Skip to main content
Advertisement
Advertisement

Singapore

SingHealth COI: Expert suggests using 2FA to access personal identifiers in health records

SingHealth COI: Expert suggests using 2FA to access personal identifiers in health records
09 Nov 2018 10:49PM (Updated: 09 Nov 2018 11:28PM)

SINGAPORE — Hospitals and clinics here should consider anonymising data that contains personal identifiers such as names, identity card numbers and home addresses, and introduce two-factor authentication (2FA) to “unlock” such data, a cyber-security expert said.

Such a system would ensure that even if hackers made off with the personal data of many patients, they would not be able to make any sense of it, Dr Lim Woo Lip said. Dr Lim is an expert witness who testified on Friday (Nov 9) before the Committee of Inquiry investigating the massive cyber attack on public healthcare group SingHealth.

Dr Lim joined cyber-security firm Ensign Infosecurity this year as its executive vice-president. He used to be vice-president of data analytics and cyber security at telecommunications firm StarHub, and was director of policy and planning at the Ministry of Defence.

Acknowledging that there would be “a lot of complaints” if 2FA is needed to access every patient record, he suggested that it be required every two or four hours for each session of access. This would “at least minimise the attack surface”.

CNA Games
Show More
Show Less

He also said that more should be done to protect the “crown jewels” of SingHealth’s IT systems and networks, which are the “sensitive medical records” and personal information.

The suggestion triggered a debate between Dr Lim and Mr Philip Jeyaretnam, the lawyer of the Integrated Health Information Systems (IHiS), the entity tasked to run the IT systems of all public healthcare institutions.

Mr Jeyaretnam said that the system could pose a greater threat to patient safety if healthcare practitioners mismatch data and patients’ names in the process.

He asked if such measures would be “not usual” in the healthcare environment, “including developed healthcare environments elsewhere in the world”.

Would Singapore be pioneering such efforts if Dr Lim’s suggestion were to go ahead, Mr Jeyaretnam questioned.

Solicitor-General Kwek Mean Luck pointed out two articles that showed 2FA has been used in hospitals in the United States, but Mr Jeyaretnam said that it was used in a different context.

In his nine-page written submission, Dr Lim also suggested conducting cyber-security exercises for IT and security professionals, corporate communications and legal professionals as well as the leadership team of SingHealth. This would “provide a forum” to practise responses in the event of cyber breaches.

“We need to be mentally prepared that a cyber attack will happen. So it is not a question of if, it is a question of when,” he said. “When it happens, what will you do and how fast can you react?”

Dr Lim agreed with Mr Jeyaretnam that cyber warfare is “an arms race”, where what is safe today might not be safe tomorrow, and where attackers have the upper hand in needing to be successful only once.

In the SingHealth cyber attack, which took place sometime between June 27 and July 4, sophisticated hackers stole the personal data of 1.5 million patients, as well as the outpatient prescription information of 160,000 of them, including Prime Minister Lee Hsien Loong.

The third phase of the Committee of Inquiry’s hearings will run till next Thursday. Cyber Security Agency's chief David Koh and representatives from the Ministry of Health are expected to testify.

Giving an update on written representations submitted by the public between Sept 11 and Oct 31 on Friday, Mr Kwek said that there were 26 submissions and he found them to be useful.

Committee chairman Richard Magnus said there was no need to call anyone who made submissions to testify.

Source: TODAY
Advertisement

Also worth reading

Advertisement