Computerworld
Temperatures run high in IT health security debate
Michael Crawford  09 September, 2005 11:42

The author of a study into firewalls prepared for general practitioners under the Broadband for Health program claims it has been dumbed down so much by federal health bureaucrats, the document is now virtually useless as an IT security guide.

The author Dr Horst Herb, director of the Dorrigo Medical Centre in NSW, is demanding his name be stripped from the final report.

Once a systems auditor, penetration tester and mainframe security analyst for Siemens, Dr Herb spent the last five months advising the government on minimum firewall standards for GPs.

Horst said he believes the government is not serious about IT security when it comes to e-health.

Although Herb's work has been published as part of the GPCG (General Practice Computing Group) Security Firewall Guidelines, he said many core technical aspects and product-specific analysis had been stripped out of the recommendations.

As a result, he said, the document prepared as an IT security guide for GPs has reached the point of irrelevance.

A Department of Health and Ageing spokesperson, asked to respond to Dr Herb's allegations, said the submitted report was "overly-technical" and had to be "simplified extensively" so that could GPs understand it.

"The original document was very technical," Herb said. "But that was the whole point, to raise interest and technical understanding of what is involved for GPs. Even if the doctors were to commission out implementing firewalls they would still need to emulate skills of the person that set it up, because generally, there is no formal qualification for implementing firewalls or formal liabilities for firewalls," Herb said.

Herb also warned many IT security products are not strong enough to protect highly sensitive, personal information.

"The main problem I had was with personal firewalls, which is just software on a computer which is, in my opinion pointless in a surgery scenario because they have too many vulnerabilities - all it takes is downloading software to disable it. GPs need a dedicated firewall where no user can dabble with it," he said.

"Surgeries should not rely on basic or personal firewalls. This [detail] was edited out of the original report, mainly so [telecommunications vendors] can just push a default firewall setting as acceptable - it is just pure nonsense."

Herb said while the strong security message was being lost on GPs as a result, though he is glad some security information has been released. However, Herb is insisting his name be stripped from the report, because he does not want to be held liable for anyone considering a personal firewall as a viable IT security solution for doctors.

Since the report was published, the federal government has axed funding for GPCG, which provided IT support and advice for doctors and clinicians. It ran for eight years under an annual, million-dollar government grant.

The Department of Health and Ageing spokesperson said all doctors involved with the now defunct General Practice Computing Group considered the original document to be far too complicated. However, when it was "simplified extensively", they gave it their full endorsement.

The department claims the document has since been well received by doctors, despite the GPCG being disbanded.

Computerworld Buyer's Guide - Vendors Matched to this Article

Comments

Post new comment

Login or register to link comments to your user profile, or you may also post a comment without being logged in.
The content of this field is kept private and will not be shown publicly.
Enter the fully qualified URL, eg. http://www.example.com/
  • Web page addresses and e-mail addresses turn into links automatically.
  • Allowed HTML tags: <a> <em> <strong> <cite> <code> <ul> <ol> <li> <dl> <dt> <dd>
  • Lines and paragraphs break automatically.

More information about formatting options

Add to Google
Computerworld Buyer's Guide - Vendors Matched to this Article
Zones
Zone logoZones provide focussed content from Computerworld and leading technology partners.
Newsletter Subscription
Newsletter Subscription
Sign up for our Computerworld newsletters!
Syndicate content
 

Computerworld Webinar

Thursday, June 11th, 2009
10:30am EST (Sydney, Australia)
Screening at your PC

Computerworld is hosting a 30 minute live webinar to help you to learn how unified communications can save you money, foster innovation and business agility by making it easier for people to find, reach and collaborate with one another.

Register Now

Whitepaper

Reducing the risk of insider abuse

The potential for insider abuse can never be eliminated completely, but the steps outlined in this white paper can reduce the potential for such abuse. Read on to ensure no one person can alter your operations to their personal advantage or to the detriment of your organisation.

Enterprise IT Buyer's Guide
Find Technology Vendors Fast
 
Find vendors by name | Find by category
Sponsored Links
 
Send Us E-mail | Privacy Policy
Features List | Media Kit | Advertising | Contact Us

Copyright 2009 IDG Communications. ABN 14 001 592 650. All rights reserved.
Reproduction in whole or in part in any form or medium without express written permission of IDG Communications is prohibited.