TLP White: In this edition of Hacking Healthcare, we detail the outcome of a German competition agency’s recent investigation into Facebook’ data practices. Then, we examine Canadian crypto giant QuadrigaCX’s loss of assets and access to its digital coins. Finally, we discuss a bipartisan effort asking the Department of Homeland Security to recognize that VPN apps could pose a national security risk.
Welcome back to Hacking Healthcare.
As a reminder, this is the public version of the Hacking Healthcare blog. For additional in-depth analysis and opinion, become a member of H-ISAC and receive the TLP Amber version of this blog.
Hot Links –
1. German Antitrust Regulator Cracks Down on Facebook’s Ad Business.
Last week Facebook’s data collection practices were cast into the spotlight, again, as Germany’s Federal Cartel Office (“FCO”) forbid the company from tracking users and collecting and combining their data without their consent. The German antitrust authority began its investigation into Facebook in 2016, and on Thursday it issued a decision condemning Facebook’s practices. The FCO alleged that Facebook requires users to assent to data tracking and collection in order to use its service, so users’ agreement to the practice through click-wrap terms does not constitute voluntary consent. Facebook, which uses the data it collects to build user profiles to enhance and enable targeted advertising, has appealed the German regulator’s ruling.
Some media outlets have reported that the FCO’s decision is especially impactful because it asserts privacy as an antitrust issue. Because Facebook is ubiquitous and serves a unique function, the argument goes, users’ only way to avoid data tracking and collection is to decline to use the social network all together. This does not give users much of a choice, so the German competition authority has asserted it is anti-competitive in nature. The FCO’s enforcement action signals that European regulators are not only looking to the General Data Protection Regulation (“GDPR”) as a way to challenge companies’ privacy practices. Antitrust authorities across Europe could also become more active in the space, as legal theories of privacy as an antitrust matter continue to gain ground.
2. Cryptocurrency Exchange Loses its Founder and $137 Million.
QuadrigaCX, a Canadian cryptocurrency exchange, lost millions of its users’ assets after founder, sole director, and officer Gerald Cotton passed away at 30 years old in December. Cotton maintained the crypto exchange’s coins in a “cold wallet”—a digital storing device for cryptocurrency that is not connected to the Internet in order to avoid threats from hackers. When Cotton died, no one could access the exchange’s digital wallet, which the founder held on his encrypted personal laptop. Experts have attempted to recover access to the laptop, digital wallet, and coins to no avail.
This instability would be enough on its own to threaten the Canadian crypto giant’s viability, but QuadrigaCX is even more vulnerable due to other liquidity issues: approximately $53 million of its assets are currently tied up with at least three of its third-party business partners. As a result, customers of the exchange are uncertain whether it will be able to pay out on their requested withdrawals once (and if) the dust settles.
Cryptocurrency’s rise in popularity and regulators’ inability to keep up has allowed online coin exchanges to grow with relatively few legal restrictions. However, investors in these financial vehicles do so at their own risk. The volatility in the crypto market has been widely reported, and it’s no secret that coin exchanges remain almost completely unregulated in many parts of the world, including Canada—QuadrigaCX’s home nation.
3. Are Foreign VPNs a National Security Risk?
That was the question posed by Senator Marco Rubio (R-FL) and Senator Ron Wyden (D-OR) to Cybersecurity and Infrastructure Security Agency (“CISA”) Director Christopher Krebs in a letter late last week. The growing use of mobile virtual private network (“VPN”) apps as a way to augment online user privacy has led to an increase in VPN app products from companies throughout the world. However, the pair of senators are concerned that some of these products route information through, or store information within, the infrastructure of nations who oppose U.S. interests and may use these VPN products illicitly to gather intelligence.
The letter made specific references to China’s Huawei and Russia’s Kaspersky Labs as examples of national security risks posed by foreign companies. It also urged the Department of Homeland Security to conduct a threat assessment on the security risks associated with government employees’ use of VPN services that may be surveilled by foreign actors. The senators have requested a “Binding Operational Directive prohibiting [such VPN apps’] use on federal government smartphones and computers” if the CISA Director assesses that their use constitutes a national security threat.
Tuesday, February 12th:
–Hearings to examine managing pain during the opioid crisis. (Senate Committee on Health, Education, Labor, and Pensions)
Wednesday, February 13th:
–“Strengthening Our Health Care System: Legislation to Reverse ACA Sabotage and Ensure Pre-Existing Conditions Protections.” (House Committee on Energy and Commerce Subcommittee on Health)
–Long Term Healthcare Challenges and Long Term Care Hearing. (House Committee on Appropriations Subcommittee on Military Construction, Veterans Affairs, and Related Agencies
Thursday, February 14th:
No relevant hearings.
International Hearings/Meetings –
EU – No relevant hearings.
Conferences, Webinars, and Summits –
–FIRST Symposium 2019 – London, UK (3/18/19-3/20/19)
–HEALTH IT Summit (Midwest) – Cleveland, OH (3/19/19-3/20/19)
–National Association of Rural Health Clinics Spring Institute – San Antonio, TX (3/20/19-3/22/19)
–HSCC Joint Cybersecurity Working Group – San Diego, CA (4/3/19– 4/4/19)
–H-ISAC Israel Showcase & Innovation – Tel Aviv, Israel (4/8/19-4/13/19)
–H-ISAC CYBER RX – IOMT Executive Symposium – Munich, Germany (4/15/2019–4/16/2019)
–HEALTH IT Summit (Southern California) – San Diego, CA (4/23/19-4/24/19)
–HEALTH IT Summit (Florida) – Wesley Chapel, FL (5/21/19-5/22/19)
–2019 NH-ISAC Spring Summit – Ponte Vedra Beach, FL (5/13/19-5/17/19) <https://www.marriott.com/hotels/travel/jaxsw-sawgrass-marriott-golf-resort-and-spa/>
–HEALTH IT Summit (Southeast) – Nashville, TN (6/13/19-6/14/19)
–CybSec and Blockchain Health – London, UK (7/11/19-7/12/19)
–HEALTH IT Summit (Rocky Mountain) – Denver, CO (7/15/19-7/16/19)
–HEALTH IT Summit (Northeast) – Boston, MA (10/3/19-10/4/19)
–2019 NH-ISAC Fall Summit – San Diego, CA (12/2/19-2/6/19)
–Apple patches FaceTime flaw and two exploited zero-days in new security update
–U.S. busts Romanian cybercrime ring that phished Americans, laundered millions of dollars
–Indecent disclosure: Gay dating app left “private” images, data exposed to Web
–LibreOffice and Apache OpenOffice vulnerable to same bug; only one is fixed
–TWITTER STILL CAN’T KEEP UP WITH ITS FLOOD OF JUNK ACCOUNTS, STUDY FINDS
–SENATORS GRILL FACEBOOK, GOOGLE, AND APPLE OVER INVASIVE APPS
–GOOGLE’S MAKING IT EASIER TO ENCRYPT EVEN CHEAP ANDROID PHONES
–Intelligence heads warn of more aggressive election meddling in 2020
–Trump likely to sign executive order banning Chinese telecom equipment next week
Contact us: follow @HealthISAC, and email at email@example.com
 https://www.wyden.senate.gov/imo/media/doc/020719%20Wyden%20Rubio%20VPN%20Letter%20to%20DHS. pdf; https://www.rubio.senate.gov/public/_cache/files/114510c9-e893-433c-a0df-f7980edb3753/368AAFFB6E7F458CC886AB96EBCC2606.020719-wyden-rubio-vpn-letter-to-dhs.pdf