Are wireless local area networks really that insecure?
HIPAA Weekly Advisor, August 8, 2003
Want to receive articles like this one in your inbox? Subscribe to HIPAA Weekly Advisor!
Q: Are wireless local area networks really that insecure?
A: In a nutshell, wireless local area networks (WLANs) aren't really any less secure that wired networks. They each have their weaknesses. As with other types of information systems, the security weakness lies in the management of WLANs. It is understood that when WLAN devices-access points (APs), network cards, etc.-are used with factory default settings, networks and information can be put at risk. Given this, some common sense and a few system-hardening best practices can help you achieve what can be considered reasonable WLAN security.
It is critical to secure the wireless backbone components, such as APs, bridges, hubs, and switches. However, there are many other components-and entry points into WLANs-that need to be considered when assessing security. Your WLAN will only be as secure as the weakest link in the overall infrastructure. You can have the most secure WLAN backbone in the world, but all it takes to expose your systems is something as simple as an exposed antenna or an insecure wireless workstation. The best answer to the above question is to give equal importance to every component in the wireless network, including workstations operating systems, wireless cards, APs, wireless bridges, antennas, hubs, switches, and any routers or firewalls on the WLAN segment.
In no particular order, you should at least do the following to secure your APs (if your system will let you):
Editor's note: Answered by Kevin Beaver, CISSP, founder and president of Atlanta-based information security consulting firm Principle Logic, LLC, and excerpted from the August 2003 issue of Healthcare Information Security.
Want to receive articles like this one in your inbox? Subscribe to HIPAA Weekly Advisor!
Related Products
Most Popular
- Articles
-
- Q/A: Volume requirement for reporting hydration services
- Featured blog post: Nurses face felony charges after reporting physician to the Texas Medical Board
- Catch up on what's new with injections and infusions
- Topic: CMS, OESS post new security compliance review information, checklist
- Capturing all necessary codes for IUD insertion and removal can be challenging
- HIPAA Q&A: Level of encryption needed for email
- Identify potential Medicaid RAC target areas
- What does case-mix index mean to you?
- QA:Coding multiple initial infusions
- OB services: Coding inside and outside of the package
- E-mailed
-
- Q/A: Volume requirement for reporting hydration services
- Featured blog post: Nurses face felony charges after reporting physician to the Texas Medical Board
- HIPAA Q&A: Level of encryption needed for email
- Q&A: Follow CMS' coding guidelines when using modifier -25
- CMS has reformulated payments for some bilateral procedures
- Catch up on what's new with injections and infusions
- New conflicts of interest create new challenges
- Q/A. One injection code or two?
- What does case-mix index mean to you?
- ED-to-inpatient transfers are flawed with safety gaps
- Searched