Two advocacy groups on data privacy urge the Department of Information and Communications Technology (DICT) and the National Privacy Commission (NPC) to warn and prepare Filipino consumers, and institutions that have received PhilHealth member information to deliver their services, on the potential impact of the PhilHealth data breach through a Medusa malware attack discovered last September 22.
“Compared to the Comelec data breach in 2016, the potential impact of this incident is even bigger as all working Filipinos are mandatorily enrolled, and need to pay monthly contributions. We urgently request the DICT and NPC that even if only a fraction of the extent of the breach has been revealed by the threat actors, they can already guide consumers, and institutions that use PhilHealth information on what to do in case their personal information was compromised by the breach,” said Sam Jacoba, President of the National Association of Data Protection Officers of the Philippines (NADPOP), the Philippines’ first advocacy group of Data Protection Officers.
Lito Averia, President of the Philippine Computer Emergency Response Team (PH-CERT), a volunteer organization that assists individuals and institutions on information security issues, agree that the regulators should already anticipate the worst case scenario as it is better to warn Filipino consumers as soon as possible as the threat actors can already exploit the illegally accessed personal information.
“PhilHealth, with the help of the DICT, is releasing information on the breach bit by bit. This is actually understandable as the discovery process for external security incidents is complicated, but they can already assume that a significant number of member data was compromised based on their recent statement,” Averia said. “Thus, better prepare PhilHealth members for the worst case scenario so they will not be caught off-guard and suffer potential financial loss or be a victim of identity theft.”
NADPOP and PH-CERT also offered to provide a third-party perspective and assist PhilHealth in its current breach investigation with the DICT and NPC.
“If PhilHealth needs unbiased third-party support, we have volunteers who are ready to assist in digital forensics and in the data breach management needs of the agency,” Jacoba and Averia jointly offered. “We are extending our support to PhilHealth and its impacted employees and members during this time as we know the value of all of us helping each other during these times. It takes a community to protect personal information.”
NADPOP and PH-CERT just concluded CyberSecConPH last September 19 attended by more than 100 cybersecurity professionals, which kickstarted the formation of a Cybersecurity Community of Practice in the Philippines that will connect with the ASEAN-Japan Cybersecurity Community this week in Tokyo. On October 25 to 27, in support of Cybersecurity Month, the two groups will host an online conference on Governance, Risk and Compliance (GRC) that will elevate the knowledge and skills of Data Protection Officers (DPOs) and Cybersecurity Professionals in fighting against internal and external threat actors. The conference is by-invitation only and exclusive to active NADPOP and PH-CERT community volunteers, members and partners.
This website is my aspiration, very good design and style and perfect articles.
Wohh exactly what I was searching for, regards for putting up.
It is actually a great and useful piece of information. I am happy that you shared this useful info with us. Please keep us informed like this. Thanks for sharing.
I and also my pals ended up taking note of the best points located on your website and so all of a sudden got a horrible feeling I had not expressed respect to the web blog owner for those techniques. These young men had been consequently very interested to read them and already have certainly been loving them. Many thanks for genuinely very kind and for selecting variety of fine areas millions of individuals are really desirous to discover. My personal honest apologies for not expressing gratitude to you earlier.
I think other website owners should take this internet site as an example , very clean and good user friendly style.
Heya i’m for the primary time here. I came across this board and I find It truly useful & it helped me out a lot. I’m hoping to present something back and aid others like you aided me.
It?¦s really a great and helpful piece of information. I?¦m happy that you simply shared this helpful information with us. Please keep us up to date like this. Thank you for sharing.
You really make it seem so easy with your presentation but I find this topic to be actually something that I think I would never understand. It seems too complicated and extremely broad for me. I’m looking forward for your next post, I’ll try to get the hang of it!
I truly appreciate this post. I have been looking all over for this! Thank goodness I found it on Bing. You have made my day! Thank you again
Thanx for the effort, keep up the good work Great work, I am going to start a small Blog Engine course work using your site I hope you enjoy blogging with the popular BlogEngine.net.Thethoughts you express are really awesome. Hope you will right some more posts.
hello there and thank you for your information – I have certainly picked up something new from right here. I did however expertise some technical points using this website, as I experienced to reload the site a lot of times previous to I could get it to load properly. I had been wondering if your web hosting is OK? Not that I’m complaining, but slow loading instances times will very frequently affect your placement in google and could damage your quality score if advertising and marketing with Adwords. Anyway I am adding this RSS to my e-mail and can look out for much more of your respective exciting content. Make sure you update this again very soon..
My spouse and I stumbled over here by a different page and thought I might as well check things out. I like what I see so now i’m following you. Look forward to looking into your web page repeatedly.
An interesting discussion is worth comment. I think that you should write more on this topic, it might not be a taboo subject but generally people are not enough to speak on such topics. To the next. Cheers
he blog was how do i say it… relevant, finally something that helped me. Thanks
Nice read, I just passed this onto a colleague who was doing a little research on that. And he just bought me lunch since I found it for him smile Therefore let me rephrase that: Thank you for lunch!
I am continually looking online for ideas that can benefit me. Thank you!