Live data from Hacker News

Australia's new e-health platform crashes as people rush to opt-out

zdnet.com

101–110 of 112 posts

Re: Australia's new e-health platform crashes as people rush to opt-out

#101

Earlier quoted context omitted.

So in my country, records are kept by the individual clinics, where I have GDPR rights over them and there isn’t a direct mechanism by which anybody but the clinic can access them. If I move clinic, there’s a process by which those records get moved with my consent.

Yep, works like this in Canada. The problem is that each clinic implements a different record system, so someone needs to undergo effort to translate them when you switch systems. Also, I worked with OSCAR, one of Canada's biggest EMRs. It is written by a bunch of academics at a local university and is individually deployed on under-the-desk computers at clinics. It is full of security holes, the whole process of man…

Your province pretty much gets and retains your records because it's paying the bills.

Re: Australia's new e-health platform crashes as people rush to opt-out

#102
post #92
post #21

Earlier quoted context omitted.

It's really not that much money as an incentive. Doctors won't do it unless they believe it's a good thing. Source: I'm an Australian doctor.

Are you opting out? I keep remembering that AHPRA applied for warrantless access to metadata, and thinking that perhaps I might be better without a record in case the wideranging provisions for access by other agencies get deployed too liberally.

This is an interesting question and I'm still pondering on the implications.

I am generally in favour of people signing up for this (or not opting out as the case is now) because it very well may save their life one day. Emergency departments especially will benefit in being able to look up details on the patient. It's amazing how little most people know about their own health history.

I suppose it may also help me if I end up in ED unconscious and have some health condition they would need to know about. That situation is unlikely, and even if it did happen they could call my wife, who is also a doctor, and she'd also know what's important in my history.

So for me, there's very little benefit I see. Couple that with my distrust of the Australian Government's ability to outsource their critical infrastructure to American companies (facepalm) and have it actually work (facepalm), I'm leaning towards opting out.

For patients in general, I think the benefit to them will outweigh the risk of their personal data being stolen.

If only our government wasn't so inept with IT (we have plenty of good developers here. Why not make our own teams to build things?) I would be able to recommend this health initiative to everyone.

Edit: autocorrect fail

Re: Australia's new e-health platform crashes as people rush to opt-out

#103
post #102
post #92

Earlier quoted context omitted.

Are you opting out? I keep remembering that AHPRA applied for warrantless access to metadata, and thinking that perhaps I might be better without a record in case the wideranging provisions for access by other agencies get deployed too liberally.

This is an interesting question and I'm still pondering on the implications. I am generally in favour of people signing up for this (or not opting out as the case is now) because it very well may save their life one day. Emergency departments especially will benefit in being able to look up details on the patient. It's amazing how little most people know about their own health history. I suppose it may also help me i…

My Health Tecird is not going to help you in the ER in any way shape or form. At best it will be useless at worst it will be wrong.

It is not a complete record, and you will only be shown a summary of medical history not a clinically useful record. In addition the patient may have sought opinions from multiple doctors, any of whom may not use MHR.

The risk to most people who don’t actually need complex diagnoses will be endless calls from lawyers and insurance sales along with a web experience modified to keep them worried about that visit to the doctor about a possible STI last Valentine’s day.

Re: Australia's new e-health platform crashes as people rush to opt-out

#104
post #44

Earlier quoted context omitted.

This is true "on paper", but in practice our whole industry is built on the fact that electronic records behave qualitively differently from paper records because they're so much easier to handle. You can't steal everyone 's paper records all at once in the way you can with electronic records, for example.

> You can't steal everyone's paper records all at once in the way you can with electronic records, for example. You're assuming you can steal the entire database at once which most certainly will also be noticed and stopped swiftly.

Hum... The real danger here is the possibility of silently target some people of interest and remotely change a small part of their health data. People could be even killed remotely from other countries before the trick would be discovered. Old politicians or oppositors could be killed faking a natural death.

Even more, any country could enter in a future war, or send soldiers somewhere in the future. The possibility of the enemy remotely mixing or changing the medication of the soldiers would be devastating. In a single strike, somebody, somewhere could close down all the hospitals in the area and the chaos could last for days or weeks. All that is needed is to take one city with one hospital connected to the same net and asking for the password to one of the prisoners.

Re: Australia's new e-health platform crashes as people rush to opt-out

#105
post #102
post #92

Earlier quoted context omitted.

Are you opting out? I keep remembering that AHPRA applied for warrantless access to metadata, and thinking that perhaps I might be better without a record in case the wideranging provisions for access by other agencies get deployed too liberally.

This is an interesting question and I'm still pondering on the implications. I am generally in favour of people signing up for this (or not opting out as the case is now) because it very well may save their life one day. Emergency departments especially will benefit in being able to look up details on the patient. It's amazing how little most people know about their own health history. I suppose it may also help me i…

> If only our government wasn't so inept with IT (we have plenty of good developers here. Why not make our own teams to build things?) I would be able to recommend this health initiative to everyone.

It's not the government IT I'm worried about so much, it's all the local doctors that get access to medical records and have inept IT security. Previously if there was a breach at a practice it was only the data of the patients of that practice, now if there is a breach at a practice they can potentially access the medical records anyone in the country.

The attack surface is huge and largely unguarded and now there is a massive reward for breaching it.

> I suppose it may also help me if I end up in ED unconscious and have some health condition they would need to know about.

This can be solved with a card in your wallet, which they have to go into to find which health records to lookup anyway.

Re: Australia's new e-health platform crashes as people rush to opt-out

#106
post #102

Earlier quoted context omitted.

This is an interesting question and I'm still pondering on the implications. I am generally in favour of people signing up for this (or not opting out as the case is now) because it very well may save their life one day. Emergency departments especially will benefit in being able to look up details on the patient. It's amazing how little most people know about their own health history. I suppose it may also help me i…

My Health Tecird is not going to help you in the ER in any way shape or form. At best it will be useless at worst it will be wrong. It is not a complete record, and you will only be shown a summary of medical history not a clinically useful record. In addition the patient may have sought opinions from multiple doctors, any of whom may not use MHR. The risk to most people who don’t actually need complex diagnoses will…

> My Health Tecird is not going to help you in the ER in any way shape or form.

So you've been a doctor working in ED?

> will only be shown a summary of medical history not a clinically useful record

I'm going to guess you're not a doctor, since then you'd know how much more useful a medical summary is than no information at all.

Hell, if I have NOTHING BUT the patient's medication list, I can usually make a pretty good guess about their medical history. If the health record contained only patients' medications it would prevent an enormous amount of morbidity and mortality, as well as saving time for doctors, nurses and pharmacists all around the country.

Sure, it might not be complete, but it's far more likely to be complete than patients' memory of what meds they take for which disease, in which doses and with which frequency.

Re: Australia's new e-health platform crashes as people rush to opt-out

#107
post #105
post #102

Earlier quoted context omitted.

This is an interesting question and I'm still pondering on the implications. I am generally in favour of people signing up for this (or not opting out as the case is now) because it very well may save their life one day. Emergency departments especially will benefit in being able to look up details on the patient. It's amazing how little most people know about their own health history. I suppose it may also help me i…

> If only our government wasn't so inept with IT (we have plenty of good developers here. Why not make our own teams to build things?) I would be able to recommend this health initiative to everyone. It's not the government IT I'm worried about so much, it's all the local doctors that get access to medical records and have inept IT security. Previously if there was a breach at a practice it was only the data of the p…

You have a really good point about local practice security. I agree.

I disagree about the card in wallet thing. Patients won't keep it updated. Also, most patients won't have it on them. And for many patients it would have to be a book, rather than a card. See my other comment talking about medications.

Re: Australia's new e-health platform crashes as people rush to opt-out

#108
post #105
post #102

Earlier quoted context omitted.

This is an interesting question and I'm still pondering on the implications. I am generally in favour of people signing up for this (or not opting out as the case is now) because it very well may save their life one day. Emergency departments especially will benefit in being able to look up details on the patient. It's amazing how little most people know about their own health history. I suppose it may also help me i…

> If only our government wasn't so inept with IT (we have plenty of good developers here. Why not make our own teams to build things?) I would be able to recommend this health initiative to everyone. It's not the government IT I'm worried about so much, it's all the local doctors that get access to medical records and have inept IT security. Previously if there was a breach at a practice it was only the data of the p…

PEXA have pointed this out in great expensive detail with conveyancers. Every week there's a $300k theft of house sale settlements, always because some hacker has gained control of the settlement party's account.

I doubt medical practices are as bad as backyard shops like conveyancers but you are spot on, the incentives are definitely there

Re: Australia's new e-health platform crashes as people rush to opt-out

#109

Earlier quoted context omitted.

The census fiasco was a truly special kind of incompetence. The best inside analysis was from the folks behind the Risky Business infosec podcast: https://risky.biz/censusfail/ Summary: The project was outsourced to IBM (that alone probably says it all), who didn't purchase any DDoS protection. A small attack crashed the first firewall, and the backup firewall didn't have rules loaded. That caused IBM's monitoring to…

All the marketing calling it "Census night" and encouraging people to do it on the same evening instead of over the week probably didn't help spreading the load out.

Furthermore, although it's true that IBM didn't purchase DDOS protection, neither did the government pay them to purchase it. IBM is incompetent but in this particular case I can't blame them for attempting to make a meager profit out of the pittance the Australian government chose to spend on their first act of digital governance.

Re: Australia's new e-health platform crashes as people rush to opt-out

#110
post #10

As part of my work, I've had to read a fair amount of the legislation and reports coming out in this sector and also the "Consumer Data Rights" legislation (similar to the UK's open banking scheme. What I found was a massive difference in policy coming out from the same government but in two seperate streams of work. A) Consumer Data Right (legislation being built into Australia Privacy Act) focusing on banking, ener…

Although I will try to find this information myself in the meantime, I'm looking forward to you sourcing this.
Post reply on HN