




Currently we allow the following HTML tags in comments:

Single tags

These tags can be used alone and don't need an ending tag.

<br> Defines a single line break

<hr> Defines a horizontal line

Matching tags

These require an ending tag - e.g. <i>italic text</i>

<a> Defines an anchor

<b> Defines bold text

<big> Defines big text

<blockquote> Defines a long quotation

<caption> Defines a table caption

<cite> Defines a citation

<code> Defines computer code text

<em> Defines emphasized text

<fieldset> Defines a border around elements in a form

<h1> This is heading 1

<h2> This is heading 2

<h3> This is heading 3

<h4> This is heading 4

<h5> This is heading 5

<h6> This is heading 6

<i> Defines italic text

<p> Defines a paragraph

<pre> Defines preformatted text

<q> Defines a short quotation

<samp> Defines sample computer code text

<small> Defines small text

<span> Defines a section in a document

<s> Defines strikethrough text

<strike> Defines strikethrough text

<strong> Defines strong text

<sub> Defines subscripted text

<sup> Defines superscripted text

<u> Defines underlined text

InformationWeek encourages readers to engage in spirited, healthy debate, including taking us to task. However, InformationWeek moderates all comments posted to our site, and reserves the right to modify or remove any content that it determines to be derogatory, offensive, inflammatory, vulgar, irrelevant/off-topic, racist or obvious marketing/SPAM. InformationWeek further reserves the right to disable the profile of any commenter participating in said activities.

Disqus Tips To upload an avatar photo, first complete your Disqus profile. | View the list of supported HTML tags you can use to style comments. | Please read our commenting policy.
T-Shirt Giveaway T-Shirt Giveaway: Each week we're selecting one great comment from our readers. The author of the comment will receive an InformaitonWeek Community t-shirt. So get posting!
Subscribe to RSS

Resource Links