Ucsf medical center case study-information security, Computer Network Security

Assignment Help:

Example : UCSF Medical Center

In the year 2002, the University of California, San Francisco (UCSF) Medical Center received an email message from someone who claimed to be a doctor working in Pakistan and who threatened to release patient records onto the internet unless money owing to her was paid. Many confidential medical transcripts were attached to the email.

UCSF staff was confused; they had no dealings in Pakistan and surely did not employ the person who sent email. The Medical Center began an immediate investigation, concentrating on the transcription service that had been outsourced to Transcription Stat, based in close Sausalito. It transpired that Transcription Stat farmed out work to some 15 subcontractors scattered across America. One of the subcontractors was Florida based Sonya Newburn, who in turn employed subcontractors further, including Tom Spires of Texas. No one at Transcription Stat realized that Spires also employed his own subcontractors, including sender of email. The sender claimed that Spires owed her money, and had not paid her.

Newburn eventually agreed to pay the $500 that the email sender claimed was owed to her. In return sender informed UCSF that she had no intention of publicizing personal information and had damaged any records in her care. Certainly, there is no way to prove that the records have been destroyed actually.

Naturally, you won’t wish your own medical records to be publicized: they should be scarce. This threat cost the organization little in money terms, but how much in the reputation? Just what is the worth of reputation? Or we can say that how much is it worth paying in information security to protect the reputation?


Related Discussions:- Ucsf medical center case study-information security

Csma/ca, CSMA/CA Wireless needs collision avoid ness rather than colli...

CSMA/CA Wireless needs collision avoid ness rather than collision checking. Transmitting computer puts very short codes to receiver. Receiver responds with short message getti

Distinguish between authorization and authentication, Question : (a) D...

Question : (a) Distinguish between authorization and authentication. (b) SSO (Single Sign On) implies a user logs in once and can access resources for a defined period of

Routing protocol for a banking network, You have been asked to design a Ban...

You have been asked to design a Banking Network with two primary types of locations.  Branches that will have 3 subnets, one /25 subnet one /26 subnet for ABMS and one /26 s

The major decision hierarchy for disclosing security problem, QUESTION ...

QUESTION The major decision hierarchy for disclosing security problems is if the problem is with the product owned by the business or if it is used by the business. Although th

The Security Systems Development Life Cycle (SecSDLCtle.., #Under what circ...

#Under what circumstances would the use of a SecSDLC be more appropriate than an SDLC?

Imap and pop functions, How does the POP functions? What are the advantages...

How does the POP functions? What are the advantages/benefits of IMAP over POP? POP stands for Post Office Protocol, version 3 (POP3) is one of the easiest message access protoc

encrypt and decryption using rsa with the prime numbers, Problem (1) -...

Problem (1) - Alice, Bob and Charlie have a secret key a=3, b=4, c=5, respectively. - They want to find a common secret key using Diffie-Hellan key exchange protocol (with g

Ids deployment overview, IDS Deployment Overview The decision regarding ...

IDS Deployment Overview The decision regarding control strategies, decisions about where to locate elements of intrusion detection systems is an art in itself. Planners should s

Listing assets in order of importance-risk management, Listing Assets in Or...

Listing Assets in Order of Importance Weighting should be created for each category based on the answers to questions. The relative importance of each asset is calculated usin

Deploying host-based idss, Deploying Host-Based IDSs -Proper implementat...

Deploying Host-Based IDSs -Proper implementation of HIDSs can be painstaking and time-consuming task .The process of deployment begins with implementing most critical systems fi

Write Your Message!

Captcha
Free Assignment Quote

Assured A++ Grade

Get guaranteed satisfaction & time on delivery in every assignment order you paid with us! We ensure premium quality solution document along with free turntin report!

All rights reserved! Copyrights ©2019-2020 ExpertsMind IT Educational Pvt Ltd