An odd line from the article, wherein it states that security researchers don’t blame vendors, but the physicians and hospitals that fail to properly secure the software. I have never, in all my years of working in healthcare, seen a hospital or physicians office directly install and manage PACS. They pay a third-party - usually the vendor - to install, configure, and walk them through it. Maybe a behemoth system lik…
Many doctors see themselves as too important to deal with security. They have an attitude of “I went to school for medicine, not computers! How dare you ask me to use a computer.” They are not only technologically inept, they are proud of it. And I’m not just talking about refusing to use complicated software. I’m talking about doctors that insist that they shouldn’t be forced to use passwords (not even complicated passwords; ANY passwords). And in most of the organizations I have dealt with, doctors are the most important people in the organization and have final say on anything, which often means that the security department’s efforts are all overridden by doctors that can’t be arsed to even type in a password before using their EMR, and don’t even dream of something more complicated like asking them to use multi-factor auth.
I once worked at a hospital where a doctor was looking at porn at work, clicked a phishing link, and gave up his network credentials. An attacker then used those credentials to breach the network and siphoned several hundred thousand dollars from the financial system (wiring money to himself). Security detected this and disabled his account. 20 minutes later the doctor had called the CEO, yelled at him (“how dare you lock me out of my account!”) who then called security to yell at us and insist we re-enable his account. The doctor was never reprimanded (for falling for phishing or for the porn) meanwhile the security team got a stern talking to and was instructed to never disable a doctor’s account again.
Healthcare is a different world for security. You have to acknowledge that yes, patient safety is more important than security, but oftentimes these doctors take it to an extreme and they are very difficult to work with. I have never met a group of people more elitist and “too important to be bothered” by security than doctors.