Live data from Hacker News

A billion medical images are exposed online

techcrunch.com

31–40 of 201 posts

Re: A billion medical images are exposed online

#31

An odd line from the article, wherein it states that security researchers don’t blame vendors, but the physicians and hospitals that fail to properly secure the software. I have never, in all my years of working in healthcare, seen a hospital or physicians office directly install and manage PACS. They pay a third-party - usually the vendor - to install, configure, and walk them through it. Maybe a behemoth system lik…

I’ve been the IT vendor in this scenario. While I’m sure there are plenty of inept vendors not doing their part to ensure the systems they implement are secure, a big part of it is doctors and their work culture.

Many doctors see themselves as too important to deal with security. They have an attitude of “I went to school for medicine, not computers! How dare you ask me to use a computer.” They are not only technologically inept, they are proud of it. And I’m not just talking about refusing to use complicated software. I’m talking about doctors that insist that they shouldn’t be forced to use passwords (not even complicated passwords; ANY passwords). And in most of the organizations I have dealt with, doctors are the most important people in the organization and have final say on anything, which often means that the security department’s efforts are all overridden by doctors that can’t be arsed to even type in a password before using their EMR, and don’t even dream of something more complicated like asking them to use multi-factor auth.

I once worked at a hospital where a doctor was looking at porn at work, clicked a phishing link, and gave up his network credentials. An attacker then used those credentials to breach the network and siphoned several hundred thousand dollars from the financial system (wiring money to himself). Security detected this and disabled his account. 20 minutes later the doctor had called the CEO, yelled at him (“how dare you lock me out of my account!”) who then called security to yell at us and insist we re-enable his account. The doctor was never reprimanded (for falling for phishing or for the porn) meanwhile the security team got a stern talking to and was instructed to never disable a doctor’s account again.

Healthcare is a different world for security. You have to acknowledge that yes, patient safety is more important than security, but oftentimes these doctors take it to an extreme and they are very difficult to work with. I have never met a group of people more elitist and “too important to be bothered” by security than doctors.

Re: A billion medical images are exposed online

#32

On the user side, we have to jump through hoops and sign so many onerous paper HIPAA compliance forms at dr’s offices, to just get doctors to share records about us. On the backend it’s free for anyone to access. It’s all backwards!

The signature demands that really annoy me are the ones in which I must acknowledge that the provider has informed me of their HIPAA policies, which demands are seldom accompanied by actual information about HIPAA policies, which I probably wouldn't read anyway even if they were included.

Re: A billion medical images are exposed online

#33
post #3

The key takeaway from that article, for me, is that the government body that is supposed to monitor, enforce, and penalize organizations who fail to follow the HIPAA rules is basically doing nothing. So with no consequence to these massive lapses, why would these companies care?

Under funded...just like the IRS.

No, just inept like all government agencies.

Re: A billion medical images are exposed online

#34

An odd line from the article, wherein it states that security researchers don’t blame vendors, but the physicians and hospitals that fail to properly secure the software. I have never, in all my years of working in healthcare, seen a hospital or physicians office directly install and manage PACS. They pay a third-party - usually the vendor - to install, configure, and walk them through it. Maybe a behemoth system lik…

I’ve been the IT vendor in this scenario. While I’m sure there are plenty of inept vendors not doing their part to ensure the systems they implement are secure, a big part of it is doctors and their work culture. Many doctors see themselves as too important to deal with security. They have an attitude of “I went to school for medicine, not computers! How dare you ask me to use a computer.” They are not only technolog…

[deleted]

Re: A billion medical images are exposed online

#35
post #12
post #7

% curl -L 'https://techcrunch.com/2020/01/10/medical-images-exposed-pacs/' curl: (7) Failed to connect to guce.advertising.com port 443: Connection refused WTF? I have a lying DNS server, and it's getting ridiculous. Here's the outline for people who care about privacy/tracking/GDPR, etc. https://outline.com/Ep5u4K

For now I'd be happy if techcrunch was blocked so people had to submit other sources. I've not been able to find a way to read content on that domain for months now. Edit: PS: unlike many here I've little against ads as long as they aren't tracking me, but the "consent screen" on techcrunch is less "consent" and more "strongarm". PPS: as others are mentioning it seems the whole thing seems to be compliance theater si…

[deleted]

Re: A billion medical images are exposed online

#36
post #9
post #7

% curl -L 'https://techcrunch.com/2020/01/10/medical-images-exposed-pacs/' curl: (7) Failed to connect to guce.advertising.com port 443: Connection refused WTF? I have a lying DNS server, and it's getting ridiculous. Here's the outline for people who care about privacy/tracking/GDPR, etc. https://outline.com/Ep5u4K

Yahoo/AOL/Oath want to set an advertising cookie before you visit any of their sites.

No, they redirect you to an advertizing domain.

Re: A billion medical images are exposed online

#37
post #7

% curl -L 'https://techcrunch.com/2020/01/10/medical-images-exposed-pacs/' curl: (7) Failed to connect to guce.advertising.com port 443: Connection refused WTF? I have a lying DNS server, and it's getting ridiculous. Here's the outline for people who care about privacy/tracking/GDPR, etc. https://outline.com/Ep5u4K

Here is the entire curl trace: http://ix.io/277P

Re: A billion medical images are exposed online

#38

An odd line from the article, wherein it states that security researchers don’t blame vendors, but the physicians and hospitals that fail to properly secure the software. I have never, in all my years of working in healthcare, seen a hospital or physicians office directly install and manage PACS. They pay a third-party - usually the vendor - to install, configure, and walk them through it. Maybe a behemoth system lik…

I’ve been the IT vendor in this scenario. While I’m sure there are plenty of inept vendors not doing their part to ensure the systems they implement are secure, a big part of it is doctors and their work culture. Many doctors see themselves as too important to deal with security. They have an attitude of “I went to school for medicine, not computers! How dare you ask me to use a computer.” They are not only technolog…

This seems like a caricature or an exception. Doctors are very aware of HIPAA (and the equivalent in every other country), and the professional and monetary costs of non-compliance.

Doctors didn't set up these systems. Doctors didn't expose them to the internet. As the other post said, vendors did. If those vendors couldn't properly communicate the needs, that's their problem.

What I think is a more rational explanation for doctor (nurse, lab technologist, etc) resistance is that the industry is rife with incompetence and vendor balkanization. So much so that every healthcare professional deals with literally dozens of logins to try to do their job. Every one of those logins has its own bizarre password policies, rotation schedules, etc. Pretty soon there is rightly hostility to whatever scheme some small niche vendor has imagined up in the illusion of security.

Re: A billion medical images are exposed online

#39
From Techcrunch's article it looks like it's possible to see so-called "protected health information" (PHI) in these images. PHI includes patient names, diagnoses, hospital and doctor names, contact information, and so forth. It's sometimes possible to "de-identify" medical images by scrubbing off patient info. But I bet most of these are not de-identified.

The examples in the TechCrunch article are redacted, but I guess that was done for publication and not on the stored images themselves.

In the USA, HIPAA and ARRA 2009 (followon legislation) made it a federal crime to knowingly or negligently disclose PHI. It's a crime that "pierces the corporate veil." That is, natural persons can be tried and convicted, even if they were acting on behalf of corporations.

The Centers for Medicare and Medicaid Services (CMS) has a Breach Notification Rule, requiring holders of data to notify patients and CMS themselves if PHI is breached. https://www.hhs.gov/hipaa/for-professionals/breach-notificat...

CMS announces breaches involving 500 or more patient records here https://ocrportal.hhs.gov/ocr/breach/breach_report.jsf

It wouldn't surprise me if the people involved in securing these sloppily configured DICOM servers are in a state of panic. I was involved in dealing with an unintentional breach of 44 patient records a few years back, and yeah, we had some panic. (Misrouted fax messages was the root cause, for what it's worth.) Also observe that I remember to this day how many records leaked out. Breaches are a big deal. It stinks to be them. I know that for sure.

I hope they get it sorted out. It will take a while. It will also take a while for the affected medical professionals and their IT providers to start responding to these breach reports rationally. Kubler-Ross's stages of grieving are still in play for them: anger, denial, negotiation, etc.

Re: A billion medical images are exposed online

#40

Clickbait-y headline that they forget to mention hospitals as well. Yes doctors should be more responsive and responsible. But they're (only) doctors. Hospitals on the other have have staff dedicated to technology and such infrastructure. Dr X being unaware of the implications is understandable. Perhaps not forgivable but certainly no surprise. But hospitals? They have no excuse.

I work in health, and I sometimes have to interact with the federal database of doctors. It's amazing the things you see in there. There are doctors who don't know their own addresses. Can't spell the name of their town. Don't know their ZIP Code. Don't know the difference between a mailing address and a physical address. Don't keep their information current. Or sometimes don't even know what town they're in, putting…

You're really blaming the subjects of a database for errors in that database? There are many reasons for errors that have nothing to do with anything a physician might or might not have done.
Post reply on HN