It feels like the places where security is of utmost importance like in banking, security cards or health are the worst at doing it. At least, lack of security of credit cards is understandable as banks are profiting from fraud by charging the victim a fee. In health? This must stop. It's a failure of regulatory bodies as they throw so much junk policies around that the things that really require attention is just ov…
A billion medical images are exposed online
11–20 of 201 posts
Re: A billion medical images are exposed online
#12% curl -L 'https://techcrunch.com/2020/01/10/medical-images-exposed-pacs/' curl: (7) Failed to connect to guce.advertising.com port 443: Connection refused WTF? I have a lying DNS server, and it's getting ridiculous. Here's the outline for people who care about privacy/tracking/GDPR, etc. https://outline.com/Ep5u4K
I've not been able to find a way to read content on that domain for months now.
Edit:
PS: unlike many here I've little against ads as long as they aren't tracking me, but the "consent screen" on techcrunch is less "consent" and more "strongarm".
PPS: as others are mentioning it seems the whole thing seems to be compliance theater since they seem to set a tracking cookie before even displaying the consent screen :-/
Re: A billion medical images are exposed online
#13The key takeaway from that article, for me, is that the government body that is supposed to monitor, enforce, and penalize organizations who fail to follow the HIPAA rules is basically doing nothing. So with no consequence to these massive lapses, why would these companies care?
Re: A billion medical images are exposed online
#14It feels like the places where security is of utmost importance like in banking, security cards or health are the worst at doing it. At least, lack of security of credit cards is understandable as banks are profiting from fraud by charging the victim a fee. In health? This must stop. It's a failure of regulatory bodies as they throw so much junk policies around that the things that really require attention is just ov…
They focus on visible security more than actually securing things. Example: making it very hard for a user to log into a system “because of security “ but not using security certificates to secure their email servers.
Re: A billion medical images are exposed online
#15The DICOM Standard does not address issues of security policies, though clearly adherence to appropriate security policies is necessary for any level of security. The Standard only provides mechanisms that could be used to implement security policies with regard to the interchange of DICOM objects between Application Entities. For example, a security policy may dictate some level of access control. This Standard does not consider access control policies, but does provide the technological means for the Application Entities involved to exchange sufficient information to implement access control policies.
http://dicom.nema.org/medical/dicom/current/output/html/part...
The original DICOM TCP protocol requires that every device connected use an encrypted tunnel, and it's not easy to get all the device venders to agree on which ones to use, and then update their software. DICOM Web Services are a thing, and at least they would get HTTPS basically for free from their choice of web client and server.
HIPAA has been out since the 90's so we need to get more fines against the providers to make them implement confidentiality and access controls. It's actually the GDPR which is now driving access controls rather than HIPAA.
To be fair though, the DICOM folks are busy constantly trying to standardize new image data coming from innovations in the modalities (scanners).
Re: A billion medical images are exposed online
#16I have never, in all my years of working in healthcare, seen a hospital or physicians office directly install and manage PACS. They pay a third-party - usually the vendor - to install, configure, and walk them through it. Maybe a behemoth system like Northwell has the IT bench to do it themselves, but that would be the exception.
So allow me to rephrase slightly: “technologically inept organization pays vendor to make machine go vroom. Vendor leaves keys in ignition. Damn that technologically inept organization.”
To take a 10,000-foot view of the situation, though:
Healthcare-related technologically was largely pushed on the industry via legislation. Said legislation was almost entirely stick, no carrot. The result was healthcare organizations with a gun to their head to buy from a handful of vendors, with no real ROI to be seen from it - aka, the government outsourcing its costs to private industry, and throwing pork to some major health IT firms along the way. When a technology is forced on you at a loss, from a vendor with little incentive to optimize ease of use or utility, you get a terrible piece of shit that no one wants to invest more time and money into than absolutely needed. That’s going to show itself in a myriad of ways.
Re: A billion medical images are exposed online
#17It feels like the places where security is of utmost importance like in banking, security cards or health are the worst at doing it. At least, lack of security of credit cards is understandable as banks are profiting from fraud by charging the victim a fee. In health? This must stop. It's a failure of regulatory bodies as they throw so much junk policies around that the things that really require attention is just ov…
Re: A billion medical images are exposed online
#18[flagged]
"...one unprotected server at one of the largest military hospitals in the United States exposed the names of military personnel and medical images"
Re: A billion medical images are exposed online
#19Sensitive data should be thrown away and the medical images could improve on the current state of the art medical image database used for machine learning. I'd be more than happy to publish my medical images with results if it would be used for an open database. I have been at doctors in third world countries, where doctors don't get the same level of education, but try to use the best tools available without paying…