There is an interesting twist to the data breach at Premera , a healthcare company, announced last week. The company was deemed compliant with the Health Insurance Portability and Accountability Act (HIPAA) in late November 2014. The general testing of the systems and the necessary application audit were conducted in January 2014 by the US Office of Personnel Management, an independent government agency that manages the federal government’s civil service, because Premera also provides healthcare to government employees.
The inspection revealed a few problems:
• Premera lacks some physical security controls that would prevent access to data.
• The company had a patch management policy, but some patches were not applied in a timely manner.
• There was no methodology to prevent the use of unsupported or out-of-date software.
• Vulnerability scan detected insecure server configuration settings
• They did not have a documented baseline of the system software, which makes it ineffective to control its security configuration settings.
• They had not performed a preventive disaster recovery test for all information systems.
However, the report states that “There is nothing that would lead us to believe that Premerais not in compliance with security, privacy, and national HIPAA regulations.” Some of these issues have already been fixed since the preliminary audit in April 2014, and as the company spokesperson states, there is no evidence to link the problems to the May 2014 breach.
But as Iain Thomson points out, this could ultimately prove that HIPAA standards are simply too low to provide security based on today's needs. Otherwise, it will simply be revealed that the attackers did indeed use one of the above holes in their attack.

