Live data from Hacker News

A billion medical images are exposed online

techcrunch.com

41–50 of 201 posts

Re: A billion medical images are exposed online

#42

Earlier quoted context omitted.

I’ve been the IT vendor in this scenario. While I’m sure there are plenty of inept vendors not doing their part to ensure the systems they implement are secure, a big part of it is doctors and their work culture. Many doctors see themselves as too important to deal with security. They have an attitude of “I went to school for medicine, not computers! How dare you ask me to use a computer.” They are not only technolog…

This seems like a caricature or an exception. Doctors are very aware of HIPAA (and the equivalent in every other country), and the professional and monetary costs of non-compliance. Doctors didn't set up these systems. Doctors didn't expose them to the internet. As the other post said, vendors did. If those vendors couldn't properly communicate the needs, that's their problem. What I think is a more rational explanat…

It may seem so, but I’ve done security consulting work for 10+ of the largest hospital chains and insurance providers in the country and I can assure you it isn’t an exception. Doctors don’t care about HIPAA (“that’s legal’s job”). They don’t care about the company’s finances (unless it’s a small private practice, “that’s the accountant’s job”).

Some of the complexity is caused by the software itself being complex, yes, but that’s not what I’m talking about. In every organization I have worked with, doctors were always the biggest obstacle to even doing something as simple as requiring them to carry around a badge for physical access to the building. As a group, they are very resistant to anything that might add an extra step to their workflow. And yes, everyone hates and is resistant to stuff being added to their workflow, but I find most people are amenable to it as long as it’s a small interruption and it’s for a good reason (security). Doctors generally don’t have that attitude, though.

Re: A billion medical images are exposed online

#43

An odd line from the article, wherein it states that security researchers don’t blame vendors, but the physicians and hospitals that fail to properly secure the software. I have never, in all my years of working in healthcare, seen a hospital or physicians office directly install and manage PACS. They pay a third-party - usually the vendor - to install, configure, and walk them through it. Maybe a behemoth system lik…

A brand new account posting scathing anti-government anti-regulation content? HIPAA and HITECH and the other legislation that you're likely referring to pushed a stagnant industry in the right direction. Yes there is pain with growth but patients are far better off for it, which is what the end goal was.

Re: A billion medical images are exposed online

#44
post #3

The key takeaway from that article, for me, is that the government body that is supposed to monitor, enforce, and penalize organizations who fail to follow the HIPAA rules is basically doing nothing. So with no consequence to these massive lapses, why would these companies care?

Office for Civil Rights (OCR) https://www.hhs.gov/ocr/index.html

Re: A billion medical images are exposed online

#45

An odd line from the article, wherein it states that security researchers don’t blame vendors, but the physicians and hospitals that fail to properly secure the software. I have never, in all my years of working in healthcare, seen a hospital or physicians office directly install and manage PACS. They pay a third-party - usually the vendor - to install, configure, and walk them through it. Maybe a behemoth system lik…

A brand new account posting scathing anti-government anti-regulation content? HIPAA and HITECH and the other legislation that you're likely referring to pushed a stagnant industry in the right direction. Yes there is pain with growth but patients are far better off for it, which is what the end goal was.

At my annual physical, as my doctor was typing away at data entry on a laptop in the exam room, I asked him whether he felt the new electronic systems had freed up his time to spend more time on patients, or whether they had taken time away from patients. He felt the later.

I realize that anecdote is not data, and I'm not sure what metric of 'better' you're using, but I wouldn't be too hasty to claim technology as an unalloyed good in health care.

Re: A billion medical images are exposed online

#46

Clickbait-y headline that they forget to mention hospitals as well. Yes doctors should be more responsive and responsible. But they're (only) doctors. Hospitals on the other have have staff dedicated to technology and such infrastructure. Dr X being unaware of the implications is understandable. Perhaps not forgivable but certainly no surprise. But hospitals? They have no excuse.

I work in health, and I sometimes have to interact with the federal database of doctors. It's amazing the things you see in there. There are doctors who don't know their own addresses. Can't spell the name of their town. Don't know their ZIP Code. Don't know the difference between a mailing address and a physical address. Don't keep their information current. Or sometimes don't even know what town they're in, putting…

Not smart at computers, but maybe they are smart about computers. Everyone thinks old people can’t use tech but what if they don’t want to and that resistance is a manifestation of wisdom that’s incomprehensible to those without the same wisdom. To believe doctors as a class of people are less intelligent than average is silly and probably ego defensive. As a group doctors are of above average intelligence and certainly smarter than most of the people they work with in IT.

I think it’s the academic and professional institutions that are most culpable for the current state of things. They should have been the ones who foisted tech requirements on doctors, instead it was done through federal regulation. Most of the blame for most of today’s problems comes back to universities. If using tech is part of the job if being a doctor, then make it so from inside the profession.

Re: A billion medical images are exposed online

#47

An odd line from the article, wherein it states that security researchers don’t blame vendors, but the physicians and hospitals that fail to properly secure the software. I have never, in all my years of working in healthcare, seen a hospital or physicians office directly install and manage PACS. They pay a third-party - usually the vendor - to install, configure, and walk them through it. Maybe a behemoth system lik…

I’ve been the IT vendor in this scenario. While I’m sure there are plenty of inept vendors not doing their part to ensure the systems they implement are secure, a big part of it is doctors and their work culture. Many doctors see themselves as too important to deal with security. They have an attitude of “I went to school for medicine, not computers! How dare you ask me to use a computer.” They are not only technolog…

>doctors that insist that they shouldn’t be forced to use passwords (not even complicated passwords; ANY passwords).

well, it is a clear voice of customer. And it has good reason behind it - time and effort that the customer would like to avoid wasting. Instead of disparaging the customers and their needs how about listening to it and trying to really solve the issues. May be doctors for example would be more happy with having RFID microchip injected under the skin than typing password in? The security industry should start solving the issues for the benefit of users instead of pushing the crap down everybody throats under the disguise of holy cow of "Security!".

>clicked a phishing link, and gave up his network credentials.

and you still continue to think that password based solutions are suitable there?

>I have never met a group of people more elitist and “too important to be bothered”

than security IT. Your post is a prrety good example of it.

Re: A billion medical images are exposed online

#48
post #3

The key takeaway from that article, for me, is that the government body that is supposed to monitor, enforce, and penalize organizations who fail to follow the HIPAA rules is basically doing nothing. So with no consequence to these massive lapses, why would these companies care?

https://compliancy-group.com/hipaa-fines-directory-year/

My honest opinion is that they know healthcare specifically is so far behind meeting their regulator requirements they have been trying to slowly phase in penalties.

Re: A billion medical images are exposed online

#49
post #47

Earlier quoted context omitted.

I’ve been the IT vendor in this scenario. While I’m sure there are plenty of inept vendors not doing their part to ensure the systems they implement are secure, a big part of it is doctors and their work culture. Many doctors see themselves as too important to deal with security. They have an attitude of “I went to school for medicine, not computers! How dare you ask me to use a computer.” They are not only technolog…

>doctors that insist that they shouldn’t be forced to use passwords (not even complicated passwords; ANY passwords). well, it is a clear voice of customer. And it has good reason behind it - time and effort that the customer would like to avoid wasting. Instead of disparaging the customers and their needs how about listening to it and trying to really solve the issues. May be doctors for example would be more happy w…

In another company, we tried rolling out RFID badges that could be scanned at any workstation to log doctors in rather than passwords. This proved to be too inconvenient for doctors as well, and the system had to be rolled back within a month because doctors kept forgetting to keep their badge with them and would then throw a hissy fit because they wanted to go back to the old system where all workstations were permanently unlocked.

Security IT is, in my experience, one of the most amenable in terms of trying to come up with new ways to serve customers because the customers require it (all customers require it, not just doctors), but doctors are on an entirely different level when it comes to resistance to change.

Re: A billion medical images are exposed online

#50
post #47

Earlier quoted context omitted.

I’ve been the IT vendor in this scenario. While I’m sure there are plenty of inept vendors not doing their part to ensure the systems they implement are secure, a big part of it is doctors and their work culture. Many doctors see themselves as too important to deal with security. They have an attitude of “I went to school for medicine, not computers! How dare you ask me to use a computer.” They are not only technolog…

>doctors that insist that they shouldn’t be forced to use passwords (not even complicated passwords; ANY passwords). well, it is a clear voice of customer. And it has good reason behind it - time and effort that the customer would like to avoid wasting. Instead of disparaging the customers and their needs how about listening to it and trying to really solve the issues. May be doctors for example would be more happy w…

Doctors are not customers, patients with their expectation of privacy are. This is similar to doctors resisting keeping checklists [1] of what goes in and out of patients during operations.

Doctors are service providers and the service is lacking.

[1] https://hbr.org/2019/05/how-one-health-system-overcame-resis...

Post reply on HN