Several employees of the National Health Insurance Administration (NHIA) are suspected of leaking people’s personal information. The news caused a public outcry and highlighted that there are big loopholes in government institutions’ information security. In view of this situation, the government should take the following steps:
First, the NHIA should as soon as possible draw up statutory regulations governing the protection of personal information. The National Health Insurance (NHI) database includes sensitive information about all insured people in Taiwan, including their health status and medical records.
However, the Constitutional Court’s Judgement No. 13 last year said that the National Health Insurance Act (全民健康保險法) lacks clear regulations regarding the subject, purpose, conditions, scope and methods of the NHI data storage, the external transmission, provision and use of the data, and about related organizational and procedural monitoring and protection mechanisms, as well as other important matters.
The judgement said that this is contrary to the intent of Article 23 of the Constitution, which embodies the principle of legal reservation, meaning laws should not unnecessarily restrict constitutionally protected rights and freedoms, as well as Article 22, which implicitly safeguards citizens’ right of private communication.
The court instructed the NHIA to amend the act and other related laws, or to enact a special law, to clearly define the matters within three years.
Considering the serious implications of the latest leak, the NHIA should speed up the drafting process of legislative amendments or a new law to bolster the regulation of personal information.
Second, the NHIA and other agencies should review and update their data security management systems. There are many public agencies that store and use people’s personal information. Besides the NHIA, these include police departments, and household registration and tax offices. The Regulations on Classification of Cyber Security Responsibility Levels (資通安全責任等級分級辦法) define government agencies’ cybersecurity responsibility levels on a five-tier scale according to the sensitivity of their purview, the type of information they store and process, and the scale of their communication systems.
The NHIA has the highest cybersecurity responsibility level.
In June 2019, the Ministry of Civil Service, which also has the highest level, discovered a leak of civil servants’ personal information. A Control Yuan investigation found out that the ministry had not fully evaluated its online operations and document management systems, which store information about the qualifications and pay grades of all civil servants, in accordance with relevant regulations, compromizing the security standards of the systems.
In view of the repeated occurrence of such incidents, the Ministry of Digital Affairs should immediately help government agencies comprehensively review the level of their internal information systems and operational processes to see whether there are any deficiencies and loopholes, and make improvements as soon as any such problem is discovered to prevent subsequent cybersecurity risks.
Third, government agencies should bolster the education of civil servants with regard to law, discipline and cybersecurity. The large number of personnel involved in the NHIA case shows that civil servants in general have an insufficient grasp of law and discipline, as well as inadequate awareness of cybersecurity.
The government should make improvements in those three aspects, so that the catchphrase “cybersecurity is national security” can be more than a mere slogan.
Wang Yu-pei is a civil servant.
Translated by Julian Clegg
China on Tuesday said it has stopped issuing short-term visas for Japanese and South Koreans, in its first retaliatory measure against countries that introduced COVID-19-related restrictions on travelers from China. More than a dozen countries, including Taiwan, introduced such curbs after China last month lifted its “zero COVID-19” policy, and stopped reporting daily case totals for the disease amid a nationwide surge triggered by the abrupt change in disease prevention policy. On Sunday last week, it also opened its border for outbound travelers Japan and South Korea require arrivals from China, regardless of nationality, to take pre-departure and on-arrival COVID-19 tests.
“Potato chips, computer chips, what’s the difference?” a top economic adviser to then-US president George H.W. Bush supposedly asked in the early 1990s. “A hundred dollars of one or a hundred dollars of the other is still a hundred dollars.” At the time, Japanese firms were pushing their US competitors out of the market for memory chips, but free-market elites in Washington staunchly opposed any form of industrial policy to protect the domestic semiconductor industry. If foreign companies could produce chips at a lower price, Americans would pocket the cost savings and direct their spending to other sectors, they argued. Chipmakers in
In 1988, young Comrade Qin Gang (秦剛) did not graduate from the China Foreign Affairs University (外交學院), China’s training academy for diplomats. He never attended the Institute. Instead, he graduated from Beijing’s “University of International Relations” (國際關係學院) which, as I recall from early in my diplomatic career, was a campus well-known for its affiliation with the Chinese Communist Party Center’s intelligence services. In 1964, because of the school’s critical status as a training ground for special operatives, the UIR was named a “key institute of higher learning” (重點高校) — together with elite Beijing and Tsinghua universities — as an academy
There is a constant debate regarding countries’ responses to a potential “Taiwan contingency,” but relatively little discussion on how to deter China from invading Taiwan. What must be reinforced is that the Indo-Pacific construct is about preventing conflicts and maintaining peace and stability in the region. India views Taiwan differently than Western countries do. For India, Taiwan is not a pawn in a game of geopolitical chess. Its perception of Taiwan is driven by its economic interests and that Taiwan is a like-minded country in the Indo-Pacific region. Unlike much of the West, India’s Taiwan policy is not limited to the “China
NHIA leak requires all-out response – 台北時報

